Jump to content


MSN virus


  • You cannot reply to this topic
50 replies to this topic

#1 Dauth

    <Custom title available>

  • Gold Member
  • 11193 posts

Posted 15 April 2009 - 17:11

Aqua has a MSN virus, be careful when talking to him, I have pidgin so dodged the problem. I recommend someone contacts him via another method.

#2 Razven

    Kidnapped

  • Member
  • 1302 posts
  • Projects: Unofficial written media specialist for ShW and RotR

Posted 15 April 2009 - 21:15

Oh, I do? Damn. Will look into how to fix it.

Logfile of HijackThis v1.99.1
Scan saved at 5:21:01, on 16/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINPENJR\Win32\pphidpad.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CP.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
D:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
C:\Program Files\Samsung\Samsung Multimedia Keyboard\mmkbd.exe
C:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
D:\Program Files\BitTorrent\bittorrent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\Eric\Local Settings\Temporary Internet Files\Content.IE5\O3U0ARUG\avast_home_setup[1].exe
D:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: QQToolbar - {29CF293A-1E7D-4069-9E11-E39698D0AF95} - C:\Program Files\Tencent\QQToolbar\IEBar.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live 登入小幫手 - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: QQToolbar - {29CF293A-1E7D-4069-9E11-E39698D0AF95} - C:\Program Files\Tencent\QQToolbar\IEBar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PPHIDPAD] C:\WINPENJR\Win32\pphidpad.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX430 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CP.EXE /P31 "EPSON Stylus Photo RX430 Series" /O6 "USB001" /M "Stylus Photo RX430"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AddrPlus3] C:\PROGRA~1\TENCENT\Adplus\stup.exe C:\PROGRA~1\TENCENT\Adplus\Adplus.dll Rundll32
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "D:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O8 - Extra context menu item: 上傳到QQ網路硬碟 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 傳送到 &Bluetooth 裝置... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: 匯出至 Microsoft Excel(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 新增到QQ自定義面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 新增到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 氝樓善QQ桶 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ MMS傳送該圖片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: 發佈至部落格 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: 使用 Windows Live Writer 發佈至部落格(&B) - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.co.../sysreqlab3.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplane...C_2.3.5.107.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games....GamesPlugin.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemreq.../sysreqlab2.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1163692307761
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca12.cust...l/java/RntX.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /m PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: 自動 LiveUpdate 排程器 - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe


This is a Hijackthis log, it helps find things that don't belong. :D

Edit 1: Hijackthis log entry
Edit 2: Added what I edited in and the Avast bit - Downloaded, updated and scanned with Avast, it didn't pick up anything.

Edited by Razven, 15 April 2009 - 21:32.


#3 Overdose

    Nice Guy Syndrome

  • Gold Member
  • 4146 posts
  • Projects: SWR Projects

Posted 15 April 2009 - 21:27

Topic moved.
Posted Image

#4 Dauth

    <Custom title available>

  • Gold Member
  • 11193 posts

Posted 15 April 2009 - 21:39

Remove the following

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: QQToolbar - {29CF293A-1E7D-4069-9E11-E39698D0AF95} - C:\Program Files\Tencent\QQToolbar\IEBar.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: QQToolbar - {29CF293A-1E7D-4069-9E11-E39698D0AF95} - C:\Program Files\Tencent\QQToolbar\IEBar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /m PifEng.dll (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

Uninstall ALL your toolbars and rescan with HJT

#5 Razven

    Kidnapped

  • Member
  • 1302 posts
  • Projects: Unofficial written media specialist for ShW and RotR

Posted 15 April 2009 - 22:22

All done, inform me if problem still persists.

#6 Dauth

    <Custom title available>

  • Gold Member
  • 11193 posts

Posted 15 April 2009 - 22:47

I'd still like to see another hjt log, all we've done so far is clean up garbage, still need to find the offending program.

#7 RaiDK

    I have an Energon Axe. Your argument is invalid.

  • Gold Member
  • 4107 posts

Posted 15 April 2009 - 23:04

I've had to block half a dozen people with these sort of things in the last week or so...

View PostMasonicon, on 17 Oct 2009, 13:44, said:

According to Conspiracy theories in internet, sci-fi and fantasy are real!

#8 Ragman

    Visitor

  • Member
  • 49 posts

Posted 16 April 2009 - 00:19

Just give your MSN a nice bowl of chicken noodle soup and let it sleep all day. That works when I get sick on the rare occasion.
Posted Image
-----My Job is to Find simple things and complicate them-----

#9 Alias

    Member Title Goes Here

  • Member
  • 11705 posts

Posted 16 April 2009 - 00:20

Times like these I realise why I love being on a Mac (even though I never got infected on Windoze).

Hope you get it fixed, Aqua, my friend.

Posted Image

#10 Sgt. Rho

    Kerbal Rocket Scientist

  • Project Leader
  • 6870 posts
  • Projects: Scaring Jebediah.

Posted 16 April 2009 - 07:54

What does that virus do? Is it the one that keeps spamming via his MSN adress?

#11 Dauth

    <Custom title available>

  • Gold Member
  • 11193 posts

Posted 16 April 2009 - 08:57

It sent me a link and some text which encourages you to follow the link. Probably self repeating from there onwards.

#12 RaiDK

    I have an Energon Axe. Your argument is invalid.

  • Gold Member
  • 4107 posts

Posted 16 April 2009 - 10:26

Yep, that's the one I've had to mass block recently. So annoying, they've started nudging you continuously.

View PostMasonicon, on 17 Oct 2009, 13:44, said:

According to Conspiracy theories in internet, sci-fi and fantasy are real!

#13 Prophet of the Pimps

    Masters of Booty Strike Force

  • Gold Member
  • 11369 posts
  • Projects: ShockWave

Posted 18 April 2009 - 15:37

thats why people should stop using a non password protected admin account. All my windows and linux pc have password for the admin account and the every day account is a standard user. this way the stupid virus gets stuck at the password prompt that makes me aware of the shit its trying to pull. Also i am a huge fan of UAC in Vista and Windows 7.
Never underestimate a Resourceful Idiot
Posted Image

#14 Razven

    Kidnapped

  • Member
  • 1302 posts
  • Projects: Unofficial written media specialist for ShW and RotR

Posted 24 April 2009 - 10:17

As far as I am concered, the problem seems to have been fixed.

#15 CommanderJB

    Grand Admiral, Deimos Fleet, Red Banner

  • Fallen Brother
  • 3736 posts
  • Projects: Rise of the Reds beta testing & publicity officer; military technology consultancy; New World Order

Posted 24 April 2009 - 10:44

In that case I'll close it. If you have any further problems, contact me or another member of the moderating team to get it re-opened, but as far as I've seen the problem is fixed as well.

Quote

"Working together, we can build a world in which the rule of law — not the rule of force — governs relations between states. A world in which leaders respect the rights of their people, and nations seek peace, not destruction or domination. And neither we nor anyone else should live in fear ever again." - Wesley Clark

Posted Image
Posted Image

#16 Dauth

    <Custom title available>

  • Gold Member
  • 11193 posts

Posted 26 April 2009 - 16:08

Unlocking, Ka1000 has also picked up an MSN virus. If someone could warn him.

#17 Razven

    Kidnapped

  • Member
  • 1302 posts
  • Projects: Unofficial written media specialist for ShW and RotR

Posted 26 April 2009 - 16:18

This one seems to be pretty virulent, isn't it? I don't remember anything spreading as fast or as persistent during my entire time using MSN since...2003.

#18 Dauth

    <Custom title available>

  • Gold Member
  • 11193 posts

Posted 26 April 2009 - 16:33

Might not be the same one this time. I think its just a spate of MSN viruses.

#19 G-sus

    batshit insane

  • Member
  • 802 posts
  • Projects: Coding Skynet

Posted 26 April 2009 - 16:37

there are so friggin much of them, thats why i dont use MSN.
and recommend for anybody else not to either. but its not like anybody would listen... :P
Posted Image
(Sig by The DR)

True beauty comes from heart and mind.
(but perfection has also big boobs)

#20 BeefJeRKy

    Formerly known as Scopejim

  • Gold Member
  • 5114 posts
  • Projects: Life

Posted 26 April 2009 - 17:49

Yahoo Messenger is teh suck and I don't like AIM. Google talk is too limited. ICQ is dead. I don't see other options Gsus. People should just be more careful following links online.
Posted Image

#21 G-sus

    batshit insane

  • Member
  • 802 posts
  • Projects: Coding Skynet

Posted 26 April 2009 - 18:11

icq isnt dead. its not what it was many years ago, but actually its fine. (for the technical stuff, the protocol sucks ass, but its way better than MSN)
you´re right that yahoo sucks, and AIM is probably the worst of all.
so maybe like switch to IRC, or at least icq, but no friggin MSN...
(also there are several exploits for every messenger that dont need you to follow links to infect you, but of course there too for MSN the most...)
that is practically the main reason i dont use it tbh, since i knew someone who used very effetive ways to do that to do very nasty stuff to people´s pcs... >_>
Posted Image
(Sig by The DR)

True beauty comes from heart and mind.
(but perfection has also big boobs)

#22 BeefJeRKy

    Formerly known as Scopejim

  • Gold Member
  • 5114 posts
  • Projects: Life

Posted 26 April 2009 - 18:12

AVG blocks attacks through MSN for me.
Posted Image

#23 G-sus

    batshit insane

  • Member
  • 802 posts
  • Projects: Coding Skynet

Posted 26 April 2009 - 18:26

View PostScope, on 26 Apr 2009, 20:12, said:

AVG blocks attacks through MSN for me.

yes, about the max. 95% it blocks everything else, like every other AV out there. :P
so even if that number looks nice, and "covering most of it", about every 20th worm/attack/ect would go through... >_>
Posted Image
(Sig by The DR)

True beauty comes from heart and mind.
(but perfection has also big boobs)

#24 Shirou

    Humble darkspawn

  • Member
  • 3328 posts

Posted 26 April 2009 - 22:14

View PostG-sus, on 26 Apr 2009, 20:26, said:

View PostScope, on 26 Apr 2009, 20:12, said:

AVG blocks attacks through MSN for me.

yes, about the max. 95% it blocks everything else, like every other AV out there. :P
so even if that number looks nice, and "covering most of it", about every 20th worm/attack/ect would go through... >_>

Yet I don't have an AV and never have anything like worms...

so if I had one and then had to wait for the 20th to get through, I could say that it is safe allright.
Posted Image

#25 G-sus

    batshit insane

  • Member
  • 802 posts
  • Projects: Coding Skynet

Posted 26 April 2009 - 22:33

View PostAftershock, on 27 Apr 2009, 0:14, said:

Yet I don't have an AV and never have anything like worms...

so if I had one and then had to wait for the 20th to get through, I could say that it is safe allright.

words can not describe... >_<


EDIT:

alright, calmed down a little... >_>
so, you´re not having an AV, and protecting of 19/20 viruses is enough, and you never had one...
lets put this straight, unless you´re not posting this from machine running BSD unix, or this is the first minute of the pc online at all (and even so, behind a good router) statistics say you´re wrong.
first of all, without proper AV/FW software you wont know if you have a virus anyway. that popular known "stuff doesnt work" is bullsh*t, since normally it only occurs when viruses are bad programmed, or have a malfunction.
which doesnt realy happen often. so you cant even say you never had a virus, you wouldnt even know.
second point, defending 19 of 20 viruses is ok: bullsh*t again. there´s more than one million different ones out there, several hundred more every day. so even on an average day its just 500, that´d basically be 25 new viruses you could get infected with. (the ones that spread the most are known fast of course, and therefor the signatures for them are made quick)
third at all, the "i dont care, what will happen anyway"-opinion: worst of all.
i personally dont care if your passwords/accounts/paypal ect are stolen. but its just irresponsible to everyone else on the net having your computer inherit the concentrated breed of dozens of evil little programs which are being used to create spam, infect other machines, and attack/take down websites ect, which doesnt affect just you but everyone else.
so get at least just a little bit responsibility, get your pc straight, put an AV and FW there, to fend of at least the worst of it, cuz we dont wanna have the stuff around your pc will be used to else.

[/end rant]

Edited by G-sus, 26 April 2009 - 22:49.

Posted Image
(Sig by The DR)

True beauty comes from heart and mind.
(but perfection has also big boobs)



1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users