# PIC675799074533-JPG-www.facebook.com.exe A VIRUS? HELP!!!

**URL:** https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928
**Category:** NYSpeed Off Topic
**Created:** [September 29, 2010, 10:57am UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928 "2010-09-29T10:57:02Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Z\_PHAT\_Z](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/z_phat_z/32/7293_2.png) [@Z\_PHAT\_Z](https://forums.speedlife.net/u/Z_PHAT_Z)
#### Post date: [September 29, 2010, 10:57am UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/1 "2010-09-29T10:57:02Z")

</div>

My wife got a message from yahoo messenger from her friend with this link “PIC675799074533-JPG-www.facebook.com.exe” Then she clicked on it and ran it. Now she is sending the same message to everyone on her list. I ran scan and stuffs but can’t find anything. Anyone has any advice or help on removing this? Thanks in advance.

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [September 29, 2010, 11:09am UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/2 "2010-09-29T11:09:05Z")

</div>

Find a new wife

---

<div class="post-metadata">

### Author: ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)
#### Post date: [September 29, 2010, 11:11am UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/3 "2010-09-29T11:11:35Z")

</div>

> [@LZ](#):
>
> Find a new wife

This…then change her password like yesterday. Notice that nice little .exe at the end of the file…That should have been a dead giveaway.

---

<div class="post-metadata">

### Author: ![Z\_PHAT\_Z](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/z_phat_z/32/7293_2.png) [@Z\_PHAT\_Z](https://forums.speedlife.net/u/Z_PHAT_Z)
#### Post date: [September 29, 2010, 11:16am UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/4 "2010-09-29T11:16:01Z")

</div>

Well she is not computer person so she wouldn’t recognized it. I spent sometimes last night looking thru registry and run removal softwares in safe mode but can’t pick up anything.

---

<div class="post-metadata">

### Author: ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)
#### Post date: [September 29, 2010, 11:23am UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/5 "2010-09-29T11:23:21Z")

</div>

Malwarebytes 1.46 with the most up-to-date definitions?

> **[Free Cyber Security & Anti-Malware Software](https://www.malwarebytes.com/)**
>
> Malwarebytes protects you against malware, ransomware, and other advanced online threats that have made antivirus obsolete and ineffective.

What A/V are you running? Uninstall Yahoo Messanger?

---

<div class="post-metadata">

### Author: ![Saxon](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@Saxon](https://forums.speedlife.net/u/Saxon)
#### Post date: [September 29, 2010, 11:25am UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/6 "2010-09-29T11:25:08Z")

</div>

generally changing the password will get rid of it

---

<div class="post-metadata">

### Author: ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)
#### Post date: [September 29, 2010, 11:25am UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/7 "2010-09-29T11:25:52Z")

</div>

Also, is this sending through facebook or the messanger program?

---

<div class="post-metadata">

### Author: ![Z\_PHAT\_Z](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/z_phat_z/32/7293_2.png) [@Z\_PHAT\_Z](https://forums.speedlife.net/u/Z_PHAT_Z)
#### Post date: [September 29, 2010, 11:44am UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/8 "2010-09-29T11:44:27Z")

</div>

The PC is running Norton AV from UB 🙂 I un-installed YM already and just changed the password. It’s jsut weird that I scanned that .exe file and it’s not detected it as a virus. Thank you everyone for your help.

---

<div class="post-metadata">

### Author: ![Gl1](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/gl1/32/5471_2.png) [@Gl1](https://forums.speedlife.net/u/Gl1)
#### Post date: [September 29, 2010, 11:59am UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/9 "2010-09-29T11:59:30Z")

</div>

> [@Z PHAT Z](#):
>
> The PC is running **Norton AV** from UB 🙂 I un-installed YM already and just changed the password. It’s jsut weird that I scanned that .exe file and it’s not detected it as a virus. Thank you everyone for your help.

there’s your problem

> **[Official Norton™ Support](https://support.norton.com/sp/en/us/home/current/help-center?docurl=20080710133834EN&wv_type=public_web)**
>
> Nortonlifelock Support

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [September 29, 2010, 12:49pm UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/10 "2010-09-29T12:49:43Z")

</div>

Anti virus doesn’t actually work go figure lol

---

<div class="post-metadata">

### Author: ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)
#### Post date: [September 29, 2010, 12:54pm UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/11 "2010-09-29T12:54:03Z")

</div>

Doesn’t ub give out symantec endpoint? Try using microsoft security essentials.

Sent from my Droid

---

<div class="post-metadata">

### Author: ![pirite](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/pirite/32/5308_2.png) [@pirite](https://forums.speedlife.net/u/pirite)
#### Post date: [September 29, 2010, 1:01pm UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/12 "2010-09-29T13:01:47Z")

</div>

ESET NOD32 Antivirus. end of story.

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [September 29, 2010, 1:15pm UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/13 "2010-09-29T13:15:50Z")

</div>

I am still willing to bet 90% of the malware people get won’t be stopped by AV 🙂

---

<div class="post-metadata">

### Author: ![Z\_PHAT\_Z](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/z_phat_z/32/7293_2.png) [@Z\_PHAT\_Z](https://forums.speedlife.net/u/Z_PHAT_Z)
#### Post date: [September 29, 2010, 2:17pm UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/14 "2010-09-29T14:17:34Z")

</div>

> [@ProgRocker](#):
>
> Doesn’t ub give out symantec endpoint? Try using microsoft security essentials.
> 
> Sent from my Droid

Yes it is. It’s AV+firewall. But I guess none of the AV can detects that. I just tried 4 different AV and none of them detect that .exe as virus.

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [September 29, 2010, 3:10pm UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/15 "2010-09-29T15:10:12Z")

</div>

[http://www.virustotal.com/](http://www.virustotal.com/) upload it there

---

<div class="post-metadata">

### Author: ![ZOMGVTEK](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/zomgvtek/32/5063_2.png) [@ZOMGVTEK](https://forums.speedlife.net/u/ZOMGVTEK)
#### Post date: [September 29, 2010, 4:45pm UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/16 "2010-09-29T16:45:56Z")

</div>

From my experience, virus scanners dont really do much to prevent infections. Theyre not even very good at removing them.  
Your best bet will always be to not run shady files.

You can try running a few different scanners at the same time and hope that one of them can get it… But changing the Facebook password is required. I wouldn’t do it on that computer if possible…

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [September 29, 2010, 6:26pm UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/17 "2010-09-29T18:26:16Z")

</div>

Besides blatantly executing a .exe file most infections are from websites with malicious code that exploits vulnerabilities in your web browser/adobe reader/flash/quicktime most anti virus can’t do anything for this.

---

<div class="post-metadata">

### Author: ![Spam16v](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/spam16v/32/5287_2.png) [@Spam16v](https://forums.speedlife.net/u/Spam16v)
#### Post date: [September 29, 2010, 6:31pm UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/18 "2010-09-29T18:31:11Z")

</div>

my wife “synchronized” her clock once in college… that was a hell of a phone call, LOL

---

<div class="post-metadata">

### Author: ![Joe\_Omerta](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@Joe\_Omerta](https://forums.speedlife.net/u/Joe_Omerta)
#### Post date: [September 29, 2010, 7:50pm UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/19 "2010-09-29T19:50:44Z")

</div>

Process explorer paired with autoruns is the best duo i’ve ever used.

---

<div class="post-metadata">

### Author: ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)
#### Post date: [September 29, 2010, 8:06pm UTC](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928/20 "2010-09-29T20:06:17Z")

</div>

> [@LZ](#):
>
> Besides blatantly executing a .exe file most infections are from websites with malicious code that exploits vulnerabilities in your web browser/adobe reader/flash/quicktime most anti virus can’t do anything for this.

Especially since both Flash and Reader install into the system32 folder IIRC. Java is another big exploit…make sure that shit is up to date.

[Next page](https://forums.speedlife.net/t/pic675799074533-jpg-www-facebook-com-exe-a-virus-help/160928.md?page=2)
