AOL Instant Messanger Virus

  • HeLpMePLz
  • Newbie
  • Newbie
  • HeLpMePLz
  • Posts: 13

Post 3+ Months Ago

ok, heres the problem... i somehow got this virus off of AIM and it somehow is spreading to everyone on my buddylist even tho they didnt click a link or anything... i've found the source of the virus (6jd5v94TG.exe and erfi009p.exe) but i cant delete them. i cant even open task manager because the virus shuts it down immediately and continually puts up an away message on my AIM. Even if i shut down AIM, a pop up keeps coming saying that i need to change a proxy and it signs me back on AIM.
SOME PLEASE HELP!!!

//please don't use all caps subjects -- b_heyer
  • Anonymous
  • Bot
  • No Avatar
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post 3+ Months Ago

  • ATNO/TW
  • Super Moderator
  • Super Moderator
  • User avatar
  • Posts: 23456
  • Loc: Woodbridge VA

Post 3+ Months Ago

I have no idea if this will help you, but read the post in it's entirety (It's the onl;y thing I could find quickly that resembles your problem) :

http://www.jacobgrier.com/blog/archives/000069.html
  • Foxy
  • Guru
  • Guru
  • User avatar
  • Posts: 1038
  • Loc: places..

Post 3+ Months Ago

Well at any rate, aol messanger isnt a very good messanger, just because a few people use it, then everyone starts... then that spreads like a virus, lol.

MSN messanger is nice.
  • rjstephens
  • Professor
  • Professor
  • User avatar
  • Posts: 774
  • Loc: Brisbane, Australia

Post 3+ Months Ago

msn sucks. get Trillian

To get rid of your virus go to Panda software activescan

if only activeScan worked as well for viruses that infect people :( I feel terrible
  • SKATER
  • Student
  • Student
  • User avatar
  • Posts: 76

Post 3+ Months Ago

HeLpMePLz wrote:
ok, heres the problem... i somehow got this virus off of AIM and it somehow is spreading to everyone on my buddylist even tho they didnt click a link or anything... i've found the source of the virus (6jd5v94TG.exe and erfi009p.exe) but i cant delete them. i cant even open task manager because the virus shuts it down immediately and continually puts up an away message on my AIM. Even if i shut down AIM, a pop up keeps coming saying that i need to change a proxy and it signs me back on AIM.
SOME PLEASE HELP!!!

//please don't use all caps subjects -- b_heyer


boot to safe mode and try it that way. if you are using XP boot to safe mode w/ networking and goto to http://www.antivirus.com and use the free online scan
  • SecureITGroup
  • Proficient
  • Proficient
  • User avatar
  • Posts: 293

Post 3+ Months Ago

Another online virus scan i seen to be very helpful is http://housecall.trendmicro.com/ I have found it to work great if you cant get to your anti virus for some reason or if you don’t have one.
  • SecureITGroup
  • Proficient
  • Proficient
  • User avatar
  • Posts: 293

Post 3+ Months Ago

This is from PC World i have justseen this after reading this post so i thought i would add this.

Viruses Target IM

Virus writers and scammers are now plying their trade via instant messaging. we identify the real threats and offer tips on avoiding them.

Liane Cassavoy
From the June 2004 issue of PC World magazine
Posted Tuesday, May 04, 2004
When it comes to viruses and worms, e-mail gets all the attention--but now that instant messaging has infiltrated both home and office, it too has become an attractive and easy target for virus writers.

From 2002 to 2003, worms and viruses that spread via IM and peer-to-peer networks increased 400 percent, according to Symantec's Internet Security Threat Report. Already this year, we've seen the Jitux.A and Bizex worms targeting MSN Messenger and ICQ, respectively.



Jitux.A spread itself by tapping users' IM contacts, but Bizex had more malicious intent: It sent you a link to a Web site that scanned your PC for data on your electronic payments and finances. The site was quickly shut down once the worm was discovered, but no one is sure how much data was collected before then.

Expect the threats to continue. As users get more adept at stopping traditional attacks, virus writers will look for softer targets, says Bill Adler, president of CyberScrub, a PC security software vendor. "Instant messaging, for many reasons, is a softer target."

But don't scrap your IM client just yet. Because most IM viruses and worms can't propagate automatically--they require you to click a link or download an applet--you can avoid many of the threats if you practice safe computing. See "Chat Protection" at the bottom of this page for tips on keeping yourself and your data safe.


No Buddy Of Mine
Steve Sanders, a student at the University of California at Berkeley, learned this safety lesson the hard way. He was reading a buddy's profile on AOL Instant Messenger when he saw a message that read, "I can't believe I found [Sanders's screen name] picture here. HAHAHA," with a hyperlink to take him to a site where he could view the photos. Sanders clicked the link and agreed to download the "necessary" applet to view the photos.

"I'm usually more careful than that," Sanders says, but the site "looked legitimate, and...it was directed right at me, so I installed the software."

The site had no photos of Sanders; instead it held the Buddypicture.net Trojan horse, which would have installed adware and spyware onto his PC and distributed itself by placing its link in his AIM profile. Luckily, his antivirus software caught it.

Another prime example is the Osama Found game, which circulated rapidly via AIM earlier this year. It spread by sending a link to AIM users, inviting them to download a game in which they could pretend to catch bin Laden. Users who clicked got the game--as well as BuddyLinks, a program that grabbed all of the user's IM contacts and sent them the same message.


Limits to threats
The very nature of instant messaging--its informality and immediacy--worsens the danger from worms, viruses, and other malware. "People tend to let their guard down when it comes to instant messaging, while we have more a healthy skepticism when it comes to e-mail," explains Bryson Gordon, a senior manager with McAfee Security's Consumer Division.

However, the most popular IM clients--such as AIM and Yahoo Messenger--work through closed networks, meaning that users can communicate only with others on the same service (unless you are one of the few who employ third-party clients, such as Trillian, that let you exchange messages with others on multiple networks). That lack of interoperability may be annoying, but it also helps to curtail the spread of viruses and makes IM a less appealing target than e-mail.

And unlike Internet Explorer or Windows, IM apps--at least so far--have fewer published holes through which viruses and worms can spread without a victim's aid.


Software Help
Antivirus and security software vendors have extended protection coverage to IM. For example, Zone Labs, maker of the popular ZoneAlarm firewall, last year released IMSecure, a $20 program that encrypts messages and blocks potentially hazardous URLs.

Symantec's Norton Antivirus includes instant message scanning, and McAfee added the same feature to its August release of VirusScan 8. Both of these programs promise to remove viruses from files received via IM, and to protect against viruses that may be downloaded through URLs or links received in messages.

And here's some more good news: In informal PC World tests of several antivirus and security applications--with or without special IM components--all caught known viruses sent via AIM.

No antivirus program or firewall--both considered must-haves for every PC user--can prevent all virus attacks. Your vigilance remains your best defense. Says Oliver Friedrichs, a senior manager at Symantec Security Response, "The primary reason why these threats are successful is that people continue to trust content that they receive."


Chat Protection


To prevent infection, keep your IM client updated and follow these tips:

Be wary of files sent via IM, especially those with .exe and .scr extensions, or ones purporting to be games. For best protection, verify with senders before opening.
Never click an unsolicited link fed via IM, or one lurking in another member's profile or away message.
Check your antivirus company's home page or a general virus site, such as About.com's antivirus.about.com, for news on current threats.
Evaluate your protection at Eicar.org, which has an antivirus test.
Upgrade employees' IM clients. Lotus offers its own secure IM program; AOL, Microsoft, and Yahoo all have paid corporate IM services with built-in security. Products from FaceTime and Akonix help secure existing consumer IM apps and let you filter messages by content.
See this month's Privacy Watch for help with IM spam, too.
  • rjstephens
  • Professor
  • Professor
  • User avatar
  • Posts: 774
  • Loc: Brisbane, Australia

Post 3+ Months Ago

SecureITGroup wrote:
Another online virus scan i seen to be very helpful is http://housecall.trendmicro.com/ I have found it to work great if you cant get to your anti virus for some reason or if you don’t have one.


SecureITGroup,
I use housecall as well but ActiveScan does its thing faster and it seems to pick up viruses that HouseCall misses.
  • SecureITGroup
  • Proficient
  • Proficient
  • User avatar
  • Posts: 293

Post 3+ Months Ago

ActiveScan i gave it a try and it works great. It is alittle more graphical that trends house call too. Ill have to scan my servers just to make sure i am clean according to panda ActiveScan Thanks.
  • bannerpad
  • Novice
  • Novice
  • bannerpad
  • Posts: 18

Post 3+ Months Ago

What is the difference between ActiveScan and such software as Norton Antivirus or McAfee VirusScan. Can those do the same job or is Active Scan better in some cases such as this IM virus.
  • SecureITGroup
  • Proficient
  • Proficient
  • User avatar
  • Posts: 293

Post 3+ Months Ago

Having a Virus scan installed can do real-time scans meaning that if you i are downloading a file which contains a virus and it gets half way done when it sees the virus it will stop it immediately. It is a nice service to have. As where a online virus scan will only scan your computer when you have it scanning. Online virus scans are good if you have a virus and something has happen to your installed antivirus you could use this as a good result. I always tell people when you get a computer do the following:

1: Run Windows Update.

2: Install a Antivirus.

3: Install a spyware/Adaware Removers.

4: Keep you computer clean by using compressed air to clean the dirt off the fans and components and keep the power supply clean too. Lots of people let the power supply get dirty.

If the fan stops spinning in the power supply it could damage the mobo, processor, drives and so on.

Post Information

  • Total Posts in this topic: 11 posts
  • Users browsing this forum: No registered users and 31 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
 

© 1998-2014. Ozzu® is a registered trademark of Unmelted, LLC.