Help!!! Last time my friend sent me MSN-9.0plusi.exe through MSN and I think its update version. Then I recieve and opened it. Now, when I open my MSN messenger it will auto send message about MSN-9.0plusi.exe
Is it a kind of spyware?

I tried many kind of programs and softwares try to remove it such as Spyware Doctors, Ad-Aware SE but failed. It say its not spyware. *sigh* :rolleyes:

I tried to delete it too but it will auto come out again.
How to remove it?? Can help me please?? Thanks!!!

Dani AI

Generated

For : the behavior you describe — an executable that reappears and is automatically sent via your messenger — strongly fits the pattern of an IM worm that keeps a persistent component and uses your contact list to spread. Immediate priorities are to stop propagation and preserve evidence: disconnect the PC from the network, quit the messenger client, and change any related passwords from a known-clean machine. Do not run the suspicious file again.

Here are practical next steps to collect useful data and remove persistence:

  • Save the suspicious file to removable media (do not double-click it) and submit it to a multi-engine scanner such as VirusTotal to see how many engines detect it.

  • Use Autoruns to enumerate and disable startup/persistence entries so the executable cannot be relaunched at logon: Autoruns for Windows.

  • Use Process Explorer to find the running process, view its full path and handle usage, and terminate it if necessary before deleting the file: Process Explorer.

  • Boot to Safe Mode (network disabled if possible) to remove files and any scheduled tasks or services that restore them. Run a current full AV scan plus a second-opinion on-demand scanner (for Windows, the Microsoft Safety Scanner is one example).

  • If removal cannot be completed, back up personal files, wipe the system, and reinstall. Worms that persist via hidden services or injected code can be difficult to remove completely.

As suggested, post the multi-engine report and the outputs from Autoruns and a process list (full paths and exact process names). Those artifacts let responders point to the precise registry keys, files, or services to remove. Also warn your contacts so they do not run the file.

Hi,
Which is your Operating System? If it is Windows 2000/XP, please download and install it. Doulbe-click on its icon to run it. You will get the warning "Database not found". Click "OK" and in the main Ewido screen, click "Update" button and click "Start update".
After updating, click on the "Scanner" button in the left menu, then click on the "Start" button.
If ewido finds anything, it will pop up a notification. You can select "Clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
When the scan finishes, click on "Save Report". This will create a text file.

After this, download HijackThis and unzip it to dedicated folder (like C:\HijackThisFolder\hijackthis.exe).
Then run it and click the button Do a System scan and save log file. HijackThis will perform a scan and saves the log file as hijackthis.log in the same folder where it is installed and it also opens the file automatically.
Copy the entire contents of the file and post it here along with Ewido log.

Also, please upload and scan the MSN-9.0plusi.exe file at http://virusscan.jotti.org/
Upload the file, and click "Submit" to scan it. Post the scan results.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.