Aim bug 2

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pav7300, Oct 8, 2005.

  1. Pav7300

    Pav7300 Private E-2

    because i cannot post on the first one so here it is... I followed the steps and dled and ran aim fix. I dled put it in a folder itself HiJackThis. I ran it and saved the log file. Here is the attachment... what do i delete in order to get rid of the pic1253 virus?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the announcement and sticky threads. HJT logs should only be posted when requested and then they must be attachments to your message but also only after the READ ME FIRST sticky has been run.

    Please run the steps below.

    Download EliteToolbar Remover do not run it yet. Just extract it to its own folder. We will run it later on in the process after we are booted in safe mode.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - After doing all the steps in the READ ME FIRST and while still in safe mode, run the ETRemover_v210.exe file (from EliteToolBar Remover) by double clicking on it.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    .
     
  3. Pav7300

    Pav7300 Private E-2

    pls man can you just tell me which to delete in order to fix this aim bug that i got from pic1253? i posted the attachment like you said.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have malware issues on your PC that need to be fixed. The procedure needs to be followed so we do not miss any possible hidden processes or files. I see several trojans that are a bigger problem than an AIM bug. If you do not follow the procedure, you will not get them fixed.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Besides you are running your system with no antivirus, no firewall and no antispyware programs. No wonder you have a problem.
     
  6. Pav7300

    Pav7300 Private E-2

    wow u can tell, well as long as these are very detailed then i will be able to do this... i get lost easily in computer stuff. if not done with all of it tonight i shall be back tommorow
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hundreds of people (novices to experts) follow them weekly. Make sure you run them as directed and in the order directed and in safe mode as directed. Do not skip any steps especially the online scanners from BitDefender and RavAntivirus. You have some nasty trojans in there. One of them even allows remote access into your PC.
     
  8. Pav7300

    Pav7300 Private E-2

    i am updating the spybot right now, jebus this one will take a while. reading the guide also. "you must use Internet Explorer." I am using mozzila firefox. so will the online scans not work for me?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use Internet Explorer for the online scans! You cannot always avoid using IE. For example, you cannot get any updates from Microsoft without it and many other websites require it too.
    Use FireFox to do all the downloading and other steps.
     
  10. Pav7300

    Pav7300 Private E-2

    OMG w/e that aim bug is its installing something now im getting scared
     
  11. Pav7300

    Pav7300 Private E-2

    i am done downloading all te programs. When I go to safe mode will i be able to go back to this website to continue with the guide? or do i HAVE to print it?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When run the online scanners you need to be connected to run them, but I would not do anything else during that time because it will slow you down and could cause problems with the scans. (Note: some people cannot connect in safe mode)

    I WOULD RECOMMEND THAT YOU DO NOT RUN AIM during this time.

    All the other cleaning steps should be run in safe mode without any internet connectivity and with no browsers opened. So yes, if necessary print or safe to a local file (not an html file because we want browsers closed).
     
  13. Pav7300

    Pav7300 Private E-2

    i shall see you tommorow after apple picking or such, for it will take 10 or so hours to scan one
     
  14. Pav7300

    Pav7300 Private E-2

    I have completed all the scans except for RavAntiVirus, i would have to scan each file one by one(meaning about 30000 scans). I will read the thread by chaslang. and it fixed my aim problem hehe i am the big man on campus :).
     
  15. Pav7300

    Pav7300 Private E-2

    I have a folder called my love though in program files, and this thing called mIRC installed though from that virus, when i try to uninstall mIRC from add/remove it tells me to stop running it. but im not. how do i uninstall it and what do i do with that folder "my love".
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to scan individual files with Rav. It allows you to scan your whole PC by selecting Auto Clean then click Scan My PC!

    Try uninstalling mIRC after booting in safe mode.

    Did you run EliteToolbar Remover in safe mode?

    Post a new HJT log as an attachment.
     
  17. Pav7300

    Pav7300 Private E-2

    i just restarted the computer and was able to uninstall the mIRC. nothing in the add/remove that shouldnt be there that i know of.
     
  18. Pav7300

    Pav7300 Private E-2

    and also this... its not attaching....
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Give it a new name!
     
  20. Pav7300

    Pav7300 Private E-2

    "If you change a file name extension, the file may become unusable." still doesnt upload
     
  21. Pav7300

    Pav7300 Private E-2

    mIRC came back! can i email the HJT to you?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's just a warning and is not a problem. Only certain file name extensions like .log, .txt, .doc can be uploaded. Do you have it named correctly? You were able to upload it in your first message. Are you doing something different? Post it inline if necessary.
     
  23. Pav7300

    Pav7300 Private E-2

    i just did the ETremover in safe mode, i got the message:
    "the instruction at "0x7c91888f" referenced memory at "0x001e6610". The memory could not be "read".
    Click on ok to terminate the program.
    Click on cancel to debug the program.

    Both ok and cancel do the same thing (exit).

    Edit by chaslang: Inline log attached

    I also still have the folder "My Love" can i just delete it?
     

    Attached Files:

    • hjt.txt
      File size:
      6.6 KB
      Views:
      0
    Last edited by a moderator: Oct 9, 2005
  24. Pav7300

    Pav7300 Private E-2

    Edit by chaslang: Inline log attached

    use this one i closed the other one before
     

    Attached Files:

    Last edited by a moderator: Oct 9, 2005
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see why your log will not upload. There is a bug in vB that has a problems with the below line in your log:
    C:\WINDOWS\system32\cmd.exe

    Why is this running anyway? Do you have a command prompt Window open?

    Your PC has new infections now. You are going to keep getting infected unless you get an antivirus, spyware blocker, and a firewall installed. See:How to Protect yourself from malware!

    But let's see what we can do with the current problem.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\My Love\c4nn0t.exe
    C:\WINDOWS\system32\cmd.exe
    C:\Program Files\Common Files\services.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [jid] C:\WINDOWS\jid.exe
    O4 - HKLM\..\Run: [SECRETSERVICE] C:\Program Files\My Love\c4nn0t.exe
    O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-67-525-0000166.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\My Love <--- the whole folder
    C:\WINDOWS\jid.exe
    C:\Program Files\Common Files\services.exe
    C:\Program Files\Common Files\mc-67-525-0000166.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  26. Pav7300

    Pav7300 Private E-2

    I did as you said. I deleted all but:
    C:\WINDOWS\jid.exe
    C:\Program Files\Common Files\mc-67-525-0000166.exe

    I did not see either of those two. Also one of the prefetch (Project64 one) wouldnt delete.

    I can attach the file now :) and i dont see anything that should not belong there.

    also do I have to download a firewall or can I just use the SP2 one?
    I do not want to use AVG because before i reformatted my computer AVG was causing some problem and I could not uninstall it. I have everything else but the sun java which i will do soon.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No the firewall in SP2 is not a true bidirectional firewall and does not provide adequate protection. Use one of the ones in the sticky.

    If you do not like AVG, use one of the others mentioned. You need an AV.

    I missed one item in you log last time. Have HJT fix the below (make sure all browsers are closed before clicking fix).

    O2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dll

    Then exit HJT and make sure the below folder is deleted:
    C:\Program Files\DNS

    You may need to delete from safe mode.

    I'm not sure what you mean by the "Project64 for one " in Prefetch. What exactly did you see? And were you or did you use some kind of Nintendo emulator that this related too?
     
  28. Pav7300

    Pav7300 Private E-2

    yea i did use an emulator
     
  29. Pav7300

    Pav7300 Private E-2

    ok I have the ZoneAlert Pro, and Avast! Pro.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! If there are no other malware problems, I assume we are finished. Surf Safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds