What happened to the Messenger Plus! forums on msghelp.net?
Shoutbox » MsgHelp Archive » Skype & Technology » Tech Talk » MSN Messenger Worm Removal

Pages: (2): « First « 1 [ 2 ] Last »
MSN Messenger Worm Removal
Author: Message:
vn2k5
New Member
*


Posts: 11
Joined: Mar 2005
O.P. RE: MSN Messenger Worm Removal
:| I AM doing all this in Safe Mode!! As I said if I open a .exe file (e.g. AntiVirus), that will just close automatically as the worm has commanded it to do! :@
03-18-2005 06:21 PM
Profile E-Mail PM Find Quote Report
user27089
Disabled Account


Posts: 6321
Joined: Nov 2003
Status: Away
RE: MSN Messenger Worm Removal
Hmm, I can't see why a worm would do this, have you considered formatting?
03-18-2005 06:25 PM
Profile PM Find Quote Report
vn2k5
New Member
*


Posts: 11
Joined: Mar 2005
O.P. RE: MSN Messenger Worm Removal
[/color][color=black][/color][color=yellow][/color][color=green][/color][color=purple][/color][color=beige][color=brown][/color][color=teal]It is part of the worm!

3. Configures itself to run each time an .exe file runs, by changing the default value of the registry key:

HKEY_LOCAL_MACHINE\Software\Classes\exefile\shell\open\command
to:
C:\%System%\Nav32_loader.exe"%1 %*



5. Attempts to end the antivirus and firewall processes. The worm inventories the active processes, and if the name of the process contains one of the following, it attempts to end the process:

This post was edited on 03-18-2005 at 06:30 PM by vn2k5.
03-18-2005 06:29 PM
Profile E-Mail PM Find Quote Report
user27089
Disabled Account


Posts: 6321
Joined: Nov 2003
Status: Away
RE: MSN Messenger Worm Removal
Why don't you just re-format the computer, if you can't run any .exe's, you can't run any anti-virus removal software, can't end any processes that are being used by the worm, therefore, not being able to delete it, re-boot and perform a re-format if I were you :-/.
03-18-2005 06:30 PM
Profile PM Find Quote Report
vn2k5
New Member
*


Posts: 11
Joined: Mar 2005
O.P. W32.Yaha.K@mm Worm
Hi,

I know I have mentioned this problem in previous posts, but to avoid any confusion I have decided to create a new thread to explain my problem in detail.

I have a worm on my computer (which I think is W32.Yaha.K@mm or something very similar - see http://securityresponse.symantec.com/avcenter/ven...32.yaha.k@mm.html). I received it through MSN Messenger, a file named 'Best_Friend.scr' (there are many variances) from a contact of mine. It is actually a .exe (executable) file disguised as a screensaver file. I regrettably accepted and ran the file, which has since edited my registry and caused numerous problems.

This worm terminates some antivirus and firewall processes. It uses its own SMTP engine to email itself to all the contacts in the Windows Address Book, MSN Messenger, .NET Messenger, Yahoo Pager, and all the files whose extensions contain the letters HT. The email message has randomly chosen the subject line, message, and attachment name.

This threat is written in the Microsoft C++ language and is compressed with UPX. The uncompressed size is about 75 KB.

I have followed the removal instructions from the Symantec website, but I am stuck on the third step - typing text into the MS DOS window once the command.com prompt has been run. I have to run .com prompts instead of .exe so that the worm does not automatically terminate the process (like it does with AntiVirus etc). It has also edited the registry so useful things like 'Folder Options' from the 'Tools' menu has been removed, so I now cannot view hidden files or change file types.

Once I am able to type in DOS, I can complete the rest of the removal process. I am in desperate need of help in this situation!

Edit by WDZ: threads merged

This post was edited on 03-18-2005 at 08:29 PM by WDZ.
03-18-2005 08:09 PM
Profile E-Mail PM Find Quote Report
Pages: (2): « First « 1 [ 2 ] Last »
« Next Oldest Return to Top Next Newest »


Threaded Mode | Linear Mode
View a Printable Version
Send this Thread to a Friend
Subscribe | Add to Favorites
Rate This Thread:

Forum Jump:

Forum Rules:
You cannot post new threads
You cannot post replies
You cannot post attachments
You can edit your posts
HTML is Off
myCode is On
Smilies are On
[img] Code is On