Another sucker for aurora

Discussion in 'Malware Help (A Specialist Will Reply)' started by Stew Murray, May 22, 2005.

  1. Stew Murray

    Stew Murray Private E-2

    Hey,

    Right, have been having very little fun for a few hours, attempting to get rid of this irritating problem. The aurora popups are getting a bit tedious and i've done a few things to get rid of the nail.exe and its friends. I looked at some similar threads and tried a few of the solutions, i.e. turning system restore off, viewing all file extensions/hiddens files, booted in safe mode and ran a variety of scanners... i reboot and i've still got the damn thing sitting smugly in the windows directory. Would be extremely grateful for any assistance anyone can spare me... as per other threads, i ran the latest version of HijackThis and have attached the log file, cheers!
     

    Attached Files:

  2. Stew Murray

    Stew Murray Private E-2

    a bit more info... i've tried using microsoft antispyware, adaware, spybot, about ccleaner, norton av, trendhouse online thing... all when the pc was in safe mode.

    i've also tried using the cmd prompt, typing nail.exe /fullremove but this thing isn't shifting without a push....

    also, this new logfile is run without msn and other stuff in the background.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the announcement and sticky threads. HJT logs should only be posted when requested. You need to install HijackThis to a safe folder as indicated later in my message.

    Please download this: ABIremover

    Unzip it into its own folder. Now boot into safe mode with no network support and do not open any browsers. Now run the the ABIremover.exe file.

    When done reboot into normal mode and follow the steps below.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    You should also go to Add/Remove programs and uninstall Messenger Plus! 3
    It can add loads of malware to your PC including a LOP infection.

    You also need to stop using msconfig to disable loading of items at startup. We need to be able to see everything. Please run msconfig and select Normal Startup. Then reboot and continue with the below.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. Stew Murray

    Stew Murray Private E-2

    online scan at Trend Micro's Free Online Virus Scan produced three results, i was hoping it would remove them but it couldn't. there were three different types of trojan, but it couldn't get rid of them.

    adaware, this recognises around 30 issues mainly ones coded VX2, i've installed the plugin but cant get rid of them

    microsoft antispyware recognises two "abetterinternet" aurora viruses and gets rid of them, only for them to reappear
    .......................................................

    couldnt find messenger plus 3 to remove, but have to go to work now so will be back later!
     
  5. Stew Murray

    Stew Murray Private E-2

    Right, have got so good progress so far it seems. Just another thing to mention, everytime i loaded the pc up, i got a request from something through ms antispyware ...

    "Name: TODO: <Product name>
    Description: TODO: <File description>
    Publisher: TODO: <Company name>
    Path: c:\windows\system32\wuugxw.exe"

    anyway, didn't know what it was and only started happening yesterday, so blocked it each time. I went through all of the steps and made notes on what stuff happened...

    ABI
    I ran this first as you said, it ran fine didn't produce any messages or anything.

    Getting prepped!
    Did the disable system restore part, sorted out the system files so all were viewable and made sure all the tools i had were uptodate...

    Online scanners -

    first up, trendhouse....
    -found three trojans... TROJ_AGENT.BA / TROJ_AGENT.F / TROJ_AGENT.ABS under these files, gristrx.exe / lcsquderkfn.exe / adqkmzc.exe

    - couldn't remove any of them though, didn't say why... i had a ticket number etc, bit weird.

    second Symantec
    - found 11 viruses, but was about halfway through and the internet completely stopped working, only on my pc though, the other one was fine. I should've run norton av instead but forgot.

    third, mcafee stinger
    - found nothing

    OK, used ccleaner next, followed by adaware. This found 11 threats, while aurora was active yesterday it would pickup 29 threats, delete them, and then rescan would find them all again, mainly vx2. Two of the files found were the same as ones found by trendhouse found earlier lcsquderkfn.exe and adqkmzc.exe. Clean rerun of ad aware, and i just did another one which came out clean... i also ran the vx2 plugin and it found nothing. Results of first scan are attached.

    Spybot found nothing and neither did kill2me.

    ............................................................

    Phew.

    I rebooted right after that, was i supposed to turn windows restore back on at any point during this?? I rebooted and have turned it on, it wanted to restart but i wasn't sure if i should yet.

    Anyway, it seems good, i ran hijackthis, have attached the logfile, and the nail.exe was gone - so no more pop-ups yet. The TODO request didn't come up either which is good, microsoft antispyware hasnt even flickered since i rebooted, apart from to let a symantec thing through - some directx addins i had to install to do their online scan.

    Briefly onto your other points, i couldn't find messenger plus3 in my add/remove programs and when i ran msconfig, it was already on the setting you spoke of.
     

    Attached Files:

  6. Stew Murray

    Stew Murray Private E-2

    Another update...

    i ran norton anti virus and it found 8 things, probably the same as the other problems which the online scanner saw before i lost the internet. It removed most of them, but left three on there which it couldn't remove. These were two apropos files, rehex.exe and rnsrw.exe, both running processes at the time as well. Went to search for a removal tool and there was a handy symantec addin for removing them, which it did once i'd stopped the processes. Gonna reboot now and hope none of it has come back...

    ... it also quarantined this...
    Source: C:\Program Files\Microsoft AntiSpyware\Quarantine\DA6E2FD3-2E4B-42FB-A45C-ACA6FA\DD79B86F-E60C-41EC-A66E-E74CF9
    Description: The file C:\Program Files\Microsoft AntiSpyware\Quarantine\DA6E2FD3-2E4B-42FB-A45C-ACA6FA\DD79B86F-E60C-41EC-A66E-E74CF9 is a Adware threat.
    Click for more information about this threat : Adware.180Search
     
  7. Stew Murray

    Stew Murray Private E-2

    i rebooted and here's the hjt file...

    one program on there wuauclt.exe, wasn't on the last one and is totally new to me! i don't reckon it should be there.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please ignore the comments about msconfig and Messenger Plus 3. That was an editing mistake on my part. They were not part of your problems. Sorry about that. When I copied and pasted in my messsage, I forgot to edit those lines out.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.

    C:\WINDOWS\system32\rnrsw.exe
    C:\WINDOWS\system32\rexhe220.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [rFrT33e] rnrsw.exe
    O4 - HKCU\..\Run: [ao03RTK8X] rexhe220.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\rnrsw.exe
    C:\WINDOWS\system32\rexhe220.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. Stew Murray

    Stew Murray Private E-2

    Thanks very much for the help mate, norton seems to have taken care of those two files (rnrsw.exe and rexhe220.exe), they aren't on the computer any more.

    and that wuauclt.exe appears to have been a windows auto update thing...

    based on this hjt, and if i get rid of:

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)

    ... am i in the clear!?
     

    Attached Files:

  10. Stew Murray

    Stew Murray Private E-2

    please ignore my previous post, i didnt realise the other lines were still in the hjt file!... i've now removed all the things you said in the hjt log, there weren't any files to delete as that had been done already, i think. Anyway, i've attached another log.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. Stew Murray

    Stew Murray Private E-2

    Cool, thanks very much for your time and help mate, is definitely appreciated after two weeks straight of hardware and software troubles... clear sailing ahead
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely.
     
  14. Stew Murray

    Stew Murray Private E-2

    One more thing...

    should i turn system restore back on??!

    Cheers!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It is now time to enable System Restore.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds