Some bad azz virus.

Discussion in 'Malware Help (A Specialist Will Reply)' started by link48010, Aug 4, 2007.

  1. link48010

    link48010 Private E-2

    There seems to be a virus I've never seen before on a pc with xp home. It isn't mine so it wasn't treated with the best AV or security (actually it was empty of Anti-virus for quite some time, I'm rather surprised it hasn't crashed a long time ago.) I visit here ever few weeks and between two visits the hard drive filled up almost 6 or 7 gigs, but nothing in that amount of size was ever installed. I used Avast antivirus to attempt to destroy the virus be now it just comes back and shuts down the PC at the first attempt to boot it up (the moment a user logs in, safe mode still works). If i disable Avast the computer will boot sometimes.

    Also i would like to point out that the Virus was found in the Free Ram program file, a program found here on this site: http://www.majorgeeks.com/BySoft_FreeRAM_d323.html so i suggest that the program be removed from the site. I tried using spybot S & D to shred the file but that didn't seem to work either. I need some help. I was going to try Ultimate boot CD's AV utilities to do a scan from the CD. any other advice. The drive is now under 10% free and can't even defrag any more. I'm thinking that somehow the virus is reacting to my attempt to destroy it.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Whatever you are detecting is a false positive. That program is not infected. All programs available for download on Major Geeks are always scanned and tested before they are made available for download.

    What program detected a virus?
    What was the name of the virus?
    Where was the virus found (file names and path)?

    If you really believe this PC has malware problems, please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. link48010

    link48010 Private E-2

    What program detected a virus?
    What was the name of the virus?
    Where was the virus found (file names and path?

    The program that detected the virus was Avast Anti-Virus.
    The virus was found in C:/Program Files/BySoft Free Ram/....
    I don't recall the name of the virus because the computer now seems to continually restart on it's own. Sometimes a five to ten minutes after starting, sometimes five seconds.

    I also might want to add that the PC doesn't want to get updates for Windows. As for do i think it really has an infection, PC don't restart on there own, drives don't bloat to 10% free space from 60% in a week, and in most cases, Avast is known to hardly ever get false positives.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still a false positive. That program is not infected.

    Yes and all of this could just be due to problems in your OS or due to software you use too. Each restore point created will take up a lot of disk space. If you have any automatic backup programs running they will take up diskspace. In short I will not know if you have malware until you run the READ ME and attach the logs.

    Not true!
     
    Last edited: Aug 4, 2007
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attached is a Word Document showing the results for scanning the installation file for
    BySoftFreeRAM32. 31 scanners (including Avast) say it is clean. It is quite possible that this PC is already infected and that anything download on it also gets infected (including Avast since you just installed it). Since you still have not given a name of what virus was found and exactly what file was supposed to be infected (it may not have even been a flle from BySoftFreeRAM), there is nothing else I can tell you other than what has already been stated. This download is clean.

    I also installed the program and it works fine and nothing on my PC detected any problems. Then I ran the FreeRAM.exe thru the 31 scanners at Virus Total and it also came up clean (other than on false detection of a suspicious Trojan/Worm by eSafe) and that includes the Avast scan which said it was clean. False detections on programs like this that tweak the operating system are normal. Infact the above statement by eSafe does not even say it is a definite problem. It said suspicious which is the same as some scans saying potentially unwanted file.
     

    Attached Files:

  6. link48010

    link48010 Private E-2

    You do know that scanning the .exe installation folder is nowhere near full proof. it commonly turns up false positives and will miss other things.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no guarantee of any scan of any kind of file being fool proof. However that fact remains that this download is not infected The Download ZIP file is not infected and neither is anything installed by it. I even have it running on a several PCs. In addition the scan of the ZIP file by many scanners did not show any infections so I don't know what you mean about false positives since there weren't any in my scan. Your scan is the one that had a false positive.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds