(Untitled)

Oct 12, 2005 21:08

If you get an IM from me asking you to click on a link, don't do it. It's a virus. It got me.

I'm working on debugging it. More later.

Leave a comment

gameshowman October 13 2005, 01:48:02 UTC
I clicked it, and it came REAL close to getting me, but I stopped it in time.

Reply

sport6449 October 13 2005, 01:50:19 UTC
Uh, how? And how do you get rid of it? Anyone?

Reply

gameshowman October 13 2005, 01:51:44 UTC
Simple. I didn't let the file download.

Reply

sport6449 October 13 2005, 01:56:05 UTC
That helps. :-P

Anyone know how to get rid of it if you already have it?

Reply

kevin October 13 2005, 08:07:40 UTC
Chuck,

Do you know the name of the virus, or symptoms of what it does (does it redirect you to a website? If so, which site? -- stuff like that)?

Reply

sport6449 October 13 2005, 11:29:19 UTC
It's something called mysxl.hackit or something like that. What it does is overtake your AIM system after so many minutes and IMs the link to crazypics.com or something and it comes up a link. It downloads a file to your HD then propagates itself through your AIM system. There's now a file called lockx.exe in my C:/Windows/System32 fold that's causing trouble and I can't see to get rid of.

It's actually gotten so bad, somehow it's now affecting my internet connection. I'm at work typing this. If you know how to debug it, please let me know. I tried to delete the mysxl.hackit and it worked but it appears to be in the registry. The lockx.exe file is now the problem. It just won't go away.

Reply

kevin October 14 2005, 01:58:39 UTC
This looks like a pretty ugly one.

Here's some info:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_IRCBOT.AV&VSect=T

...and a "solution" from them. It involves rebooting into safe mode and then editing your registry to remove the calls to lockx.exe:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR%5FIRCBOT%2EAV&VSect=Sn

If you have not done so, you might be interested in downloading "HijackThis", which is a somewhat-advanced spyware/adware/malware removal tool: http://www.majorgeeks.com/download3155.html

Good luck!

Reply


Leave a comment

Up