What happened to the Messenger Plus! forums on msghelp.net?
Shoutbox » MsgHelp Archive » Skype & Technology » Skype & Live Messenger » Spreading Virus

Pages: (4): « First « 1 2 [ 3 ] 4 » Last »
Spreading Virus
Author: Message:
lavey92
Junior Member
**


Posts: 16
Joined: Jun 2010
O.P. RE: Spreading Virus
Well that was unsuccessfull! Still sending out links.......

Here is a screenshot of my processes:

[Image: V07AvkMM.jpeg]

Also you mentioned deleting that file, I cannot locate it anywhere. Could you perhaps make a guess as to where it could be located?
Thanks!

EDIT: Will perhaps deleting and reinstalling windows live messenger help with the problem?

This post was edited on 07-01-2010 at 11:55 AM by lavey92.
07-01-2010 11:49 AM
Profile E-Mail PM Find Quote Report
Chris4
Elite Member
*****

Avatar

Posts: 4461
Reputation: 84
33 / Male / Flag
Joined: Dec 2004
RE: Spreading Virus
quote:
Originally posted by lavey92
EDIT: Will perhaps deleting and reinstalling windows live messenger help with the problem?
Sure, worth a try. Thought there might be a chance the virus was inside Messenger's program files, or modified an existing program file, but probably unlikely.

I can't really see anything out of the ordinary, possibly apart from taskeng.exe which is the Task Scheduler. It may be worth going to Start > typing Task Scheduler > enter. See if there's any suspicious tasks.

Process Explorer can be used as an advanced Task Manager, which may help.

Also try my suggestion before of Anti-Malware.

This post was edited on 07-02-2010 at 03:53 AM by Chris4.
Twitter: @ChrisLozeau
07-01-2010 03:48 PM
Profile PM Find Quote Report
Spunky
Former Super Mod
*****

Avatar

Posts: 3658
Reputation: 61
36 / Male / Flag
Joined: Aug 2006
RE: Spreading Virus
The 1st rundll32.exe seems a bit suspect. No description or path like the other one has... It's also not something that should just be running in the background.
<Eljay> "Problems encountered: shit blew up" :zippy:
07-01-2010 10:02 PM
Profile PM Find Quote Report
CookieRevised
Elite Member
*****

Avatar

Posts: 15517
Reputation: 173
– / Male / Flag
Joined: Jul 2003
Status: Away
RE: Spreading Virus
quote:
Originally posted by lavey92
Here is a screenshot of my processes:
[Image: V07AvkMM.jpeg]

You're not showing all processes. Click on "Show processes for all users"

quote:
Originally posted by lavey92
Also you mentioned deleting that file, I cannot locate it anywhere. Could you perhaps make a guess as to where it could be located?
Search for it using Windows Search...

Note on using search for stuff like this: make absolutely sure you are searching "all files" and including "system and hidden" files. These settings are _not_ enabled by default. So make sure they are enabled first.

quote:
Originally posted by lavey92
EDIT: Will perhaps deleting and reinstalling windows live messenger help with the problem?
No, it wont help at all.

The malware and WLM are two different programs/processes. The malware probably doesn't care what Messenger is installed either. And by uninstalling WLM you don't uninstall or remove the malware; you wouldn't even touch it. So:

1) You would still be infected if you uninstall WLM. Eventhough the malware might (note: 'might' - because it could be using other ways to send links) stop sending links to your contacts.

Note: since your are infected with this malware on your computer, it might be possible that this malware now also knows your login and password, and even has sent it to some unknown 'hacker'. And because you are infected, it is dead easy for the malware to detect if you have changed your password; it would simply take your latest used login and password you use for signin into Messenger....

2) As soon as you install WLM again, everything will be back like it was before...  aka: malware sending links.



This post was edited on 07-03-2010 at 05:39 AM by CookieRevised.
.-= A 'frrrrrrrituurrr' for Wacky =-.
07-02-2010 01:59 AM
Profile PM Find Quote Report
Gooner Mark
New Member
*


Posts: 1
Joined: Jul 2010
RE: Spreading Virus
Hi, I googled the virus and found this forum so thought it best to join. I'm also having the same problem with the image-bucket issue and I'm really concerned by it - the concept of some hacker having my password(s). I'm not ususally stupid when it comes to these links but I had a dumb moment.

Today, I even passed it onto another contact because while talking to a mate on msn, obviously, I sent him a youtube link and said something like "check out this song" so he assumed the link was safe but the image-bucket link actually fucking took over my youtube link and put its own in! The weird thing was, it still showed up as the normal link on my computer so it took us a minute to realise the problem.

The other thing I noticed is that it only happened with the first link I sent, after that, when I tried to send the link again, it worked fine (When I tried sending it again, I didn't know the previous one had been the ib link). I don't mean to waste your time but I just felt the need to put that story out there as it's probably something msn needs to take care of.

Basically I just joined up in the hope that someone has/will soon work out how to fix it. Sending annoying links to friends on msn is bad enough as it is but the thought of my whole online set-up now being at risk is really concerning me. From what you guys know, does this sound like a proper virus, or malware? Which do you reckon is more serious?

Hope someone can help me clear this up. Cheers.

Edit: I also scanned my machine with McAfee security scan and it found no threats to my computer but obviously something isn't write if links are being tampered with on msn and that sort of thing. Advice much welcomed and much needed. Thanks.

This post was edited on 07-02-2010 at 10:59 PM by Gooner Mark.
07-02-2010 10:57 PM
Profile E-Mail PM Find Quote Report
CookieRevised
Elite Member
*****

Avatar

Posts: 15517
Reputation: 173
– / Male / Flag
Joined: Jul 2003
Status: Away
RE: Spreading Virus
Follow all the advise given in this thread from the top.

quote:
Originally posted by Gooner Mark
as it's probably something msn needs to take care of.
MS can't do much about this sort of things other than blocking all outgoing image-bucket links (which many other people might not like). But this doesn't prevent malware from infecting you and doesn't prevent malware using other kind of free image services or url services.

Bottom line is to never download/install stuff you don't know, certainly not stuff you find on random sites or even stuff send my known people via email or IMs.

Configuring your browser correctly and understanding how things work might also help a great deal. eg: a properly configured browser shows you a "execute this file Y/N?" confirmation dialog prior to executing a so called "image". This should alarm you that something isn't right. If the file was truely an image, the image would simply show in your browser, without a "file will be executed" dialog.

This post was edited on 07-03-2010 at 05:47 AM by CookieRevised.
.-= A 'frrrrrrrituurrr' for Wacky =-.
07-03-2010 05:46 AM
Profile PM Find Quote Report
lavey92
Junior Member
**


Posts: 16
Joined: Jun 2010
O.P. RE: Spreading Virus
Hi There
Thanks for the replies, sorry I haven't been in touch I have been away for the weekend

Here are all of the processes from all users.

[Image: 6J41oa6C.jpeg]

[Image: 8pQmne.jpeg]

currently making a thorough search for that .log file
will update when it finishes!
07-04-2010 10:51 AM
Profile E-Mail PM Find Quote Report
Chris4
Elite Member
*****

Avatar

Posts: 4461
Reputation: 84
33 / Male / Flag
Joined: Dec 2004
RE: Spreading Virus
Images aren't working, lavey92. Please upload to a reliable image hosting website such as imgur or imageshack.

Edit: They're working now.

This post was edited on 07-06-2010 at 12:48 PM by Chris4.
Twitter: @ChrisLozeau
07-04-2010 11:45 AM
Profile PM Find Quote Report
lavey92
Junior Member
**


Posts: 16
Joined: Jun 2010
O.P. RE: Spreading Virus
sorry didnt realise you replied! Here it is!

http://img824.imageshack.us/i/taskman1.jpg/

http://img517.imageshack.us/i/taskman2.jpg/

I havent had much news from my friends via msn about this virus spreading, none of them have said they have recieved it since i got back from my weekend trip.
However, in the search the hvex.exe doesn't come up anymore but when i type in its full previous direction in appdata and roaming, and press enter, the .exe runs itself. So this means it is still there! haha damn thing.

Furthermore, I did thorough searches to find that .log file however no results were found!
Thanks
Dave
07-06-2010 12:37 PM
Profile E-Mail PM Find Quote Report
Chris4
Elite Member
*****

Avatar

Posts: 4461
Reputation: 84
33 / Male / Flag
Joined: Dec 2004
RE: Spreading Virus
The ThreatExpert report for hvex.exe can be found here:

http://www.threatexpert.com/report.aspx?md5=75049...a68cd607615ff12095

If you've unselected it from startup, checked for the log file and keep trying to use Unlocker and remove the exe, you should be fine for now.

Like I suggested before, Anti-Malware should remove this for you if you're unable to do it manually.
Twitter: @ChrisLozeau
07-06-2010 12:57 PM
Profile PM Find Quote Report
Pages: (4): « First « 1 2 [ 3 ] 4 » Last »
« Next Oldest Return to Top Next Newest »


Threaded Mode | Linear Mode
View a Printable Version
Send this Thread to a Friend
Subscribe | Add to Favorites
Rate This Thread:

Forum Jump:

Forum Rules:
You cannot post new threads
You cannot post replies
You cannot post attachments
You can edit your posts
HTML is Off
myCode is On
Smilies are On
[img] Code is On