Author Topic: MSN opens conversations  (Read 2220 times)

0 Members and 1 Guest are viewing this topic.

Strupi

  • Guest
MSN opens conversations
« on: January 09, 2011, 09:56:15 PM »
Hello,
My MSN is opening conversations and send's the next text " Foto :D hxxp://apps.facebook.com/nnettetoll/photo.php?=lizzyverhoeven@hotmail.com" (the mail adress is from the receiver)
I have run the Avast scanner and windows defender. Nothing helped.
Anyone a solution for this problem?

I'm running on windows Vista
« Last Edit: January 09, 2011, 10:58:13 PM by igor »

argus

  • Guest
Re: MSN opens conversations
« Reply #1 on: January 09, 2011, 10:46:58 PM »
W32.Yimfoca worm

Strupi, Strupi  ;D  

The next time Do not click on links that you are not sure what they are
Here's what it is http://www.virustotal.com/file-scan/report.html?id=722542629a0fe95392fa72bbe669429fd479a4908b823a0f183089f2213adbd1-1294608139

Malwarebytes removes the worm  http://www.malwarebytes.org/mbam.php

Code: [Select]
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
c:\WINDOWS\nvsvc32.exe (Trojan.Agent) -> 1016 -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NVIDIA driver monitor (Trojan.Agent) -> Value: NVIDIA driver monitor -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NVIDIA driver monitor (Trojan.Agent) -> Value: NVIDIA driver monitor -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run\NVIDIA driver monitor (Malware.Trace) -> Value: NVIDIA driver monitor -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\nvsvc32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
« Last Edit: January 09, 2011, 10:53:41 PM by argus »