Messenger virus - d'oh

Status
Not open for further replies.
Hello everyone - used to post here a while back but forgot username etc. and can't seem to find old email addy in the search but oh well - greetings. Now a friend of a friend whom I sort of know has been added to my msn messenger contacts and we have been chatting a bit of late.. now meing being the ***** today I clicked on a link she provided with the words "heh, is this really you" with the link www.messengertools.or(g) etc. etc. can post the link if needed.. so I stupidly clicked on it and opera (my browser) asked me if I wanted to install contacts.exe.. now I may be stupid but not that stupid until about 20 mins later when the page was still in Opera when I restarted it and DO'H I installed it and things went a little haywire.. to cut to the chase -

Norton Antivirus Auto-Protect & email scanning is disabled and I cannot get new updates
Windows task manager is disabled and only pops up for a second before shutting itself down
Homepage in IE is now set to forums-united.com

I did the usual things as in restart in safe mode and ran a virus check with norton but it not pick anything up

ran ad-aware and it picked up 'DyFuCa' which I removed

The hijackthis log is attached and there is some strange stuff in there.

If anyone can help I would be most greatful
 

Attachments

  • hijackthis.txt
    7.3 KB · Views: 5
Thanks very much for that, I had seen those as "Reads" and had a look but was unsure if these were appropriate for this particular nasty.. shall do all these things and report back - thanks again
 
Okay thanks for the help - did all the things mentioned and symantec is now working correctly along with windows task manager and IE back to normal. I was astounded that I had 81 nasties picked up by ewido that NAV has never seen etc. think I will be switching over to that Kerpersky mentioned in other threads.. A mix of things such as 'bonjour' and wildtangent were running around some of which must have been there for quite some time.

Anyway I think all is well but if you could have a quick run over the after-flushed HJT log that would be great.
Thanks Again.
 
Status
Not open for further replies.
Back