Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
I got uber flooded and need some major help
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > I got uber flooded and need some major help  
Forum Quick Jump
 
New Topic Post reply to : I got uber flooded and need some major help Printable version of : I got uber flooded and need some major help
[ << Previous Thread | Next Thread >> ]

fs_xecutioner
New Member


Date Joined Mar 2005
Total Posts : 37
 
   Posted 4-27-2005 4:45 (GMT +1)    Quote: I got uber flooded and need some major helpAlert an admin about: I got uber flooded and need some major help
Here is my Hijack this log.
 
 
 
Logfile of HijackThis v1.99.1
Scan saved at 8:44:12 PM, on 4/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\FarStone\VirtualDrive\VDTask.exe
C:\WINDOWS\vcdplayx.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Motherboard Monitor 5\MBM5.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.csnation.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [VirtualDrive] "C:\Program Files\FarStone\VirtualDrive\VDTask.exe" /AutoRestore
O4 - HKLM\..\Run: [vcdplayx] "C:\WINDOWS\vcdplayx.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service Client v.3.4) - http://ccon.futuremark.com/global/msc34.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\Object Desktop\WindowBlinds\fastload.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (MpfService) - Unknown owner - C:\PROGRA~1\McAfee.com\Personal Firewall\MPFSERVICE.exe (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: System Startup Service  (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
 
Back to Top
 

fs_xecutioner
New Member


Date Joined Mar 2005
Total Posts : 37
 
   Posted 4-28-2005 7:57 (GMT +1)    Quote: I got uber flooded and need some major helpAlert an admin about: I got uber flooded and need some major help
Bump.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16739
 
   Posted 4-28-2005 8:20 (GMT +1)    Quote: I got uber flooded and need some major helpAlert an admin about: I got uber flooded and need some major help
Hey
 
Your log is clean;-)
 
What´s the problem?


Touch
Back to Top
 

fs_xecutioner
New Member


Date Joined Mar 2005
Total Posts : 37
 
   Posted 4-28-2005 10:05 (GMT +1)    Quote: I got uber flooded and need some major helpAlert an admin about: I got uber flooded and need some major help
I still get this Aurora popup or what ever, and I am not sure if it was the viruses, or the massive malware.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16739
 
   Posted 4-29-2005 6:16 (GMT +1)    Quote: I got uber flooded and need some major helpAlert an admin about: I got uber flooded and need some major help
Ok;-)
Unzip to desktop. Run it, and post find it log, you will find it here C: log txt


Touch
Back to Top
 

fs_xecutioner
New Member


Date Joined Mar 2005
Total Posts : 37
 
   Posted 4-29-2005 7:06 (GMT +1)    Quote: I got uber flooded and need some major helpAlert an admin about: I got uber flooded and need some major help
Ok here it is
 
 
Microsoft Windows XP [Version 5.1.2600]
The current date is: Thu 04/28/2005
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
»»»»»»»»»»»»»»»»»»»»»»»» Todo Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»
 
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
 
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
»»»»»»»»»»»»»»»»»»»»»»»» aurora Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»
 
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
 
»»»»»»»»»»»»»»»»»»»»»»»» Suspect's »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Dont delete file's in the section without guidance
If any doubt back them up first
 
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
 
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
»»»»» lagitamate file's can/will show in this section.
 
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
»»»»»»»»»»»»»»»»»»»»»»»» Buddy file's »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
 
»»»»»»»»»»»»»»»»»»»»»»»» SAHAgent Files found »»»»»»»»»»»»»»»»»»»»»»»»»
 
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
»»»»»»»»»»»»»»»»»»»»»»»» Misc checks »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
 
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
Cannot execute C:\DOCUME~1\USER\DESKTOP\FIND_IT__S\FIND-IT'S\XFIND.COM
 
»»»»» Checking Windir\svcproc.exe and nail.exe.
 
 svcproc.exe
 Nail.exe
»»»»» Checking for System32\DrPMon.dll.
 
 DrPMon.dll
»»»»» Check for Windows\SYSTEM32\cache32_rtneg* folder.
 
 Volume in drive C has no label.
 Volume Serial Number is A824-0508
 Directory of C:\WINDOWS\SYSTEM32
»»»»» Checking for SAHAgent ico files.
 Volume in drive C has no label.
 Volume Serial Number is A824-0508
 Directory of C:\WINDOWS\system32
 
»»»»»»»»»»»»»»»»»»»»»»»».
 
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\aurora

! REG.EXE VERSION 3.0
HKEY_CLASSES_ROOT\BolgerDll.BolgerDllObj
    <NO NAME> REG_SZ Bolger Functional Class

! REG.EXE VERSION 3.0
HKEY_CLASSES_ROOT\CLSID\{302A3240-4805-4a34-97D7-1645A0B08410}
    <NO NAME> REG_SZ BolgerObj Class
 
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16739
 
   Posted 4-29-2005 7:38 (GMT +1)    Quote: I got uber flooded and need some major helpAlert an admin about: I got uber flooded and need some major help
It does´nt look right, you may have got some error messages?


Touch
Back to Top
 

fs_xecutioner
New Member


Date Joined Mar 2005
Total Posts : 37
 
   Posted 4-29-2005 8:42 (GMT +1)    Quote: I got uber flooded and need some major helpAlert an admin about: I got uber flooded and need some major help
Hmmm what should I do then?
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16739
 
   Posted 4-29-2005 9:59 (GMT +1)    Quote: I got uber flooded and need some major helpAlert an admin about: I got uber flooded and need some major help
Run Find it Bat


Touch
Back to Top
 
New Topic Post reply to : I got uber flooded and need some major help Printable version of : I got uber flooded and need some major help
 
Forum Information
Currently it is Saturday, March 13, 2010 5:23 AM (GMT +1)
There are a total of 76.142 posts in 17.592 threads.
In the last 3 days there were 8 new threads and 56 reply posts. View Active Threads
Who's Online
This forum has 31124 registered members. Please welcome our newest member, teddy.
32 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Redirect Virus (10)12-03-2010 22:42:47 (drewplz)
I suspect ad-divert virus; HiJackThis! log included (8)12-03-2010 21:38:12 (ouiouilee)
Blue Screen on Windows Vista x32 (5)12-03-2010 17:06:01 (markusg)
How to remove a redirect virus that also stops my Antivirus for updating (3)12-03-2010 10:56:27 (markusg)
Internet browser redirect virus (9)12-03-2010 10:48:06 (markusg)