Shoutbox

Virus downloaded with Messenger Plus - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Messenger Plus! for Live Messenger (/forumdisplay.php?fid=4)
+---- Forum: WLM Plus! Bug Reports (/forumdisplay.php?fid=7)
+----- Thread: Virus downloaded with Messenger Plus (/showthread.php?tid=35175)

Virus downloaded with Messenger Plus by bartona on 12-03-2004 at 11:45 AM

I have just downloaded and installed Messenger PLus. Immediately after instalation, my antivirus software (Sophos) detected a virus in a file called knobcastrulecopy.exe which was installed into a directory called DRVMAGS. I don't know whether this is part of the sponsor section or not as I am new to MSG+. What I do know is that the date and time on the directory and file match perfectly with the files installed by MSG+.
Not a good start after having read the rumours pages.

At this stage I am not prepared to uninstall and reinstall as I don't know what else this is likely to kick off. I have locked the directories so that they cannot be accessed by anyone.



RE: Virus downloaded with Messenger Plus by Sunshine on 12-03-2004 at 11:55 AM

You can safely uninstall the sponsor by following the next steps:

1. uninstall plus! with sponsor (make sure you exit your internetbrowser fully, from taskbar and systray also)
2. if you used ad/spyware programs in between reinstall plus! again with sponsor as this could have crippled the uninstaller (if not go to step 4)
3. uninstall plus! again right away as said in point 1
4. reboot
5. reinstall plus! and select NO on the sponsoragreement (if you like to continue using plus!, plus! will install without the sponsor aswell)

This should totally remove the sponsor (toolbar etc etc).

For more detailed info have a look at uninstalling the Messenger Plus! Sponsor Program

Asfor knobcastrulecopy.exe: i don't know wether this is part of the sponsor. Only Patchou can answer this one.


RE: Virus downloaded with Messenger Plus by CookieRevised on 12-03-2004 at 02:21 PM

quote:
Originally posted by bartona
my antivirus software (Sophos) detected a virus in a file called knobcastrulecopy.exe which was installed into a directory called DRVMAGS
Could you take a screenshot of the warning you get with your anti-virus and post it here?
RE: Virus downloaded with Messenger Plus by bartona on 12-03-2004 at 03:25 PM

Sorry, for some reason I cannot paste into here so I have added it as an attachment


RE: Virus downloaded with Messenger Plus by riahc4 on 12-03-2004 at 10:26 PM

quote:
Originally posted by bartona
Sorry, for some reason I cannot paste into here so I have added it as an attachment

No this has nothing at all to do with Plus! Must have been something else....
RE: Virus downloaded with Messenger Plus by GameGuy on 12-03-2004 at 11:16 PM

Nope. No way it's msgplus!.

Looks like a game or something!


RE: Virus downloaded with Messenger Plus by CookieRevised on 12-03-2004 at 11:24 PM

quote:
Originally posted by bartona
Sorry, for some reason I cannot paste into here so I have added it as an attachment
no problem, that's what I meant ;)

anyways...

Yes some virusscanners do detect some file from the sponsor as being the virus Swizzor. However the sponsor does not contain any virus at all. This is a false warning. It is nothing to worry about, but if you do worry, then follow the instructions given by Sunshine to uninstall the sponsor, but do not use the virusscanner to remove it. Thus make sure you first disabled the virusscanner as it might interfear (and damage) the proper uninstall process.

Also see: "Note about Trojan detection"


So, to get rid of the sponsor:

1) close virusscanner, close any other anti-adware/spyware monitoring program
2) reinstall Plus! with the sponsor (to fix the uninstallers)
3) right after, uninstall Plus! from add/remove programs. And follow the given instructions (like closing every browser window and then rebooting the system)
4) after rebooting, you can turn on the virusscanners and anti-adware/spyware tools again.
5) If you wish, you can now install Plus! again, but make sure you don't accept the sponsor when you install Messenger Plus! (or the virusscanner will give you a warning again)

Also see: "How to uninstall ad-ware/sponsor"