Results 1 to 5 of 5

Thread: Got a virus from facebook team?

  1. #1
    Join Date
    Jun 2009
    Posts
    360

    Got a virus from facebook team?

    Hello everybody, I use facebook a lot and i think i am addicted to it. One time o have got a mail from the facebook team saying that Dear Facebook user, Due to some changes in Facebook policy, all Facebook users must submit a new agreement, otherwise your account will be restricted and so and so. And they gave me one “agreement.exe” to run but then i realized that it should be the source of infection. Is it a file containing any virus?, As i am not able to run my spyware properly due loss of serial key.

  2. #2
    Join Date
    Jan 2006
    Posts
    4,221

    Your computer is infected by the Trojan.Sasfis.A.

    Actually the e-mail which you have got from the facebook team is not sent from the facebook team, It is a spam mail which takes you to the virus unfection. The mail about which you are talking is the same mail which i got before few days and i have just deleted it. These kind of mails have attachments which you had opened. This attachments contains infected files by which opening this file inserts Trojan.Sasfis.A in to your system. Beware of this type of mails with the attachments from now onwards.

  3. #3
    Join Date
    Apr 2008
    Posts
    3,424

    Symptoms by Trojan.Sasfis.A.

    Here are some symptoms that are been shown by your computer when it gets threatened by the Trojan.Sasfis.A.
    1. Presence of "rundll32.exe ifmq.kqo bmhyn" string in "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell".
    2. 27KB dll file with 4 random-looking exports (bmhyn, nhccck, ocqbk, plljlt) in the "%USERPROFILE%\Local Settings\Temp\[random digits].tmp" and "%SYSTEM%\ifmq.kqo".
    3. That dll file will be an instance of svchost.exe.
    4. MS Word's macro security level is set to low, i.e.
    "Software\Microsoft\Office\10.0\Word\Security\Level" = 1
    "Software\Microsoft\Office\10.0\Word\Security\AccessVBOM" = 1
    5. "HKEY_CLASSES_ROOT\idid\url0" has a binary value.

  4. #4
    Join Date
    May 2008
    Posts
    2,945

    What Trojan.Sasfis.A will do.

    I would like to tell you about some actions that will be taken by the Trojan.Sasfis.A when your computer gets infected by it.
    1. It drops a dll file in to two locations which is %USERPROFILE%\Local Settings\Temp\[random digits].tmp and %SYSTEM%\ifmq.kqo.
    2. dll will be injected as a new instance of svchost.exe
    3. It is also added to the system startup.
    4. If your computer has MS Office installed on it , the malware will try to run a VB script with OLE automation in the context of MS Word's process.

  5. #5
    Join Date
    Apr 2008
    Posts
    3,339

    Boot scanning by Quick Heal antivirus.

    Use Boot Scan provided in the Quick Heal Anti Virus System. Quick Heal is an anti virus software which you can use to delete any kind of viruses from your computer. And Boot Scan is a feature which runs before your operating system runs. So that the virus would not be having your OS to affect. This feature is cool when you know use it regularly.

Similar Threads

  1. Replies: 7
    Last Post: 03-11-2011, 11:33 PM
  2. Battle without team in Dragon Age Legends on Facebook
    By Victorious mind in forum Video Games
    Replies: 5
    Last Post: 23-03-2011, 10:14 AM
  3. Replies: 6
    Last Post: 19-03-2011, 11:01 PM
  4. Nasty facebook virus!
    By Jorgea in forum Networking & Security
    Replies: 4
    Last Post: 30-04-2010, 05:17 PM
  5. Remove Koobface aka Facebook Virus
    By Larry ward in forum Tips & Tweaks
    Replies: 3
    Last Post: 20-03-2009, 04:36 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,711,708,849.60107 seconds with 17 queries