msn virus dos

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shell38, Sep 26, 2007.

  1. shell38

    shell38 Private E-2

    Hi
    tonight i came bk to my msn and a friend who i certainly trust sent me (well i thought had sent me a zip file) i downloaded it and now everytime i go onto msn it sends the same message to everyone. it ask things like look at this funny pic i thought of u etc. some of my friends including my daughter have downloaded it as they trust things from me. so please can anyone please help me get rid of this i have deleted the file, ran agv and ad ware prog but it not showing on any.

    any help wld be most grateful as i can not sign in well i can but it just sends it out to everyone on my list everytime

    thanx shell
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. shell38

    shell38 Private E-2

    Hi sorry it been few days since i have got bk to u only i have been away.

    please find enclosed all the information that you require:
    Counterspy run= no virus found only normal cookies

    Bitdefender = enclosed log
    Panda = Enclsoed log
    Runkeys = enclosed log

    will post following on another message

    Show new
    hijack this.

    thanx shell
     

    Attached Files:

  4. shell38

    shell38 Private E-2

    enclosed further 2 logs

    with thanx
    shell
     

    Attached Files:

  5. shell38

    shell38 Private E-2

    Wld also like to add that one of my friends who also got this said she did a system restore and it seem to work for her, but i am just bit wary of just doing that incase there are any underline things lurking bout still, but do u think this wld b a good idea.

    thanx
    shell
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not seeing any obvious malware reasons for messages (spam) being sent from your PC. Let's cleanup a few miscellaneous things and also run a scan for rootkits. If we do not find anything, you may want to try a System Restore like your friend did. It is possible that something was setup in your registry that runs when MSN is loaded.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Java(TM) SE Runtime Environment 6 Update 1
    Sunbelt CounterSpy <-- we are finished with this trial program now

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Delete the below file
    C:\3F7.tmp

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O1 - Hosts: 74.208.68.100 www.winmx.com
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.



    Now attach the below new logs and tell me how the above steps went.

    1. BlackLight log
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. shell38

    shell38 Private E-2

    Hi

    Thanx for the help, well i did all u ask except for disable windows messenger, the reason for this is that i do use this in times like i have had recently so bit reluctant to get rid of it.

    The second bit is i tried to download the bk light i saved it to the desk top but wen double click it to open it says that it has expired and to go to the home page wen i clicked on that i was not sure if it was the same thing, so thought better check what to do.

    Also i did a avg scan it did not pick up nothing but 1st oct it did several scans on its own and picked up back door trojan i looked in the vault and they were in there but it says they are not healable. but if they are in the vault does that mean its safe.

    my son today tried msn (he forgot i told him not to) and it worked, so i thought well either its only to my email address its doing it or its cured. so i decided to give it ago and it worked an it did not send out any of them zip files to anyone!!

    what do u want me to do bout the back light is there another link or shall i just post the other logs u asked for.

    many thanx
    shell
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you are using Windows Messenger? Read my instructions again. Don't confuse Windows Messenger with MSN Messenger. Almost no one uses Windows Messenger.

    Yes it means it removed them from the normal location on your PC and locked them in its vault.

    If there are no spam mails being sent anymore, I don't need a log from BlackLight but you should complete my other steps.
     
  9. shell38

    shell38 Private E-2

    Hi Sorry taken few days get bk but been very busy.

    right bout this messenger. I normally use windows live 8.1 version. but this was where they were sending out the bogus files to everyone on my list. for a few days i did not use it and tried to use it again and it was still doing the same. While reading through some threads on this site, i saw that someone else had simular probs, and u told them to delete Windows messenger (yes i no they are different) now i do not normally use this but i hit upon an idea to try to sign in windows messenger instead of windows live. and wen i did it worked. That was the reason that i said i was reluctant to uninstall windows messenger (the one tha comes with xp) as if i get another problem with Windows live (msn) i no i can use this.

    right i am now enclosing runkeys and getnew and hjt logs.

    Thanx for all your help

    Best wishes
    Shell
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need Windows Messenger. You already have MSN Messenger and Windows Live Messenger. Windows Messenger is a frequent cause of popups.

    You're logs are clean but you can delete the below left over from CounterSpy:
    C:\Documents and Settings\Shell\Application Data\Sunbelt Software

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds