HFT Online Technical Support Forums - Professional computer help ... with a personal touch.
 
 


Go Back   HFT Online Forums > Internet > Viruses and Trojans

Reply
 
Thread Tools Search this Thread
  #1  
Old August 21, 2001, 08:30 am
mandapanda2002 mandapanda2002 is offline
New Member
 
Join Date: Aug 2001
Posts: 2
Rep Power: 5
mandapanda2002 is on a distinguished road
Default MSN Messenger Virus

Here is some information on a new MSN Messenger virus that is going around. I emailed the Messenger Service and here is what I got in return.

It has recently been brought to our attention, that a new virus has been
identified that is specifically targeting messaging applications, such as MSN
Messenger. This virus is known as "PIC1324(1)(1).exe". As you know, computer
viruses can be passed around in a variety of ways: via e-mail messages, on
floppy disks, and increasingly, through messaging applications like MSN
Messenger. We are continuing to investigate the situation and explore more ways
in which we can protect you from problems like this.

This particular virus and viruses like it exist in an .exe file. The virus
will only be released if you run the file, in other words double-click the link
or download it. If "PIC1324(1)(1).exe" is sent to you through MSN Messenger, you
will be asked whether you want to download "PIC1324(1)(1).exe". Then you would
have to double-click the link and execute the file itself to propagate the
virus.

There are a number of ways you can protect your computer against
"PIC1324(1)(1).exe" virus and other similar types of viruses:

- Do not double-click the "PIC1324(1)(1).exe" or virus link. Delete the
file immediately.
- Make sure your computer's anti-virus software is up-to-date (go to your
anti-virus company’s Web site or call them to get more
information).
- Back up the data on your hard drive(s) on a regular basis.
- Be cautious about opening messages from people you do not know.

Remember that in MSN Messenger you can control who is on your buddy list and
can send you messages.

For more information about protecting your computer from viruses and about
viruses in general, go to the McAfee website at:
http://vil.mcafee.com/dispVirus.asp?virus_k=99077&

To remove this worm, you must:

Terminate the application registered as MsgSprd. Delete infected files. Remove
the registry value that was added by the worm.

To terminate the application:
1. Press Ctrl+Alt+Delete one time.
2. If you are running Windows NT/2000, click Task Manager.
3. In the list box (on the Applications tab if you are running Windows (NT/2000)
select MsgSprd.
4. Click End Task.

To delete infected files:
1. Run LiveUpdate to make sure that you have the most recent virus definitions.
2. Start Norton AntiVirus (NAV), and run a full system scan. Be sure that NAV
is configured to scan all files.
3. Delete all files that are detected as W32.Annoying.Worm.

To edit the registry:

CAUTION: We strongly recommend that you back up the system registry before you
make any changes. Incorrect changes to the registry could result in permanent
data loss or corrupted files. Please make sure that you modify only the keys
specified. Please see the document How to back up the Windows registry before
you proceed. This document is available from the Symantec Fax-on-Demand system.
In the U.S. and Canada, call (541) 984-2490, select option 2, and then request
document 927002.
1. Click Start, and click Run. The Run dialog box appears.
2. Type regedit and then click OK. The Registry Editor opens.
3. Navigate to the following key:
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run
4. In the right pane, delete the following value: MSN Messenger %download
location%\PIC1324.exe
5. Click Registry, and then click Exit.

For additional online help, please go to:
http://messenger.msn.com/support/helphome.asp


Sincerely,
MSN Messenger Support


------------------
Amanda
Reply With Quote
  #2  
Old August 22, 2001, 05:35 am
Techguy's Avatar
Techguy Techguy is offline
Forum Administrator
Elusive Member
 
Join Date: Nov 2000
Location: Cambridge, UK
Posts: 6,716
Rep Power: 15
Techguy will become famous soon enough
Default

Welcome to Help From Techs!
Some more on this:
http://www.helpfromtechs.com/ubb/For...ML/000476.html
http://www.helpfromtechs.com/ubb/For...ML/000377.html

------------------
Techguy
__________________
Were these forums helpful to you? - Recommend us to a friend
Reply With Quote
  #3  
Old August 22, 2001, 07:49 pm
mandapanda2002 mandapanda2002 is offline
New Member
 
Join Date: Aug 2001
Posts: 2
Rep Power: 5
mandapanda2002 is on a distinguished road
Default

The choke.exe virus you gave links to is not the same as the Pic1324 virus. I know because I received both, but at different times.



------------------
Amanda
Reply With Quote
  #4  
Old September 29, 2001, 07:38 pm
Aegis Aegis is offline
New Member
 
Join Date: Sep 2001
Location: ON
Posts: 1
Rep Power: 5
Aegis is on a distinguished road
Default

Whenever I try and message someone on MSN now, the chat window is all grey. I (like an idiot) clicked on the PIC1324(1)(1)(5)(2)(1)(1)(1)(1)(2).exe and now this happens. Is there anything new on this? HELP!
Reply With Quote
  #5  
Old September 30, 2001, 12:17 am
HKEd HKEd is offline
Regular Member
 
Join Date: Nov 2000
Location: Hong Kong
Posts: 209
Rep Power: 5
HKEd is on a distinguished road
Default

Hi Aegis...the above info should be enough to help deal with this worm. Here's a little more:

W32.Annoying.Worm

The delightful Jerry, author of this worm, who comes "in piece" (wish it was "in pieces"), has even included a readme.txt file with uninstall instructions:

How to remove me:

1) Click Start, select Run. The Run dialog box pops up.
2) Type: msconfig The System Configuration Utility pops up.
3) Click the Startup tab at the top. In the list, find MsgSprd, Messenger, or pic1324, uncheck, press Apply, then press Ok.
4) Restart your computer Or press Ctrl - Alt - Del, select MsgSprd from the list, then press End Task.

You may freely delete the files or the 'C:\Messenger1324' directory.


*Sigh* - a$$wipes like Jerry make me sick.

You may need to uninstall/reinstall Messenger after ridding your system of this bugger. Good luck.
__________________
"And that's all I have to say about that."
Reply With Quote
  #6  
Old February 17, 2008, 08:04 pm
skls29 skls29 is offline
New Member
 
Join Date: Feb 2008
Posts: 1
Rep Power: 1
skls29 is on a distinguished road

Can someone please help me? I got the virus too and I dont know what to do. The picture file is called pic003.jpg-profiles.msn.com ??? Has anyone heard of it or have any idea of how to remove it? Any help is appreciated! Thanks!
Reply With Quote
  #7  
Old June 11, 2008, 08:41 pm
Doushite_imo Doushite_imo is offline
New Member
 
Join Date: Jun 2008
Posts: 3
Rep Power: 1
Doushite_imo is on a distinguished road
Default

Anyone heard of a virus going round in MSN.... i got caught by it... i was talking with a friend and it came up with a link.. asking if it was me and in the link it contained my username along with a youtube link.... it smashed me with a worm.. my virus checker got it.. however, since then i have been having huge trouble with messenger... everytime i sign in.. it signs me out.. can anyone help??
Reply With Quote
  #8  
Old August 20, 2008, 10:53 am
raypen raypen is offline
New Member
 
Join Date: Aug 2008
Posts: 2
Rep Power: 1
raypen is on a distinguished road



I received a virus similar yesterday in an instant messaging chat. The other person (in an internet cafe in Mexico) had no idea it was sent. It was in a zip file, I hit receive and it said not able to receive and to check the settings on my received files. However it was in my received files and not picked up by current McAfee. The problem I have after tinkering around for an hour or so is that ctrl alt delete has been "disabled by administrator". This whole virus seems dormant and then acts up after a while by sending an instant message from my msn chat id to yahoo and freezing screens. I don't have to have Yahoo chat signed in. Also it has some nasty language sort of like calling you an idiot in espanol and another time stating that all contacts in this folder will be eliminated (doesn't do that). Does anyone know how or what this is? I found some text files referring to lcapi0. Help please; anyone!
Reply With Quote
  #9  
Old August 20, 2008, 10:54 am
raypen raypen is offline
New Member
 
Join Date: Aug 2008
Posts: 2
Rep Power: 1
raypen is on a distinguished road

kk

Last edited by raypen: August 20, 2008 at 12:29 pm. Reason: duplicate
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 06:22 pm.


Copyright © HFT Online, 2000-2006. All rights reserved.
vBulletin Copyright © Jelsoft Enterprises Ltd., 2000-2010.