<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>msn suprise in Security</title>
<link>http://www.dslreports.com/forum/r13164886</link>
<description></description>
<language>en</language>
<pubDate>Thu, 10 Dec 2009 04:22:04 EDT</pubDate>
<lastBuildDate>Thu, 10 Dec 2009 04:22:04 EDT</lastBuildDate>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13200840</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : It appears I have also, recieved stuff like this from a contact, I knew right away, that links that are sent over msn randomly are usually viruses. I think you have one of the Kelvir versions virus.. I suggest reformatting if ANY of you have visited that website. And remember, UNLESS you ask for a link, don't click one. And for the person who made this thread, you have a virus.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13200840</guid>
<pubDate>Mon, 18 Apr 2005 15:35:16 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13175334</link>
<description><![CDATA[<A HREF="/useremail/u/839734"><b>DevilFrank</b></A> : See here also:<br>&raquo;<A HREF="http://www.symantec.com/avcenter/venc/data/w32.kelvir.t.html" >www.symantec.com/avcenter/venc/d&middot;&middot;&middot;r.t.html</A><br><SMALL>--<br>Regards from Germany. Please excuse my stumbling English</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13175334</guid>
<pubDate>Fri, 15 Apr 2005 01:43:59 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13173605</link>
<description><![CDATA[<A HREF="/useremail/u/933831"><b>Lefty</b></A> : One of my contacts has this same exact problem. Her msn keeps sending,<br><br>"Its You!"<br><br>"http://***************/pictures.php?email=***************.com"<br> <br>Update: The download link is from T35 hosting. I emailed the president asking him to cancel "jackofspades" that is the user that is hosting the virus.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13173605</guid>
<pubDate>Thu, 14 Apr 2005 21:40:09 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13173171</link>
<description><![CDATA[<A HREF="/useremail/u/1144666"><b>jabarnut</b></A> : Heheh....This is one very interesting thread to say the least! <br><br>Wonder what ever happened to  unimind <A HREF="/useremail/u/623723"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>???  :o  :hmm:<br><SMALL>--<br>I had a life once.....now I have a Computer and a Modem.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13173171</guid>
<pubDate>Thu, 14 Apr 2005 20:53:55 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13172655</link>
<description><![CDATA[<A HREF="/useremail/u/1030204"><b>NetFixer</b></A> : <div class="bquote"><SMALL>said by  novaflare <A HREF="/useremail/u/570051"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>Hmm i guess i know where to go if i decide to test a new anti spyware app heh<br> </DIV>I was thinking the same thing. In fact, I bookmarked it for future testing purposes.<br><SMALL>--<br><A HREF="http://www.nature-pics.com">We can never have enough of nature.</A><BR>We need to witness our own limits transgressed, and some life pasturing freely where we never wander.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13172655</guid>
<pubDate>Thu, 14 Apr 2005 20:04:20 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13172628</link>
<description><![CDATA[<A HREF="/useremail/u/1030204"><b>NetFixer</b></A> : I suspect that most AV providers will have updated their def files by now for the new Kelvir variants. F-Prot did not detect it last night, but the updates today caught it with no problems (including the copy from last night which was still in my browser cache).<br><SMALL>--<br><A HREF="http://www.nature-pics.com">We can never have enough of nature.</A><BR>We need to witness our own limits transgressed, and some life pasturing freely where we never wander.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13172628</guid>
<pubDate>Thu, 14 Apr 2005 20:02:14 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13172551</link>
<description><![CDATA[<A HREF="/useremail/u/570051"><b>novaflare</b></A> : Hmm i guess i know where to go if i decide to test a new anti spyware app heh]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13172551</guid>
<pubDate>Thu, 14 Apr 2005 19:55:53 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13172509</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : <div class="bquote"><SMALL>said by  bpm3k <A HREF="/useremail/u/1058588"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>I went to the malignancy website and let it have its way with my computer.  </DIV>WOW!<br>I hope the LU just released has got this covered [ in part - at least]<br>&raquo;<A HREF="/forum/remark,13172211">NAV IU & LU   --  14 April 2005</A><br><br>;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13172509</guid>
<pubDate>Thu, 14 Apr 2005 19:51:15 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13172457</link>
<description><![CDATA[<A HREF="/useremail/u/1058588"><b>bpm3k</b></A> : I went to the malignancy website and let it have its way with my computer.  It was fully updates xp sp2 install.  Only protection it had turned on was spybot immunize and a NAT firewall.  The computer was clean before i went to the website.  Here is the hijackthis log:<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 11:44:03 PM, on 04/13/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Norton Internet Security\ISSVC.exe<br>C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\GEARSec.exe<br>C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe<br>C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE<br>C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>C:\PROGRA~1\Toolbar\TBPSSvc.exe<br>C:\Program Files\Belkin Bulldog Plus\upsd.exe<br>C:\Program Files\Common Files\WinTools\WToolsS.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\WINDOWS\system32\nvraidservice.exe<br>C:\WINDOWS\system32\RUNDLL32.EXE<br>C:\Program Files\Media Access\MediaAccK.exe<br>C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe<br>C:\Program Files\Internet Optimizer\optimize.exe<br>C:\PROGRA~1\Toolbar\TBPS.exe<br>C:\Program Files\ISTsvc\istsvc.exe<br>C:\WINDOWS\vjwrsyo.exe<br>C:\Program Files\Common Files\WinTools\WSup.exe<br>C:\WINDOWS\system32\imgtuf.exe<br>C:\Program Files\AutoUpdate\AutoUpdate.exe<br>C:\WINDOWS\system32\gah95on6.exe<br>C:\PROGRA~1\Toolbar\PIB.exe<br>C:\Program Files\Media Access\MediaAccess.exe<br>C:\program files\zango\zango.exe<br>C:\PROGRA~1\LeapFrogMessenger\LeapFrogMessenger.exe<br>C:\WINDOWS\system32\spas.exe<br>c:\PROGRA~1\Toolbar\radio.exe<br>C:\WINDOWS\system32\l?gonui.exe<br>C:\WINDOWS\system32\mnmadhlp.exe<br>C:\Program Files\Belkin Bulldog Plus\MUPS.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\WINDOWS\System32\wbem\unsecapp.exe<br>C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>C:\Documents and Settings\billy\Desktop\hijackthis\HijackThis.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = &raquo;<A HREF="http://searchmiracle.com/sp.php" >searchmiracle.com/sp.php</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://www.websearch.com/ie.aspx?tb_id=50245" >www.websearch.com/ie.aspx?tb_id=50245</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://www.oemji.com" >www.oemji.com</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.oemji.com" >www.oemji.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = &raquo;<A HREF="http://www.websearch.com/ie.aspx?tb_id=50245" >www.websearch.com/ie.aspx?tb_id=50245</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &raquo;<A HREF="http://www.websearch.com/ie.aspx?tb_id=50245" >www.websearch.com/ie.aspx?tb_id=50245</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa<br>R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &raquo;<A HREF="http://www.oemji.com/side_search.html" >www.oemji.com/side_search.html</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)<br>F3 - REG:win.ini: load=C:\Program Files\WAFFLEz\mlg1.exe<br>O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll<br>O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll<br>O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll<br>O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - C:\WINDOWS\EliteSideBar\EliteSideBar 08.dll<br>O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll<br>O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe<br>O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe<br>O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe<br>O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"<br>O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe<br>O4 - HKLM\..\Run: [etbrun] C:\windows\system32\eliteins32.exe<br>O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe<br>O4 - HKLM\..\Run: [uchHPF88E] C:\WINDOWS\vjwrsyo.exe<br>O4 - HKLM\..\Run: [AutoLoaderAproposClient] "C:\DOCUME~1\billy\LOCALS~1\Temp\cxtpls_loader.exe" /PC=CP.IST /ForSupportedBrowsers /ShowLegalNote=nonbranded<br>O4 - HKLM\..\Run: [v33V38i] imgtuf.exe<br>O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"<br>O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe<br>O4 - HKLM\..\Run: [zango] c:\program files\zango\zango.exe<br>O4 - HKLM\..\Run: [LFM] C:\PROGRA~1\LeapFrogMessenger\LeapFrogMessenger.exe<br>O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySpotter.exe -onreboot<br>O4 - HKCU\..\Run: [Ettm] C:\WINDOWS\system32\spas.exe<br>O4 - HKCU\..\Run: [Elatiieo] C:\WINDOWS\system32\l?gonui.exe<br>O4 - HKCU\..\Run: [e0s9RUG8S] mnmadhlp.exe<br>O4 - Global Startup: MUPS.lnk = C:\Program Files\Belkin Bulldog Plus\MUPS.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll<br>O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll<br>O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: v3cab - &raquo;<A HREF="http://searchmiracle.com/cab/2.cab" >searchmiracle.com/cab/2.cab</A><br>O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - &raquo;<A HREF="http://static.windupdates.com/cab/CDT/ie/bridge-c46.cab" >static.windupdates.com/cab/CDT/i&middot;&middot;&middot;-c46.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1109900464234" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;00464234</A><br>O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - &raquo;<A HREF="http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab" >www.xxxtoolbar.com/ist/softwares&middot;&middot;&middot;dult.cab</A><br>O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - &raquo;<A HREF="http://www.mt-download.com/MediaTicketsInstaller.cab?refid=3965" >www.mt-download.com/MediaTickets&middot;&middot;&middot;fid=3965</A><br>O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe<br>O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe<br>O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe<br>O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe<br>O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE<br>O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>O23 - Service: WebSeach Toolbar support NT service (TBPSSvc) - Unknown owner - C:\PROGRA~1\Toolbar\TBPSSvc.exe<br>O23 - Service: UPS - UPSentry Service (UPSentry_Smart) - Delta - C:\Program Files\Belkin Bulldog Plus\upsd.exe<br>O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13172457</guid>
<pubDate>Thu, 14 Apr 2005 19:46:03 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13166642</link>
<description><![CDATA[<A HREF="/useremail/u/818836"><b>Schouw</b></A> : The file downloaded is an sfx archive.<br><br>It contains a new Kelvir variant, IM-Worm.Win32.Kelvir.k and Backdoor.Win32.Rbot.gen.<br><SMALL>--<br>Not speaking for Kaspersky Lab</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13166642</guid>
<pubDate>Thu, 14 Apr 2005 04:50:07 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13166327</link>
<description><![CDATA[<A HREF="/useremail/u/1058588"><b>bpm3k</b></A> : I downloaded the file from the OP.  Then i went to the main malignancy website on my test computer.  And WOW, it does bad things.  I will post a hijackthis log soon.<br>Here is jotti results:<br><br>AntiVir  Found nothing <br>Avast  Found nothing <br>AVG Antivirus  Found nothing <br>BitDefender  Found BehavesLike:Win32.IRC-Backdoor (probable variant)  <br>ClamAV  Found nothing <br>Dr.Web  Found nothing <br>F-Prot Antivirus  Found nothing <br>Fortinet  Found nothing <br>Kaspersky Anti-Virus  Found Backdoor.Win32.Rbot.gen  <br>mks_vir  Found Trojan.Rbot.Lv  <br>NOD32  Found nothing <br>Norman Virus Control  Found nothing <br>VBA32  Found nothing <br><br>Here is virus total results:<br>Antivirus Version Update Result <br>AntiVir 6.30.0.7 04.13.2005 no virus found <br>AVG 718 04.13.2005 no virus found <br>BitDefender 7.0 04.13.2005 BehavesLike:Win32.IRC-Backdoor <br>ClamAV devel-20050307 04.14.2005 no virus found <br>DrWeb 4.32b 04.14.2005 no virus found <br>eTrust-Iris 7.1.194.0 04.14.2005 Win32/Kelvir.G!SFX!Worm <br>eTrust-Vet 11.7.0.0 04.13.2005 no virus found <br>Fortinet 2.51 04.14.2005 no virus found <br>F-Prot 3.16a 04.13.2005 no virus found <br>Ikarus 2.32 04.13.2005 no virus found <br>Kaspersky 4.0.2.24 04.14.2005 Backdoor.Win32.Rbot.gen <br>McAfee 4468 04.13.2005 W32/Kelvir.worm.gen <br>NOD32v2 1.1060 04.14.2005 no virus found <br>Norman 5.70.10 04.12.2005 no virus found <br>Panda 8.02.00 04.13.2005 no virus found <br>Sybari 7.5.1314 04.14.2005 Win32/Kelvir.G!SFX!Worm <br>Symantec 8.0 04.14.2005 no virus found]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13166327</guid>
<pubDate>Thu, 14 Apr 2005 02:06:55 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13165671</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : No worries friend! <br><br>It WOULD be a good idea to follow the instructions here: &raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/8428">I think my computer is infected or hijacked. What should I do?</A>  Just to be sure that nothing made it in.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13165671</guid>
<pubDate>Thu, 14 Apr 2005 00:01:16 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13165420</link>
<description><![CDATA[<A HREF="/useremail/u/1110758"><b>spooler0</b></A> : <div class="bquote"><SMALL>said by  unimind <A HREF="/useremail/u/623723"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR><I>"Also, is it possible that the link itself may have triggered msn to send another link to a seperate contact once it was recieved from the first contact?" </I> </DIV>You might want to download and run an A2 anti-trojan scan (A-squared).  Also try the Avast program used by Dadkins and consider the 30 free trial of TDS-3 and Trojan Hunter.<br><br>Let us know what you find.  Lots of interest here.<br><br>Mr. B is rarely wrong.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13165420</guid>
<pubDate>Wed, 13 Apr 2005 23:32:59 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13165370</link>
<description><![CDATA[<A HREF="/useremail/u/1030204"><b>NetFixer</b></A> : The domain malignancy.us is appropriately named. <br><br>Whois shows it to be a cloaked registration (the true owners identification is not available), and the url you provided attempts to automatically download an executable file. <br><br>I can only think of one reason for either a cloaked domain registration or for attempting to automatically download an executable file to a web site visitor. Need I say more?<br><SMALL>--<br><A HREF="http://www.nature-pics.com">We can never have enough of nature.</A><BR>We need to witness our own limits transgressed, and some life pasturing freely where we never wander.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13165370</guid>
<pubDate>Wed, 13 Apr 2005 23:27:53 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13165335</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : <div class="bquote"><SMALL>said by  unimind <A HREF="/useremail/u/623723"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>As I said in my first post, I have run spyware checks and norton runs 24-7. I can't find any spyware or viruses so I doubt it is due to that. I have edited my post to say I'll run a hijack this log tomorrow.<br><br>My main interest is how this link appeared, i.e. is there a programme which is involved.<br><br></DIV>By "programme" may I assume you mean the malware that you don't think you have?<br><br>Are you really under the impression that Norton or any antivirus program will prevent virus and other malware infections?  If so, you are operating under false assumptions.  The software does a decent job of detecting known threats.  But NONE of them catches everything, and NONE of them can detect all new threats, or attacks geared specifically to you.<br><br>I don't know what your problem is; it could be something as simple as HTML or Javascript redirects.  But please follow up on some of the advice given in this thread.  We have ALL taken your post seriously, and dismissing well-intentioned advice doesn't serve your cause well.  Good luck.<br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13165335</guid>
<pubDate>Wed, 13 Apr 2005 23:23:15 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13165279</link>
<description><![CDATA[<A HREF="/useremail/u/1003137"><b>garys_2k</b></A> : <div class="bquote"><SMALL>said by  unimind <A HREF="/useremail/u/623723"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>dadkins:<br><br>Thanks for your post. I'll have a look into that more tomorrow. Appreciate the fact that you have obviously taken some time to look at the matter in hand and I would like to thank you for the time that you have taken. I will look further into this when I get up tomorrow. <br><br>Richard.<br> </DIV>Good idea. Start by following ALL of the steps in the link I posted. If you don't your thread will be locked. Good night.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13165279</guid>
<pubDate>Wed, 13 Apr 2005 23:15:40 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13165266</link>
<description><![CDATA[<A HREF="/useremail/u/623723"><b>unimind</b></A> : dadkins:<br><br>Thanks for your post. I'll have a look into that more tomorrow. Appreciate the fact that you have obviously taken some time to look at the matter in hand and I would like to thank you for the time that you have taken. I will look further into this when I get up tomorrow. <br><br>Richard.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13165266</guid>
<pubDate>Wed, 13 Apr 2005 23:14:23 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13165261</link>
<description><![CDATA[<A HREF="/useremail/u/1003137"><b>garys_2k</b></A> : What are you asking? You say you got a message from someone with a link to a porn site. OK. You also say you seem to have somehow sent that same link to another person. If you didn't do this, are you asking how that went out without your help? My suggestion is that perhaps your system has been compromised and that's how that took place.<br><br>If I missed your point, I guess even after rereading your original post four times I still can't figure out what you want. Send that dos file to one of the online checkers (in the link you dismissed), I'll bet Kaspersky will ID the bad guy in it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13165261</guid>
<pubDate>Wed, 13 Apr 2005 23:13:23 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13165222</link>
<description><![CDATA[<A HREF="/useremail/u/623723"><b>unimind</b></A> : As I said in my first post, I have run spyware checks and norton runs 24-7. I can't find any spyware or viruses so I doubt it is due to that. I have edited my post to say I'll run a hijack this log tomorrow.<br><br>My main interest is how this link appeared, i.e. is there a programme which is involved. I haven't installed anything new at all over the last few days and my internet use has been just looking at news and emails for the last couple of days so nothing new has been installed or downloaded over the last 48 hours or so. <br><br>Also, is it possible that the link itself may have triggered msn to send another link to a seperate contact once it was recieved from the first contact? <br><br>I'm off to bed now. Thank you for the replies I have recieved and as stated, I'll post a hijack this log as soon as possible. If anyone has any information with regards to the site involved then I would be most grateful.<br><br>Richard. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13165222</guid>
<pubDate>Wed, 13 Apr 2005 23:10:21 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13165141</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : <div class="bquote"><SMALL>said by  unimind <A HREF="/useremail/u/623723"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>I've run anti spyware checks etc. I DON'T think than my system is infected or hijacked.<br> </DIV>Funny; <B>I</B> do.<br><br>Your instant messaging program is sending out specially coded links to your contacts, all by itself, and you don't think you're infected with anything?<br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13165141</guid>
<pubDate>Wed, 13 Apr 2005 23:01:37 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13165134</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : That would be IstBar! Nasty little POS!<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13165134?c=807570&ret=L2ZvcnVtL3IxMzE2NDg4Ni54bWw%3D"><IMG TITLE="84083 bytes" BORDER=0 WIDTH=437 HEIGHT=355 SRC="/r0/download/807570~bd97848c20e3bd40c38faf08dc70e9ec/ScreenShot027.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13165134</guid>
<pubDate>Wed, 13 Apr 2005 23:01:05 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13165089</link>
<description><![CDATA[<A HREF="/useremail/u/623723"><b>unimind</b></A> : I've run anti spyware checks etc. I DON'T think than my system is infected or hijacked.<br><br>Does anyone have any information about the mentioned site which might be of interest?<br><br>Edit<br><br>As it's late (4am) I'm going to bed now. I look forward to any suggestions, but I'll run a hijack this log tomorrow just incase it drags up anything. I doubt it is a problem due to being hijacked etc, as I was sent the link by a single contact and it was sent to a single (but different) contact.) But then, to be honest, I'm puzzled as I have not seen anything like this before, and I would like to make sure it doesn't happen again. <br><br>I'm more curious as to the nature of the link, as I would quite like to be able to ensure my contacts computer is ok. (It is a family computer which I don't have immediate access to) so I would really appreciate any information as to where this link might have come from, and why it has been automatically sent on by msn messenger)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13165089</guid>
<pubDate>Wed, 13 Apr 2005 22:57:03 EDT</pubDate>
</item>

<item>
<title>Re: msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13165064</link>
<description><![CDATA[<A HREF="/useremail/u/1003137"><b>garys_2k</b></A> : Follow these instructions:<br><br>&raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/8428">I think my computer is infected or hijacked. What should I do?</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13165064</guid>
<pubDate>Wed, 13 Apr 2005 22:54:48 EDT</pubDate>
</item>

<item>
<title>msn suprise</title>
<link>http://www.dslreports.com/forum/remark,13164886</link>
<description><![CDATA[<A HREF="/useremail/u/623723"><b>unimind</b></A> : I've just got in from a night out, and I noticed that one of my contacts has sent me an message with the following link:<br><br>The link .... <B><I>Link Removed</I> --WCB!</B><br><br>When I shut that down, I noticed that my own msn messenger has also sent a link to one of my contacts with the same link detail, but containing their own msn email address.<br><br>Out of interest, I saved the file that the link was pointed to and it was an msDOS file, which i then scanned with a fully updated copy of Norton anti-virus 2005. It showed up clean in the virus check.<br><br>From that, I went back to the original link. Loading up the page <B><I>Link Removed</I> --WCB!</B><br><br>just opened up a page which to cut a short story even further, suggested I install some spyware.<br><br>I did a search on this forum (which i thought would be the most appropriate place) and found no link to this website. I would be interested if any other member has either a link to this site, or further any information with regards to what this site trying to do.<br><br>I am currently running windows xp, with sp2. I also have the newly released version of msn 7. I have performed a full scan using ad-aware (with the latest updates) which came up clean, so i doubt that this is due to spyware. <br><br>If anyone has any ideas as to how this problem came about I would be very thankful, also, any further questions regarding network setup, computer setup or software setup which may help with regards to this problem are welcome.<br><br>Thanks for any help. <br><br>Richard.<br><br>ps, I haven't posted the link which was sent from my own msn as I would prefer to keep my contacts email privite. I have also put in some ** because I don't want to create a link to the site incase anyone clicks it and ends up with spyware on my behalf. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13164886</guid>
<pubDate>Wed, 13 Apr 2005 22:36:09 EDT</pubDate>
</item>

</channel>
</rss>
