………Or, how I was able to remove this annoying aim virus from 2 different computers(with help from Gina and John Beasley)
Unfortunately the newest AIM virus is tricky, and therefore unable to be removed by just anyone. A little computer knowledge is needed. So if you got here because you are infected by the virus and you don’t know anything about computers you have two choices. One, you can format your hard drive and reinstall everything(works well—and is needed once in a while anyways) or you can get someone you know that is computer savy to follow my directions here.
Tools you will need:
- Barts PE Builder CD(http://www.nu2.nu/pebuilder/download/)
- A good file manager(Servant Salemander) for BartPE. The page where it can be found is here: http://www.hallsted.us/barts-pe-plugins-mlh/barts-pe-plugins-mlh.html
- A good antivirus installed on BartPE Builder(winclam antivirus works well—helped to identify that the virus hides in the paging file the first time I did this)
- Your Head
- Your Eyes
- A good antivirus installed in Windows(I recommend AVG: http://free.grisoft.com/doc/5390/lng/us/tpl/v5)
- Crap cleaner(http://www.ccleaner.com/)
- Security Task Manager(http://www.neuber.com/taskmanager/)
Ok, so to remove this nasty W32.Pipeline virus, there are a few steps. It seems like a lot on here, but once you get going, it goes by pretty fast.
The first step in the process is to create a good BartPE Builder CD. All you need is the basic cd as well as winclam antivirus and the file manager plugin. The BartPE site has an excellent tutorial on how to create their disk, so I will let you read their information on their site. I recommend that you create the disk on another person’s computer. Also, please note that there is important information on there about licensing. I can/will not be held responsible if you do not follow the licensing. This is an important legal/moral issue so I suggest you fully read and understand it. The website has an excellent FAQ, and licensing is covered under there.
The next step is to install and run Security Task Manager. This is a great program because it sorts out items by threat level based on different characteristics of the program. Go into the program, and notice any processes that are marked with a high danger level that you do not recognize on the system. Note those processes, and if you have internet access, use your favorite search engine to locate where those processes should be on the machine. If any of those processes are in the wrong location, write them down. We will remove them in a little bit.
Update your Antivirus to the latest definition files if it isn’t already updated.
Next, you need to disable system restore. How do you do this? I thought you would never ask.
In Windows XP:
Go to your control panel(STARTSETTINGSCONTROL PANEL or (WINDOWS KEY)+R control.exe)
On the control panel, choose System
Inside of System, Click on the system restore Tab
Check the box that says: “Turn off system restore”
It will take a moment as all the system restore items are erased. After that is done, the next item of business is to install a good antivirus program onto your system.
I recommend AVG antivirus for a good free personal antivirus. AVG FREE can be found at the following link(http://free.grisoft.com/doc/5390/lng/us/tpl/v5)
Make sure to update the antivirus fully before continuing.
Next, use Crap Cleaner
Download and install Crap Cleaner
Reboot the computer into safe mode
Run Crap Cleaner and have it delete all of the temporary files
Reboot the computer, and boot to the cd created with the BART PE Builder
Load the file manager
After that is done, the real fun begins:
Navigate to your root directory(default: c:\), or if you have a custom setup, to where your paging file is located.
Delete the paging file. Don’t worry. It will be recreated when Windows reboots.
Delete the files ntp or any variation on the name ntp as well as any other unusual files that are on the root of your hard drive. (again, default is C:\) The reason that this virus is so effective is that it is able to create randomly named files that sit on the hard drive, and in the paging file(sneaky little beast)
Navigate to the system32 folder
This is where the whole thing either goes or it fails. The system32 folder is where each of the last few executables will be. And by few, I mean many processes with long random names. An example of one of these processes names is: cjnr4r4lxitfrdp.exe You will need to make sure that the file manager is set to show hidden files as well as system files and is sorting by name. Go through the directory and delete any files that have names that are long and random like the file above. They can start with any letter of the alphabet, so it can be a long and tedious processes to find them all. After you have checked through the directory once, check it again to make sure you didn’t miss one.
If there were any processes on the list you created earlier, delete those processes now.
Using clamantivirus, run a full virus scan on the system. If it detects any viruses on the system, delete those files as well.
Reboot your computer back into safe mode.
Run a full scan with your antivirus again just to make sure that all viruses are cleaned up.
Another way to make sure that the virus has been removed is to make sure to remove the b2_log.txt file on the root of the hard drive. If this file is removed, and then you reboot(not into safe mode) and after about ten minutes it still is not present, then you have successfully removed this annoying virus.
If you have any questions or comments, please feel free to reply below. I will check on messages that I get once in a while. Thanks for sticking in there!
Categories: Tricks and Tips
1 Comment »