another AIM link BestFriends.scr (i've tried everything)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sweetleah3, Oct 10, 2004.

  1. sweetleah3

    sweetleah3 Private E-2

    I've been trying all day to get rid of this virus that I got by stupidly clicking on a link in someone's away message. Now AIM automatically puts the virus in my away message.

    I've read past posts and I've followed all the instructions written here: DO NOT POST UNTIL YOU HAVE READ THIS.. except i could not get my computer to go into safe mode while doing everything.

    I installed Hijack This and read the tutorial, so I will run the scan and post the log file when [hopefully] asked.

    Please help me out, im desperate. Thanks in advance.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. PhilliePhan

    PhilliePhan Guest

    Hi Sweetleah3,

    Did you try: AIM Fix 1.0 (Updated)

    Try that before HijackThis.

    I doubt the moderators would mind a HJT log as long as you follow the instructions for proper scanning and safe the log as a .txt file and attach it via the "Attachment Manager" tool :)


    ***Hey Chas - Didn't see you.

    PP
     
    Last edited by a moderator: Oct 10, 2004
  4. sweetleah3

    sweetleah3 Private E-2

    Yes, I did also try the AIMFix, and no luck. I think Hijack This might be my last hope.

    Also, thanks for the info on how to get my pc into safe mode, however i am using Windows XP and it says "Due to the nature of Safe mode in Windows XP, it is not possible to install software while in Safe mode. "
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We did not ask you to install any software in safe mode? Are you talking about the online scans and what they try to put onto your PC? Did you actually boot in safe mode now?
    If yes, you should run the scans in safe mode.
     
  6. sweetleah3

    sweetleah3 Private E-2

    Sorry, nevermind, I thought I was supposed to be in safe mode when installing the scan software. My mistake.

    Anyway, I follwed those safe mode instructions, closed all my programs, typed in msconfig in the Run box, clicked OK, and a screen pops up for a split second and disappears before i can even click on it. I tried that a few times and the same thing happens every time. So i tried pressing f8 when restarting and that didnt work either. =/
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Make sure you have HJT Version 1.98.2 installed in its own non-temp, non-desktop directory and post your log as a .txt file attachment.
     
  8. sweetleah3

    sweetleah3 Private E-2

    ok, here it is. thank you so much. I have the program saved to Program Files, but the log is saved on my desktop, i hope that is ok.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should goto Add/Remove Programs and uninstall the following:
    Viewpoint Manager
    P2P Networking
    WildTangent <-- anything that says WildTangent

    Now make sure you have enabled viewing of hidden files.

    Now click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\System32\sfg0352.dll
    then click OK. If a dialog box confirming this action appears, click OK.


    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below process and End it:
    SVCHOSTE.EXE


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: Core Library - {83B3E0C1-DEF1-4df5-A3F5-92D10B7A396A} - C:\WINDOWS\System32\sfg0352.dll
    O4 - HKLM\..\Run: [SafeGuard Popup Blocker Updater (required)] regsvr32 /s C:\WINDOWS\System32\sfg0352.dll
    O4 - HKLM\..\Run: [Tray Temperature] C:\DOCUME~1\Owner\LOCALS~1\Temp\MiniBug.exe 1
    O4 - HKLM\..\Run: [Windows Logon Procedure] SVCHOSTE.EXE
    O4 - HKCU\..\RunOnce: [Windows Logon Procedure] SVCHOSTE.EXE
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/297263ecb789ca2f3314/netzip/RdxIE601.cab

    Boot in safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\SVCHOSTE.EXE
    C:\WINDOWS\System32\sfg0352.dll
    Now boot in normal mode and post a new HJT log attachment and tell me how things are working.
     
  10. sweetleah3

    sweetleah3 Private E-2



    Now when i hit CTRL-ALT-DEL, the window pops up for a second then disappears, just like what happened when i tried to get into safe mode by typing in msconfig into the Run box.

    I don't know why this is happening. Could i have deleted something I wasnt supposed to when doing the spyware scans?

    Is that a really important step or should i forget that part? Or is there any other way to get to the Task Manager?

    Sorry for all this trouble.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try using HijackThis to kill processes:

    Please run HijackThis and click on the "Config" button in the bottom-right hand corner. Then click on "Misc tools" on the top, and then "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.

    SVCHOSTE.EXE

    After killing all the above processes, click "Back".
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. sweetleah3

    sweetleah3 Private E-2

    phew! ok. a few things:
    i could not find these two listed in Hijack This:
    O2 - BHO: Core Library - {83B3E0C1-DEF1-4df5-A3F5-92D10B7A396A} - C:\WINDOWS\System32\sfg0352.dll
    O4 - HKLM\..\Run: [SafeGuard Popup Blocker Updater (required)] regsvr32 /s C:\WINDOWS\System32\sfg0352.dll

    but i took care of all the other ones.

    Also, I have not done this step yet:
    Boot in safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\SVCHOSTE.EXE
    C:\WINDOWS\System32\sfg0352.dll

    but the AIM problem seems to be fixed already. It's getting late and I think I will do that last step tomorrow (along with that BlasterWorm removal) and then post the log, does that sound ok?

    I cant thank you enough for all the help!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's a bad idea not to finish all the steps in one continuous flow. The SVCHOSTE.EXE trojan could startup a load of problems again.
     
  15. sweetleah3

    sweetleah3 Private E-2

    Ok. I had to finish the last step this morning, which i know you said is a bad idea, but everything seems to be working fine.

    here is the final Hijack This Log. Thanks.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Other than

    O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART

    Your log looks clean. I would go to Add/Remove programs and uninstall P2P Networking. See if that cleans up that O4 line in your HJT log.
     
  17. sweetleah3

    sweetleah3 Private E-2

    Ok, my computer is working great. The problem is fixed. I cant thank you enough for all the help. You're a lifesaver! :)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds