UNSOLVED

Wiley Eiley

updated

21 years ago

0

330

July 3rd, 2005 15:00

hating 'aurora'

Hi. So, my computer has been cursed by this horrible aurora/nail trojan. I'm hoping someone can help me. I've gone through the steps recommended in the FAQ. I'm posting the results of the ewido scan, followed by the results of the hijackthis scan. THANK YOU TO ANYONE WHO CAN OFFER ME ANY HELP!!!

RESULTS OF EWIDO:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 11:00:42 AM, 7/3/2005
+ Report-Checksum: 61F972A4

+ Date of database: 7/3/2005
+ Version of scan engine: v3.0

+ Duration: 34 min
+ Scanned Files: 46606
+ Speed: 22.69 Files/Second
+ Infected files: 101
+ Removed files: 101
+ Files put in quarantine: 101
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0

+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes

+ Scanned items:
C:\

+ Scan result:
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@a.websponsors[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@adknowledge[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@ads.addynamix[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@ads.vnuemedia[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@bluestreak[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@citi.bridgetrack[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@gator[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@perf.overture[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@realguide.real[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@realmedia[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@real[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@www.ebates[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@z1.adserver[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Cookies\emily eilertson@zedo[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Local Settings\Temp\8Ya04004\enhupdt.exe -> TrojanDownloader.OneClickNetSearch.h -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Local Settings\Temp\HRa01016\enhupdt.exe -> TrojanDownloader.Intexp.c -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Local Settings\Temp\II57.tmp -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Local Settings\Temp\mxTarget.dll -> Spyware.BiSpy.t -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Local Settings\Temp\preInsMt.exe -> Spyware.BiSpy.q -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Local Settings\Temp\stmtreco.exe -> TrojanDropper.Agent.ch -> Cleaned with backup
C:\Documents and Settings\Emily Eilertson\Local Settings\Temp\wupdt.exe -> TrojanDownloader.Intexp -> Cleaned with backup
C:\WINDOWS\bsx32\ADTMI1.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ADVC5.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ADVCTX2.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIB9894.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIC29667.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASID12180.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIE17070.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIF29819.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIF4502.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIFWH29233.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIG21943.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIGT10102.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIH7853.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASII21469.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIL18549.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIOG19375.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIOT25456.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIPF1965.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIR21184.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIRE20082.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIS24110.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIS31590.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIT17011.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIT26116.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIW11211.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\ASIWS3.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\BID1.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\BingoRoom1.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\CARD2.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\CARS3.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\DATE4.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\EECH1.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\EML1.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\FAST1.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\FINC3.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\FINC5.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\FLWR1.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\HERBS1.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\INK1.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\JOBS4.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\MOVS2.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\NEWS2.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\SHOP2.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\SPZ3.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\TECH2.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\UTONE2.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\WWW3.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\bsx32\XTFL2.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\conscorr.exe -> Spyware.ConsCorr -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\MediaTicketsInstaller.ocx -> Spyware.MediaTickets.c -> Cleaned with backup
C:\WINDOWS\enhuninstall.exe -> Spyware.NoName.f -> Cleaned with backup
C:\WINDOWS\enhupdt.exe -> TrojanDownloader.Intexp.c -> Cleaned with backup
C:\WINDOWS\mfrlkqedcl.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\preInsln.exe -> Spyware.BiSpy.o -> Cleaned with backup
C:\WINDOWS\remtm3.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\systb.dll_tobedeleted -> Spyware.ToolBar.ImiBar.b -> Cleaned with backup
C:\WINDOWS\systb.PSR -> Spyware.ToolBar.ImiBar.b -> Cleaned with backup
C:\WINDOWS\system32\abetterinternet.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\system32\angelex.exe -> Spyware.BargainBuddy.n -> Cleaned with backup
C:\WINDOWS\system32\apuc.PSR -> Spyware.BargainBuddy.j -> Cleaned with backup
C:\WINDOWS\system32\DrTemp\randreco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\system32\exdl1.exe -> Spyware.BargainBuddy.j -> Cleaned with backup
C:\WINDOWS\system32\exul.exe -> Spyware.BargainBuddy.i -> Cleaned with backup
C:\WINDOWS\system32\exul1.exe -> Spyware.BargainBuddy.i -> Cleaned with backup
C:\WINDOWS\system32\exul3.exe -> Spyware.BargainBuddy.i -> Cleaned with backup
C:\WINDOWS\system32\host.exe -> Trojan.Qhost.x -> Cleaned with backup
C:\WINDOWS\system32\IF01.exe -> Spyware.Look2Me.n -> Cleaned with backup
C:\WINDOWS\system32\in10b6s.dll -> Spyware.404Search.a -> Cleaned with backup
C:\WINDOWS\system32\javexulm.vxd -> Spyware.BargainBuddy.i -> Cleaned with backup
C:\WINDOWS\system32\k404SearchSetup_MS14.exe -> Spyware.404Search.a -> Cleaned with backup
C:\WINDOWS\system32\ln_reco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\system32\lsp.dll_tobedeleted -> Spyware.Sahat.f -> Cleaned with backup
C:\WINDOWS\system32\randreco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\system32\sfbbebw.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\system32\SplWbr.dll -> TrojanDropper.Small.sf -> Cleaned with backup
C:\WINDOWS\system32\stmtreco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\system32\SWRT01.dll -> Spyware.VirtualBouncer.g -> Cleaned with backup
C:\WINDOWS\system32\thin-94-2-x-x.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\system32\WebRebates_Auto_InstallSilent.exe -> Spyware.WebRebates.b -> Cleaned with backup
C:\WINDOWS\Temp\OLD14.tmp -> Spyware.ConsCorr -> Cleaned with backup


::Report End