Options

Bestfriends.pif

Ihave read around your forums and tried a ton of things, but i still can't seem to figure out how to get rid of this stupid bestfriends.pif trojan/virus thing. please help me out! It is bugging me that AIM logs on without me doing anything and i can't use my task manager. :mad:

Here is my hijack log

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\44978.exe
C:\WINDOWS\System32\jwlogn.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\BSHARELITE.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Home\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.134.117.159:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://vip.pcsolution.com.br/cgi-bin/koc/friendtrade.pl"); (C:\Documents and Settings\Home\Application Data\Mozilla\Profiles\default\lta10mvp.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Home\Application Data\Mozilla\Profiles\default\lta10mvp.slt\prefs.js)
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: Clear Search - {00000000-0000-0000-0000-000000000240} - C:\Program Files\ClearSearch\IE_ClrSch.DLL (file missing)
O2 - BHO: (no name) - {002EB272-2590-4693-B166-FBD5D9B6FEA6} - C:\WINDOWS\multimpp.dll
O2 - BHO: (no name) - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll


thanks in advance!
P.S. i have run spybot and adware, but it hasn't helped.

Comments

  • edited December 2004
    i am not with short-media, but i was having the same problem, and my friends are too...i'm just curious, is it when yur on aim and then out of no where an away message goes up and it has a link to the virus or w/e it is?!

    i helped them make it so task manager comes back up, just go find a program u can temporarily use for it that will end processes, and just google them, like the last part the bla bla.exe...usually u can find something that will tell u what it is...that helped out a lot for us...other then that idk what else there is to do...i even tried totally getting rid of aim and that didnt work...if u find out what to do help us out man...i posted on this site and am sitll... waiting for a reply

    good luck!
  • edited December 2004
    hey, try removing C:\WINDOWS\System32\BSHARELITE.EXE you will have to do it in safe mode,or stop bsharelite.exe from starting up. It is a hidden file too. there is also another txt file that was created on the same day that keeps track of everything that you have typed (perty kewl, huh) well not realy. Hope this helps. Also look on the root of C: for a x.bat file and thre is also a .reg file and 3 html (web page) files. They are all created on the same day as the bsharelite file.

    This was the case wiht me and its fixed now. hope this helps

    n
Sign In or Register to comment.