Shoutbox

My msn messenger infected - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Skype & Live Messenger (/forumdisplay.php?fid=10)
+----- Thread: My msn messenger infected (/showthread.php?tid=38307)

My msn messenger infected by sheep69or on 02-12-2005 at 12:02 PM

Help i'm infected with a virus it sent it self to all my contacts!.it shows a funny counter it was at 343 & when i came back on computer few hrs l8a it show that funny counter its at 21077 & it some how signed my messenger in & sent it self again plz help me get this off it..

i have Attached the file i got sent!

[edit by Chris: Attachment removed]


RE: My msn messenger infected by Tasha on 02-12-2005 at 12:04 PM

WARNING:

DO NOT DOWNLOAD THIS. IT IS A VIRUS. HE HAS ALREADY TRIED HIS TRICKS ON MESS.BE


RE: My msn messenger infected by user27089 on 02-12-2005 at 12:05 PM

Please don't attach virus'!!!

I'm afraid that there are many virus' going around msn messenger, all that you can do really is decline anything that is dodgy that comes through, this is usually small.exe's and .pif's... they're all dodgy...

If its the funny.exe then heres some information:

quote:
What is it?
funny.exe is a file associated with the w32.funner worm.

What does is do?
W32.Funner is a worm that spreads using Microsoft's Windows Messenger
instant message program and modifies the hosts file.

When W32.Funner is executed, it performs the following actions:

  1. Copies itself as:
         * %System%\IEXPLORE.EXE
         * %System%\EXPLORE.EXE
         * %Windir%\rundll32.exe
         * %System%\userinit32.exe
         * c:\funny.exe

           and executes the first three files listed.

           Notes:
         * The three files make sure that the other two are running
and will restart them if any are stopped.
         * These files require the MSVBVM60.DLL file, which is a
component of the Microsoft Visual Basic run-time environment.
         * %System% is a variable that refers to the System folder.
By default this is C:\Windows\System (Windows 95/98/Me),
C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows
XP).
         * %Windir% is a variable that refers to the Windows
installation folder. By default, this is C:\Windows or C:\Winnt.
  2. Creates a log file named %System%\bsfirst2.log.
  3. Adds the value:

     "Userinit"="userinit32.exe,"

     to the registry key:

     HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

     so that the userinit32.exe runs when you start Windows.

Instructions on removal can be found at the Norton antivirus website:
http://www.sarc.com/avcenter/venc/data/w32.funner.html


[edit]
quote:
Originally posted by TashaJ
WARNING:

DO NOT DOWNLOAD THIS. IT IS A VIRUS. HE HAS ALREADY TRIED HIS TRICKS ON MESS.BE


its not a trick, I think she's looking for help or somethings... its a she btw...
RE: My msn messenger infected by absorbation on 02-14-2005 at 11:10 AM

it's funny.exe + is extemly annoying 2 get rid of.

u should have an anti virus a free 1 is avg free.

If u hav a resue disk perfect restart ur pc in safe mode and floow the on screen instrustions.

If u dont disable sytem restore restart ur pc in safe mode then delte the virus and the registry entry.

I h8t this virus because it infects an important processor.