Best Friends Virus (Reprise)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Ryanyde, Oct 5, 2004.

  1. Ryanyde

    Ryanyde Private E-2

    I know this might be cross posting, but someone suggested I start a new thread.

    Unfortunately, I just got it today.

    Here's the deal

    Within 5 minutes (through windows search), I had tracked down most of the "prefetch" files and the original files that had been modified and deleted them. I pretty much deleted anything I'd consider suspect, and I'm hopefully not a total n00b (aside from the fact that I clicked the link in the first place).
    But problems still persist.
    I downloaded the AIM virus removal and it said that my AIM is clean.

    The problem is that I can not see my task manager. The virus doesn't seem to still be active. Symantec picks up nothing. Is there anything I can do to fix the task manager problem? Any way to make sure my computer is free of virii? I tried your browser check, but it didn't like it because I'm using mozilla.

    On a side note, I can't system restore. It just says the system restore was unsuccessful.

    What can I do?

    Please Help.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow all the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  3. Ryanyde

    Ryanyde Private E-2

    I've pretty much done all of that

    I've done all the relevant stuff.
    What now?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I've pretty much done all of that

    What does "elevant stuff" mean? Please do all of it.
     
  5. Ryanyde

    Ryanyde Private E-2

    Re: I've pretty much done all of that

    Okay, so I've turned off system restore.
    I'm not on a network.
    Viewing hidden files.
    Ad-aware's on my computer, but it's a virus, not ad-aware.
    CCleaner Installed.
    Spy Stuff installed, even though it's not spyware.
    The rest of the other ones pertain to problems I don't have.
    Trend Micro doesn't work because i"m using mozilla.
    I've run stinger in safe mode.

    SO that's what I"ve done. Did I miss anythign important? I've also done a full scan with Norton Anti-Virus Corporate Edition.

    Could we please address my question now.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I've pretty much done all of that

    What do you mean by:
    1) "Ad-aware's on my computer, but it's a virus, not ad-aware." Are you saying you have an virus infected version of Ad-aware? What version of Ad-Aware SE do you have?
    2) "CCleaner Installed." Okay did you run it?
    3) "Spy Stuff installed, even though it's not spyware." WHAT??? What's not spyware? Do you mean your problem is not spyware? Did you install SpyBot S&D and run a full scan with it? Did it find anything?

    Did you run the Symantec scan?
    Run TrendMicro using IE.
    Run CWShredder too.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I've pretty much done all of that

    For your Task Manager problem, you could try to rename it or copy it elsewhere to a a totally different filename and extension. Try mytmgr.com. Then see if you can run that. If not, download (and I'm assuming you have WinXP, you did not say) ProcessExplorer for Win NT/2K/XP and use it instead to look at processes.
     
  8. Ryanyde

    Ryanyde Private E-2

    Okay...

    Not to sound annoying, but I've read the other thread. I have the Best Friends virus. Not ad-aware. Not spyware. A virus. One that needs to be dealt with.

    I've spent two hours, and running a SPYWARE scan isn't going to show me any viruses. CWShredder is for a specific problem that I DONT have.

    I don't see why I should go through all of this procedure when it's doing nothing to help my computer. I run spybot S&D everyday, along with ad-aware. I've run stinger, Norton Corporate. I'm trying to focus on my specific problem. One with the best friend virus.
    As a consequence, my task manager doens't open, and I don't know what to do.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The processes are there for a reason. To get your system into a known state. And I'm sure you were not 100% clean. Your Task Manager problem is also a symptom of some malware. If your problem were merely a virus, then explain why Symantec did not fix it.

    And by the way, spyware scanners DO show many viruses and trojans.

    Please do what I gave you below for Task Manager and if that does not help do this:

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  10. Ryanyde

    Ryanyde Private E-2

    I actually have that program

    I downloaded it when my task manager didn't work. It doesn't seem to list as many task as the original task manager though.

    I'll post my hijack this logfile shortly.
     
  11. Ryanyde

    Ryanyde Private E-2

    HIjack this logfile

    Alright here it is.

    Aside from that, I use spykiller S&D and ad-aware every day. I am aware that malicious programs come in the form of adaware, I just know that's not the problem. Maybe I did have some malware on my computer, but very little, as far as i"m concerned.

    In any case, I tried renaming the task manager, and it just created a new instance of the file in the c/system32 file.

    Also, what is C:\I386?
    It seemed to have a copy of task manager in there at one point. Maybe I"m confusing things now.

    But as I've said, the virus (which puts up an away message) seems to have ceased, I just want to make sure that the virus is completely eradicated.
    As for the logfile, I already killed the stuff that blocks my task manager. Should I restart and put a new logfile up?
    If so, I'll do it tomorrow morning, because I"ve already spent way too much time dealing with the virus tonight, and I have early class tomorrow.

    THanks a lot for your help up to this point.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: HIjack this logfile

    It's SpyBot S&D. Spykiller is crapware. If you have Spykiller get rid of it.

    Did you try running the renamed version of task manager. You have to double click on the new named file from Windows Explorer. You cannot just use CTRL-ALT-DEL to run it.

    C:\I386 is the directory where Windows stores all of its files that it use for installation and for additions and changes to your system. It comes right off the original CD.

    You said "But as I've said, the virus (which puts up an away message) seems to have ceased". Does that mean that Task Manager and AOL are both working okay now?

    Your HijackThis is out of date and does not look like a complete file. Maybe it looks incomplete because you never ran the online scans from Symantec or TrendMicro.
    All I see in your current log that could be fixed is (but they are not the reason behind your problems):
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    By the way a new version AIM Fix 1.0 (Updated) came out today!
     
  13. Ryanyde

    Ryanyde Private E-2

    I have spybot S&D, not spykiller...

    Sorry for calling it spykiller...
    The AIM thing as I've said seems to have gone away, but my task manager still doesn't work. If I rename my task manager and want to run it, will I just not be able to use Control + Alt + Del anymore?
    When I run mytskmgr.exe from the Windows System32 file, It runs fine. I'll upload another HIjack This File because I had already killed a bunch of processes last time when I ran it.

    The virus does seem to be gone, but I don't want any performance drops (as I said my computer takes longer to start up), and I'd like to be able to use my task manager. Aside from that, I'd like to make sure that my computer doesn't have any backdoors/trojans that are still dormant. Basically I'd like to know if I'm clean of this thing or not, and until my task manager runs, I'm pretty sure i"m not.

    I downloaded AIMFix last night, if there's a new one out today, I'll try it.

    So what should I do now? My logfile is below.

    On a side note, if my HJT is out of date, where's the newest version?
     

    Attached Files:

    Last edited: Oct 5, 2004
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I have spybot S&D, not spykiller...

    Download the latest HJT from the link given in the READ ME FIRST thread !
    The current version is 1.98.2. Post a log using it.

    And yes I understood that renaming taskmgr.exe would make it not possible to use CTRL-ALT-DEL. I just wanted to see if it would work. It most like means you have a virus/trojan causing a problem. If it still did not work, the file may have been corrupted.

    By the way, ProcessExplorer that I gave you is far superior to TaskManager and can show things and kill things that TaskManager cannot. It also gives full paths to executables and shows the DLLs being loaded to.
     
  15. Ryanyde

    Ryanyde Private E-2

    It may be unnecessary...

    I downloaded the latest AIMfix and it found and deleted the file that was causing a lot of my problems. My task manager works now, and my computer starts up fine. On a side (probably very newbie) note, why does my system idle process say it's take up 99% of the CPU when task manager is open, and when the CPU load is often at 0 or 2%?

    I'll post a hijack this file shortly, to make sure I"ve got nothing else bad.


    Thanks for your continued help.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: It may be unnecessary...

    When your not doing anything (your idle), so System Idle Process is where CPU cycles are spent. The idle process is not considered CPU useage.
     
  17. Ryanyde

    Ryanyde Private E-2

    Maybe I'm done with it.

    I downloaded the latest AIMfix and it found and deleted the file that was causing a lot of my problems. My task manager works now, and my computer starts up fine. On a side (probably very newbie) note, why does my system idle process say it's take up 99% of the CPU when task manager is open, and when the CPU load is often at 0 or 2%?

    The Hijack this file is up. Can you see anymore malware or any other stuff I should remove? I'm generally pretty careful with the stuff I download etc, and scan every other day for spyware/malware/adware. So I'm hoping I'm clean, but I just want to make sure this damned thing is gone.

    The Latest AIMfix seems to be working quite well now.

    Cheers.

    P.S. For some reason it won't let me attach my logfile, it is currently "in progress" of being attached under my attachments. If you can't find the newest one, let me know.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Maybe I'm done with it.

    I cannot see it. Did you give it a different name than last time and also make it a .txt file?

    If still having a problem, post it as inline text and I'll change it. I'm curious to see if anything changed.
     
  19. Ryanyde

    Ryanyde Private E-2

    Here it is.

    Here
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Here it is.

    Okay just have HJT fix the below lines and you should be done:


    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
     
  21. Ryanyde

    Ryanyde Private E-2

    Thanks a lot...

    It seems my problems have been fixed. Anyone with this problem can use the latest version of AIMFix.exe as that cleaned it out, along with some strategic hijack this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds