TechSpot

messenger virus - d'oh

By MUZ
Oct 23, 2005
  1. Hello everyone - used to post here a while back but forgot username etc. and can't seem to find old email addy in the search but oh well - greetings. Now a friend of a friend whom i sort of know has been added to my msn messenger contacts and we have been chatting a bit of late.. now meing being the ***** today i clicked on a link she provided with the words "heh, is this really you" with the link www.messengertools.or(g) etc. etc. can post the link if needed.. so i stupidly clicked on it and opera (my browser) asked me if i wanted to install contacts.exe.. now i may be stupid but not that stupid until about 20 mins later when the page was still in Opera when i restarted it and DO'H i installed it and things went a little haywire.. to cut to the chase -

    Norton Antivirus Auto-Protect & email scanning is disabled and i cannot get new updates
    Windows task manager is disabled and only pops up for a second before shutting itself down
    Homepage in IE is now set to forums-united.com

    I did the usual things as in restart in safe mode and ran a virus check with norton but it not pick anything up

    ran ad-aware and it picked up 'DyFuCa' which i removed

    The hijackthis log is attached and there is some strange stuff in there.

    If anyone can help i would be most greatful
     

    Attached Files:

  2. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

  3. MUZ

    MUZ TS Rookie Topic Starter

    Thanks very much for that, I had seen those as "Reads" and had a look but was unsure if these were appropriate for this particular nasty.. shall do all these things and report back - thanks again
     
  4. MUZ

    MUZ TS Rookie Topic Starter

    Okay thanks for the help - did all the things mentioned and symantec is now working correctly along with windows task manager and IE back to normal. I was astounded that I had 81 nasties picked up by ewido that NAV has never seen etc. think I will be switching over to that Kerpersky mentioned in other threads.. A mix of things such as 'bonjour' and wildtangent were running around some of which must have been there for quite some time.

    Anyway I think all is well but if you could have a quick run over the after-flushed HJT log that would be great.
    Thanks Again.
     
  5. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    As far as I can see. Everything looks ok.

    Regards Howard :)
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...