Shoutbox

new virus? - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Skype & Live Messenger (/forumdisplay.php?fid=10)
+----- Thread: new virus? (/showthread.php?tid=49565)

new virus? by NiteMare on 08-26-2005 at 10:28 PM

ok, i don't have this virus but a friend does(in a hurry and can't report it), this is what the virus sent me:

hey, look at this:
              hxxp://vbulettin.com/msn.php?email=<Insert the resiprcents e-mail>

then she went offline

she hasn't removed it yet, anybody know how?


RE: new virus? by M73A on 08-26-2005 at 10:32 PM

seems like a virus... but i'm not an expert on anything like it, but i still think it looks like a virus :P

its bit hard to say how to remove it because can't tell what it is..


RE: new virus? by sn1p3r on 08-26-2005 at 10:38 PM

Yep it's definitely a virus, there's loads similar to that floating around MSN now causing many users computers to be infected. Your friend could try looking here for more help on the matter as i don't really have much knowlege of how to remove it, if not try doing a scan with a good virus scanner to see if it picks anything up.


RE: new virus? by Lou on 08-26-2005 at 10:43 PM

I had reported this on mess.be a month back tbh...they posted about it but never an anti-virus :S


RE: new virus? by Sunshine on 08-26-2005 at 10:57 PM

Let her do an online virusscan here ;)

The viruses going around most on MSNM are variants of Kelvir, there's a removal tool for that right here. Read the instructions given on how to use the tool.


RE: new virus? by Dane on 08-27-2005 at 12:05 AM

Submitted this virus to Symantec and McAfee.  Will update you when the results come back.  I am guessing it is W32.Kelvir, as Sunshine said.


RE: new virus? by Dane on 08-27-2005 at 05:52 AM

This is the virus outbreak of W32.IRCBot. Symantec has issued RapidRelease Virus Defintions for this thread, so users of Norton AntiVirus can download and apply them for immediate protection.

Information: W32.IRCBot

Rapid Release Virus Definitions: Download Here for Immediate Protection


RE: new virus? by DJeX on 08-27-2005 at 05:57 AM

Nice Work Dane (Y)

Btw, how would the virus infect you with this url "hxxp://vbulettin.com/msn.php?email=<Insert the resiprcents e-mail>" ? and exploit?


RE: new virus? by Dane on 08-27-2005 at 06:19 AM

quote:
Originally posted by DJeX
Nice Work Dane (Y)

Btw, how would the virus infect you with this url "hxxp://vbulettin.com/msn.php?email=<Insert the resiprcents e-mail>" ? and exploit?

Nope.  It generates a ".com" file in most cases (unless your email has a different extension like .co.uk) and most computers automatically run ".com" files. So there is little to no user interaction.  Good Question (y)!
RE: new virus? by Fergy on 08-27-2005 at 09:15 AM

How to remove the W32.IRCBot messenger virus
Based on info by Symantec Security Repsonse

Step 1: Killing the process

  • Press Ctrl + Alt + Del to bring up the windows task manager
  • Click on the processes tab (if you are using an older version of Windows, eg: Windows 98. Do not worry about this step
  • Scroll down to the process: winapii.exe, and click End Process (or End Task for older versions of windows
Step 2: Removing the files
  • Navigate to where Windows is installed on your hard drive (Usually C:\Windows)
  • Find and delete the folder named: Winapii
Step 3: Fixing the registry
  • Open your registry editor (Start > Run > regedit.exe) and navigate to "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
  • Delete the key named winapii
    (For a small tutorial on this, go to this site, because deleting the wrong keys could corrupt Windows).
Step 4: Finalising the removal
  • Clean out your recycle bin to totally remove the files from your HDD.
  • Do a complete system scan of your system to make sure that no other files have been infected

     
I liked the way cookie wrote the block checker removal instrucions, so i used it as a template.
RE: new virus? by dennis on 08-27-2005 at 10:48 PM

hmmm if i were you id get AVG its awsome it will check your comp for viruses everytime your comp boots up and it only takes a few seconds


RE: new virus? by ShawnZ on 08-27-2005 at 10:52 PM

quote:
Originally posted by Dane
This is the virus outbreak of W32.IRCBot. Symantec has issued RapidRelease Virus Defintions for this thread, so users of Norton AntiVirus can download and apply them for immediate protection.

Information: W32.IRCBot

Rapid Release Virus Definitions: Download Here for Immediate Protection

In case you forgot some people are smart enough to stay away from norton, so why not link to a scanner instead of useless defs? 



RE: new virus? by Sunshine on 08-27-2005 at 11:07 PM

The scanner i mentioned before in this thread oughta remove it. Another stand-alone utility (you can use this alongside your own Av program) that will remove this one is Avert Stinger ;)


RE: new virus? by Dane on 08-28-2005 at 01:21 AM

quote:
Originally posted by dennis
hmmm if i were you id get AVG its awsome it will check your comp for viruses everytime your comp boots up and it only takes a few seconds
AVG doesnt have a new definition yet to detect this virus.   I only submit viruses to Symantec and McAfee and then if they're Category 3 or higher I submit to others.