Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,194,706 members, 7,955,670 topics. Date: Sunday, 22 September 2024 at 12:22 PM

Can't Stop This Yahoo Msger Popper! - Computers - Nairaland

Nairaland Forum / Science/Technology / Computers / Can't Stop This Yahoo Msger Popper! (1265 Views)

Hackers Steal Over 400,000 Yahoo Passwords / Learn How To Hack Yahoo Or Facebook Account For Free / Web Version of Yahoo, MSN and AOL Messenger (2) (3) (4)

(1) (Reply) (Go Down)

Can't Stop This Yahoo Msger Popper! by jiddah: 11:42am On Sep 04, 2007
how do i stop my yahoo msg from popping msgs to contacts? this often contains silly sites more or less like a virus do i have to format my system to get it off?help!
Re: Can't Stop This Yahoo Msger Popper! by Maleeq(m): 12:12pm On Sep 04, 2007
Ooops! Dearie, you've been hit by a virus! grin It spreads itself as links to all your contacts that are online. I guess you got infected when you clicked on a similar unsolicited link sent to you. Advice: Avoid clicking on suspicious links that friends might forward, it could be a virus!

Well, I have been receiving this kind of links for a while but never did click on any.

It has been reported to do some or all of this:

1: It sets your default IE page to the virus name (nsl-school.org ,coolpics.net), you can’t even change it back to other pages. If you open IE on your computer, some malicious code will automatically be executed.

2: It disables the Task manager / registry editor. So you can’t kill the Trojan process anymore. Smart move!!!

3: Files that are gonna be installed by this virus are svhost.exe , svhost32.exe , internat.exe. You can find these files in %\windows & temp\ directories.

4: It will send secured & protected information on your system to attacker!!! Watch out!

There are so many variations of these malware out there but the most common ones are nsl-school.org , lottery-news.info and coolpics.net malwares. Can you post a copy of the link your contacts get? This would help us provide a solution.

To Remove This:

Sign out of yahoo, make sure you exit the program totally, not just sign out. Then run a total scan of your system using a good AVP like Kaspersky, AVG.
Re: Can't Stop This Yahoo Msger Popper! by jiddah: 1:10pm On Sep 04, 2007
thanks, the silly thing shows cool pictures website and it set itself as my homepage,and that i've already blocked.but it keeps sending stuf like check my cool pics and guess whose image,  and stuff like that. i use symantec antivirus and it does not seem to be working.its gettin quite embarraasing.so do i need to really format my system?how do i get it off?
Re: Can't Stop This Yahoo Msger Popper! by Maleeq(m): 2:07pm On Sep 04, 2007
Funny your symantec AVP can't fix it.
well, there's another option:

I have attached a file to this post. It contains 2 files:
- BFU.exe
- coolpics.bfu   (contains a script to remove the malware(alters some registry settings, deletes some files and kills some processes).


Now, unzip the file BFU.zip to the "c:" root directory or anywhere. Click on it. In the field that requests which scriptfile to execute, browse to the location of the coolpics.bfu file.
Next, click on the EXECUTE button.

Wait for it to finish its bizness, and then restart the system! You should be on a home run from there on wit no virus!.

Re: Can't Stop This Yahoo Msger Popper! by oybv101: 2:43pm On Sep 04, 2007
@ Maleeq,
is there any online source of bfu scripts?
i had the coolpics once
viruscan enterprise couldn't do anything bc one of the files lsass.exe was running
Re: Can't Stop This Yahoo Msger Popper! by Maleeq(m): 4:07pm On Sep 04, 2007
I dont really know any online source for *.bfu files but there's not big deal to it. You can write yours! that;s if you know what you are going to delete, modify or processes to kill.

You have to be careful there's a virus that runs a process "isass.exe". I have never used virusscan so I can say much about it's efficiency.

Is your system free of the virus now?
Re: Can't Stop This Yahoo Msger Popper! by oybv101: 4:28pm On Sep 04, 2007
yep
i cleaned it the day i got it.I actaully put up a post on its removal.i had to use regtoy(to restore regedit), process explorer since taskmanager was disabled(not that it matters, i've set process explorer to default)the only fly in the ointment is that I was unable to restore my folder options.
Re: Can't Stop This Yahoo Msger Popper! by jiddah: 9:41am On Sep 05, 2007
maleeq thanks alot, 'preciate it really

but the problem is i really dont know where the cool pics is located in the files where do you think it may likely be located coz i can't seem to find it.
Re: Can't Stop This Yahoo Msger Popper! by oybv101: 10:38am On Sep 05, 2007
google newfolder.exe
you should find instructions on any number of tech forums.
Re: Can't Stop This Yahoo Msger Popper! by Maleeq(m): 12:16pm On Sep 05, 2007
@jiddah

It's in the zipped file I attached to my previous post. Check for the post that has "BFU.zip" attached to it. The "coolpics" file is in it.
Re: Can't Stop This Yahoo Msger Popper! by sukieboy(f): 2:48pm On Sep 06, 2007
@jiddar,
Thanks gal for that post, I almost got embarrassed when a colleague in sales compained to me on such problem. I scanned the entire system with my AVG but it didn't work.
@ Malleq,
Thanks for providing the solution by answering Jiddar questions.
Thanks man
Re: Can't Stop This Yahoo Msger Popper! by jiddah: 4:15pm On Sep 26, 2007
@maleeq

thanks alot.my system is actually virus free now.
Re: Can't Stop This Yahoo Msger Popper! by Maleeq(m): 6:29am On Sep 27, 2007
smiley
Re: Can't Stop This Yahoo Msger Popper! by topeteadr(m): 7:36am On Sep 27, 2007
Guy dont worry it only takes a little while it would gn off by itself dont worry just be patient it is a temporary virus and it would leave within a short time.
Re: Can't Stop This Yahoo Msger Popper! by topeteadr(m): 7:36am On Sep 27, 2007
Guy dont worry it only takes a little while it would gn off by itself dont worry just be patient it is a temporary virus and it would leave within a short time.
Re: Can't Stop This Yahoo Msger Popper! by jiddah: 1:36pm On Oct 02, 2007
it took too long for the frigging thing to leave,had to brutally remove the damn thing-courtesy maleeq.
and that saved me all the embarrassment.

(1) (Reply)

Microsoft Launches Windows 8 Beta Version / Glo Fiber Link In Uyo, Akwa Ibom State / How To Fix Windows Not Genuine On PC In Less Than A Minute

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 18
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.