Aurora Popups Virus Please Help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by bekka24, May 17, 2005.

  1. bekka24

    bekka24 Private E-2

    Please Help Me,

    I am trying to get rid of this virus that causes popups to come up even when I am not browsing the internet. I am running a Wireless Cable modem and so I am always connected to the internet. I have read the tutorial and run all of the virus detection suggestions. This didn't fix the problem, although it did help me to delete MANY MANY other smaller issues I didn't even know I had. I have run Hijack This! and I haev read through the tutorial and fixed some stuff, however I am seeking some assistance to help me finish getting rid of this obnoxious virus! Please help! :D

    Thanks, Bekka
     
  2. marcello

    marcello Private E-2

  3. bekka24

    bekka24 Private E-2

    I went to this website and downloaded this information and ran it. I have not had any more popups, however I still am getting an error message from my Symantec Antivirus that pops up on the screen and tells me that a virus was quarantined, however the access was denied. I am not sure what to do next. I am going run the antivirus instructions again and see if anything has changed. Any further suggestions would be appreciated. Also, I believe the virus is called Nail.exe? I don't know what this is....Thanks! ;)
    Bekka
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download this: ABIremover

    Unzip it into its own folder. Now boot into safe mode with no network support and do not open any browsers. Now run the the ABIremover.exe file.

    When done reboot into normal mode and let me know how things look.
     
  5. bekka24

    bekka24 Private E-2

    Did as you asked, and went back through all of the instructions again. Here's what I got....House Call found two viruses Troj_Stervis.C and Worm_SDBOT.Bkw. Deleted both of them, but they keep coming back next time I scan. Adaware keeps finding Ezula, LycosSideSearch, and eSyndicate. HSRemove removed 8 items (again, this is the second time 8 items were removed). Symantec keeps alerting to a Trojan found in a file rdriv.sys. I feel like I am working in circles. The popups are back again as well, everytime I boot in safe mode it's fine, then regular mode everything comes back again. Please Help! Thanks!
    Bekka
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you running HSremove? You did not say anything about having and HSA hijacker issue.

    Are your Aurora popups fixed?

    If you have run all the steps in the READ ME, perform the steps below.


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  7. bekka24

    bekka24 Private E-2

    The Aurora Popups are gone, but now I'm getting Internet Explorer popups. I ran HSRemove because it was on the list of things to download. I have followed the instructions about the Hijack This! Here is the attached log file.....Thanks for all your help!
    Bekka
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The READ ME FIRST explains that you only need HSremove (and also about:blank) for specific hijacker problems. The HSA and about:blank hijacks. It is not necessary for you to waste any time running these since you do not have those hijackers. The 8 files that HSremove is indicating is a bug. It always shows 8 when clean.

    Why didn't you run the two online scanners from the READ ME FIRST? Did you skip any other steps?
     
    Last edited: May 17, 2005
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The first thing I want you to do is go to Add/Remove programs (from Control Panel) and look for the below programs and uninstall if found:

    Media Access
    salm
    IST Service or ISTbar
    Internet Optimizer
    BullsEye Network
    WinTools
    Power Scan
    TBPS

    Tell me which ones you find and if they uninstall.

    Now download and install Microsoft® Windows AntiSpyware and make sure you get the updates but do not run a scan yet.

    Now reboot into safe mode with no network support, make sure you have no browsers opened and then run a full scan with MS Antispyware and let it fix what it finds. Tell me what it finds and fixes (or does not fix).

    Now reboot into normal mode and post a new HJT log attachment.
     
  10. bekka24

    bekka24 Private E-2

    I did one of the online scans, the Trend Micro/House Call one, but the link for the other is broken and comes back with an error message that the page has expired. Then I ran Stinger....As for running HSRemove...I didn't know what I had as far as if it was a hijack whatever so I ran it because I didn't know that I didn't have it....I will follow the next instructions and let you know the result...Thanks
    Bekka
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. bekka24

    bekka24 Private E-2

    I ran the Sun Java one as the other one would not work because I use Mozilla Firefox. Actually, I am helping a friend fix her computer which is why I am here...I have had no further problems with my own.

    As for the Add/Remove process I have found and removed the following:
    ISTService
    Media Access
    Internet Optimizer
    WinTools
    Bullseye Network
    Power Scan

    All seem to have been removed fine. One required a restart to complete, and when the computer was restarted everything seemed to have been deleted successfully.

    I have also downloaded Microsoft AnitSpyware and I am in the process of installing and searching for updates. Will let you know how it goes.
    Bekka
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! Don't forget to run MS Antispyware in safe mode. And then post a new HJT log because I expect a few additional items to remain that require manual removal procedures.
     
  14. bekka24

    bekka24 Private E-2

    After running Microsoft AniteSpyware I found the following:
    SearchEnhancement
    AvenueMedia.DyFuCA
    SideFind
    WebSearch Toolbar
    Network Essentials
    eZula.TopText
    WindUpdates
    AproposMedia
    180Assistant
    IST.SlotchBar
    Cydoor
    HuntBar
    eXact.BargainBuddy
    IEPlugin
    IST.ISTbar
    IST.PowerScan
    SEP
    DownloadWare
    eXact Search Bar
    Superlogy.com
    MediaTicket CDT
    Twain Tech
    ShopAtHome

    I am now removing/quarantining these items (per the recommendation) then I will restart in Normal mode and run Hijack This! again and post another attachment for the new LogFile.
    Bekka
     
  15. bekka24

    bekka24 Private E-2

    Here is the new Hijack This! LogFile....Thanks Again!
    Bekka
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is very important that you always remember to exit browsers before running HJT. You had the below running:
    C:\program files\internet explorer\iexplore.exe


    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Software Secure Service ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above for: Windows Management Construct

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Software Secure Service

    If that does not work try entering the short name: SSISvr32
    You will need to cut and paste the short name since the characters are not easily typed.

    Now repeat the above HJT step for: Windows Management Construct
    Or short name: winmgmc

    Now exit HijackThis.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\ssisvr32.exe
    C:\WINDOWS\userint32.exe
    C:\word.exe
    C:\windows\system32\xlg.exe
    C:\windows\system32\xlg.exe
    C:\WINDOWS\system32\je86qvu8.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\userint32.exe
    O4 - HKLM\..\Run: [Windows Service Manager] C:\WINDOWS\userint32.exe
    O4 - HKLM\..\Run: [WinScMngr] C:\WINDOWS\winsmc.exe
    O4 - HKLM\..\Run: [czMR] C:\windows\system32\czMR.exe
    O4 - HKLM\..\Run: [EBcF] C:\windows\system32\EBcF.exe
    O4 - HKLM\..\Run: [3NtFWtRdq] C:\windows\system32\3NtFWtRdq.exe
    O4 - HKLM\..\Run: [Lsass] C:\word.exe
    O4 - HKLM\..\Run: [xlg] c:\windows\system32\xlg.exe
    O4 - HKLM\..\Run: [xlg.exe] C:\windows\system32\xlg.exe
    O4 - HKLM\..\Run: [je86qvu8] C:\WINDOWS\system32\je86qvu8.exe
    O15 - Trusted Zone: *.westlaw.com
    O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
    O23 - Service: Software Secure Service (SSISvr32) - SoftwareSecure Inc - C:\WINDOWS\system32\ssisvr32.exe
    O23 - Service: Windows Management Construct (winmgmc) - Unknown owner - C:\WINDOWS\winmgc.exe


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\ssisvr32.exe
    C:\windows\system32\3NtFWtRdq.exe
    C:\WINDOWS\userint32.exe
    C:\word.exe
    C:\windows\system32\xlg.exe
    C:\WINDOWS\system32\je86qvu8.exe
    C:\WINDOWS\winsmc.exe
    C:\windows\system32\czMR.exe
    C:\windows\system32\EBcF.exe
    C:\WINDOWS\winmgc.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  17. bekka24

    bekka24 Private E-2

    Okay, I followed your directions, but there were some things that didn't exist in the list so I couldn't delete them. here is the new logfile....Thanks
    Bekka
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just two minor items left to hav HJT fix (one is from running HSremove which you do not need to be running):

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O15 - Trusted Zone: *.westlaw.com

    Other than those you are clean. How are things working?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds