Know your ISP.

User #184322   1203 posts
Whirlpool Enthusiast

hey all, i've been using live messenger recently when my friend sends me some wierd file. i open it and now my account starts spamming all of my contacts. is there some way i can remove this damn thing? it's causing me a lot of trouble at the moment. thanks in advance.

posted 2007-Oct-29, 7pm AEST
User #31115   1962 posts
Whirlpool Enthusiast

Try housecall.trendmicro.com, its a free online virus scanner, usually picks up stuff pretty well.

You might also want to download a permanent Anti Virus program such as NOD32 (www.eset.com) or Avast! Failing that, check out www.download.com, they have free software you can use (whether it freeware or a trial basis). Good luck.

posted 2007-Oct-29, 7pm AEST
edited 2007-Oct-29, 7pm AEST
User #184322   1203 posts
Whirlpool Enthusiast

scanned with AVG free ad-aware and spybot:search and destroy bout 3 times each but no dice

posted 2007-Oct-29, 7pm AEST
User #97340   1142 posts
Whirlpool Enthusiast

why did u download it in the first place?? and i would sudgets maybe ad-aware 2007 or spybot search and destroy..

posted 2007-Oct-29, 8pm AEST
User #97067   8623 posts
Whirlpool Forums Addict

If a friend sends you a file, ask them what it is. If it's malicious, they won't even be aware they've sent it.

Usually such a file will be followed by comments like 'hey check this out! A friend sent me this, it's awesome!' or some other such rubbish.

But ask them about it.

And even more importantly, scan EVERYTHING you download before you open it - even if your friend is sending a legitimate file, you don't know that it isn't infected.

posted 2007-Oct-29, 8pm AEST
User #184322   1203 posts
Whirlpool Enthusiast

which program would be better 2 use then for scanning?

posted 2007-Oct-29, 8pm AEST
User #97067   8623 posts
Whirlpool Forums Addict

You need an antivirus program - those two programs are only antispyware.

Try Avast!

posted 2007-Oct-29, 9pm AEST
User #70613   1520 posts
Whirlpool Enthusiast

check your task manager and if its a program called v.exe that looks like its a been complied in Visual Basic, it shows up in the process list using a seemily random number each time it starts, ive seen 4, 16, 42 and others, it just monitors you msn till you open a convo and eventually spams everyone in your contact list, i removed it by removing uknown listings and suspscious startup programs in the msconfig list, use your common sense, i then also scanned with NOD32 v3 ESS.

posted 2007-Oct-29, 9pm AEST
User #141578   1580 posts
Whirlpool Enthusiast

Run these free online scans and see if they come up with anything:

a-squared Web Malware Scanner
malwarescan.emsisoft.com

ESET Online Scanner (uses the same signatures as ESET NOD32 Antivirus)
www.eset.com/onlinescan/index.php

Do any malware removal in safe mode and disable System Restore during the cleaning process. Re-enable System Restore once the system has been cleaned.

posted 2007-Oct-29, 10pm AEST
User #184322   1203 posts
Whirlpool Enthusiast

Problematic© writes...


Problematic©...

check your task manager and if its a program called v.exe that looks like its a been complied in Visual Basic, it shows up in the process list using a seemily random number each time it starts, ive seen 4, 16, 42 and others, it just monitors you msn till you open a convo and eventually spams everyone in your contact list


you think you could guide me through this in a more simpler way?

posted 2007-Oct-29, 11pm AEST
User #47400   3700 posts
Whirlpool Forums Addict

haha funny i came across this thread, one of my contacts obviously has a virus. his account keeps trying to send me image22.zip through messenger.

posted 2007-Oct-30, 12am AEST
User #112110   273 posts
Forum Regular

same thing happened to me today.. luckily for me just as the file was sending i had DC :D

posted 2007-Oct-30, 1am AEST
User #110660   441 posts
Forum Regular

if it's a new exploit i doubt any av will detect it.

posted 2007-Oct-30, 1am AEST
User #168814   1105 posts
Whirlpool Enthusiast

Karmacode writes...

haha funny i came across this thread, one of my contacts obviously has a virus. his account keeps trying to send me image22.zip through messenger.

A friend of mine had that last night... I did a quick google and then replied to his send file request with this link.

www.cisrt.org/enblog/read.php?170

He managed to remove it and I haven't got anything bad from him since.
Winnah.

posted 2007-Oct-30, 5am AEST
User #115085   2065 posts
Whirlpool Forums Addict

Karmacode writes...

haha funny i came across this thread, one of my contacts obviously has a virus. his account keeps trying to send me image22.zip through messenger.

Yeah i was getting last night at home when i was on my ibook, its nice to be immune to somthing which is pretty much a .exe file..

posted 2007-Oct-30, 10am AEST
User #149679   706 posts
Whirlpool Enthusiast

There are two Variants of MSN Worm

First variant

File name: imageXX.zip(imageXX.JPG-www.photob­ ucket.com)
Size:10,752 bytes
MD5:8fdb1cc56c2d9a801c843946e08404­ 82
Detection: Backdoor.Win32.IRCBot.ane (Kaspersky)

Details:

(1) Drops the following files.
%system%\nvbsvc.exe
%temp%\imageXX.zip (XX is random digitals, e.g. "image14.zip")

(2) Adds the following registry keys.
HKEY_LOCAL_MACHINE\SOFTWARE\Micros­ oft\Windows\CurrentVersion\Run
"Volume Shadow Organizer" = "nvbsvc.exe"

How to remove?

STEP 1
Delete registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Micros­ oft\Windows\CurrentVersion\Run
"Volume Shadow Organizer" = "nvbsvc.exe"

STEP 2
Restart WINDOWS

STEP 3
Delete virus files:
%system%\nvbsvc.exe
%temp%\imageXX.zip (XX is random digitals, e.g. "image14.zip")

Second variation

File name: imageXX.zip(imageXX.JPG-www.photob­ ucket.com)
Size:10,752 bytes
MD5: fc086c2123ce97006ddf8513ecb171d4
Detection: N/A

Details:

(1) Drops the following files.
%system%\abgsvc.exe
%temp%\imageXX.zip (XX is random digitals, e.g. "image22.zip")

(2) Adds the following registry keys.
HKEY_LOCAL_MACHINE\SOFTWARE\Micros­ oft\Windows\CurrentVersion\Run
"Application Layer Browser"="abgsvc.exe"

How to remove?

STEP 1
Delete registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Micros­ oft\Windows\CurrentVersion\Run
"Application Layer Browser"="abgsvc.exe"

STEP 2
Restart WINDOWS

STEP 3
Delete virus files:
%system%\abgsvc.exe
%temp%\imageXX.zip (XX is random digitals, e.g. "image22.zip")

The above information was gathered from the

Chinese Internet Security Response Team Web Site

posted 2007-Oct-30, 12pm AEST
User #103079   2502 posts
Whirlpool Forums Addict

Just got a message from a mate that said.
"hey man accept my pics. :( i just edited it to look maad funny.."

The file name was.
"image22.zip"

So strait away i canceled it.
A few of my other contacts have this virus sending out crap, I have just blocked them.
BTW I use Pidgin IM not that Windows Live junk.

posted 2007-Oct-30, 3pm AEST
edited 2007-Oct-30, 3pm AEST
User #184322   1203 posts
Whirlpool Enthusiast

where do you find those files Thunder Bird? i also downloaded avast last night and ran a scan but i don't think anything came up, even though there must be a virus somewhere on my computer

posted 2007-Oct-30, 4pm AEST
edited 2007-Oct-30, 4pm AEST
User #109339   1241 posts
Whirlpool Enthusiast

no offense but who ever downloads + runs it is a noob. lulz

check out the top msn worm *wink wink*

The worm, W32/Impard-A, is a highly sophisticated program with multi-lingual support that can effectively spread itself, delete and send other, rival malware present on the computer back to its creator, and utilise BitTorrent in achieving its goal.

Like most such malware, W32/Impard-A is controlled over IRC. Richard Cohen, a security expert with Sophos, said:

It’s controlled by a remote user over IRC, and is capable of sending itself via AIM and MSN, storing itself as a file called IMG009.jpg-www.imagehosting.com inside a zip file called C:RECYCLERmyphoto.zip, and then sending this zip with a message that promises pictures, written in the same language as the infected computer. This sort of social engineering tries to maximize the chance that recipients will believe it to be legitimate and open the attachment, though this is shot in the foot somewhat by the fact that many of the the phrases have been cut off abruptly.

I have personally seen the messages generated by this worm, when a Yahoo! Messenger-using friend of mine asked me to visit some obscure URL to look at her photos. She uploads all her photographs to Facebook, so I became suspicious right away. It turns out, this worm is so versatile, it can hijack just about every popular IM client and use the signed in account to spread to its contacts. What’s very interesting, though, is how the worm utilises BitTorrent.

Once running on the host computer, the worm searches for the BitTorrent mainline client executable (bittorrent.exe). If it finds the file, it opens up a torrent and, after downloading a copy of itself to a specific location on your hard disk, starts seeding it.

This is the first reported instance of malware making use of BitTorrent to achieve its creators’ ends. If you think about it, it makes perfect sense. Why should the malware author waste bandwidth downloading his worm to thousands of Windows computers around the globe, when he can make his army of zombified ones redistribute it for him, free of cost?

posted 2007-Oct-30, 5pm AEST
edited 2007-Oct-30, 5pm AEST
User #184322   1203 posts
Whirlpool Enthusiast

so anyone got ideas to combat this damn thing?

looked on www.cisrt.org/enblog/read.php?178

but don't get the
HKEY_LOCAL_MACHINE\SOFTWARE\Micros­ oft\Windows\CurrentVersion\Run
"Remote Terminal Service" = "rpmsvc.exe " .how do i get to this?

posted 2007-Oct-30, 5pm AEST
edited 2007-Oct-30, 5pm AEST
User #149679   706 posts
Whirlpool Enthusiast

www.microsoft.com/protec.../viruses/im.mspx

posted 2007-Oct-30, 5pm AEST
User #109339   1241 posts
Whirlpool Enthusiast

flaggen writes...

so anyone got ideas to combat this damn thing?

looked on www.cisrt.org/enblog/read.php?178

but don't get the
HKEY_LOCAL_MACHINE\SOFTWARE\Micros­ oft\Windows\CurrentVersion\Run
"Remote Terminal Service" = "rpmsvc.exe " .how do i get to this?


its not rocket science...

go to start > run > msconfig > startup

look for unknown exe's and disable them from startup then reboot find location and delete.

posted 2007-Oct-30, 5pm AEST
User #184322   1203 posts
Whirlpool Enthusiast

lulz writes...

look for unknown exe's and disable them

what kind of exes should i be looking for?

posted 2007-Oct-30, 6pm AEST
edited 2007-Oct-30, 6pm AEST
User #127221   660 posts
Whirlpool Enthusiast

flaggen writes...

but don't get the
HKEY_LOCAL_MACHINE\SOFTWARE\Micros­ oft\Windows\CurrentVersion\Run
"Remote Terminal Service" = "rpmsvc.exe " .how do i get to this?


start>run>regedit

posted 2007-Oct-30, 6pm AEST
User #109339   1241 posts
Whirlpool Enthusiast

flaggen writes...

unknown exes? how do you know which ones?

i guess the ones that don't look familiar to you or the filename of the virus eg: the filename you posted with the registry key location.

posted 2007-Oct-30, 6pm AEST
User #149679   706 posts
Whirlpool Enthusiast

Here are some to start looking for

abgsvc.exe

mdn.exe

nvbsvc.exe

rpmsvc.exe

posted 2007-Oct-30, 6pm AEST
User #184322   1203 posts
Whirlpool Enthusiast

ok got something called "snpstd" is this something?

posted 2007-Oct-30, 8pm AEST
edited 2007-Oct-30, 8pm AEST
User #256370   9 posts
I'm new here, please be nice

have you tried – http://virusscan.jotti.org/
also a small program called autoruns
http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx
Otherwise its fry and reload.

posted 2008-Nov-10, 11am AEST
User #196421   135 posts
Forum Regular

Thunder Bird writes...

abgsvc.exe

mdn.exe

nvbsvc.exe

rpmsvc.exe

so these are the ones that should be blocked?

wat about "NVCpl

posted 2008-Nov-10, 3pm AEST
edited 2008-Nov-10, 3pm AEST
User #260517   2 posts
I'm new here, please be nice

I received a virus via msn messenger 2 weeks ago and I was unable to send emails for days because I was being spam blocked. The virus seemed to come from my niece asking me to look at some photos. I know...stupid me just wasn't thinking at the time and opened it. The grief it caused from then on was immeasurable and extremely costly.

I tried two days doing every scan known to man. I have CA Security Suite which I have now removed because obviously it's hopeless. The computer then went to an IT company, and still the virus was not removed (even though they told me it was).

Anyway, to make a long story longer, I eventually rang CA and they told me to go to my Windows/System32 File and look for a file called "doomi.exe"; cut and paste it into a folder on my desktop called "virus", then zip it and email it to them. However, I was not then able to delete the "virus" folder from my desktop or move it to the recycle bin. So, I restarted my computer and then was able to move the folder into the recycle bin and delete it. However, doomi.exe reinstalled itself into the System32 folder. Arrgghh!

So...to make a long story even longer...I installed Hijack This and ran a scan, and deleted it from there. However, I had to do this about 3 times! It seems to have worked as I am no longer having my emails spammed.

I'm just curious why there aren't more solutions to this problem on the web.

I'd welcome your replies to this post.

Cheers
Caroline

posted 2008-Dec-7, 8am AEST
User #54337   1988 posts
Section Moderator

Have a look at this site http://www.msnvirusremoval.com/ and see if it helps you.

Cheers :)

posted 2008-Dec-7, 9am AEST
User #260517   2 posts
I'm new here, please be nice

Yes...tried that, but it didn't work. But thank you. The only thing that worked was removing the doomi.exe

Honestly...it was a nightmare!

Caroline

posted 2008-Dec-8, 7am AEST
Hosted by
Bulletproof Networks
Big numbers
1,001,073 threads
17,676,823 posts
2,051,740 whims sent
3,158 wiki topics
228 ISPs listed
8,113 broadband plans
831 modems & routers
41,217 features filled