1
   

General Virus Cleanup and getting rid of pesky "Aurora"

 
 
novice
 
Reply Wed 15 Jun, 2005 04:15 pm
I am VERY, VERY, VERY new at doing any tech stuff for my computer. I followed Timberlandko's instructions for getting rid of yuckware but I still have a virus that my virus scan cannot seem to clean or delete: BackDoor-CQQ <c:\windows/system32\hgraip.exe> AND I still have ABetterInternet or Aurora popping up -- Curse it!!!!. Help -- Please!!! Here is my Hijack This log:

Logfile of HijackThis v1.99.1
Scan saved at 3:11:01 PM, on 6/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
c:\windows\system32\nrczyjr.exe
C:\DOCUME~1\Admin\LOCALS~1\Temp\Temporary Directory 2 for hijackthis[1].zip\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://education.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://education.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://education.dellnet.com/
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {0007522A-2297-43C1-8EB1-C90B0FF20DA5} - C:\WINDOWS\enhtb.dll (file missing)
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [jolhbn] c:\windows\system32\nrczyjr.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .tiff: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin7.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O15 - Trusted Zone: *.softpedia.com
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\SYSTEM32\ckpNotify.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Iap - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 1,213 • Replies: 4
No top replies

 
PC dr
 
  1  
Reply Thu 16 Jun, 2005 04:36 pm
Do you have any of these Aurura files in your anti-virus quarantine? There are three files that need to be dealt with but one of them changes names. the filename is xxxxxxx.exe where the x's are just a bunch of letters.
If you can find this filename I can help.....
0 Replies
 
novice
 
  1  
Reply Fri 17 Jun, 2005 01:37 pm
No, there is nothing in the anti-virus quarantine. I only have registry key entries. I will post all I have and maybe you can see what I cannot. THANKS!!!!

This is the SpyBot entry:
AbetterInternet: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1109032279-1165640157-1476159949-1005\Software\aurora

Ad-Aware entries:
VX2
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[9]=Regkey : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora
obj[10]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUC3n5trMsgSDisp"
obj[11]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUL3a5stMotsSDay"
obj[12]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUL3a5stSSChckin"
obj[13]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUP3D5om"
obj[14]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUB3D5om"
obj[15]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUs3t5icky1S"
obj[16]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUs3t5icky2S"
obj[17]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUs3t5icky3S"
obj[18]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUs3t5icky4S"
obj[19]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUE3v5nt"
obj[20]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUT3h5rshSBath"
obj[21]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUT3h5rshSysSInf"
obj[22]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUT3h5rshSCheckSIn"
obj[23]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUT3h5rshSMots"
obj[24]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUL3n5Title"
obj[25]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AU3N5a7tionSCode"
obj[26]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUD3s5tSSEnd"
obj[27]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUC3u5rrentSMode"
obj[28]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUC3n5tFyl"
obj[29]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUM3o5deSSync"
obj[30]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUI3g5noreS"
obj[31]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUC1o3d5eOfSFinalAd"
obj[32]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUT3i5m7eOfSFinalAd"
obj[33]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUI3d5OfSInst"
obj[34]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUI3n5ProgSCab"
obj[35]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUI3n5ProgSEx"
obj[36]=RegValue : S-1-5-21-1109032279-1165640157-1476159949-1005\software\aurora "AUI3n5ProgSLstest"
obj[55]=RegValue : software\microsoft\internet explorer\toolbar\webbrowser "{0E5CBF21-D15F-11D0-8301-00AA005B4383}"
obj[56]=File : C:\WINDOWS\SYSTEM32\DrPMon.dll_tobedeleted
0 Replies
 
PC dr
 
  1  
Reply Tue 21 Jun, 2005 05:02 pm
Sorry to just get back to you. Try changing attributes on drpmon.dll in the system32 folder to read-only attribute.
Change the user rights to deny all on your username and the alluser username. There is also the nail.exe file in the windows folder. Create a text document with notepad on your desktop and call it nail.exe. Set the attributes/permissions to the same settings as above. Cut/paste into the windows folder andaccept replace file.
Save these settings and then go and delete the aurora registry entry under localmachine/software using regedit. Reboot. This should work to stop the problem.
0 Replies
 
timberlandko
 
  1  
Reply Thu 23 Jun, 2005 06:27 pm
Have a look at This Topic. While technically still a "Beta", it has been tested extensively, the procedure has worked well for many folks, and no problems related directly to it have been reported.
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » General Virus Cleanup and getting rid of pesky "Aurora"
Copyright © 2025 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.03 seconds on 12/27/2025 at 07:52:48