Booche
12-01-2011, 08:20 PM
Well i thought i would update my MSN and guess what i've been hit with some dodgy virus called FACEBOOK-PIC000934519.EXE.
Now it wont let me contact anyone on msn and ive looked on the net and it affects FaceBook and MSN so if you get anything like this it says to check A.S.A.P
Just a heads up just incase as my anti virus didnt pick it up for some strange reason when i updated :(
Im now scanning all drives to hopefully sort this matter out.
Bit of info about it:
* Cloaked Malware
File Behavior
FACEBOOK-PIC000934519[1].EXE has been seen to perform the following behavior:
* Executes a Process
* Injects code into other processes
* This Process Deletes Other Processes From Disk
* This process creates other processes on disk
* Modifies firewall settings, without user permission so it is not blocked from accessing the Internet
* Performs DNS look ups to resolve URL IP addresses
* Uses Instant Messaging to communicate without the user's knowledge
* Uses embeded Instant Message Channel Settings
* Uses rootkit techniques to conceal its presence, interrogation or removal
FACEBOOK-PIC000934519[1].EXE has been the subject of the following behavior:
* Executed as a Process
* Deleted as a process from disk
* Created as a process on disk
* Added as a Registry auto start to load Program on Boot up
FACEBOOK-PIC000934519[1].EXE can also use the following file names:
* 79798543.EXE
* 50840262.EXE
* 12976171.EXE
* 21443387.EXE
* NVSVC32.EXE
* FACEBOOK-PIC000934519.EXE
* FACEBOOK-PIC000934519 (1).EXE
This file has been seen with the following file size:
* 86,016 bytes
Now it wont let me contact anyone on msn and ive looked on the net and it affects FaceBook and MSN so if you get anything like this it says to check A.S.A.P
Just a heads up just incase as my anti virus didnt pick it up for some strange reason when i updated :(
Im now scanning all drives to hopefully sort this matter out.
Bit of info about it:
* Cloaked Malware
File Behavior
FACEBOOK-PIC000934519[1].EXE has been seen to perform the following behavior:
* Executes a Process
* Injects code into other processes
* This Process Deletes Other Processes From Disk
* This process creates other processes on disk
* Modifies firewall settings, without user permission so it is not blocked from accessing the Internet
* Performs DNS look ups to resolve URL IP addresses
* Uses Instant Messaging to communicate without the user's knowledge
* Uses embeded Instant Message Channel Settings
* Uses rootkit techniques to conceal its presence, interrogation or removal
FACEBOOK-PIC000934519[1].EXE has been the subject of the following behavior:
* Executed as a Process
* Deleted as a process from disk
* Created as a process on disk
* Added as a Registry auto start to load Program on Boot up
FACEBOOK-PIC000934519[1].EXE can also use the following file names:
* 79798543.EXE
* 50840262.EXE
* 12976171.EXE
* 21443387.EXE
* NVSVC32.EXE
* FACEBOOK-PIC000934519.EXE
* FACEBOOK-PIC000934519 (1).EXE
This file has been seen with the following file size:
* 86,016 bytes