Guild Wars Forums - GW Guru
 
 

Go Back   Guild Wars Forums - GW Guru > Forest of True Sight > Technician's Corner

Notices

Reply
 
Thread Tools Display Modes
Old Nov 26, 2006, 07:30 PM // 19:30   #1
Lion's Arch Merchant
 
LiamR's Avatar
 
Join Date: Jul 2006
Guild: Prefer Unlight Beer [PuB]
Advertisement

Disable Ads
Unhappy Oh ****!

It seems a huge virus has been shot all over MSN.

Someone sends you a file called

"Is this you in the pic :P"

I clicked accept thinking WTF.

It loaded, AVG popped up saying virus found.

Then, it loaded up ALL my contacts, sending that message forward.

Anyone else experiencing this, how to counter it?

Just a warning
LiamR is offline   Reply With Quote
Old Nov 26, 2006, 07:38 PM // 19:38   #2
Lion's Arch Merchant
 
LiamR's Avatar
 
Join Date: Jul 2006
Guild: Prefer Unlight Beer [PuB]
Default

People this is way important. Nudge!
LiamR is offline   Reply With Quote
Old Nov 26, 2006, 07:38 PM // 19:38   #3
Forge Runner
 
Tachyon's Avatar
 
Join Date: Nov 2005
Location: Stoke, England
Guild: The Godless [GOD]
Profession: W/
Default

Quote:
Originally Posted by LiamR
how to counter it?
Simple, don't accept anything over MSN. You wouldn't automatically open any old attachment that arrived via email so why do it on MSN?
Tachyon is offline   Reply With Quote
Old Nov 26, 2006, 07:43 PM // 19:43   #4
Forge Runner
 
Join Date: Jan 2006
Default

Best way is of course to stop using MSN altogether. That thing is a security disaster.
Antheus is offline   Reply With Quote
Old Nov 26, 2006, 07:44 PM // 19:44   #5
Lion's Arch Merchant
 
LiamR's Avatar
 
Join Date: Jul 2006
Guild: Prefer Unlight Beer [PuB]
Default

I meant how to counter it when it is installed. Also, when i open remove programs, i see '888bar'. When i try to remove, it disapears.. i open remove programs again, it's back. Please help T_T

EDIT, I removed msn, stop that Red Engine in his tracks. Shoouldnt it?

Last edited by LiamR; Nov 26, 2006 at 07:50 PM // 19:50..
LiamR is offline   Reply With Quote
Old Nov 26, 2006, 08:00 PM // 20:00   #6
Banned
 
Yanman.be's Avatar
 
Join Date: Dec 2005
Location: Belgium
Guild: [ROSE]
Profession: A/
Default

I just got it from a mate too. Offcourse, I didn't accept it ,because I know he doesn't speak english.
Yanman.be is offline   Reply With Quote
Old Nov 26, 2006, 08:08 PM // 20:08   #7
Lion's Arch Merchant
 
LiamR's Avatar
 
Join Date: Jul 2006
Guild: Prefer Unlight Beer [PuB]
Default

Oh, damn. I *think* i removed it.. it stops popping up, not in remove programs list. Eek
LiamR is offline   Reply With Quote
Old Nov 26, 2006, 08:12 PM // 20:12   #8
Krytan Explorer
 
exiled mat's Avatar
 
Join Date: Dec 2005
Location: The netherlands > friesland > balk
Guild: [JAMM] Justified Ancients of Moo Moo
Profession: E/Me
Default

avg should take care of the virus part for you (if you have the latest version)
and about that 888 bar thingy: try using hitman pro http://www.hitmanpro.com/|
Just install it and it automaticly runs all well known spyware removal tools, that should do the trick
exiled mat is offline   Reply With Quote
Old Nov 26, 2006, 09:01 PM // 21:01   #9
Lion's Arch Merchant
 
PanGammon's Avatar
 
Join Date: Aug 2006
Location: The Underworld
Guild: Leader of Grenth Gaming Inc [GG]
Profession: Mo/Me
Default

Whats MSN :>
PanGammon is offline   Reply With Quote
Old Nov 26, 2006, 10:02 PM // 22:02   #10
Forge Runner
 
Tachyon's Avatar
 
Join Date: Nov 2005
Location: Stoke, England
Guild: The Godless [GOD]
Profession: W/
Default

Download and run this, once it's finished scanning delete (fix) whatever it finds and re-boot your PC.

http://www.majorgeeks.com/VundoFix_d4954.html

No installation is required, it's a stand-alone app. Just run the exe.
Tachyon is offline   Reply With Quote
Old Nov 26, 2006, 11:04 PM // 23:04   #11
Frost Gate Guardian
 
Tera's Avatar
 
Join Date: May 2006
Location: England
Guild: Society of Souls [Argh]
Profession: E/
Default

lol, ppl are saying dont open anything over msn, and we are giving him links to 'anti virus and spyware' things.
kinda irnoic cos the same thing could happen
Tera is offline   Reply With Quote
Old Nov 26, 2006, 11:34 PM // 23:34   #12
Forge Runner
 
Tachyon's Avatar
 
Join Date: Nov 2005
Location: Stoke, England
Guild: The Godless [GOD]
Profession: W/
Default

Quote:
Originally Posted by Tera
lol, ppl are saying dont open anything over msn, and we are giving him links to 'anti virus and spyware' things.
kinda irnoic cos the same thing could happen
Quoted for the sole reason of possibly being the dumbest post yet!

Anyway, what's with the "we" part? I haven't seen you offer any advice to sort this guy's problem out. I'm guessing that you haven't downloaded any anti-spyware or anti-virus software before then.
Tachyon is offline   Reply With Quote
Old Nov 27, 2006, 12:41 AM // 00:41   #13
Ascalonian Squire
 
Zarn's Avatar
 
Join Date: Nov 2006
Guild: The Lost Heroes Guild
Profession: W/
Default

Best advice is of course never to accept anything through msn, but then again, sometimes u get something from friends, and suddenly something like that pops up and u dont think for a second it may be hazardous.

Well personall Id use Spywareblaster to prevent that crap even entering my pc, and i use Avast as anti virus... I feel that works quite well.
Zarn is offline   Reply With Quote
Old Nov 27, 2006, 05:21 AM // 05:21   #14
BFG
Lion's Arch Merchant
 
BFG's Avatar
 
Join Date: Feb 2006
Location: Lost
Guild: DCSB
Default

Well, no use telling you what NOT to do in the future. I will assume that you are using WinXP, so getting this off of your machine may not be totally futile. I would suggest the use of Ad-Aware SE and Spybot Search & Destroy to compliment your antivirus. While they may detect malware, the removal part gets tricky sometimes. This seems to be some sort of toolbar or similar item that automagically reappears no matter how many times you delete it. Try running those two programs in Safe Mode and they should be able to remove what they find.

Next, you may want to do a manual search on your machine to find some things that may not belong.
  • First, you need to reveal hidden files and folders:

    Start->Control Panel->Folder Options->View tab->Hidden Files and Folders->Show Hidden Files and Folders

  • Next, do a manual search.

    Start->My Computer->C:/Documents and Settings->(profile name)->Application Data (look for anything that is out of place; don't worry, it will be obvious)

  • Further your manual search.

    Start->My Computer->C:/Documents and Settings->(profile name)->Local Settings->Application Data (do the same as you did above)

  • Search more.

    Start->My Computer->C:/Documents and Settings->All Users->Application Data (again, note oddities)
The folders in the above locations should correspond to software that you have installed on your machine. Anything out of place that you are confident does not belong there (for example, a folder named "888tool" or such) should be deleted. There are times when you'll get the classic "OMG it's being used" error from Windows, but don't fret. Simply reboot into Safe Mode without Networking and banish those bad folders.

This is only a procedure I use to find what the scanners do not find. It may be a waste of time to even look in those locations, but if for just the peace of mind, give it a go.
BFG is offline   Reply With Quote
Old Nov 27, 2006, 10:56 AM // 10:56   #15
Frost Gate Guardian
 
Tera's Avatar
 
Join Date: May 2006
Location: England
Guild: Society of Souls [Argh]
Profession: E/
Default

Quote:
Originally Posted by Azagoth
Quoted for the sole reason of possibly being the dumbest post yet!

Anyway, what's with the "we" part? I haven't seen you offer any advice to sort this guy's problem out. I'm guessing that you haven't downloaded any anti-spyware or anti-virus software before then.
thnx for the comment.

and by 'we' i mean the GW guru community.

And i have downloaded anti virus software and spyware before, but its automated through the systems i use.

I never meant to insult any1, but on other forums i know people who posted links to malicious things under the disguise of anti spyware tools.

you, and other people here may not be doing that, but i just dont want the same thing to happen to someone else.
Tera is offline   Reply With Quote
Old Nov 27, 2006, 11:21 AM // 11:21   #16
Jungle Guide
 
Gorebrex's Avatar
 
Join Date: Jan 2006
Default

You can also try Hijack This - http://www.pcworld.com/downloads/fil...scription.html
Good instructions on its use are here http://forums.g4tv.com/messageview.c...hreadid=466949
Also, can you post a pic of your Task Manager, so we can see what processes are running? If something "doesnt look right", you can usually type the process name in your browsers search window, and find out what it is.
Gorebrex is offline   Reply With Quote
Old Nov 27, 2006, 11:52 AM // 11:52   #17
Lion's Arch Merchant
 
Join Date: Feb 2006
Guild: Mina Sucks [Blz]
Default

I would say use hjackthis after using Ad-Aware and Spybot. When you use hijackthis search for hijackthis log analyzer so you can see what is dangerous and not, but be careful dont automatically remove everything as this will (prob) damage your system.

Also take a look in your received folder, I think when i got something like this once, there were files in my received and the windows\system folder
TheYellowKid is offline   Reply With Quote
Old Nov 27, 2006, 08:59 PM // 20:59   #18
Technician's Corner Moderator
 
Tarun's Avatar
 
Join Date: Jan 2006
Location: The TARDIS
Guild: http://www.lunarsoft.net/ http://forums.lunarsoft.net/
Default

Get Avast and visit www.lunarsoft.net for comprehensive help getting your computer cleaned up good as new.
Tarun is offline   Reply With Quote
Old Nov 28, 2006, 05:47 AM // 05:47   #19
Krytan Explorer
 
Superdarth's Avatar
 
Join Date: Aug 2006
Default

I remember someone posting the solution in the Runescape forums.

The damn mods deleted it though..Jagex's mods are far to trigger happy.
Superdarth is offline   Reply With Quote
Reply

Share This Forum!  
 
 
           

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 12:55 PM // 12:55.


Powered by: vBulletin
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
jQuery(document).ready(checkAds()); function checkAds(){if (document.getElementById('adsense')!=undefined){document.write("_gaq.push(['_trackEvent', 'Adblock', 'Unblocked', 'false',,true]);");}else{document.write("