This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

nasty aurora

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i have aurora. please analyze my logLogfile of HijackThis v1.99.1
Scan saved at 10:30:00 AM, on 18/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
c:\windows\system32\rzcuugc.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe
C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmon.exe
C:\Program Files\TELUS eCare\bin\mpbtn.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Krysta\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://svcs.microsoft.com/svcs/mms/addin.a…nger&Country=US
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [xbicutu] C:\WINDOWS\system32\xbicutu.exe
O4 - HKLM\..\Run: [znjjfr] c:\windows\system32\rzcuugc.exe r
O4 - Global Startup: TELUS eCare.lnk = C:\Program Files\TELUS eCare\bin\matcli.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.neededware.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

. thx
Hello and Welcome to TomCoyote forum. If you still need help, please follow these directions.

We need to get your HJT out of the Temporary folder into a permanent one where it can store backups for safety and logs. Please use the information in the following links to to do this.
http://www.bleepingcomputer.com/forums/tutorial94.html
Note: This video tutorial requires Macromedia Flash to play.
http://www.spywareaid.com/index.php?file=svideo&id=1
_____________________________________________________________

Aurora pop-up\Nail.exe thanks to racooper, miekiemoes and Swandog

Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.

Please download Nailfix from here:
http://www.noidea.us/easyfile/file.php?…5010747824
Unzip it to the desktop but please do NOT run it yet.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml


Once in Safe Mode, please double-click on Nailfix.cmd. Your desktop and icons will disappear and reappear, and a window should open and close very quickly — this is normal.

Then please run Ewido, and run a full scan. Save the logfile from the scan.

Next please run HijackThis, click Scan, and check:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

Close all open windows except for HijackThis and click Fix Checked.

Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
pskelley- thanks a bunch for the help with aurora. followed your instructions and it

all appears to be gone. you folks are great. :)


———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 8:56:09 AM, 19/06/2005
+ Report-Checksum: 6CAA9AF7

+ Date of database: 19/06/2005
+ Version of scan engine: v3.0

+ Duration: 33 min
+ Scanned Files: 86240
+ Speed: 42.30 Files/Second
+ Infected files: 95
+ Removed files: 95
+ Files put in quarantine: 95
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0

+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes

+ Scanned items:
C:\

+ Scan result:
C:\WINDOWS\system32\ctjdw.exe -> TrojanDownloader.Lastad.i -> Cleaned with backup
C:\WINDOWS\system32\ctjdwndw301lib.dll -> TrojanDownloader.Lastad.h -> Cleaned with backup
C:\WINDOWS\system32\hpqftow.exe -> TrojanDownloader.Lastad.d -> Cleaned with backup
C:\WINDOWS\system32\vbn.exe -> TrojanDropper.Agent.jl -> Cleaned with backup
C:\WINDOWS\system32\pslixks.exe -> TrojanDownloader.Lastad.n -> Cleaned with backup
C:\WINDOWS\system32\epx30103.exe -> TrojanDownloader.Lastad.h -> Cleaned with backup
C:\WINDOWS\system32\ivmroxe.exe -> TrojanDownloader.Lastad.h -> Cleaned with backup
C:\WINDOWS\system32\epx30105.exe -> TrojanDownloader.Lastad.p -> Cleaned with backup
C:\WINDOWS\system32\pslixksndw30102lib.dll -> TrojanDownloader.Lastad.h -> Cleaned with backup
C:\WINDOWS\system32\ivmroxendw30103lib.dll -> TrojanDownloader.Lastad.h -> Cleaned with backup
C:\WINDOWS\system32\mmxodvndw30104lib.dll -> TrojanDownloader.Lastad.h -> Cleaned with backup
C:\WINDOWS\system32\WinStat12.dll -> Spyware.Winsta -> Cleaned with backup
C:\WINDOWS\system32\prjd.exe -> TrojanDownloader.Small.vh -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\EPXActiveX.ocx -> Spyware.Winsta -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\epx301.exe -> TrojanDownloader.Lastad.i -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\epx30101.exe -> TrojanDropper.Agent.jl -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.5\epx30102.exe -> TrojanDownloader.Lastad.n -> Cleaned with backup
C:\Documents and Settings\Krysta\Local Settings\Temp\temp.fr566B -> Trojan.Agent.db -> Cleaned with backup
C:\Documents and Settings\Krysta\SSK3_B5 Verticlick 8.exe -> TrojanDropper.Small.qn -> Cleaned with backup
C:\Program Files\Windows Media Player\NDW.exe -> TrojanDownloader.Small.vh -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP246\A0008008.exe -> TrojanDropper.Small.aaq -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP246\A0008021.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP248\A0008036.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP249\A0008043.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP251\A0008063.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP252\A0008067.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP253\A0008074.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP253\A0008099.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP254\A0009191.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP255\A0009195.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP256\A0009202.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP256\A0009206.exe -> TrojanDownloader.Adload.a -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP257\A0009211.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP257\A0009213.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP257\A0009225.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP257\A0009227.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP257\A0009259.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP257\A0009261.exe -> Spyware.Bargainbuddy -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP264\A0009304.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP264\A0009305.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP265\A0009359.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP267\A0009375.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP267\A0009388.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP268\snapshot\MFEX-1.DAT -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP268\A0009473.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP269\snapshot\MFEX-1.DAT -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP269\A0009483.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP269\A0009488.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP271\A0009508.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP272\A0009600.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP272\A0009601.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP273\A0009611.dll -> Spyware.Winsta -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP273\A0009612.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP273\A0009613.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP273\A0009620.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP273\A0009626.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP273\A0009628.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP275\A0009649.exe -> TrojanDownloader.Adload.a -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP276\A0009655.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP276\A0009700.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP276\A0009701.dll -> Spyware.Winsta -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP276\A0009704.exe -> Spyware.Bargainbuddy -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP276\A0009705.exe -> Spyware.BargainBuddy -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP276\A0009709.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP276\A0009718.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP276\A0009720.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP276\A0009721.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP276\A0009752.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP278\A0009763.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP279\A0009771.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP280\A0009774.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP281\A0009777.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP282\A0009785.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP282\A0009786.exe -> TrojanDownloader.Lastad.h -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP282\A0009787.exe -> TrojanDownloader.Lastad.h -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP282\A0009788.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP282\A0009813.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP282\A0009819.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP282\A0009823.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP282\A0009824.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP282\A0009831.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009929.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009942.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009953.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009959.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009961.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009962.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009966.dll -> Trojan.Agent.db -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009973.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009974.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009976.dll -> TrojanDownloader.Lastad.h -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009981.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009992.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009994.exe -> TrojanDownloader.Lastad.p -> Cleaned with backup
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP283\A0009996.dll -> TrojanDownloader.Lastad.h -> Cleaned with backup

Logfile of HijackThis v1.99.1
Scan saved at 9:12:10 AM, on 19/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\ewido\security suite\SecuritySuite.exe
C:\Documents and Settings\Krysta\Desktop\HJK\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://svcs.microsoft.com/svcs/mms/addin.a…nger&Country;=US
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - Global Startup: TELUS eCare.lnk = C:\Program Files\TELUS eCare\bin\matcli.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.neededware.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE


::Report End
Hi smithrjones…who's Krysta? :) Great job with the Nail fix instructions. Just a little more to do but first the instruction were this:

Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.

It appears you created that last HJT log in Safe Mode. Please make sure you are in Normal Startup mode, then open HJT and click on "Do a system scan and save a logfile". Wait until HJT puts the logfile in a Notepad for you. The click Edit and Select All then copy and paste that information to this thread. Thanks.

Ewido Scan log:

Much of that stuff is in System Restore, please wait until the all clean then purge (turn off, reboot and turn back on System Restore) this will give you a clean restore point. Here are instructions:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

I will make one other suggestion, once you are clean and have purged System Restore, run Ewido again, it should show nothing at that point. Let me know if that is the results. Waiting on that HJT log in Normal Mode.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Krysta is my daughter. Her computer. Here is the correct log. Somehow during the process I lost my(her) mm driver to mmsystem002( error message ). Any fantastic fixes for this? Logfile of HijackThis v1.99.1
Scan saved at 3:57:58 PM, on 19/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe
C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmon.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\TELUS eCare\bin\mpbtn.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Messenger\YPAGER.EXE
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Krysta\Desktop\HJK\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://svcs.microsoft.com/svcs/mms/addin.a…nger&Country=US
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - Global Startup: TELUS eCare.lnk = C:\Program Files\TELUS eCare\bin\matcli.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.neededware.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

Also, can I delete things from this list like 015 ? Thank You
OK thanks, nice to be a father that can help his daughter on father's day.

Somehow during the process I lost my(her) mm driver to mmsystem002( error message ). Any fantastic fixes for this?

mm driver? What is the program? Let's finish this cleanup and I will see what I can do. I will need the exact error message, word for word.


I wish to give you some information about this item and the dangers of it. While I do not know what version she has this is some of the available information:
C:\Program Files\LimeWire\LimeWire.exe
http://castlecops.com/startuplist-5068.html
http://www3.ca.com/securityadvisor/pest/pe…px?id=453088059

See this for more information about Limewire and other bad P2P software, also included in the information are P2P software that can be used safely.
http://www.spywareinfo.com/articles/p2p/

Here is some information your daughter should know about:
http://www.mainstream.net/security_howto/d…e_sharing.shtml
http://www.infopackets.com/gazette/2003/20…ng_software.htm
http://www.infopackets.com/gazette/2003/20…ware_part_2.htm

The program can be uninstalled in Add Remove programs.

I also notice this program: C:\Program Files\Common Files\Command Software\dvpapi.exe See next link:
http://www.spywareaid.com/023l.php?action=…ch2&name=DvpApi

and this program: C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe See next link:
http://castlecops.com/startuplist-1267.html are both reading as antivirus programs. I would look at this because you should only run one AV program at a time. Conflicts between running AV programs can make you less secure than you would be with one good program well maintained.


Let's finish the cleanup like this:

1) Download CCleaner from this link: http://www.ccleaner.com/ Take the time to review the instructions on the download page so that when I ask you to run it you will know what you are doing.

2) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R3 - Default URLSearchHook is missing
O15 - Trusted Zone: http://www.neededware.com

3) Close all programs but HJT and all browser windows, then click on "Fix Checked"

4) Run CCleaner then restart the computer and post a new log in this same thread along with any feedback you have. Let us know how you are running.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Run CCleaner then restart the computer and post a new log in this same thread along with any feedback you have. Let us know how you are running. No response in over ten days, I will close this thread in 24 hours. Thanks…pskelley
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI