http://bestfind4u.com/index.htm Get Rid of

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mononga, Jan 7, 2005.

  1. Mononga

    Mononga Private E-2

    Hello this is my first time posting in this forum and really need some help. No matter what I have tried to get rid of the bestfind4u it keeps comming back. There was a post here with the same problem but it was not much help to me. What I have tried is running Ad-aware, Spybot S-D, NoAdware, CSWhredder, hijackthis, and the new microsoft AntiSpyware. It seems to find it all but it just keeps comming back. Any help would be great. Thanks.
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi Mononga,

    Generally, it is a good idea to start with the Cleanup Tutorial HERE:

    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    There are only a few of us Volunteers who regularly offer advice in this forum. Running through the above Tutorial will remove a lot of stuff that would otherwise clog a HijackThis Log and save us valuable time.

    Please let us know the steps that you are able to complete and the ones that give you problems. Note that you need to be in Safe Mode with System Restore OFF (if you have it) and have the Viewing of Hidden Files ENABLED as per the instructions in the link. Make sure to do the Online Scans.

    Post back and let us know how you fared. Also, send us a HijackThis Log. Please be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!
    Should you need a Fresh Download of HJT, get it HERE: HijackThis v1.99

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    I’m not around this forum too often these days, but somebody will try to take a look when they get a chance.

    Best luck :)
    PP
     
  3. Mononga

    Mononga Private E-2

    I followed the guide to a T. Disabled system restore did the scans in safe mode. Rebooted its back. I attached the log.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have HJT running from the ZIP file using RAR to extract it to a temp folder. Please follow the directions given and extract HJT to the folder Phillie gave you. You must do that before continuing.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you followed the guide to a T, why is there no evidence that the online scanners where not run?

    Please follow directions and run the online scanners. Did you skip anything else?

    Edit: Sorry I see that one (TrendMicro) was run. Why was the Symantec scan skipped?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    gwaftuj.exe


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bestfind4u.com/sp.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://bestfind4u.com/index.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://bestfind4u.com/index.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://bestfind4u.com/sp.htm
    O4 - HKCU\..\Run: [vqjxvhm] c:\windows\jchtovt.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\windows\gwaftuj.exe
    c:\windows\jchtovt.exe

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. Mononga

    Mononga Private E-2

    I think its gone hehe. Took a long time but the bestfind4u is not comming back and I dont have unwanted favorites. This time I did follow the guied the best I could running the online virus scan and online security check. went into safe mode ran the scans again then ran all the spyware tools you have in your guide. Ran the hijackthis removed the bestfind4u and deleted the two files you listed in windows\gwaftuj.exe and jchtovt.exe. I ran the hijackthis again when I rebooted into normal and posted the log. Thanks again for all the help this thing was driving me crazy.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have a problem showing.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKCU\..\Run: [odnuqnl] c:\windows\dkctyeg.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    c:\windows\dkctyeg.exe

    Let me know if you have a problem finding or deleting this file.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. Mononga

    Mononga Private E-2

    Thanks for all your help on this. I did what you said and had no problem finding the file to delete in safe mode. Here is my log file again. thanks again.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds