blonde poker forum

Community Forums => The Lounge => Topic started by: Ginger on March 25, 2008, 10:53:02 PM



Title: MSN VIRUS
Post by: Ginger on March 25, 2008, 10:53:02 PM
There is a virus rushing through msn in JPG form now, don't click any links to pics!!!

so far all I have found on it is this link (safe to click lol) http://www.bleepingcomputer.com/forums/topic137142.html

Off to fix Kev's PC....


Title: Re: MSN VIRUS
Post by: action man on March 25, 2008, 11:09:16 PM
lol how do i see if i have a virus and how do i fix it plz?


Title: Re: MSN VIRUS
Post by: Ginger on March 25, 2008, 11:14:08 PM
we've run a scan and so far it's coming back with some nasty stuff.

Rick, just run whatever virus software you have, or go to symantec and run one of their online ones.

So far I've not got round to finding removal info as we're still scanning and warning a few people not to click!


Title: Re: MSN VIRUS
Post by: mondatoo on March 25, 2008, 11:15:39 PM
Whichever virus protection you have run scan and it will check your whole computer for viruses and then warn u of the 1s which are harmful to your comp normally takes bout 45mins - 1hr to run


Title: Re: MSN VIRUS
Post by: technolog on March 26, 2008, 12:42:16 AM
LOL toolateaments

Get a IM from a certain Colchester Pompey Kev saying 'is this really you?' with a link to (what looked like a photo). I panic thinking he's stumbled on the picture of me, the German Shepherd and the lard-covered dwarf and before I can stop myself I've clicked the link - immediate sinking feeling!

Keep getting a command prompt window titled lux.exe appear and I'm sure it's doing naughty things (although not perhaps on the Alsation/midget scale - obv imo fk my life)


Title: Re: MSN VIRUS
Post by: Shogun112 on March 26, 2008, 12:57:08 AM
Yes Jack, you MSN also sent it to your other contacts...  Me included and The Duke...  Me...  I never opened the file...  The Duke did...  Then it sent to all his contacts...  He has removed MSN and installed it again...


Title: Re: MSN VIRUS
Post by: Laxie on March 26, 2008, 09:28:01 AM
I got it from Kev and Duke, but didn't open it either time, so hopefully ok.  Whatever it was, it sure did spread fast.


Title: Re: MSN VIRUS
Post by: kinboshi on March 26, 2008, 09:43:03 AM
Lucky I have no friends.


Title: Re: MSN VIRUS
Post by: technolog on March 26, 2008, 01:12:39 PM
I ran a virus scan overnight (AVG Free obv) and it found nothing. Does anyone know how to get rid of it? Surely, just uninstalling and re-installing MSN won't rid me of the virus, will it? Though granted, it may stop it spitting nasty messages out to my (ex) mates.


Title: Re: MSN VIRUS
Post by: scotty2hatty on March 26, 2008, 01:18:04 PM
A friend of mine has had this for a few weeks now - god knows why he doesn't remove it.  Some of the messages it sends are ridic and it's fairly obv it's a virus imo. 


Title: Re: MSN VIRUS
Post by: Ginger on March 26, 2008, 03:05:57 PM
I ran a virus scan overnight (AVG Free obv) and it found nothing. Does anyone know how to get rid of it? Surely, just uninstalling and re-installing MSN won't rid me of the virus, will it? Though granted, it may stop it spitting nasty messages out to my (ex) mates.

You're correct - uninstalling MSN won't fix the problem.

AVG found a few virus/trojan's/keylogger's on Kev's pc overnight, spybot's Search and Destroy found handfuls of other things too.

I'm now running a scan with Dr.Web (I'd never heard of this one before) and it seems to have picked up about 6 or 7 other nasty bits and pieces that the others missed. After all this is finished I'll go back and do another online scan and see if it's all gone - I'm not holding my breath.


Title: Re: MSN VIRUS
Post by: The_duke on March 26, 2008, 06:04:38 PM
Yep I clicked the fecking thing -- I am soooooo silly

Anyway  it creates %windir%\msn.com file, which it marks as an system file and hides. After that it creates registry key under HKEY_LOCAL_MACHINE\ Software\ Microsoft\ Windows\ CurrentVersion\ Run    to autorun itself. This key is given name "Microsoft live messenger" and value "msn.com" . When this key is removed via regedit and computer restarted the virus file itself can be removed by going to WINDOWS in C:. Click view, go to folder options tab, click "show hidden files and folders" and click apply. Scroll to the bottom of that "Windows" page, and then work your way up looking for "msn.com" saved as a MS-DOS Application.


http://nz.answers.yahoo.com/question/index?qid=20080325093135AAfgwsy


Title: Re: MSN VIRUS
Post by: action man on March 26, 2008, 07:46:10 PM
I ran a virus scan overnight (AVG Free obv) and it found nothing. Does anyone know how to get rid of it? Surely, just uninstalling and re-installing MSN won't rid me of the virus, will it? Though granted, it may stop it spitting nasty messages out to my (ex) mates.

You're correct - uninstalling MSN won't fix the problem.

AVG found a few virus/trojan's/keylogger's on Kev's pc overnight, spybot's Search and Destroy found handfuls of other things too.

I'm now running a scan with Dr.Web (I'd never heard of this one before) and it seems to have picked up about 6 or 7 other nasty bits and pieces that the others missed. After all this is finished I'll go back and do another online scan and see if it's all gone - I'm not holding my breath.


thats not the virus thats kevs porno!  he has used the virus to cover up his collection LDO


Title: Re: MSN VIRUS
Post by: Nem on March 27, 2008, 06:51:03 AM
jotti's virus scan, panda active scan...


Title: Re: MSN VIRUS
Post by: Ginger on March 27, 2008, 10:21:04 AM
Thanks Nem, I'll try those too, might as well - I've chucked everything else at it lol.

I've removed the actual "msn.com" one but it seemed to be riddled with others within minutes. I know it was a clean machine a week or two ago as I look after all of the pc's in the house myself, but in the last 24 hours I must have cleaned it of at least 20 trojans. I'm still fighting with getting the last 2 off.



Edit: make that 3... sigh!


Title: Re: MSN VIRUS
Post by: Bongo on April 07, 2008, 02:59:19 PM
Sounds remarkably like this:

http://www.theregister.co.uk/2008/04/07/kraken_botnet_menace/

Which is very poorly detected by AV products...