UNSOLVED

Vortex150

updated

21 years ago

V

Vortex150

25 Posts

0

1738

November 7th, 2005 13:00

Viruses Got Me

Logfile of HijackThis v1.99.1
Scan saved at 9:13:15 AM, on 11/7/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\fzelqks.exe
C:\WINDOWS\System32\zvxmwns.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\finch\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50141
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=10345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
F2 - REG:system.ini: UserInit=userinit.exe
N1 - Netscape 4: user_pref("browser.startup.homepage", " http://www.google.com/"); (C:\Program Files\Netscape\Users\indiator\prefs.js)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [vnfomc] C:\WINDOWS\System32\vnfomc.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [Nfo] C:\WINDOWS\System32\nfomon\nfomon.exe
O4 - HKLM\..\Run: [vidmon] C:\WINDOWS\System32\vidmon\vidmon.exe
O4 - HKLM\..\Run: [msst] C:\Documents and Settings\All Users\Application Data\msst\mssts.exe
O4 - HKLM\..\Run: [jnbvop] C:\WINDOWS\System32\kcybo\jnbvop.exe
O4 - HKLM\..\Run: [omilpax] c:\windows\system32\omilpax.exe -start
O4 - HKLM\..\Run: [vsogpfyt] C:\WINDOWS\System32\gyxplvp\vsogpfyt.exe
O4 - HKLM\..\Run: [pwwj] C:\WINDOWS\System32\cwtscs\pwwj.exe
O4 - HKLM\..\Run: [lwjv] C:\WINDOWS\System32\kemx\lwjv.exe
O4 - HKLM\..\Run: [rcwljn] C:\WINDOWS\System32\ihuykvl\rcwljn.exe
O4 - HKLM\..\Run: [iplmsa] C:\WINDOWS\System32\apgpyhom\iplmsa.exe
O4 - HKLM\..\Run: [ms03302707794] C:\WINDOWS\ms03302707794.exe
O4 - HKLM\..\Run: [FtkCPY] "C:\Program Files\Common Files\Java\ftkcpy.exe"
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [qxlmglq] C:\WINDOWS\System32\fdjffn.exe r
O4 - HKLM\..\Run: [win3208547818305] C:\WINDOWS\win3208547818305.exe
O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [nhnsdjk] C:\WINDOWS\System32\zvxmwns.exe r
O4 - HKLM\..\Run: [tpkzvg] C:\WINDOWS\System32\mkdgcq.exe r
O4 - HKCU\..\Run: [Jipjkmrr] C:\WINDOWS\System32\w?nspool.exe
O4 - HKCU\..\Run: [SysCheck32] C:\WINDOWS\SysCheckBop32.exe
O4 - HKCU\..\Run: [mvueac] C:\WINDOWS\System32\mvueac.exe
O4 - HKCU\..\Run: [syszdl] c:\windows\system32\syszdl.exe
O4 - HKCU\..\Run: [strrvi] C:\windows\system32\strrvi.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [Adtc] "C:\Program Files\maat\oiao.exe" -vt rbnd
O4 - HKCU\..\RunOnce: [strrvi] C:\windows\system32\strrvi.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: {11311111-1111-1111-1111-111111111157} - file://C:\Program Files\Q330994.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4571/mcfscan.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/WinFixer2005ScannerInstall.cab
O20 - Winlogon Notify: Vfwwdm - C:\WINDOWS\system32\o0nsla571d.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\ZmluY2gA\command.exe (file missing)
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: System Startup Service  (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: vsogpfytgyxplvp - Unknown owner - C:\WINDOWS\System32\gyxplvp\vsogpfyt.exe
 
  • ky331

    5 Journeyman

    15622 Posts

    45048 Points

    417

    0

    Posted November 7th, 2005 18:00

    First, you should move HJT from your Desktop:

    C:\Documents and Settings\finch\Desktop\HijackThis.exe

    into a separate folder of its own... We recommend using folder C:\HJT , so that it will then appear in your log under running processes as C:\HJT\HijackThis.exe

    This is important because HJT generates log files, and backup files, in the folder from which it is run. So at present, all these logs/backups will just "clutter-up" your Desktop. And if you simply delete them from there, you'll lose the important backup information, which may be needed in case you have to "undo" [restore] some of the things you "FIX" incorrectly.

     
    After you move HJT, as i've just instructed:
     
    Among other things, you have a NAIL/(triple) epolvy/SvcProc infection... I'm going to try to help you to remove this first.   This fix involves using Ad-Aware, and its VX2-cleaner.   It is critical that you use the current versions as indicated below... if you use an older/obsolete version, the fix will not work.
     
    If you don't already have it, download Ad-Aware SE Personal 1.06 from http://www.majorgeeks.com/Ad-Aware_SE_Personal_d506.html
    [Note:  If you have an older "build" of Ad-Aware SE --- or even worse, if you're still using Ad-Aware 6 --- you must upgrade to this version/build,  SE 1.06 ]
     
    Install the Ad-Aware program (following any indicated directions).   [As part of the installation, it will check to see if you already have an older version of Ad-Aware installed, and if one is found, it will ask ("advise") you to allow the older one to be removed...  so if asked, please allow it.]
     
    Open/start Ad-Aware SE.     Click on Check for Updates Now, and Connect .  if found, follow the directions to download/install the latest reference file, till you FINISH.
     
    After updating, from the STATUS screen, click on START.  
    then make sure you have a RED X in front of "Search for negligible risk entries
    (if you see a GREEN CHECK, then CLICK on it, to change it to the RED X )
    then hit NEXT to perform a S mart Scan.  Allow it to remove any problems founds.
     
    Close-down Ad-Aware.  
     
    then download the VX2-cleaner add-on by clicking-on the link near the bottom of
    This will download the file  vx2cleaner_inst.exe ; click on it, and follow the directions to install the VX2-cleaner.
     
    Start Ad-Aware SE again.  Click on the Add-Ons button.   Click on the VX2-Cleaner.  Click on Run Tool, and then click OK .    If it finds any VX2 problems, follow all the directions to CLEAN things.   (I believe this will include a reboot, and directions to run another smart scan.   Follow all indicated directions [i.e., various/multiple scans] until it tells you you're clean of VX2.
     
    This should have removed all traces of NAIL/Aurora/epolvy.  Please generate and post a new HiJackThis log, appending it to this same thread.

    Message Edited by ky331 on 11-07-2005 04:55 PM

  • Vortex150

    25 Posts

    417

    0

    Posted November 7th, 2005 19:00

    Thanks ky331, You guys don't know how glad I am for this support, I would be lost without it, so you guys rock! To bad the Green Bay Packers didn't...ha...they got rocked by Pittsburg...anyway I am very happy to talk to someone who has experience in virus removal!

    I had installed the HJT folder as instructed into the C: drive. But my CPU is so hammered I have trouble keeping the computer going for any length of time without going into SAFE MODE. So I think this is why it showed on the desktop? Anyway later on a virus hammered my .exe that was in the folder and now is made useless.

    So is it ok to run the ADAWARE SE Personal, just new version loaded yesterday, and then get Ad ons for VX2 removal in SAFE MODE?

    Thanks
  • ky331

    5 Journeyman

    15622 Posts

    45048 Points

    417

    0

    Posted November 7th, 2005 22:00

    if at all possible, see how much you can run in NORMAL mode... but if it's absolutely impossible, it certainly couldn't hurt to try running some/all of these in safe mode....
     
    [by the way, my goal with you is to take care of the NAIL/epolvy/SvcProc problem... and maybe a few more minor points... after which, the plan is to call in someone else for the remainder of your problems.   so if it turns out you're having any "major" problems in getting things to run because of your "hammered" system and/or a need to run in SAFE mode, please let me know ASAP, and if need be, we'll put out that "rescue" call sooner than later...]
     
    if you can't access the internet on your bad PC, then you'll have to do your downloads on another "good" PC (at work?  a friend's?), and then copy/transfer the files... by floppy, CD/RW, or memory-stick... from the good PC to the infected one.
     
     ****************
     
    if i understand what you said, you've lost your copy of hijackthis.exe ?  if so, you can download a self extracting copy of HijackThis from http://downloads.malwareremoval.com/hijackthis_sfx.exe and save it to your desktop. Double-click on the file hijackthis_sfx.exe file and it will self extract into its own folder in C:\Program Files\HijackThis
     
    ***************

    you say you just got Ad-Aware SE  yesterday?  did you also get the updated definition/reference file at the same time?  if not, you can also perform this update onto your good machine, and then, [assuming you've accepted the Ad-Aware defaults], transfer the file:

    C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref

    *****************

    and we certainly need to download/install the VX2-cleaner add-on.


  • Vortex150

    25 Posts

    417

    0

    Posted November 8th, 2005 00:00

    Ok, I ran all this NORMAL mode, ran the Adware SE after udpate defs and did a Smart Scan and delete, the got the VX2 cleaner downloaded ok and ran the tool. Then had to get the HiJackThis.exe back and copy and pasted into HJT folder and ran and made this current log.

    Logfile of HijackThis v1.99.1
    Scan saved at 8:51:06 PM, on 11/7/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\atievxx.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\WINDOWS\System32\LVCOMSX.EXE
    C:\WINDOWS\System32\nfomon\nfomon.exe
    C:\Documents and Settings\All Users\Application Data\msst\mssts.exe
    C:\WINDOWS\System32\kcybo\jnbvop.exe
    C:\WINDOWS\System32\cwtscs\pwwj.exe
    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\WINDOWS\SysCheckBop32.exe
    C:\Program Files\maat\oiao.exe
    C:\WINDOWS\System32\taskmgr.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\HJT\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=10345
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
    F2 - REG:system.ini: UserInit=userinit.exe
    N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.google.com/"); (C:\Program Files\Netscape\Users\indiator\prefs.js)
    O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
    O2 - BHO: (no name) - {54075D5A-C1C7-CA15-EB49-B7EEFAF7BDE8} - C:\WINDOWS\System32\pkbgqrlw.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
    O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [vnfomc] C:\WINDOWS\System32\vnfomc.exe
    O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
    O4 - HKLM\..\Run: [Nfo] C:\WINDOWS\System32\nfomon\nfomon.exe
    O4 - HKLM\..\Run: [msst] C:\Documents and Settings\All Users\Application Data\msst\mssts.exe
    O4 - HKLM\..\Run: [jnbvop] C:\WINDOWS\System32\kcybo\jnbvop.exe
    O4 - HKLM\..\Run: [pwwj] C:\WINDOWS\System32\cwtscs\pwwj.exe
    O4 - HKLM\..\Run: [lwjv] C:\WINDOWS\System32\kemx\lwjv.exe
    O4 - HKLM\..\Run: [ms03302707794] C:\WINDOWS\ms03302707794.exe
    O4 - HKLM\..\Run: [FtkCPY] "C:\Program Files\Common Files\Java\ftkcpy.exe"
    O4 - HKLM\..\Run: [win3208547818305] C:\WINDOWS\win3208547818305.exe
    O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32
    O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
    O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O4 - HKCU\..\Run: [Jipjkmrr] C:\WINDOWS\System32\w?nspool.exe
    O4 - HKCU\..\Run: [SysCheck32] C:\WINDOWS\SysCheckBop32.exe
    O4 - HKCU\..\Run: [mvueac] C:\WINDOWS\System32\mvueac.exe
    O4 - HKCU\..\Run: [syszdl] c:\windows\system32\syszdl.exe
    O4 - HKCU\..\Run: [Adtc] "C:\Program Files\maat\oiao.exe" -vt rbnd
    O4 - HKCU\..\Run: [strrvi] C:\windows\system32\strrvi.exe
    O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
    O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
    O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
    O16 - DPF: {11311111-1111-1111-1111-111111111157} - file://C:\Program Files\Q330994.exe
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4571/mcfscan.cab
    O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/WinFixer2005ScannerInstall.cab
    O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\p0p6la7s1d.dll (file missing)
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\ZmluY2gA\command.exe (file missing)
    O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
  • ky331

    5 Journeyman

    15622 Posts

    45048 Points

    417

    0

    Posted November 8th, 2005 01:00

    Great work so far.  While there's still a lot more to do, it seems that you've successfully removed the NAIL/ (triple) epolvy /SvcProc problem... Have you noticed any difference (probably in terms of popups from "Aurora")?... does the system seem ANY more responsive yet?

    At this point, I'm gonna ask someone else to step-in, to help you with your remaining problems.   Please be patient, as we're very much "understaffed" and "overworked" here at the moment. 

    Good luck.

     

    P.S.  If i'm not mistaken, you have MANY virus infections (which the next person will hopefully tend to)... my question:   do you keep your anti-virus subscription, and its definitions/signatures up to date?  I strongly recommend you check for updates every time you log onto the internet.  [and you should do a complete system scan at least once a month.]  

  • Vortex150

    25 Posts

    417

    0

    Posted November 8th, 2005 01:00

    Thanks KY,

    Things to seem to be running less CPU intensive, but get lots of Ads running from SSK..or Sidekick? When I connect on the net and start a browser, pop ups will start coming in and I have to continually close these before the computer loads up and crashes. But yes I think currently I see some improvment. This computer was inherited from a friend and he did not keep windows updated and did not have a antivirus program, so he just used it until it crawled. Now have McAfee on it; and then trying to run his Windows Updates that he never ran either. When I ran McAfee scan it showed I had Downloader-KL and Adware-Gator, but ran the Adware-Gator tool from Symantic but could not find anything. McAfee could not fix Downloader-KL or Gator so should I quarantine these, or delete them? Thanks very much for all of your kind help!!
  • RKinner

    2 Intern

    5851 Posts

    417

    0

    Posted November 8th, 2005 13:00


    Start, Control Panel, Add/Remove Programs and see if you can find Surf SideKick and remove it.  IF not then
    Start, Run, cmd, OK to bring up the black cmd screen.  Type:

    cd "\Program Files\SurfSideKick 3"
    ssk.exe /u

    (that should uninstall it.  Close the window.  You can copy each line of the above =>highlight and ctrl + c then move to the cmd screen and right click to paste it)

     

    Download the Hoster from:


    http://www.funkytoad.com/

    Unpack to your desktop and run it.  If you have green print at the top then just press Restore Original Hosts then OK. 
    IF you have red print then press make Hosts Writeable first.
     

     

    Get DelDomain.inf from:
     
    http://www.mvps.org/winhelp2002/DelDomains.inf  and then right click on it and Install. 

    Nothing obvious will happen.


    Download and install ccleaner.exe from http://www.ccleaner.com. Don't let
    it clean anything yet. 

    Download the killbox:

    http://www.bleepingcomputer.com/files/killbox.php

    Unzip it to your desktop but don't run it.


    Shutdown and Restart and Boot into Safe Mode by tapping the F8 key when you see the PC
    maker's logo.
    Keep tapping until it tells you it is going to Safe Mode or you see the Safe
    Mode menu. Select the top option.

    Run HijackThis and just do a Scan only. Check then Fix Checked the following:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
    F2 - REG:system.ini: UserInit=userinit.exe
    O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
    O2 - BHO: (no name) - {54075D5A-C1C7-CA15-EB49-B7EEFAF7BDE8} - C:\WINDOWS\System32\pkbgqrlw.dll

    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
    O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll

    O4 - HKLM\..\Run: [vnfomc] C:\WINDOWS\System32\vnfomc.exe
    O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
    O4 - HKLM\..\Run: [Nfo] C:\WINDOWS\System32\nfomon\nfomon.exe
    O4 - HKLM\..\Run: [msst] C:\Documents and Settings\All Users\Application Data\msst\mssts.exe
    O4 - HKLM\..\Run: [jnbvop] C:\WINDOWS\System32\kcybo\jnbvop.exe
    O4 - HKLM\..\Run: [pwwj] C:\WINDOWS\System32\cwtscs\pwwj.exe
    O4 - HKLM\..\Run: [lwjv] C:\WINDOWS\System32\kemx\lwjv.exe
    O4 - HKLM\..\Run: [ms03302707794] C:\WINDOWS\ms03302707794.exe
    O4 - HKLM\..\Run: [FtkCPY] "C:\Program Files\Common Files\Java\ftkcpy.exe"
    O4 - HKLM\..\Run: [win3208547818305] C:\WINDOWS\win3208547818305.exe
    O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32
    O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
    O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O4 - HKCU\..\Run: [Jipjkmrr] C:\WINDOWS\System32\w?nspool.exe
    O4 - HKCU\..\Run: [SysCheck32] C:\WINDOWS\SysCheckBop32.exe
    O4 - HKCU\..\Run: [mvueac] C:\WINDOWS\System32\mvueac.exe
    O4 - HKCU\..\Run: [syszdl] c:\windows\system32\syszdl.exe
    O4 - HKCU\..\Run: [Adtc] "C:\Program Files\maat\oiao.exe" -vt rbnd
    O4 - HKCU\..\Run: [strrvi] C:\windows\system32\strrvi.exe
    O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
    O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
    O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
    O16 - DPF: {11311111-1111-1111-1111-111111111157} - file://C:\Program Files\Q330994.exe
    O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/WinFixer2005ScannerInstall.cab
    O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\p0p6la7s1d.dll (file missing)
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\ZmluY2gA\command.exe (file missing)


    Run ccleaner.exe, uncheck everything on the first page except the two entries
    with Temporary and then Run Cleaner.


    Run killbox.  Where it says Full Path of File to Delete you need to type or copy (Hightlight and Ctrl + c)
    and Paste (move to the killbox and place the cursor in the box and Ctrl + V):

    C:\Program Files\TBONAS

    Then check the Delete on Reboot box and DELTREE box  then the red button. 
    Agree you want to remove the file but do not let it reboot yet.

    Repeat for:
    C:\WINDOWS\System32\kcybo
    C:\WINDOWS\System32\cwtscs
    C:\WINDOWS\System32\kemx
    C:\WINDOWS\System32\nfomon
    C:\Program Files\maat
    C:\Program Files\SurfSideKick 3 (it may not find it)

    Repeat with only Delete on Reboot:

    C:\Program Files\Q330994.exe
    C:\WINDOWS\dinst.exe

    If it doesn't find one then just go on to the next.

    Let it reboot after the last one.

     


    Run another HijackThis log and post it as a reply. Let's
    see how we did.

    Ron

  • Vortex150

    25 Posts

    417

    0

    Posted November 8th, 2005 17:00

    Hi RKinner,

    Thanks very much for taking me on! I apreciate all of you guys.

    Stupid me, I did not see that Sidekick way down below the Windows Updates in the Remove Programs Menu otherwise I would have killed the darn thing faster than lightning. So last night after my last post I found it and deleted the program.

    So now do I continue with what you advised after that, from Download Hoster on down?
  • RKinner

    2 Intern

    5851 Posts

    417

    0

    Posted November 8th, 2005 18:00

    Yes.  Just don't worry if you can't find a line or a file.  Probably removed by Surf SideKick when it went.

    Ron

  • Vortex150

    25 Posts

    181

    0

    Posted November 8th, 2005 18:00

    Ok Ron,

    Thanks, I am at work now, but will try to do this after 6 pm tonight and send a new HiJack Log. By the way I ran a McAffee virus check this morning and shows no viruses. I have also had to uncheck several programs in my msconfig Start to keep from overwhelming the CPU when startup, so should I keep these unchecked or go full speed ahead?

    I am also low on Hard Disk Space with only 5 to 10 percent free when I use System Restore and I could not run a defrag so I turned off System Restore and have now 15 percent so I can Defrag ok. Should I keep System Restore always going, or leave off? I also plan on moving some files to another external disk to free up some much needed Free Space, as currently it is choking.