MSN Messenger Obscure Malaware1

Discussion in 'Malware Help (A Specialist Will Reply)' started by jobella, Oct 29, 2006.

  1. jobella

    jobella Private E-2

    Hello,

    Norman Support suggested I write to you for help as I seem to have a very rare, obscure malaware attached to my MSN Messenger Live (and before that Messenger 7.5). They only realized this after I did a NFI.
    Each time I was signed in on my computer (I could be off line or not) my MSN Messenger decided to send dialogue boxes to various contacts (signed in or not). I would see these message boxes leaving my computer but it only lasted a split-second. Usually it would be multiple dialogue boxes that would open and close in almost unison. These Dialogue boxes were not empty: friends and family informed me that in the conversation windows the following appeared "jobanna says (time) EH POR TUDO O QUE PASSAMOS JUNTOS KKKKKK, with a sad emoticon after the text.
    I had this problem on both my hotmail adresses: jobella1@hotmail.com, joannamenda69@hotmail.com
    None of my friends getting these dialogue boxes seem to be infected...
    This problem appeared when I moved to Paris and started using my boyfriends wireless connection. I also had a little problem with my hotmail. I was getting emails and sometimes the little envelope icon (on the left hand) was not appearing. This only happened twice.
    My computer is also slower than usual.
    I have followed your instructions on this page. But I don't know what to do and am terrified to download Messenger LIVE once again.
    I can't seem to be able to remove MY WEB SEARCH (which you list as problematic)
    I have uploaded PandaActive Scan, Get Run Key, Show New.
    I will upload the rest on a second thread (Hope this is correct????
    - Messenger version: LIVE MESSENGER 8.0.0812.00
    - Operating System: Microsoft Windows XP Professional Version 2002 Service Pack 2 (5.1.2600)
    - Browser type: Internet Explorer, version 6.0.2900.2180.xpsp_gdr.060220-1746IS
    - Connection Type: Wireless Network Connection, Intel(R)Pro/Wireless LAN
    - I use One Live Care, Norman Anti-virus, XP firewall, Google toolbar, and Registry Mechanic and Ad-Aware.

    HOPE YOU CAN HELP ME
     

    Attached Files:

  2. jobella

    jobella Private E-2

    MSN Messenger Obscure Malaware Part 2

    Hello,
    Please find attached the 2 other attachments you request:

    -Bitdefender
    -Hijack this
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: MSN Messenger Obscure Malaware Part 2

    Welcome to Majorgeeks!

    First a couple of quick comments! You are violating step 3 of the READ & RUN ME. You have both Norman and Microsoft Windows OneCare Live installed! You must decide which you want to use and uninstall the other. Also if the Norman package you are using has a firewall, you also have two firewalls running which is not acceptable. I also see a folder named Securitoo. Which is another antivirus and firewall application. Do you also have this installed?

    I find it rather interesting that a company in the software security business (Norman) is referring you to us for help. If you paid for their software, why aren't they helping you fix a problem that they should be detecting and fixing. Did you ask them why they are not finding the root problem and why they are not fixing it?

    PandaActiveScan indicated the it fixed the Nabload.ML infection in your operating system. Are you still actually having problems? Run a new PandaActiveScan and see if it finds the infection again or if it comes up clean.

    You need to uninstall the below:
    J2SE Runtime Environment 5.0 Update 6 <--- old version and you have the new version already
    My Web Search (Outlook, Outlook Express, and IncrediMail) <--- step 0 of the READ ME requested that you uninstall this
    Viewpoint Media Player <--- step 0 of the READ ME requested that you uninstall this

    Apparently you did not allow Ccleaner to cleanup your Temp folders or you did not run it at all.
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\joanna\Local Settings\Temp
     
    Last edited: Nov 1, 2006
  4. jobella

    jobella Private E-2

    Thanks for the quick reply!!!

    I am terribly sorry if I violated step 3!! I have been bombarded by a minimum of 20 various emails from hotmail to fix this problem and one of their solutions was to contact my antivirus and download my One Live. I understand that I need to unninstal one of them but seeing that I am paying a Norman subscription and that they have not been much help with this I am not sure which one to zap (One Live is also a 90 day trial)

    You mentioned Securitoo but I have no idea what it is or how it got there... Should I remove it?? Could you tell me where to find it???

    I completely agree with you that the service at Norman is not great but as hotmail was of no help what's so ever I thought this was the service people got... AND I was soooo happy to have at least the same technician on the line (hotmail has a very bad system where you never get the same person twice helping you). At first he didn't even want to acknowledge I had a problem. He then said it was VERY rare, that nothing was written about it, told me to contact you, and asked that all my friend send him a Norman scan...

    Is Nabload. ML the name of my infection??? I will run a new PandaActiveScan ASAP. Will I be able to see if the infection is still there???

    I have uninstalled J2SE and Viewpoint Media Player. But as previously mentioned in my other email I cannot seem to remove MY Web Search. When I click remove a blank screen appears... Any suggestions???

    I did run Ccleaner in the safe mode so I don't understand why my Temp folders are still full.
    I have found my C: WIndows/Temp files but cant seem to find a "Local Settings" in my Joanna Folder????

    I can't thank you enough for this... I am currently in a foreign country where I know nobody who can help me with my computer and it is the only way for me to communicate with the outside world ;)

    I will do another Ccleaner and PandaScan and I will download MSN Live. Looking forward to reading your suggestions about My Web Search and One Live vs. Norman

    Merci
     
  5. jobella

    jobella Private E-2

    Hi
    I reinstalled MSN Live and it seems to be running ok...
    I ran another PandaScan and it found again that Nabload Virus. Is it normal that after each scan it says it disinfected it and it comes back???
    Have attached the latest PadaScan
    Cheers
    PS. Can I remove all the Zip files I downloaded and all the old log files???
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I saw a folder for it here: C:\Program Files\Securitoo but it may no longer be installed. It does not appear in your Uninstall List shown in the newfiles.txt log. What is in this folder?


    Well other forms of Nabload have been associated with problems related to Messenger so I would think it probably is your problem or at least part of your problem.

    Try using the following to uninstall it: Your Uninstaller! 2006


    Then you are not looking in the right place because it showed in your newfiles.txt log. The full path is:

    C:\Documents and Settings\joanna\Local Settings\Temp

    If you run a new scan with ShowNew and look in the newfiles.txt log you will more than likely see this folder listed right after C:\WINDOWS\Temp


    Well since neither Microsoft Windows OneCare Live nor Norman seem to be helping anyway, it is rather a moot point. I don't know if another antivirus program would find it and remove it or not. But either way, you don't need both programs fighting each other and they are not helping you! So if you don't plan on buying One Care after the trial period, uninstall it now.

    Panda found the same infection but this time it was a file that it cleaned. Last time it your OS was infected. Locate this file C:\WINDOWS\temqr1z.tmp and delete it!

    Then reboot and run another Panda scan and attach a new log from it and also a new log from ShowNew.

    Now please run the below procedure and attach the requested log:

    Using Sophos Anti-Rootkit
     
  7. jobella

    jobella Private E-2

    Hi,
    Thanks for your help!
    I've removed the software thanks to Your Uninstaller! and removed Microsoft One Live.
    I did Sophos search however I got the following message "Failed to flush drive c:.". Also it wouldn't allow me to save the log "common dialogue error (0x3002).
    Please find attached the other 2 logs you requested... Panda found 14 malaware and didn't disinfect them....
    FYI My computer is running much faster and I don't seem to be having the problem with my MSN....
     

    Attached Files:

  8. matt.chugg

    matt.chugg MajorGeek

    Chas is taking a much deserved vacation right now,

    What program did the log for sophos anti rootkit open with ? did you mean this is the program that gave the common dialog error ?

    Your activescan is fine. The files it found are just cookies and nothing to worry about.

    Please try and run Sophos Anti Rootkit again, the flushing c:\ is a common problem. Since you say everything is running fine now, I don't expect it to find much but we will check just to be on the safe side.
     
  9. jobella

    jobella Private E-2

    Hi Matt,
    Thanks for your quick reply :)
    I was able to save the Sophos log this time but I still had that message "The process cannot access the file because it is being used by another process". I also had 2 other exclamation points saying that it might be blocked by malaware + it found 2 hidden items:eek:
    Hope it's not too bad:rolleyes:
    Cheers again
    J
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see any problems in your log! Are you still having problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds