MSN Worm spreading German virus (mufa.exe)

Discussion in 'Malware Help (A Specialist Will Reply)' started by jazzking, Oct 14, 2008.

  1. jazzking

    jazzking Private E-2

    Hi there,

    I stupidly downloaded and ran an unchecked exe file yesterday (I thought my on-board Symantec AV would pick it up) and now my MSN messenger is sending out messages in german asking them to click a link to another exe file.

    I've run a full check with Symantec AV, and run Spybot S&D and Spywareblaster before I found this site.

    I've now followed the instructions here and I attach the logs produced by the four programmes suggested. Nothing appears to have been detected but maybe one of the experts here would be able to help...

    For info - the text that comes up is described here http://www.msghelp.net/printthread.php?tid=86541 but that thread seems to describe the problem that occurs when you click the link to mufa.exe rather than how to remove the worm that is sending out the messages.

    I've changed my hotmail password today and am currently not running Messenger but unless someone tells me that I've sent them a dodgy link I'm not going to know whether I've fixed the problem or not!
     

    Attached Files:

  2. jazzking

    jazzking Private E-2

    Re: MSN Worm spreading German virus

    and here's the MGLogs attachment....

    Thanks in advance!
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    HI could you please attach the last log needed when you get a chance?

    • MGlogs.zip

    Cheers
    Kes
     
  4. jazzking

    jazzking Private E-2

    Oops - sorry!

    Here you go - thanks :)

    I've uninstalled, restarted, installed and logged back into MSN and nobody has contacted me to say they've got a message from me but you never know...
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks :)

    Your logs are being looked at, please be patient whilst we decipher them and work up a fix for your machine

    Kes
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi jazzking

    I'm not seeing any signs of malware in your logs other than one infected file picked up by MWB's. There are a couple of non malware related things to do though.

    1) Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT

    2) Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    3) Go to add and Remove Programs and uninstall the following:
    • J2SE Runtime Environment 5.0 Update 2
    • Reboot your machine

    4) Now run Ccleaner!

    5) Download and install the latest version of Java

    Java 6

    So...

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds