Tuesday, November 3, 2009

Windows Live (MSN) Viruses

Messenger Viruses

I am sick of them.

For those of you who don't know what they are, have you ever seen this?

"HEY!

I CAN'T BELIEVE YOU WERE NAKED IN THESE PHOTOS!

http://www.thisisnotavirus.com/honest=you@youremail.com

LOL"

They are usually structured like so.

a) The Greeting - Pretty self explanatory, it usually consists of "Hey You!" or something like that. They will not mention your name personally (the ones I have seen) and will be fairly ambiguous.
b) The Bait - Usually some phrase or sentence, which is totally ambiguous and designed to shock, enrage or confuse you. Usually, there will be references to the sender or yourself being naked or embarrassing themselves (and there being photographic evidence of that fact) or a deal/promotion/product which can't be missed.
c) The Trap- Finally to seal the deal, there will be a hyperlink. Usually the link will have your email address (or part thereof) in it, however this is not always the case. Less commonly, I have seen instances where instead of a link, the host sends a file containing the virus. Just note that there are a few different ways.

They are automated messages sent in various ways ultimately to get other suckers to click them and download the virus onto their computer. Furthermore, majority of the well known virus scanners seem to be unable to pick them up, leaving users baffled.

So, how do I beat it?

I know, you just want me to shut up and tell you how to get rid of it. But like all good parents, I need to give you a little lecture before I start...

The Best Cure is Prevention!


3 Words would have saved you all the trouble in the world, "Don't, Click, It!" Seriously, taking two seconds to actually ask the person what they are sending would have potentially ended it all. See, the viruses generally will send a bulk of text, or a few shorter messages in quick succession then either sign the user off, or simply do nothing until it wants to send it again. This means that, you saying "What the hell are you sending me?!" will result in no reply. Instead of the Click First, Ask Questions Later attitude, asking for confirmation for any link (especially the ones which you are not familiar with) will usually stop this problem. Before we begin, please check that Windows (or your OS), Windows Live Messenger, and your Virus protection is all up to date.

Ok, enough lecturing, I am not angry, I am just disappointed...

Let's start with the obvious...

Now usually hosts will be totally oblivious to the fact they have a virus. Most of the time, they may not even be at the computer when this is all happening. If you see someone who has one, send them an email telling them what to do. After you have found out that you have the virus, you really need to do the first logical step, RUN A VIRUS SCAN. "Now wait a minute, didn't you just say that most popular virus scanners will not pick this up?!" I hear you say. Well, yes I did, but a) You might get lucky and b) Let me finish. Popular (i.e. Ones that you have to Pay For) are not ALWAYS bad, clunky, terribly engineered and overpriced pieces of garbage, just most of them. If you happen to be one of the lucky few who get a good one, then this problem might be over before it began. My personal favourite scanner, and the one which works the most often, is AVG Free (link below). As the name suggests, the product is free for personal use, and has a higher kill rate than Norton, McAfee and Trend Micro products (from my own personal/anecdotal experiences). It is also from a trusted source, and does not have any of its own nasties that come along with it. I would highly recommend uninstalling your existing virus scanner at the end of your subscription and downloading this one. If you have found one that it better, then by all means, use it. Just get it fired up, and get it running the MOST thorough scan (usually labelled "Full System Scan" "Full Scan" "Complete Scan" etc). A lot of virus scanners won't have this set as a default, so making sure you are running a complete scan is important. This may take a few hours, depending on your PC, so go grab a coffee and something to eat and come back later.

Ok, that didn't work, now what?

So your virus scanner came back with zilch. Or, it came back with stuff, you removed all the viruses, but this this is like a Hydra, and just won't die. Funnily enough, I half expected the virus scanner to show up with nothing of relevance. But, this is usually the first step people overlook, and is a good starting point. Now we move onto Spyware. Spyware, is similar to a virus, but usually takes information from your computer and steals it. Compare this to Viruses, which are usually designed to destroy or disable parts of your computer, Spyware can pose similar symptoms but need a different cure. You will need a Spyware Scanner. I do realise that some Virus scanners have inbuilt Spyware protection, however the one I trust is again Free and genuine. Spybot: Search and Destroy (link below) is fast and accurate, and offers ongoing protection both preventative and retrospective. I would recommend installing this and activating "Tea Timer," Run an Immunisation, and then Run a Scan. This should not take as long as the Virus scan, but may still take a while. Again, wait for the results, remove any Spyware, and continue on your merry way.

What the hell? It is STILL Alive!?


Ok ok, most people give up around this phase of the game. They think "Well, if it isn't being picked up by BOTH scanners, then it a) Isn't a Virus/Spyware or b) Cannot be fixed. This is incorrect on both levels. People just don't think outside the box. Perhaps the offending program can be hiding? Perhaps it has fooled your computer into thinking it is legitimate? Perhaps, Messenger Viruses aren't a high priority for the programmers of said Virus Scanners? Who knows? All I know is that there are still a few more things to do, like...

Clean up your S#^t!

Viruses usually hide in spots where it will be hard to find them (duh?). So logically, cleaning out all of the filth of your computer can result in you accidentally deleting or disabling the virus. Almost ALL of the cases of Messenger Viruses I have encountered were solved with this method. Firstly, start by getting rid of all the files in "My Received Files" (usually in My Documents). Delete them, and only keep the stuff you know isn't a virus (like pictures, etc). Next, you will need to conduct a "System Cleanup". There is a program I recommend, and surprise surprise, it is Free, called CCleaner (which stands for Crap Cleaner - link below). It will clean out all of the temporary files on your computer. Keep note, this will whipe your Browser History, as well as any saved Passwords in your browser. It will also make your computer run quicker overall (so, it is Win-Win). The first time I used this program, I had 9 Gigabytes of crud cleaned off of my computer. Rest assured, it won't delete anything Vital, nor will it get rid of any Documents or Media. After running a clean, I would also recommend running a "Registry Fix" (which is built into CCleaner). Ultimately, this will fix a lot of problems, not just relating to viruses.

After all of this is done, make sure you restart your computer.

How is this thing still kicking?!


Ok, so if this thing is still alive, you have got quite a few problems. It is very likely that this is not a virus, but a result of your Account being insecure (i.e. someone or something knows your password). Easiest thing to do is to change your password AND security questions (there should be guide on the website on how to do this. Just for the heck of it, I would also uninstall and reinstall Windows Live Messenger, and remove any programs you have downloaded which interact which Messenger (even if you think they are safe).

If you are still having problems, you are in knee deep and sinking fast. You probably need to keep having a look around the web, or get a computer technician/guru/etc to go work their magic. If you discover any alternative solutions, send them to me so I can spread the word.

As a side note, I will be reviewing all of the programs mentioned in future articles.

LINKS

**The sites linked here were safe and secure at the time of being posted to be best of my knowledge. Please make sure that you check and scan (with virus and spyware scanners) any programs your download before installing or running them. You are using them at your own risk**

AVG Free
(if that doesn't work, try HERE)
Spybot: Search and Destroy
CCleaner (if that doesn't work, try HERE)