Reply
How to Remove MSN Virus Project 1/ Generic2.EXO / Backdoor.Generic3.SAT
Old 11-30-2007, 01:38 PM How to Remove MSN Virus Project 1/ Generic2.EXO / Backdoor.Generic3.SAT
Average Talker

Posts: 20
Trades: 0
This MSN virus is a new virus which spreads via MSN Messenger. Once a computer is infected it will send copies of itself to every online contact on the infected users contact list.

Important Notice: A new MSN Virus removal tool has been created. It is recommend you try this first by downloading and running this before trying the instructions below. You can download the tool HERE. Please let us know if it worked for you so we can keep improving our products.
The message says (or similar to):
“is that u on that photo
http://lollypics.xx.funpic.org/pictu...656.jpg” (link edited to prevent people getting further infected)

Other links may include:

http://www.picture-database99.com


Once clicked, it will open Internet Explorer and prompt you to download a file called photo656.pif or another file with a similar name (note: it is now a .pif file being downloaded, not a .jpg). Once run, the computer will be infected.
This virus also installs a toolbar into Internet Explorer called “Toolbar888”.
AVG Antivirus Detects this threat as:
- Trojan horse Generic2.EXO
- Trojan horse BackDoor.Generic3.SAT
How to Remove MSN Virus Project 1/ Generic2.EXO / Backdoor.Generic3.SAT:
Goto: Start > Control Panel > Add/Remove Programs.
Find Toolbar888 and click the “Change/Remove” button to uninstall it

Press CTRL+ALT+DELETE all at the same time so you are viewing the “Process” Tab. If you find any (or all) of the following (dont worry if you cant find all of them):
  • Update.exe
  • goll.exe
  • loadadv455.exe
  • drsmartload.exe
  • goll.exe
  • two.exe
  • vcncr.exe
  • rorjxk.exe
  • eyewblbby.exe
  • cgqrvrva.exe
Highlight the name and click the button “End Process” to each of the above you find in the list.
Find and Delete The Following Folders and their Contents:
  • C:\Program Files\Common Files\{28676FB5-0AE9-3081-1205-03030930003d}\
  • C:\Program Files\Common Files\{38676FB5-0AE9-3081-1205-03030930003d}\
Find and Delete the Following Files with the Folder (NOT the folder itself):
In the folder: C:\Windows\system32\ (dont worry if you cant find all of them)
Find and Delete:
  • goll.exe
  • drv.exe
  • loadadv455.exe
  • one.exe
  • two.exe
In the folder: C:\Documents and Settings\[current user]
(replace [current user] with the name you are currently logged on as, dont worry if you cant find all of them)
Find and Delete:
  • goll.exe
  • drv.exe
  • loadadv455.exe
  • one.exe
  • two.exe
In the folder: C:\ (main level of C drive, be careful here, dont worry if you cant find all of them)
Find and Delete:
  • goll.exe
  • drv.exe
  • loadadv455.exe
  • one.exe
  • two.exe
  • drsmartload.exe
Update your Antivirus with the most current virus definitions and run a full system scan to clean up any remaining files. If you do not have any antivirus software. AVG Free is a great option.
You may need to reinstall MSN Messenger again.

If you like this post then please consider subscribing to our full feed RSS. You can also subscribe by Email and have new posts sent directly to your inbox.
anas55 is offline
Reply With Quote
View Public Profile
 
 
When You Register, These Ads Go Away!
Old 11-30-2007, 01:48 PM Re: How to Remove MSN Virus Project 1/ Generic2.EXO / Backdoor.Generic3.SAT
whym's Avatar
Defies a Status

Posts: 3,429
Trades: 0
No need to copy and paste!

http://www.technibble.com/how-to-rem...orgeneric3sat/

It would probably be better to tell people about it via a link (when you are a respected member, so you don't seem like a spammer).

Thanks for the information anyway. I'll remember this if I get infected sometime.
__________________
Whym Web Design

Last edited by whym; 11-30-2007 at 01:49 PM..
whym is offline
Reply With Quote
View Public Profile Visit whym's homepage!
 
Old 12-02-2007, 08:04 AM Re: How to Remove MSN Virus Project 1/ Generic2.EXO / Backdoor.Generic3.SAT
Average Talker

Posts: 20
Trades: 0
i know that's no need for copy past but i want be publishing the website that's why :d
anas55 is offline
Reply With Quote
View Public Profile
 
Old 12-04-2007, 08:35 AM Re: How to Remove MSN Virus Project 1/ Generic2.EXO / Backdoor.Generic3.SAT
dansgalaxy's Avatar
Eat, Sleep, Code

Posts: 6,516
Name: Dan
Location: Swindon
Trades: 0
What about the other new one which is REALLLY PEVING ME OFF!! and i dont even have it!!!

where (i think) someone has nicked users passwords, and then the thing automatically logs in sends a url to everyone and the logs off (ur is soemthing like www.free-somin-somin.com )

the reason im saying they nicked the passord and not a normal virus because, a friend logged on when she was in bed and her computer (and net connection) was turned off...

also i know people who were on msn have been logged offf the message send, and then been able to log back in.

im advising people to change their passwords...

Anyone know any thing about it?
__________________
Discounted Web Hosting With XDnet!
>> Get 25% of hosting~ Promo: Webmaster-talk <<
dansgalaxy is online now
Reply With Quote
View Public Profile Visit dansgalaxy's homepage!
 
Reply     « Reply to How to Remove MSN Virus Project 1/ Generic2.EXO / Backdoor.Generic3.SAT
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML

 


Page generated in 0.10356 seconds with 13 queries