Logfile of HijackThis v1.99.1
Scan saved at 9:13:15 AM, on 11/7/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
C:\Documents and Settings\finch\Desktop\HijackThis.exe
into a separate folder of its own... We recommend using folder C:\HJT , so that it will then appear in your log under running processes as C:\HJT\HijackThis.exe
This is important because HJT generates log files, and backup files, in the folder from which it is run. So at present, all these logs/backups will just "clutter-up" your Desktop. And if you simply delete them from there, you'll lose the important backup information, which may be needed in case you have to "undo" [restore] some of the things you "FIX" incorrectly.
After you move HJT, as i've just instructed:
Among other things, you have a
NAIL/(triple) epolvy/SvcProc infection... I'm going to try to help you to remove this first. This fix involves using Ad-Aware, and its VX2-cleaner.
It is critical that you use the current versions as indicated below... if you use an older/obsolete version, the fix will not work.
[Note: If you have an older "build" of Ad-Aware SE --- or even worse, if you're still using Ad-Aware 6 --- you must upgrade to this version/build, SE 1.06 ]
Install the Ad-Aware program (following any indicated directions). [As part of the installation, it will check to see if you already have an older version of Ad-Aware installed, and if one is found, it will ask ("advise") you to allow the older one to be removed... so if asked, please allow it.]
Open/start
Ad-Aware SE. Click on
Check for Updates Now, and
Connect . if found, follow the directions to download/install the latest reference file, till you
FINISH.
After updating, from the STATUS screen, click on
START.
then make sure you have a
RED X in front of "Search for negligible risk entries"
(if you see a GREEN CHECK, then CLICK on it, to change it to the RED X. )
then hit
NEXT to perform a S
mart Scan. Allow it to remove any problems founds.
Close-down Ad-Aware.
then download the
VX2-cleaner add-on by clicking-on the link near the bottom of
This will download the file vx2cleaner_inst.exe ; click on it, and follow the directions to install the VX2-cleaner.
Start
Ad-Aware SE again. Click on the
Add-Ons button. Click on the
VX2-Cleaner. Click on
Run Tool, and then click
OK . If it finds any VX2 problems, follow all the directions to
CLEAN things. (I believe this will include a reboot, and directions to run another smart scan. Follow all indicated directions [i.e., various/multiple scans] until it tells you you're clean of VX2.
This
should have removed all traces of NAIL/Aurora/epolvy. Please generate and post a new HiJackThis log, appending it to this same thread.
Thanks ky331, You guys don't know how glad I am for this support, I would be lost without it, so you guys rock! To bad the Green Bay Packers didn't...ha...they got rocked by Pittsburg...anyway I am very happy to talk to someone who has experience in virus removal!
I had installed the HJT folder as instructed into the C: drive. But my CPU is so hammered I have trouble keeping the computer going for any length of time without going into SAFE MODE. So I think this is why it showed on the desktop? Anyway later on a virus hammered my .exe that was in the folder and now is made useless.
So is it ok to run the ADAWARE SE Personal, just new version loaded yesterday, and then get Ad ons for VX2 removal in SAFE MODE?
if at all possible, see how much you can run in NORMAL mode... but if it's absolutely impossible, it certainly couldn't hurt to try running some/all of these in safe mode....
[by the way, my goal with you is to take care of the NAIL/epolvy/SvcProc problem... and maybe a few more minor points... after which, the plan is to call in someone else for the remainder of your problems. so if it turns out you're having any "major" problems in getting things to run because of your "hammered" system and/or a need to run in SAFE mode, please let me know ASAP, and if need be, we'll put out that "rescue" call sooner than later...]
if you can't access the internet on your bad PC, then you'll have to do your downloads on another "good" PC (at work? a friend's?), and then copy/transfer the files... by floppy, CD/RW, or memory-stick... from the good PC to the infected one.
****************
if i understand what you said, you've lost your copy of hijackthis.exe ? if so, you can download a
self extracting copy of HijackThis from
http://downloads.malwareremoval.com/hijackthis_sfx.exe and save it to your desktop. Double-click on the file
hijackthis_sfx.exe file and it will self extract into its own folder in
C:\Program Files\HijackThis
***************
you say you just got Ad-Aware SE yesterday? did you also get the updated definition/reference file at the same time? if not, you can also perform this update onto your good machine, and then, [assuming you've accepted the Ad-Aware defaults], transfer the file:
C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
*****************
and we certainly need to download/install the VX2-cleaner add-on.
Ok, I ran all this NORMAL mode, ran the Adware SE after udpate defs and did a Smart Scan and delete, the got the VX2 cleaner downloaded ok and ran the tool. Then had to get the HiJackThis.exe back and copy and pasted into HJT folder and ran and made this current log.
Logfile of HijackThis v1.99.1
Scan saved at 8:51:06 PM, on 11/7/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Great work so far. While there's still a lot more to do, it seems that you've successfully removed the NAIL/ (triple) epolvy /SvcProc problem... Have you noticed any difference (probably in terms of popups from "Aurora")?... does the system seem ANY more responsive yet?
At this point, I'm gonna ask someone else to step-in, to help you with your remaining problems. Please be patient, as we're very much "understaffed" and "overworked" here at the moment.
Good luck.
P.S. If i'm not mistaken, you have MANY virus infections (which the next person will hopefully tend to)... my question: do you keep your anti-virus subscription, and its definitions/signatures up to date? I strongly recommend you check for updates every time you log onto the internet. [and you should do a complete system scan at least once a month.]
Things to seem to be running less CPU intensive, but get lots of Ads running from SSK..or Sidekick? When I connect on the net and start a browser, pop ups will start coming in and I have to continually close these before the computer loads up and crashes. But yes I think currently I see some improvment. This computer was inherited from a friend and he did not keep windows updated and did not have a antivirus program, so he just used it until it crawled. Now have McAfee on it; and then trying to run his Windows Updates that he never ran either. When I ran McAfee scan it showed I had Downloader-KL and Adware-Gator, but ran the Adware-Gator tool from Symantic but could not find anything. McAfee could not fix Downloader-KL or Gator so should I quarantine these, or delete them? Thanks very much for all of your kind help!!
Start, Control Panel, Add/Remove Programs and see if you can find Surf SideKick and remove it. IF not then Start, Run, cmd, OK to bring up the black cmd screen. Type:
cd "\Program Files\SurfSideKick 3" ssk.exe /u
(that should uninstall it. Close the window. You can copy each line of the above =>highlight and ctrl + c then move to the cmd screen and right click to paste it)
Unpack to your desktop and run it. If you have green print at the top then just press Restore Original Hosts then OK. IF you have red print then press make Hosts Writeable first.
Shutdown and Restart and Boot into Safe Mode by tapping the F8 key when you see the PC maker's logo. Keep tapping until it tells you it is going to Safe Mode or you see the Safe Mode menu. Select the top option.
Run HijackThis and just do a Scan only. Check then Fix Checked the following:
Run ccleaner.exe, uncheck everything on the first page except the two entries with Temporary and then Run Cleaner.
Run killbox. Where it says Full Path of File to Delete you need to type or copy (Hightlight and Ctrl + c) and Paste (move to the killbox and place the cursor in the box and Ctrl + V):
C:\Program Files\TBONAS
Then check the Delete on Reboot box and DELTREE box then the red button. Agree you want to remove the file but do not let it reboot yet.
Repeat for: C:\WINDOWS\System32\kcybo C:\WINDOWS\System32\cwtscs C:\WINDOWS\System32\kemx C:\WINDOWS\System32\nfomon C:\Program Files\maat C:\Program Files\SurfSideKick 3 (it may not find it)
Repeat with only Delete on Reboot:
C:\Program Files\Q330994.exe C:\WINDOWS\dinst.exe
If it doesn't find one then just go on to the next.
Let it reboot after the last one.
Run another HijackThis log and post it as a reply. Let's see how we did.
Thanks very much for taking me on! I apreciate all of you guys.
Stupid me, I did not see that Sidekick way down below the Windows Updates in the Remove Programs Menu otherwise I would have killed the darn thing faster than lightning. So last night after my last post I found it and deleted the program.
So now do I continue with what you advised after that, from Download Hoster on down?
Thanks, I am at work now, but will try to do this after 6 pm tonight and send a new HiJack Log. By the way I ran a McAffee virus check this morning and shows no viruses. I have also had to uncheck several programs in my msconfig Start to keep from overwhelming the CPU when startup, so should I keep these unchecked or go full speed ahead?
I am also low on Hard Disk Space with only 5 to 10 percent free when I use System Restore and I could not run a defrag so I turned off System Restore and have now 15 percent so I can Defrag ok. Should I keep System Restore always going, or leave off? I also plan on moving some files to another external disk to free up some much needed Free Space, as currently it is choking.
ky331
5 Journeyman
•
15623 Posts
•
45050 Points
417
0
Posted November 7th, 2005 18:00
First, you should move HJT from your Desktop:
C:\Documents and Settings\finch\Desktop\HijackThis.exe
into a separate folder of its own... We recommend using folder C:\HJT , so that it will then appear in your log under running processes as C:\HJT\HijackThis.exe
This is important because HJT generates log files, and backup files, in the folder from which it is run. So at present, all these logs/backups will just "clutter-up" your Desktop. And if you simply delete them from there, you'll lose the important backup information, which may be needed in case you have to "undo" [restore] some of the things you "FIX" incorrectly.
Message Edited by ky331 on 11-07-2005 04:55 PM