** VIRUS ALERT **
- Bobber
- Diamond Participant
- Posts: 3182
- Joined: Mon Sep 30, 2002 10:40 am
- Location: Stittsville, Ontario
- Contact:
** VIRUS ALERT **
I just got wacked by a virus that was sent to me via MSN messenger. When the virus executed, it may have sent a message to anyone in my Contacts list.
If you recieve a message from me, with the text...
lol, look at this
and a link
DO NOT CLICK ON IT AND GET OUT RIGHT AWAY.
I'm in the process of trying to remove this virus right now.
If you recieve a message from me, with the text...
lol, look at this
and a link
DO NOT CLICK ON IT AND GET OUT RIGHT AWAY.
I'm in the process of trying to remove this virus right now.
Rob Atkinson
Site Admin (retired)
Site Admin (retired)
- M.T. Livewell
- Diamond Participant
- Posts: 2891
- Joined: Mon Mar 03, 2003 3:05 pm
- Location: Rockland
Re
Yeah it's going around.. I was gonna accept it but turned it down at the last second.. good thing. I'm getting that stupid message from everyone!
- fishforfun
- Gold Participant
- Posts: 1408
- Joined: Sun Apr 11, 2004 2:45 pm
- Location: Georgetown Ont.
- fishforfun
- Gold Participant
- Posts: 1408
- Joined: Sun Apr 11, 2004 2:45 pm
- Location: Georgetown Ont.
Critters
HW ran my antivuris, Fprot, but when I reboot the mach is froze?
Sound like this guy?
Beware of accepting file transfer requests from a person on your buddy list, where the file is one of the following; hahaha.pif, naked_drunk.pif, WebCam.pif, me_2005.pif and there may be more. If you've opened the transferred document then your PC has been infected. If you did not open the file, then you can just erase the file that was transferred (whew!).
The dropper files, received via the MSN file transfer, have been identified as W32.Bropia.J. This is a worm that propagates using MSN Messenger and drops a variant of the W32.Spybot.Worm. When the file is opened (run) it places a SpyBot file on the system and runs it. The file is ~140KB and when run it installs a file called "winins.exe" to C:\{winnt, windows}\system32\ and has the file attributes of System, Hidden, Read Only (SHR). As with all the SpyBots, this one goes off to connect to an IRC server on the Internet, reports in and waits for further instructions or new versions of the worm from the worms creator.
LOL @ Crazyhook!
HW
Beware of accepting file transfer requests from a person on your buddy list, where the file is one of the following; hahaha.pif, naked_drunk.pif, WebCam.pif, me_2005.pif and there may be more. If you've opened the transferred document then your PC has been infected. If you did not open the file, then you can just erase the file that was transferred (whew!).
The dropper files, received via the MSN file transfer, have been identified as W32.Bropia.J. This is a worm that propagates using MSN Messenger and drops a variant of the W32.Spybot.Worm. When the file is opened (run) it places a SpyBot file on the system and runs it. The file is ~140KB and when run it installs a file called "winins.exe" to C:\{winnt, windows}\system32\ and has the file attributes of System, Hidden, Read Only (SHR). As with all the SpyBots, this one goes off to connect to an IRC server on the Internet, reports in and waits for further instructions or new versions of the worm from the worms creator.
LOL @ Crazyhook!
HW
- fishforfun
- Gold Participant
- Posts: 1408
- Joined: Sun Apr 11, 2004 2:45 pm
- Location: Georgetown Ont.
Hey guys, I dont know if this will work, but its cured all of my Virus problems. And I know you shouldnt generally plug people's stuff, but Google for AVG
Its a free antivirus program that updates as much as any payed-for program I've ever used. Maybe that will help you out. Grisoft should be the company name, I think.
Good Luck and good riddance
BigSim
Its a free antivirus program that updates as much as any payed-for program I've ever used. Maybe that will help you out. Grisoft should be the company name, I think.
Good Luck and good riddance
BigSim
- Cancatchbass
- Gold Participant
- Posts: 1692
- Joined: Fri Jan 10, 2003 4:30 pm
- Location: 1000 Islands
Link to removal
Here's a link to the removal tool that will fix you up:
http://securityresponse.symantec.com/av ... .tool.html
Good luck!
CCB
http://securityresponse.symantec.com/av ... .tool.html
Good luck!
CCB
same thing for me "LOL look at this" and like an idiot,i open it and boom 32 msn windows waiting for the accept ...outch...i tryed to kill that piece of crap for 3h than i decide to run my NorthonGhost,,so all the system was restore in 5min 30... 
if you're don't know if you got it..just do ctrl+alt+del and administrator and you're gonna see PROJECT1,,maybe one or a lot of that in running mode

if you're don't know if you got it..just do ctrl+alt+del and administrator and you're gonna see PROJECT1,,maybe one or a lot of that in running mode
