Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: Smb Worm Msn Messenger

  1. #1
    SMB Worm spreading through MSN Messenger

    A new network virus called Worm.Win32.Smbmsn.163840 was discovered two days ago by Asia-based Global Hauri. This worm spreads through MSN Messenger through a file called SMB.EXE. If the user accepts this file, it will send itself to all contacts on his or her contact list. If the user executes it, a DOS prompt will come up for about a second and disappears. This occurs because it unzips a couple of files to the C: root and windows directories. The file also tempers with the registry (see below for details).

    Do NOT accept the file transfer of SMB.EXE (or any other suspicious file) in MSN Messenger!

    An MSN spokesperson said the company is aware of the virus, and that users' best means of protection is to have a desktop anti-virus solution already installed, and to use MSN Messenger 6's anti-virus feature. The feature enables customers to link their desktop anti-virus software to the IM client, automatically scanning incoming files for viruses.


    SOURCE

  2. Software & Hardware   -   #2
    Out of The Ordinary
    Join Date
    Feb 2003
    Posts
    3,927
    Thanks for the post sharedholder!

    BOT

  3. Software & Hardware   -   #3
    razorsharp013's Avatar Fountain of Wit
    Join Date
    May 2003
    Posts
    671
    Would the file actually be compressed in another so to not be obvious?

  4. Software & Hardware   -   #4
    An MSN spokesperson said the company is aware of the virus, and that users' best means of protection is to have a desktop anti-virus solution already installed, and to use MSN Messenger 6's anti-virus feature.
    Would anyone happen to know wich file i have to use ? I use xp pro and i don´t know wich file to use from nav. Thanks

  5. Software & Hardware   -   #5
    Regular Member BT Rep: +5
    Join Date
    Sep 2003
    Posts
    922
    right....hmmmm B)

  6. Software & Hardware   -   #6
    iMartin's Avatar ♥Home Grown♥ BT Rep: +9BT Rep +9
    Join Date
    Mar 2003
    Location
    BFE
    Posts
    1,827
    This has "Blaster Spawn" written all over it.



  7. Software & Hardware   -   #7
    Poster
    Join Date
    Dec 2002
    Location
    England
    Posts
    2,369
    Cheers for the heads up Sharedholder.

  8. Software & Hardware   -   #8
    PAiNKiLLER
    Join Date
    Sep 2003
    Location
    New York
    Posts
    917
    Hey, I've seen that file yesterday but I didn't accept it. Thank God!!! Thanks shareholder. I must be careful from now onward...

    Image Resized


  9. Software & Hardware   -   #9
    iMartin's Avatar ♥Home Grown♥ BT Rep: +9BT Rep +9
    Join Date
    Mar 2003
    Location
    BFE
    Posts
    1,827
    If you already accepted this SMB.exe file, here's how to remove it manually:

    1) Go to task manager. (Ctrl+alt+del) and select the Process tab.
    2) Click admagic.exe then click End Process
    3) Go to the C: drive and delete smb.exe and admagic.exe.
    4) Go to Windows directory and delete atl.dll, raw32x.dll, sm.dll and uz.exe.
    5) Go to the registry (Start > Run > type "regedit" > click ok) and go to HKEY_LOCAL_MACHINE\SOFTWARE\Micorosoft\Windows\CurrentVersion\Run. Delete the svchost = admagic.exe string value.



  10. Software & Hardware   -   #10
    Wolfmight's Avatar Poster BT Rep: +1
    Join Date
    Feb 2003
    Location
    Location: Location:
    Posts
    5,545
    Norton Antivirus 2003 should be able to kill it.

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •