This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis Log, Popup Problem(tryed Everything)

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok Nokturnal, time for another tool :)
Download pv.zip and extract it from the zip.
Start internet explorer, minimize it but leave it running.
Double click runme.bat in the pv folder you extracted.
Choose option 2 (Internet Explorer DLLs) and hit the enter key.
A text file will open, copy the complete contents of it to this thread.
Module information for 'iexplore.exe' MODULE BASE SIZE PATH iexplore.exe 400000 102400 C:\Program Files\Internet Explorer\iexplore.exe 6.00.2800.1106 (xpsp1.020828-1920) Internet Explorer ntdll.dll 77f50000 684032 C:\WINDOWS\System32\ntdll.dll 5.1.2600.1217 (xpsp2.030429-2131) NT Layer DLL kernel32.dll 77e60000 942080 C:\WINDOWS\system32\kernel32.dll 5.1.2600.1560 (xpsp2_gdr.040517-1325) Windows NT BASE API Client DLL msvcrt.dll 77c10000 339968 C:\WINDOWS\system32\msvcrt.dll 7.0.2600.1106 (xpsp1.020828-1920) Windows NT CRT DLL USER32.dll 77d40000 573440 C:\WINDOWS\system32\USER32.dll 5.1.2600.1561 (xpsp2_gdr.040517-1325) Windows XP USER API Client DLL GDI32.dll 7f000000 266240 C:\WINDOWS\system32\GDI32.dll 5.1.2600.1561 (xpsp2_gdr.040517-1325) GDI Client DLL ADVAPI32.dll 77dd0000 577536 C:\WINDOWS\system32\ADVAPI32.dll 5.1.2600.1106 (xpsp1.020828-1920) Advanced Windows 32 Base API RPCRT4.dll 78000000 552960 C:\WINDOWS\system32\RPCRT4.dll 5.1.2600.1361 (xpsp2.040109-1800) Remote Procedure Call Runtime SHLWAPI.dll 70a70000 430080 C:\WINDOWS\system32\SHLWAPI.dll 6.00.2800.1584 (xpsp2.040720-1705) Shell Light-weight Utility Library SHDOCVW.dll 71700000 1347584 C:\WINDOWS\System32\SHDOCVW.dll 6.00.2800.1584 Shell Doc Object and Control Library comctl32.dll 71950000 933888 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1579_x-ww_7bbf8d08\comctl32.dll 6.0 (xpsp2.040720-1705) User Experience Controls Library SHELL32.dll 4f510000 8458240 C:\WINDOWS\system32\SHELL32.dll 6.00.2800.1580 (xpsp2.040720-1705) Windows Shell Common Dll comctl32.dll 77340000 569344 C:\WINDOWS\system32\comctl32.dll 5.82 (xpsp1.020828-1920) Common Controls Library ole32.dll 771b0000 1196032 C:\WINDOWS\system32\ole32.dll 5.1.2600.1362 (xpsp2.040109-1800) Microsoft OLE for Windows uxtheme.dll 5ad70000 212992 C:\WINDOWS\System32\uxtheme.dll 6.00.2800.1106 (xpsp1.020828-1920) Microsoft UxTheme Library BROWSEUI.dll 71500000 1036288 C:\WINDOWS\System32\BROWSEUI.dll 6.00.2800.1584 Shell Browser UI Library browselc.dll 72430000 73728 C:\WINDOWS\System32\browselc.dll 6.00.2800.1106 (xpsp1.020828-1920) Shell Browser UI Library appHelp.dll 75f40000 126976 C:\WINDOWS\system32\appHelp.dll 5.1.2600.1106 (xpsp1.020828-1920) Application Compatibility Client Library CLBCATQ.DLL 7c890000 528384 C:\WINDOWS\System32\CLBCATQ.DLL 2001.12.4414.53 OLEAUT32.dll 77120000 569344 C:\WINDOWS\system32\OLEAUT32.dll 3.50.5016.0 Microsoft OLE 3.50 for Windows NT™ and Windows 95™ Operating Systems COMRes.dll 77050000 806912 C:\WINDOWS\System32\COMRes.dll 2001.12.4414.42 VERSION.dll 77c00000 28672 C:\WINDOWS\system32\VERSION.dll 5.1.2600.0 (xpclient.010817-1148) Version Checking and File Installation Libraries WININET.dll 63000000 614400 C:\WINDOWS\system32\WININET.dll 6.00.2800.1468 Internet Extensions for Win32 CRYPT32.dll 762c0000 557056 C:\WINDOWS\system32\CRYPT32.dll 5.131.2600.1152 (xpsp2.021217-1051) Crypto API32 MSASN1.dll 762a0000 65536 C:\WINDOWS\system32\MSASN1.dll 5.1.2600.1362 (xpsp2.040109-1800) ASN.1 Runtime APIs Secur32.dll 76f90000 65536 C:\WINDOWS\System32\Secur32.dll 5.1.2600.1106 (xpsp1.020828-1920) Security Support Provider Interface cscui.dll 76620000 319488 C:\WINDOWS\System32\cscui.dll 5.1.2600.1106 (xpsp1.020828-1920) Client Side Caching UI CSCDLL.dll 76600000 110592 C:\WINDOWS\System32\CSCDLL.dll 5.1.2600.0 (xpclient.010817-1148) Offline Network Agent SETUPAPI.dll 76670000 946176 C:\WINDOWS\System32\SETUPAPI.dll 5.1.2600.1106 (xpsp1.020828-1920) Windows Setup API urlmon.dll 1a400000 503808 C:\WINDOWS\system32\urlmon.dll 6.00.2800.1474 OLE32 Extensions for Win32 shdoclc.dll 76170000 557056 C:\WINDOWS\System32\shdoclc.dll 6.00.2600.0000 (xpclient.010817-1148) Shell Doc Object and Control Library mlang.dll 74770000 585728 C:\WINDOWS\System32\mlang.dll 6.00.2600.0000 (xpclient.010817-1148) Multi Language Support DLL wsock32.dll 71ad0000 32768 C:\WINDOWS\System32\wsock32.dll 5.1.2600.0 (xpclient.010817-1148) Windows Socket 32-Bit DLL WS2_32.dll 71ab0000 86016 C:\WINDOWS\System32\WS2_32.dll 5.1.2600.0 (xpclient.010817-1148) Windows Socket 2.0 32-Bit DLL WS2HELP.dll 71aa0000 32768 C:\WINDOWS\System32\WS2HELP.dll 5.1.2600.0 (xpclient.010817-1148) Windows Socket 2.0 Helper for Windows NT nl_lsp.dll 10000000 86016 C:\Program Files\NetLimiter\nl_lsp.dll nl_msgc.dll 16d0000 69632 C:\WINDOWS\System32\nl_msgc.dll mswsock.dll 71a50000 241664 C:\WINDOWS\system32\mswsock.dll 5.1.2600.0 (xpclient.010817-1148) Microsoft Windows Sockets 2.0 Service Provider wshtcpip.dll 71a90000 32768 C:\WINDOWS\System32\wshtcpip.dll 5.1.2600.0 (xpclient.010817-1148) Windows Sockets Helper DLL RASAPI32.DLL 76ee0000 225280 C:\WINDOWS\System32\RASAPI32.DLL 5.1.2600.1106 (xpsp1.020828-1920) Remote Access API rasman.dll 76e90000 69632 C:\WINDOWS\System32\rasman.dll 5.1.2600.1106 (xpsp1.020828-1920) Remote Access Connection Manager NETAPI32.dll 71c20000 319488 C:\WINDOWS\System32\NETAPI32.dll 5.1.2600.1562 (xpsp2_gdr.040517-1325) Net Win32 API DLL TAPI32.dll 76eb0000 176128 C:\WINDOWS\System32\TAPI32.dll 5.1.2600.1106 (xpsp1.020828-1920) Microsoft® Windows™ Telephony API Client DLL rtutils.dll 76e80000 53248 C:\WINDOWS\System32\rtutils.dll 5.1.2600.0 (xpclient.010817-1148) Routing Utilities WINMM.dll 76b40000 180224 C:\WINDOWS\System32\WINMM.dll 5.1.2600.1106 (xpsp1.020828-1920) MCI API DLL sensapi.dll 722b0000 20480 C:\WINDOWS\System32\sensapi.dll 5.1.2600.1106 (xpsp1.020828-1920) SENS Connectivity API DLL USERENV.dll 75a70000 675840 C:\WINDOWS\system32\USERENV.dll 5.1.2600.1106 (xpsp1.020828-1920) Userenv SXS.DLL 75e90000 708608 C:\WINDOWS\System32\SXS.DLL 5.1.2600.1579 (xpsp2.040720-1705) Fusion 2.5 rsaenh.dll ffd0000 143360 C:\WINDOWS\System32\rsaenh.dll 5.1.2600.1029 (xpsp1.020426-1800) Microsoft Base Cryptographic Provider rasadhlp.dll 76fc0000 20480 C:\WINDOWS\System32\rasadhlp.dll 5.1.2600.0 (xpclient.010817-1148) Remote Access AutoDial Helper DNSAPI.dll 76f20000 151552 C:\WINDOWS\System32\DNSAPI.dll 5.1.2600.1106 (xpsp1.020828-1920) DNS Client API DLL winrnr.dll 76fb0000 28672 C:\WINDOWS\System32\winrnr.dll 5.1.2600.0 (xpclient.010817-1148) LDAP RnR Provider DLL WLDAP32.dll 76f60000 180224 C:\WINDOWS\system32\WLDAP32.dll 5.1.2600.1106 (xpsp1.020828-1920) Win32 LDAP API DLL mshtml.dll 63580000 2830336 C:\WINDOWS\System32\mshtml.dll 6.00.2800.1476 Microsoft ® HTML Viewer msimtf.dll 746f0000 155648 C:\WINDOWS\System32\msimtf.dll 5.1.2600.1106 (xpsp1.020828-1920) Active IMM Server DLL MSCTF.dll 74720000 278528 C:\WINDOWS\System32\MSCTF.dll 5.1.2600.1106 (xpsp1.020828-1920) MSCTF Server DLL IMM32.DLL 76390000 114688 C:\WINDOWS\System32\IMM32.DLL 5.1.2600.1106 (xpsp1.020828-1920) Windows XP IMM32 API Client DLL jscript.dll 6b700000 589824 c:\windows\system32\jscript.dll 5.6.0.8513 Microsoft ® JScript MSLS31.DLL 746c0000 159744 C:\WINDOWS\System32\MSLS31.DLL 3.10.349.0 Microsoft Line Services library file iepeers.dll 66e50000 241664 C:\WINDOWS\System32\iepeers.dll 6.00.2800.1106 (xpsp1.020828-1920) Internet Explorer Peer Objects WINSPOOL.DRV 73000000 143360 C:\WINDOWS\System32\WINSPOOL.DRV 5.1.2600.1106 (xpsp1.020828-1920) Windows Spooler Driver mshtmled.dll 74cb0000 454656 C:\WINDOWS\System32\mshtmled.dll 6.00.2800.1106 (xpsp1.020828-1920) Microsoft ® HTML Editing Component inetcpl.cpl 58a20000 319488 C:\WINDOWS\System32\inetcpl.cpl 6.00.2800.1106 (xpsp1.020828-1920) Internet Control Panel inetcplc.dll 667d0000 118784 C:\WINDOWS\System32\inetcplc.dll 6.00.2600.0000 (xpclient.010817-1148) Internet Control Panel wdmaud.drv 72d20000 36864 C:\WINDOWS\System32\wdmaud.drv 5.1.2600.0 (XPClient.010817-1148) WDM Audio driver mapper msacm32.drv 72d10000 32768 C:\WINDOWS\System32\msacm32.drv 5.1.2600.0 (xpclient.010817-1148) Microsoft Sound Mapper MSACM32.dll 77be0000 81920 C:\WINDOWS\System32\MSACM32.dll 5.1.2600.0 (xpclient.010817-1148) Microsoft ACM Audio Filter midimap.dll 77bd0000 28672 C:\WINDOWS\System32\midimap.dll 5.1.2600.0 (xpclient.010817-1148) Microsoft MIDI Mapper actxprxy.dll 71d40000 110592 C:\WINDOWS\System32\actxprxy.dll 6.00.2600.0000 (XPClient.010817-1148) ActiveX Interface Marshaling Library plugin.ocx 72b20000 98304 C:\WINDOWS\System32\plugin.ocx 6.00.2600.0000 (xpclient.010817-1148) ActiveX Plugin OCX comdlg32.dll 763b0000 282624 C:\WINDOWS\system32\comdlg32.dll 6.00.2800.1106 (xpsp1.020828-1920) Common Dialogs DLL ntshrui.dll 76990000 147456 C:\WINDOWS\System32\ntshrui.dll 5.1.2600.1106 (xpsp1.020828-1920) Shell extensions for sharing ATL.DLL 76b20000 86016 C:\WINDOWS\System32\ATL.DLL 3.00.9435 ATL Module for Windows NT (Unicode) LINKINFO.dll 76980000 28672 C:\WINDOWS\System32\LINKINFO.dll 5.1.2600.1579 (xpsp2.040720-1705) Windows Volume Tracking
Nokturnal, please be patient. We are all volunteers here and have lives outside of this forum. I am looking over your log now. At first look I don't see any problems, I am going to go through it again to make sure. While I am doing that, please download Registry Search Tool. You will need to scroll about halfway down the page to find it.

Unzip and run it. If your AV complains that it is a malicious script allow it to run, it is harmless. Copy and paste the following into the search term box.
712564B5-8817-46A3-9E29-BA19CD2A41CB
Copy the contents of the file that opens as a reply here.
Make sure you give it enough time to finish, it can take awhile.

We'll deal with the recycle bin after we get your hosts file hijacking fixed.
Nokturnal,

The HijackThis log posted shows the computer has acquired the VX2 Trojan malware. It has some unique characteristics, and files that may keep reloading as well as renaming themselves when removed or upon reboot.

We do need to find the files that are making this beast prevail. If you are still interested, please do the following:

Download Find_It.zip:
http://forums.spywareinfo.com/index.php?ac…ype=post&id=484
Unzip its contents to its own folder
Open the folder and double click on Find.bat (File with a gear symbol)
Ignore any File not found messages
It runs for a minute, and produces a log
Please copy and paste the log on your next response.

Download DllCompare:
http://forums.subratam.org/index.php?showtopic=1725
Save the program in its own folder
Double click DllCompare to start the program
-Press: Run Locate.com
-Press: Compare (It will run for a short while)
-When finished, press: Make A Log of What was Found
-Copy/Paste the log on your next response.

Assuming at one point you ran VX2Finder(126).exe
If that was not the version, download it from here:
http://downloads.subratam.org/VX2Finder(126).exe
Save the program in its own folder.
Run VX2Finder(126).exe
Select: Click to Find VX2.Betterinternet
When the scan is done, select the Make Log
It will open the log in Notepad.
Copy and paste the log to on your response.

Will wait for the logs from the programs above. However, please do not restart the computer. If you do, any information you provide may change, and we are back to square one.

Thank you.
Rand: Yes i know you guys had lifes and sorry about rushing you guys, i just was gonna be gone for a few weeks, but im back now and hopefully you can still help me and thanks for the help so far

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "712564B5-8817-46A3-9E29-BA19CD2A41CB" 12/12/2004 3:23:31 AM

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{712564B5-8817-46A3-9E29-BA19CD2A41CB}"=""




————————————————————————




Logfile of HijackThis v1.98.2
Scan saved at 3:27:07 AM, on 12/12/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097456561584
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
Just to let you know, i have not been online in 2 weeks.. and i look at my host file 127.0.0.1 r1.clrsch.com 127.0.0.1 sds.clrsch.com 127.0.0.1 status.clrsch.com 127.0.0.1 www.clrsch.com 127.0.0.1 clr-sch.com 127.0.0.1 sds-qckads.com 127.0.0.1 status.qckads.com 127.0.0.1 www.igetnet.com 127.0.0.1 code.ignphrases.com 127.0.0.1 clear-search.com 69.20.16.183 auto.search.msn.com 69.20.16.183 search.netscape.com 69.20.16.183 ieautosearch 69.20.16.183 ieautosearch 69.20.16.183 ieautosearch
Nokturnal, this is a new version of look2me. I have benn away for a few days myself. I will be on tomorrow evening (my time, I am in Michigan USA) with some instructions for you. I don't see any reason why we shouldn't be able to get this fixed.
Hi Nokturnal, sorry to be getting to this so late, it has been very busy around my house. ;)

Please perform the following steps in order and DO NOT REBOOT unless specifically instructed to do so (not even while you are waiting for the next instructions, just leave the computer turned on).
Every time you reboot the malware changes the file names and/or updates the files.

You will need to show hidden files and folders. The following script will set that up and show super hidden files also. Copy the contents of the code box to notepad, name it showhidden.vbs and save it as type "all files"
Double click showhidden.vbs and allow it to run if you get a warning box about a possibly malicious script, it is perfectly safe.
'sets the XP search  and explorer settings to show all files
'by Mosaic1
Dim Wshshell
Set Wshshell= Wscript.CreateObject("Wscript.Shell")

Wshshell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\IncludeSubFolders", 1, "REG_DWORD"
Wshshell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SearchHidden", 1, "REG_DWORD"
Wshshell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SearchSystemDirs", 1, "REG_DWORD"
Wshshell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden", 1, "REG_DWORD"
Wshshell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden", 1, "REG_DWORD"

MsgBox "Done"
 
Wscript.quit

Download the following tools and unzip them:
Find_It
VX2 finder << This is a newer version than what you ran before.
Pocket Killbox

Next, run VX2Finder and Click to find VX2.BetterInternet then Make Log.

Now, for another log.
Open the unzipped FindIt folder and double click find.bat. It will produce a log file, probably along with some "File Not Found" error messages, don't worry about those.

Look in C:/Windows/system32
for a file called guard.tmp. Let us know if it is there.

Post both logs here along with the results of looking for guard.tmp. Remember, no matter what do not reboot until you get further instructions or the file names will change and we'll have to start over.

I am going to bed now, if you like do these steps tomorrow around 6 p.m. EST (23:00 GMT) so you don't have to leave the computer turned on all the time. Once the logs are posted you then don't reboot.
Yes Guard.tmp is in my systems folder


Logfile of HijackThis v1.98.2
Scan saved at 12:45:41 AM, on 12/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Nokturnal\Desktop\VX2Finder.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097456561584
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab








Warning! This utility will find legitimate files in addition to

malware.
Do not remove anything unless you are sure you know what you're

doing.

——- System Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/15/2004 12:33 AM 222,555 srftpub.dll
12/15/2004 12:32 AM 226,292 e2202cfmgf2a2.dll
12/13/2004 03:50 PM dllcache
12/13/2004 03:48 PM 226,292 Hgperman.dll
12/13/2004 03:48 PM 222,555 r4r60e9seh.dll
12/13/2004 01:18 PM 225,583 wgnsta.dll
12/12/2004 07:36 PM 225,583 j6j60g1se6.dll
12/12/2004 07:35 PM 223,039 o266lcjs1fo6.dll
12/12/2004 06:06 PM 225,046 o6nslg5716.dll
12/12/2004 05:57 AM 223,120 mmsign32.dll
12/12/2004 05:26 AM 223,078 sne.dll
12/12/2004 04:00 AM 223,834 o6ns0g57e6.dll
12/12/2004 03:19 AM 223,381 fp0o03d3e.dll
12/06/2004 11:06 PM 223,078 kddmac.dll
12/05/2004 08:06 AM 225,244 nzmsdba.dll
12/05/2004 01:18 AM 225,653 cmcdll.dll
12/05/2004 01:00 AM 225,244 kmdsl.dll
12/04/2004 06:47 PM 224,570 jBvart.dll
12/04/2004 06:24 PM 222,891 sarobj.dll
12/04/2004 06:21 PM 225,559 igetcplc.dll
12/04/2004 07:56 AM 224,976 fZultrep.dll
12/03/2004 10:50 PM 224,804 irr6l59s1.dll
12/03/2004 10:34 PM 223,825 slrrun.dll
12/03/2004 09:27 PM 225,842 mliavi32.dll
12/03/2004 08:29 PM 222,952 csusapi.dll
12/03/2004 12:35 AM 223,561 wgigest.dll
12/02/2004 10:24 PM 224,098 dawsock.dll
12/02/2004 08:33 PM 224,098 dgrgui.dll
12/02/2004 08:21 PM 223,232 kcdycc.dll
12/02/2004 08:20 PM 223,232 irrsl5971.dll
12/02/2004 05:35 PM 223,232 irl8l53u1.dll
12/02/2004 05:33 PM 224,354 f22mlcf11f2.dll
10/09/2004 09:53 PM Microsoft
31 File(s) 6,950,803 bytes
2 Dir(s) 32,851,308,544 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
10/09/2004 06:15 PM 488 logonui.exe.manifest
10/09/2004 06:15 PM 488 WindowsLogon.manifest
10/09/2004 06:14 PM 749 nwc.cpl.manifest
10/09/2004 06:14 PM 749 sapi.cpl.manifest
10/09/2004 06:14 PM 749 ncpa.cpl.manifest
10/09/2004 06:14 PM 749 cdplayer.exe.manifest
10/09/2004 06:14 PM 749 wuaucpl.cpl.manifest
11/29/2003 10:11 AM 2,045 whlpda32e.dll
8 File(s) 6,766 bytes
1 Dir(s) 32,851,304,448 bytes free

———- Files Named "Guard" ————-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/15/2004 12:35 AM 222,555 guard.tmp
1 File(s) 222,555 bytes
0 Dir(s) 32,851,300,352 bytes free

——— Temp Files in System32 Directory ——–

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/15/2004 12:35 AM 222,555 guard.tmp
07/16/2003 03:25 PM 2,577 CONFIG.TMP
2 File(s) 225,132 bytes
0 Dir(s) 32,851,300,352 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Interne

t Settings\User Agent\Post Platform]
"{712564B5-8817-46A3-9E29-BA19CD2A41CB}"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify\Unimodem]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\r4r60e9seh.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————







Log for VX2.BetterInternet File Finder (ALL)

Files Found—

Additional Files—

Keys Under Notify—
crypt32chain
cryptnet
cscdll
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
Unimodem
wlballoon


Guardian Key— is called:

Guardian Key— :

User Agent String—
{712564B5-8817-46A3-9E29-BA19CD2A41CB}
I woke up (Didn't Restart) and got worse, so i decided to post new logs of everything.



Logfile of HijackThis v1.98.2
Scan saved at 3:59:08 PM, on 12/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\BitTornado\btdownloadgui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\aacusouma.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.popupsearches.com/sidesearch.html
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [kalvsys] c:\windows\system32\kalvzcl32.exe
O4 - HKLM\..\Run: [C:\WINDOWS\aacusouma.exe] C:\WINDOWS\aacusouma.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097456561584
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab








Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/15/2004 12:32 AM 226,292 e2202cfmgf2a2.dll
12/13/2004 03:50 PM dllcache
12/13/2004 03:48 PM 226,292 Hgperman.dll
12/13/2004 03:48 PM 222,555 r4r60e9seh.dll
12/13/2004 01:18 PM 225,583 wgnsta.dll
12/12/2004 07:36 PM 225,583 j6j60g1se6.dll
12/12/2004 07:35 PM 223,039 o266lcjs1fo6.dll
12/12/2004 06:06 PM 225,046 o6nslg5716.dll
12/12/2004 05:57 AM 223,120 mmsign32.dll
12/12/2004 05:26 AM 223,078 sne.dll
12/12/2004 04:00 AM 223,834 o6ns0g57e6.dll
12/12/2004 03:19 AM 223,381 fp0o03d3e.dll
12/06/2004 11:06 PM 223,078 kddmac.dll
12/05/2004 08:06 AM 225,244 nzmsdba.dll
12/05/2004 01:18 AM 225,653 cmcdll.dll
12/05/2004 01:00 AM 225,244 kmdsl.dll
12/04/2004 06:47 PM 224,570 jBvart.dll
12/04/2004 06:24 PM 222,891 sarobj.dll
12/04/2004 06:21 PM 225,559 igetcplc.dll
12/04/2004 07:56 AM 224,976 fZultrep.dll
12/03/2004 10:50 PM 224,804 irr6l59s1.dll
12/03/2004 10:34 PM 223,825 slrrun.dll
12/03/2004 09:27 PM 225,842 mliavi32.dll
12/03/2004 08:29 PM 222,952 csusapi.dll
12/03/2004 12:35 AM 223,561 wgigest.dll
12/02/2004 10:24 PM 224,098 dawsock.dll
12/02/2004 08:33 PM 224,098 dgrgui.dll
12/02/2004 08:21 PM 223,232 kcdycc.dll
12/02/2004 08:20 PM 223,232 irrsl5971.dll
12/02/2004 05:35 PM 223,232 irl8l53u1.dll
12/02/2004 05:33 PM 224,354 f22mlcf11f2.dll
10/09/2004 09:53 PM Microsoft
30 File(s) 6,728,248 bytes
2 Dir(s) 29,468,741,632 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
10/09/2004 06:15 PM 488 logonui.exe.manifest
10/09/2004 06:15 PM 488 WindowsLogon.manifest
10/09/2004 06:14 PM 749 nwc.cpl.manifest
10/09/2004 06:14 PM 749 sapi.cpl.manifest
10/09/2004 06:14 PM 749 ncpa.cpl.manifest
10/09/2004 06:14 PM 749 cdplayer.exe.manifest
10/09/2004 06:14 PM 749 wuaucpl.cpl.manifest
11/29/2003 10:11 AM 2,045 whlpda32e.dll
8 File(s) 6,766 bytes
1 Dir(s) 29,468,741,632 bytes free

———- Files Named "Guard" ————-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/15/2004 12:35 AM 222,555 guard.tmp
1 File(s) 222,555 bytes
0 Dir(s) 29,468,737,536 bytes free

——— Temp Files in System32 Directory ——–

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/15/2004 12:35 AM 222,555 guard.tmp
07/16/2003 03:25 PM 2,577 CONFIG.TMP
2 File(s) 225,132 bytes
0 Dir(s) 29,468,737,536 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{712564B5-8817-46A3-9E29-BA19CD2A41CB}"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Unimodem]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\r4r60e9seh.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————










Log for VX2.BetterInternet File Finder (ALL)

Files Found—

Additional Files—

Keys Under Notify—
crypt32chain
cryptnet
cscdll
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
Unimodem
wlballoon


Guardian Key— is called:

Guardian Key— :

User Agent String—
{712564B5-8817-46A3-9E29-BA19CD2A41CB}
Read through all these steps before doing anything else

Update Ad-aware
Copy these instructions to a text document for reference.
Disconnect from the internet (unplug your modem or router from the computer).

Copy the following to a notepad document, name it fix.reg and save it to your desktop. Well use it later.
REGEDIT4
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Unimodem]

The following list of files is very long. I recommend you copy the list to notepad, use cut to take it out of the notepad document and then paste it into killbox, that way you won't miss any. You must get them all or the infection will reinstate itself.

Run Pocket Killbox
Select the "Delete on Reboot" option.
For each of the files listed below:
1. Make sure Delte on Reboot is selected
2. Paste the path in the Full Path of File to Delete box.
3. Click to check mark the Use Dummy box
4. Click the red highlighted X button and say yes to the first prompt
5. Answer No to the "Reboot Now?" prompt.
Do these steps for all files in the following list:

c:\windows\system32\kalvzcl32.exe << Dont use the dummy option
C:\WINDOWS\aacusouma.exe << don't use the dummy option
C:\WINDOWS\System32\e2202cfmgf2a2.dll
C:\WINDOWS\System32\whlpda32e.dll
C:\WINDOWS\System32\dllcache\Hgperman.dll
C:\WINDOWS\System32\dllcache\r4r60e9seh.dll
C:\WINDOWS\System32\dllcache\wgnsta.dll
C:\WINDOWS\System32\dllcache\j6j60g1se6.dll
C:\WINDOWS\System32\dllcache\o266lcjs1fo6.dll
C:\WINDOWS\System32\dllcache\o6nslg5716.dll
C:\WINDOWS\System32\dllcache\mmsign32.dll
C:\WINDOWS\System32\dllcache\sne.dll
C:\WINDOWS\System32\dllcache\o6ns0g57e6.dll
C:\WINDOWS\System32\dllcache\fp0o03d3e.dll
C:\WINDOWS\System32\dllcache\mmsign32.dll
C:\WINDOWS\System32\dllcache\sne.dll
C:\WINDOWS\System32\dllcache\o6ns0g57e6.dll
C:\WINDOWS\System32\dllcache\fp0o03d3e.dll
C:\WINDOWS\System32\dllcache\kddmac.dll
C:\WINDOWS\System32\dllcache\nzmsdba.dll
C:\WINDOWS\System32\dllcache\cmcdll.dll
C:\WINDOWS\System32\dllcache\kmdsl.dll
C:\WINDOWS\System32\dllcache\jBvart.dll
C:\WINDOWS\System32\dllcache\sarobj.dll
C:\WINDOWS\System32\dllcache\igetcplc.dll
C:\WINDOWS\System32\dllcache\fZultrep.dll
C:\WINDOWS\System32\dllcache\irr6l59s1.dll
C:\WINDOWS\System32\dllcache\slrrun.dll
C:\WINDOWS\System32\dllcache\mliavi32.dll
C:\WINDOWS\System32\dllcache\csusapi.dll
C:\WINDOWS\System32\dllcache\wgigest.dll
C:\WINDOWS\System32\dllcache\dawsock.dll
C:\WINDOWS\System32\dllcache\dgrgui.dll
C:\WINDOWS\System32\dllcache\kcdycc.dll
C:\WINDOWS\System32\dllcache\irrsl5971.dll
C:\WINDOWS\System32\dllcache\irl8l53u1.dll
C:\WINDOWS\System32\dllcache\f22mlcf11f2.dll
C:\Windows\System32\Guard.tmp

After you paste the last file in then accept the reboot option.

Do not connect to the internet or start Internet Explorer until told to.

Look in C:\windows\system32 for guard.tmp. If it still exists then do the following:
Paste C:\WINDOWS\SYSTEM32\guard.tmp into Pocket Killbox
Select the "Standard File Kill" option then click the red highlighted X

Run HijackThis and check the following for fixing (with all other programs shut down).
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.popupsearches.com/sidesearch.html
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dl
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [kalvsys] c:\windows\system32\kalvzcl32.exe
O4 - HKLM\..\Run: [C:\WINDOWS\aacusouma.exe] C:\WINDOWS\aacusouma.exe

Click "Fix Checked"

Run VX2Finder, click the "find VX2" button. When it finishes, click the "Restore Policy" button, then the "User Agent" button.

I recommend you uninstall SpyHunter. While it is no longer classified as rogue/suspect it does not do a very good job (you can get much better results with free programs, I recommend Spybot S&D and Ad-Aware, two of the best out there). See this note from a respected expert on the subject.


Reboot

Run Killbox again and paste the following, using the standard file kill option:
C:\RECYCLER\Desktop.ini
Click the red highlighted X

Double Click the fix.reg file you made at the beginning of this fix and say ok to add it to the registry.

Do a full system scan with Ad-aware

Reboot one last time. Plug your modem or router back in first.

Post fresh logs from HijackThis, VX2Finder and Find_All

Good Luck !

Sometimes multiple attempts are necessary to clean up this infection so don't reboot after you post the fresh logs.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI