There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
Malware Removal & HijackThis Logs
Tag Cloud
adware audio bios blue screen boot bsod computer connection crash dell desktop driver email error excel firefox freeze google hard drive hardware hijackthis install internet laptop linux malware network no sound outlook problem recovery router screen server slow sound speakers spyware startup trojan usb video virus vista webcam windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Malware Removal & HijackThis Logs >
Aurora windows??? help? (New)

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
nrussellmn's Avatar
Junior Member with 1 posts.
 
Join Date: Jun 2005
Experience: AComputerDude
19-Jun-2005, 12:57 AM #1
Try This
This has been a nasty one (sexandpoker.com, fake Windows Security Center dialogs, etc...). Think I've got it nailed, but want to verify.

It is spyware/malware that none of the popular and not so popular anti-spyware products I've tried have removed. Latest HJT log was no real help.

Symptoms: Causes a lot of casino and adult popups, plus unwanted IE Favorites keep getting added (even after deletion) such as "Kill Annoying Popups", "(bleep) REAL GIRLS", "AdultGambling", "Free Online Dating", "Online Sex Poker Rooms", "Remove Toolbars", "Spyware Uninstall", "SPYWARE", "XXX Personal Photos", "Play Adult-Poker" etc... Popups can launch with no browser open. "Fake" Windows Security Center popups also occur. Some may have noticed in trying to install Windows service packs to fix problem reveals files such as wbemtest.exe, or pingtest.exe, or tcptest.exe cannot be found... turns out that any files ending in "test.exe" seem to be "invisible" (even in safe mode or safe mode with command prompt).

After pounding on this one for a while and examining numerous posts to no evail, I think I've beat it, but wanted to verify as this thing seems to have a nasty habit of coming back when you think you've got it beat.

I had to boot to NTFS from DOS (i.e. "NTFS for DOS" {freeware} or NFTSPRO for DOS) and delete the following files from c:\windows\system32:
csixi.exe
cisvvc.exe
rdsndin (was either .exe or .dll)

Also seems I had to take cisvvc*.pf file out of c:\windows\prefetch folder as well.

I also used HJT to take out some registry references to hosts beginning with .69

Seems to be gone now. I work on computers for a living and this is the nastiest bug I've ever battled. Has anyone any experience with this one to share as I'm not totally sure I've completely nailed it.

Nate
Flrman1's Avatar
Distinguished Member with 46,429 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
19-Jun-2005, 10:12 AM #2
HI nrussellmn

Welcome to TSG!

I have split your post off into your own thread. In the future if you have a Question/Problem please start a "New Thread". It get's too confusing trying to address two different people's problem in the same thread and you may get overlooked.

Please continue in this thread.
__________________
If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site.
Flrman1's Avatar
Distinguished Member with 46,429 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
19-Jun-2005, 10:12 AM #3
Please do this:

First create a permanent folder somewhere like in My Documents and name it Hijack This.

Now Click here to download Hijack This. Download it and click "Save". Save it to the Hijack This folder you just created.

Click on Hijackthis.exe to launch the program. Click on the Do a system scan and save a logfile button. It will scan and then ask you to save the log. Click "Save" to save the log file and then the log will open in notepad.

Click on "Edit > Select All" then click on "Edit > Copy" then Paste the log back here in a reply.

DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
__________________
If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site.
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 06:23 PM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.