Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

MSN trojan

Thread Tools
 
Search this Thread
 
Old 29 April 2005, 03:01 PM
  #1  
stevem2k
Scooby Regular
Thread Starter
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Default MSN trojan

10+ variants of Kelvir trojan/worm reported today <grrr>

One we got
(14:11:44) <name>: lol you'll like this
(14:11:44) <name>: http://pictures.templates4fr1ends.com/gallery.php?email=<address>

(I have munged the link deliberately)


I have uploaded the sample to webimmune ~ Analysis ID: 1746512


Steve
Old 29 April 2005, 03:20 PM
  #2  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

Any idea how to get rid of it as fulham71 keeps sending it to me?
Old 29 April 2005, 03:24 PM
  #3  
Markus
Scooby Regular
 
Markus's Avatar
 
Join Date: Mar 1999
Location: The Great White North
Posts: 25,080
Likes: 0
Received 0 Likes on 0 Posts
Default

Lynne,
If you've got Norton, get the latest update and it should fix it. Have a peek here

I'd certainly get Paul to give it a go as well, as it sounds as though he might have been infected.
Old 29 April 2005, 03:24 PM
  #4  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

Tell him to switch off his PC until he disinfects it.
Old 29 April 2005, 03:28 PM
  #5  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

I don't have Norton Mark. I have had to block him on MSN to stop it being sent through and I have posted in NSR to him too.
Old 29 April 2005, 03:31 PM
  #6  
Markus
Scooby Regular
 
Markus's Avatar
 
Join Date: Mar 1999
Location: The Great White North
Posts: 25,080
Likes: 0
Received 0 Likes on 0 Posts
Default

Lynne,
Bugger, I've had a look and can't find a stand-alone cleaner app for it.
Old 29 April 2005, 03:34 PM
  #7  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

WTF do I do then? I didn't do 'save' on it but did do 'open'

Trending Topics

Old 29 April 2005, 03:37 PM
  #8  
Markus
Scooby Regular
 
Markus's Avatar
 
Join Date: Mar 1999
Location: The Great White North
Posts: 25,080
Likes: 0
Received 0 Likes on 0 Posts
Default

I'm wondering if something like Spybot Search and Destroy or AdWare might kill it, it's worth a shot.

From the look of the defintion on Symantec's site it was only added yesterday, which would explain why there aren't any standalone chappies out there yet.
Old 29 April 2005, 03:43 PM
  #9  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Markus
I'm wondering if something like Spybot Search and Destroy or AdWare might kill it, it's worth a shot.

From the look of the defintion on Symantec's site it was only added yesterday, which would explain why there aren't any standalone chappies out there yet.
I have run AVG and Spybot and it showed up nothing.
Old 29 April 2005, 03:43 PM
  #10  
stevem2k
Scooby Regular
Thread Starter
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Default

No , it's not picked up by spybot / adware or the M$ spyware software.

I have an extra.dat for ut back from webimmune if you are running McAFee a/v software.


Steve


Lynne, can you ring Paul ? - I don't have his number and he's on my msn contacts list too....
Old 29 April 2005, 03:46 PM
  #11  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

Steve I don't have his number, I'm sorry. He was just a contact on my MSN list and haven't spoken to him in ages. I don't have McAfee either...
Old 29 April 2005, 03:47 PM
  #12  
stevem2k
Scooby Regular
Thread Starter
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Default

Ok , I'll txt tango see if he has it....
Old 29 April 2005, 03:48 PM
  #13  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

Actually I do know someone who has it....

BRB
Old 29 April 2005, 03:56 PM
  #14  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

Nope can't get it. Is there a demo MacAFee or anything I can download?
Old 29 April 2005, 03:58 PM
  #15  
stevem2k
Scooby Regular
Thread Starter
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Default

http://uk.mcafee.com/root/runapplication.asp?appid=73
Old 29 April 2005, 04:01 PM
  #16  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

Am I missing summat Steve, there's no icon to do a scan?
Old 29 April 2005, 04:10 PM
  #17  
stevem2k
Scooby Regular
Thread Starter
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Default

I have phoned Paul.

It's missed even on the online scanner Lynne - I have just tried it...
Old 29 April 2005, 04:12 PM
  #18  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

Búgger, what now then? Is there anyway to check PC to see if I have got it by using Search?
Old 29 April 2005, 04:36 PM
  #19  
Markus
Scooby Regular
 
Markus's Avatar
 
Join Date: Mar 1999
Location: The Great White North
Posts: 25,080
Likes: 0
Received 0 Likes on 0 Posts
Default

Steven,
Do you know what variants of Kelvir MacAfee currently detects?
Old 29 April 2005, 04:43 PM
  #20  
stevem2k
Scooby Regular
Thread Starter
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Default

up to AX I think Markus

This one isn't even 'named' to my knowledge.
Old 29 April 2005, 04:49 PM
  #21  
stevem2k
Scooby Regular
Thread Starter
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Default

OK ,

**caveat ** this may toast your system *** caveat ***


deleting windows\system32\run.exe



and the reg keys:

HKEY_CURRENT_USER\Software\Microsoft\OLE\windows run.exe
Windows\CurrentVersion\Run\windows run.exe
Windows\CurrentVersion\RunServices\windows run.exe

and a couple of other keys .. ( do a search on run.exe in regedit ) - the only 'good' ones were AUTORUN.EXE and CTRUN.EXE on mine.

exit and reboot.

The process hasn't restarted and the registry is still clean at the moment.


steve
Old 29 April 2005, 05:16 PM
  #22  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

Can you explain that in simple terms please...
Old 29 April 2005, 05:32 PM
  #23  
stevem2k
Scooby Regular
Thread Starter
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Default

erm .. that was ...


Paul didn't have run.exe so your system might be slightly different too...


Steve
Old 29 April 2005, 09:35 PM
  #24  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

I ran the MacAfee scan (it took ages) but it scanned over 50k files and found nothing.
Old 29 April 2005, 10:21 PM
  #25  
stevem2k
Scooby Regular
Thread Starter
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Default

if you bring up task manager and click on the processes tab is there a run.exe running ?

Steve
Old 30 April 2005, 09:10 AM
  #26  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by stevem2k
if you bring up task manager and click on the processes tab is there a run.exe running ?

Steve
Yes
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Avi
Computer & Technology Related
6
01 May 2002 03:19 PM
polarbearit
Non Scooby Related
9
02 October 2001 08:30 PM



Quick Reply: MSN trojan



All times are GMT +1. The time now is 09:33 PM.