AIM virus going around

Discussion in 'Malware Help (A Specialist Will Reply)' started by Amazingant, Aug 23, 2006.

  1. Amazingant

    Amazingant Private E-2

    Yes, I know. AIM is a bad thing to use because so many viruses go around. Well, for the first time in about a decade, (the entire portion of my lifetime that's had computers in it) I have never gotten a virus. I keep both McAffe and Norton on my system, even though they hate each other. (don't ask how i made that work)
    Unfortunatly, it would seem that something i ended up at via a link, has messed with my copy of AIM, so that I now end up sending that link to anyone on my buddy list every few hours. It's a bit of a bother. So, I've been told by the only person who clicked a link they got from me, that re-installing AIM fixed the problem. For me? Not good enough. I wanna find out where it's getting the randomized URL for the links from, and report the SOB who started this to that fancy-pancy group of cops that track down virus-makers. Does anyone know where I might find a way to look at the data my computer is recieving

    It might be good for me to note that I'm not quite posting this in search of removing the virus, but tracking it's source instead.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was two very bad ideas!
    1) they are both terrible resource hogs which slow your PC own
    2) they will conflict with each other making it difficult to impossible for the other to work properly and making them less effective than having only one of them installed. (thus you did not make them work). And it will possibly mess up the ability for Windows Security Center to work properly.

    YOU MUST only have one antivirus application install.

    I'm not exactly sure what it is you want us to do for you. Since we are not sitting in front of your PC, we have limited capabilities. They only thing we can tell you is to run the below to see what (if any) malware is found.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Amazingant

    Amazingant Private E-2

    Few things to say. First, maybe you started typing a reply before I had finished editing my message, or maybe for some strange reason you can't read. I doubt that the latter is the case, for if you were unable to read, you woldn't have replied to begin with. But I said,
    There was a reason for that. I am not looking to remove the virus. I managed that in 30 seconds. The problem is that I want to-
    Second thing, I don't care what the companies say, I have both running, and they both work. Not only that, but the last time I got anywhere near a virus, I got two pop-ups notifying me that there was a virus to be killed. The only choice I had to make is which program to tell to shut-up, and which to tell to destroy the virus. But yet again, I'm not looking to kill the virus that I already got rid of.

    Third and finally, It is of no use to you what HIJackThis says is running on my comptuer, when all I'm asking for, is-
    And, Just to make this clear, Before deleting the virus, I copied it to a CD. Thus, I can still re-infect my computer for the purpose of watching the connections it makes, without causing anything to happen that I can't already fix.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! I read it but that is not the goal of what we do in the forum. We remove malware and we do not have time to play hunting games on a PC that is not in our hands. If you don't want to follow our procedures and you believe that you are an expert in handling all of this, then perhaps you would have more success posting elsewhere. You obviously think you know more than all the antivirus companies and malware fighters that exist.

    So go right ahead and reinfect your PC and trace everything that it does. Then reverse engineer everything that goes on. Capture all the packets being transmitted and received by your PC and perhaps you will find something of use.
     
  5. Amazingant

    Amazingant Private E-2

    Ok, so just say so. "We're not here to help trace viruses, we're here to help get rid of them." Is that so hard?
    That's all I was looking for here to begin with, was something to help me capture said packets. Majorgeeks.com- Is not the main purpose of the site programs with a forum for discussing them? If not, then the site needs to be reorganized to be a forum with programs on the side.
    I really don't care how much they know, or how much more/less I know. I know, that If I use an emulator to run another instance of windows, I can have one anti-virus program in one instance, and the other in a second instance. I'm not saying I'm smarter than them, I'm saying that I'm running them under different systems on the same machine. No problems that way!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And you said no such thing in your first post or your second post. You said you were running both of them and even wondered how you got it to work. So now you are changing your mind?

    If you have so much knowledge about all this stuff, why don't you know about a packet capturing/sniffing tools. Like Ethereal or maybe other tools in http://www.majorgeeks.com/downloads2.html
     
  7. Amazingant

    Amazingant Private E-2

    No, I originally said don't ask how. Running emulators isn't something most people would take the time to do, or would care about having me explain. It's easier to say don't ask, than it is to explain it.
    Because I don't have any knowledge about packet capturing and sniffing tools as of yet, hence my coming here and asking. But anyway, thanks for telling me where I can start my search for learning this stuff. That's all I was after.
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Running an AV scanner inside an emulator and an AV scanner on the native OS, is not the same as running the 2 antivirus applications on the same OS; for all pratical purposes you are running two seperate systems.

    Before you tell me I have no idea what i'm talking about. I run VmWare Server on CentOS 4.3 with Windows 2000 Professional running inside VmWare; and unless you connect the "Virtual Machine" to the network it won't see the other "Machine".
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds