Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijackthis log - Please help AURORA


  • Please log in to reply
1 reply to this topic

#1 Uplandway

Uplandway

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:08:01 PM

Posted 16 May 2005 - 09:02 AM

Running processes:
C:\WINDOWS\XP\System32\smss.exe
C:\WINDOWS\XP\system32\winlogon.exe
C:\WINDOWS\XP\system32\services.exe
C:\WINDOWS\XP\system32\lsass.exe
C:\WINDOWS\XP\system32\svchost.exe
C:\WINDOWS\XP\System32\svchost.exe
C:\WINDOWS\XP\Explorer.EXE
C:\WINDOWS\XP\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\XP\System32\nvsvc32.exe
C:\WINDOWS\XP\System32\svchost.exe
C:\WINDOWS\XP\System32\MsPMSPSv.exe
C:\WINDOWS\XP\system32\svchost.exe
C:\WINDOWS\XP\system32\wscntfy.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\XP\system32\devldr32.exe
C:\PROGRA~1\COMMON~1\AOL\111076~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\111076~1\EE\AOLServiceHost.exe
C:\WINDOWS\XP\System32\svchost.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\BTU\polupg.exe
c:\windows\xp\system32\lpvglnl.exe
C:\WINDOWS\XP\explorer.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\CXS\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\QTF\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\DFG\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\DUN\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\HKE\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\SSQ\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\RVE\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\EWT\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\NOL\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\JAR\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\GTH\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\SFE\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\MZY\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\AGT\aurareco.exe
C:\DOCUME~1\FAMILY\LOCALS~1\TEMP\thunst.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\IUC\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\FEH\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\IOH\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\UNO\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\IOS\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\ULV\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\QRV\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\LGE\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\FGT\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\EJY\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\PPL\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\CBG\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\MMM\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\LVG\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\WGI\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\WTY\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\TUW\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\DJH\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\ZYH\aurareco.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\DQI\aurareco.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\Program Files\America Online 9.0a\shellmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Family\Local Settings\Temporary Internet Files\Content.IE5\JN9J7LSW\HijackThis[1].exe
C:\WINDOWS\XP\system32\notepad.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = www.searchant.com/r=6&s=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\XP\Nail.exe
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\XP\Bolger.dll
O2 - BHO: CleanMyPC Popup Blocker - {7A9BC6B1-7F27-47c6-A66D-13582E81E537} - C:\Program Files\Popup Blocker\CleanBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: CleanMyPC Toolbar - {04164EC4-1E48-4279-818E-3721931E7636} - C:\Program Files\Popup Blocker\CleanBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1110760728\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [dpiin] C:\WINDOWS\XP\system32\dpiin.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WTST] C:\WINDOWS\XP\System32\wapisvtr.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\XP\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: updater.lnk = C:\Program Files\Common Files\updater\wupdater.exe
O4 - Global Startup: stamp.dat
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\XP\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\XP\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\XP\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {7F241C00-DAB6-11d5-AA - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\xp\system32\aplsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\xp\system32\aplsp.dll
O15 - Trusted Zone: http://free.aol.com
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri...b?rand=20035117
O16 - DPF: {31932A5C-9234-4377-A920-72E7DD340DB4} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O16 - DPF: {36C66BBD-E667-4DAD-9682-58050E7C9FDC} (CDKey Class) - http://www.cdkeybonus.com/cdkey/ITCDKey.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsc...76/mcinsctl.cab
O16 - DPF: {5763F8E8-0DD7-4A0F-ADB0-9F64C8F2C349} (Pixami/Snapfish Upload UI Control) - http://www.snapfish.com/SnapfishUploader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg...,16/mcgdmgr.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\XP\svchost.exe (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\XP\System32\nvsvc32.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\XP\svcproc.exe

BC AdBot (Login to Remove)

 


#2 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:06:01 PM

Posted 16 May 2005 - 12:49 PM

Hello Uplandway,

LSPfix tutorial

Please Download LSPFix and Run the Program. Disconnect from the Internet and close all Internet Explorer Windows.
Check the "I know what I'm doing" Button and remove all traces of aplsp.dll
and nothing else.
Reboot.

*********************************************

Please download, update and run (one at a time of course!)
Spybot 1.3 and Adaware SE

Fix whatever they suggest.

***************************************************

If you need help running these tools, here are some helpful tutorials.
Spybot 1.3 Tutorial
Adaware SE Tutorial


***************************************************

Be sure to run Adaware SE with a Full Scan in the Safe Mode.

How to Reboot into Safe Mode
tap F8 key during reboot, until the boot menu appears...use the arrow keys to choose "Safe Mode" from the menu......,then press the "Enter" key.



The following explains how to set Ad-aware's settings to perform a "Full Scan."

In Ad-aware click the Gear to go to the Settings area.

The following items should be on a green check, not on a red X.

Under the Scanning button:
Scan within archives
Under Memory & Registry, Check EVERYTHING
In Check Drives & Folders, make sure all of your hard drives are selected

Under the Advanced button, check ALL under Log detail level.

Under the Tweak button...

Some of these may not be an available option, depending on your version of Ad-aware and your version of Windows. Do not be concerned if you cannot select a certain item.

In Scanning Engine:
Unload recognized processes during scanning
Include info about ignored objects in logfile, if detected in scan
Include basic Ad-aware settings in logfile
Include additional Ad-aware settings in logfile
Include used command line parameters in logfile

In Cleaning Engine:
XP/2000: Allow unloading explorer to unload shell extensions prior to deletion
Let Windows remove files in use at next reboot
UNCHECK: Automatically try to unregister objects prior to deletion

Click Proceed to save these settings. When you would like to perform a "Full Scan," switch the scan mode from SmartScan to Custom.



***************************************************


Let's empty the temp files:

Download CCleaner and install it. (default location is best).
Select the Windows Tab, Run CCleaner ,(click Run Cleaner (bottom right) then, when it finishes scanning click Exit.)
When you see "Complete" on the top line, it's done. It's very fast.

I recommend that you DO NOT run anything under the Issues Tab and the Applications Tab.
To prevent accidently running the Issues Tab and Applicatons tabs, clear all check boxes are under them.

*********************************************

You need to post your entire Hijackth log, as you are missing the header portion. The header portion looks like this:

Logfile of HijackThis v1.99.1
Scan saved at 11:47:00 PM, on 5/13/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


C:\Documents and Settings\Family\Local Settings\Temporary Internet Files\Content.IE5\JN9J7LSW\HijackThis[1].exe


You need to put HijackThis into its own folder, but not a temp folder. It won't save the backups if it is run from a temporary folder. We do not want to lose the backups.

Here is how to make a Hijackthis folder:

Click My Computer, then C:\
In the menu bar, File->New->Folder.
That will create a folder named New Folder, which you can rename to "HJT". Now you have C:\HJT\ folder. Put your hijackthis.exe there.
Please post a new log.

Edited by SifuMike, 16 May 2005 - 01:35 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users