Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

HijackThis & Ewido logs after fixin Aurora


  • Please log in to reply

#1
thedragonreborn

thedragonreborn

    New Member

  • Member
  • Pip
  • 2 posts
Hi!

I had been infected with Aurora, Dr.PMon.dll, Nail and god knows what else!!! This even though i have been using Spyware Blaster, AVG, AdAware, MS Firewall and RegCleaner for over two years!!! Not to mention daily scans and updates ;) :tazz:

I went through all the instructions metted out to folk out here with the same problem and have saved the log files for both Ewido and Hijack This.

Could someone please take a look at them and let me know if I have any clean up left to do?

Also i would be grateful if advised how to avoid infections, especially in the light of I having had taken precautionary measures ;)

Thanks a cartload!!!!

Hijack This Log :

Logfile of HijackThis v1.99.1
Scan saved at 12:15:09 PM, on 7/5/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
E:\Program Files\ewido\security suite\ewidoctrl.exe
E:\WINDOWS\System32\Smtray.exe
E:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
E:\WINDOWS\System32\SK2690DM.EXE
E:\Program Files\AnalogX\CookieWall\cookie.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
E:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\WINDOWS\System32\ctfmon.exe
E:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
E:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
E:\WINDOWS\System32\nvsvc32.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\wuauclt.exe
F:\Software\Aurora Removal\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://bbc.co.uk/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - E:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - E:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Smapp] Smtray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] E:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [Hot Key Kbd 2690 Daemon] SK2690DM.EXE
O4 - HKLM\..\Run: [Microsoft System Checkup] ntsysman.exe
O4 - HKLM\..\Run: [NT Logging Service] syslog32.exe
O4 - HKLM\..\Run: [CookieWall] E:\Program Files\AnalogX\CookieWall\cookie.exe
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [edatjp] e:\windows\system32\kwypfvd.exe
O4 - HKLM\..\RunServices: [Microsoft System Checkup] ntsysman.exe
O4 - HKLM\..\RunServices: [Microsoft Update Machine] Winregs32.exe
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Update Machine] Winregs32.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "E:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\RunServices: [MSN Messanger] msnmsng.exe
O8 - Extra context menu item: &Google Search - res://e:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///E:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://e:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://e:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Save with Download Manager... - E:\Program Files\J River\Media Jukebox\DMDownload.htm
O8 - Extra context menu item: Similar Pages - res://e:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://e:\program files\google\GoogleToolbar3.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///E:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///E:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\j2re1.4.1\bin\npjpi141.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\j2re1.4.1\bin\npjpi141.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - E:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - E:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - E:\Program Files\Yahoo!\Common\yiesrvc.dll
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - E:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1099494571311
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - E:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - E:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NT login service (ntlogin32) - Unknown owner - E:\WINDOWS\System32\ntsysman.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\System32\nvsvc32.exe


Ewido Log File:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 12:09:17 PM, 7/5/2005
+ Report-Checksum: A3C3E7DF

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{3646C2BD-3554-49CA-8125-44DEEFB881DE} -> Spyware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3f4d4f88-0198-4921-b630-957f3eb814e0} -> Spyware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6DF5E318-6994-4A41-85BD-45CCADA616F8} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{258A3625-183B-4477-AEE2-EA54DF6D878D} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D273D427-57C6-4B12-860F-BBB8195F6E2A} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{EFA52460-8822-4191-BA38-FACDD2007910} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Web Offer -> Spyware.eZula : Cleaned with backup
C:\WINDOWS\TEMP\targetsaver.exe -> TrojanDownloader.TSUpdate.f : Cleaned with backup
C:\WINDOWS\TEMP\GLFD070GLFD070.EXE -> TrojanDownloader.TSUpdate.f : Cleaned with backup
:mozilla.7:C:\WINDOWS\Application Data\Mozilla\Users50\aryakm\6ulrlb3y.slt\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\WINDOWS\All Users\Application Data\Grisoft\Avg7Data\avg7upd\install.1\avgemc.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\WINDOWS\All Users\Application Data\Grisoft\Avg7Data\avg7upd\backup\avgemc.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\v3.dll -> Spyware.EliteBar : Cleaned with backup
:mozilla.7:C:\WINDOWS\Profiles\Pukul\Application Data\Mozilla\Users50\aryakm\6ulrlb3y.slt\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\WINDOWS\Profiles\Pukul\Cookies\pukul@stats3.porntrack[1].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\RECYCLED\Q330995.exe -> TrojanDownloader.Agent.ew : Cleaned with backup
C:\Program Files\Internet Explorer\jhclphin.exe -> Trojan.Starter : Cleaned with backup
C:\Program Files\Internet Explorer\dmldqa.exe -> Trojan.Starter : Cleaned with backup
C:\Program Files\Internet Explorer\wzdqdvgk.exe -> Trojan.Starter : Cleaned with backup
C:\Program Files\Grisoft\AVG Free\AVGEMC.EXE -> Heuristic.Win32.Dialer : Cleaned with backup
C:\Program Files\DAP\DAP.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\Program Files\GoldenSoft\Recovery Genius 21st\Win9X\YzDll32.dll -> Trojan.LaSta : Cleaned with backup
C:\p.exe -> Spyware.WinComm : Cleaned with backup
D:\Adobe Albums\Cat35\Sexual or Erotic Films.htm -> Spyware.BookedSpace : Cleaned with backup
D:\Adobe Albums\Cat35\Sexual or Erotic Films 02.htm -> Spyware.BookedSpace : Cleaned with backup
E:\WINDOWS\system32\drivers\etc\hosts -> Trojan.Qhost : Cleaned with backup
E:\WINDOWS\system32\criepe.exe -> Trojan.Agent.cp : Cleaned with backup
E:\WINDOWS\qmusybl.exe -> Adware.BetterInternet : Cleaned with backup
:mozilla.74:E:\Documents and Settings\Aryak\Application Data\Mozilla\Firefox\Profiles\84ebcbby.default\cookies.txt -> Spyware.Cookie.Goldenpalace : Cleaned with backup
E:\Program Files\Common Files\GMT\GatorStubSetup.exe -> Adware.Gator : Cleaned with backup
E:\Program Files\Common Files\GMT\GUninstaller.exe -> Adware.Gator : Cleaned with backup
E:\Program Files\Grisoft\AVG Free\avgemc.exe -> Heuristic.Win32.Dialer : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP8\A0004399.exe -> Trojan.Agent.cp : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP8\A0004400.exe -> Adware.BetterInternet : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP8\A0004407.exe -> Trojan.Agent.cp : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP8\A0004415.exe -> Adware.BetterInternet : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP8\A0004429.exe -> Trojan.Agent.cp : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP8\A0004435.exe -> Trojan.Agent.cp : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP8\A0004439.exe -> Adware.BetterInternet : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP8\A0004440.exe -> Adware.BetterInternet : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP9\A0004443.exe -> Adware.BetterInternet : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP9\A0004449.exe -> Trojan.Agent.cp : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP9\A0004455.exe -> Trojan.Agent.cp : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP9\A0004461.exe -> Adware.BetterInternet : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP9\A0004462.exe -> Adware.BetterInternet : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP9\A0004472.exe -> Trojan.Agent.cp : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP9\A0004480.exe -> Adware.BetterInternet : Cleaned with backup
E:\System Volume Information\_restore{5A2001BE-65E1-44F9-A544-E573396E848A}\RP9\A0004497.exe -> Trojan.Agent.cp : Cleaned with backup
F:\Software\Haunt.zip/Haunt.exe/hauntpc.exe -> Not-A-Virus.Joke.Hauntpc : Cleaned with backup


::Report End



cheers!!!
  • 0

Advertisements


#2
thedragonreborn

thedragonreborn

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
i have come across something called ntsysman in the logs!!!
folk say that it is a drop off from a worm!!!!

Wud be grateful for any advice about it and a review of the logs posted above!!!

cheers!!!

*Edited by an Administrator

Hello! Bumping your thread will not get you helped any quicker, as we look for threads with no replies. Also, we work from oldest to newest, and currently are working on logs that have been posted three to five days ago , sometimes even older. Please be patient with us. We are working as fast as we can without compromising the integrity of our work.

While you are waiting:

We can definitely help you, but first you need to help us. The first step in this process is to apply Service Pack 1a for Windows XP. Without this update, you're wide open to re-infection, and we're both just wasting our time.
Click here: http://www.microsoft...p1/default.mspx
Apply the update and reboot. This step MUST be done prior to recieving help here. :tazz:





Edited by ~Kat~, 07 July 2005 - 10:57 PM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP