PDA

View Full Version : Msn virus/spammer



Nave
08-21-2005, 06:12 PM
my friends have recently fallen victim to a virus that displays
"I know who's blocking me on MSN because I use http://www.block-checker.com"

now 2 people on my list have it as far as i know and i was wondering if anyone new how to get rid of it

frostyone
08-21-2005, 09:21 PM
I think this is a very scummy program.
Very dubious.

It uses 2 excutables:
Program Files\Block Checker\block-checker.exe
and
Program Files\Block Checker\csrss.exe

This:
Program Files\Block Checker\csrss.exe appears to replace block-checker.exe if it is missing

CAUTION:
There is a legitimate Windows file called csrss.exe
THIS IS A CRITICAL SYSTEM FILE.
They chose the same name on purpose of course.
To make life difficult.

Now this, for the moment, is not considered a virus.

Read jayloden:
http://www.jayloden.com/block-checker.htm
------
FIRST try to uninstall through add/remove programs.

Then they offer this from the blockchecker site:

"How can I disable the Block Checker tell a friend program?
Block Checker has a powerful fun feature to tell your friends about Block Checker without the headache of telling EACH friend about it. This is how we let other people know about our application. If you wish to remove this function from our software you can do so by downloading this tool (if in the event our uninstaller doesn't work use this to remove it) ."

I've downloaded the tool. LOL!!
Here's what you what get:

A processkiller and these instructions:

Steps to remove the Automatic Block Checker tell a friend (method 1):

1. Boot your computer into safe mode:

2. Open up your registry and navigate to

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run

Delete the "BlockChecker" Key


3. Open up My Computer and Navigate to your "Program Files"

4. Find the "Block Checker" folder

5. Delete the folder.

6. The Automatic Block Checker tell a friend is removed. Reboot your computer into regular mode.
-----
Steps to remove the Automatic Block Checker tell a friend (method 2):

1. Run ProcessKill.exe:

a.Find Process:

Program Files\Block Checker\block-checker.exe
and
Program Files\Block Checker\csrss.exe

b. Hold Control and Click both of them with your mouse

c. Click Terminate Selected

d. Click Refresh List to verify it worked

2. Open up your registry and navigate to

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run

Delete the "BlockChecker" Key


3. Open up My Computer and Navigate to your "Program Files"

4. Find the "Block Checker" folder

5. Delete the folder.

6. The Automatic Block Checker tell a friend is removed
---

frostyone
08-21-2005, 09:45 PM
Crap, wasn't real clear.

Your friends may not have this "virus"

They are receiving that message from one of their buddies who has installed the program.

And now the "powerful fun feature" is telling their friends all about Block Checker.
The friend probably doesn't know he's doing it.

In effect, whoever installs the program ends up spamming their friends.

If they click on the link and install the program, they end up spamming too.
It works using various instant messaging programs.

frostyone
08-24-2005, 09:26 AM
Update:
For those who have installed block-checker and are having difficulty removing it:
After hearing complaints that the uninstall is unnecessarily difficult Jay Loden has created a removal tool for the program and updated his webpage.

" I received four or five emails about this program, so I decided to write a separate removal tool that automates the steps in the instructions from block-checker's website. If you would like to remove Block-Checker, please download BlockRemove to your Desktop, boot into Safe Mode, and then run BlockRemove and it should automatically erase files and entries associated with the program."
http://jayloden.com/block-checker.htm

Nave
08-25-2005, 03:45 PM
thanks a bundle frostyone, me and my friends were getting annoyed with the spam!

frostyone
08-28-2005, 02:34 PM
Good to hear Nave.

Appears McAfee is now detecting this .
http://vil.nai.com/vil/content/v_135579.htm

Jay Loden has updated removal tool again.
"After receiving some more information on the Block-Checker malware, I spent an hour or two last night updating BlockRemove to remove as many components as I could and make it a more complete tool. There's a bit more work to be done in cleaning up the registry, but I will work on that as time allows next week."