This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis Log, Popup Problem(tryed Everything)

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok here it is, i got an error with the recycling bin file but it still seems to work
C:\windows\system32\kalvzcl32.exe won't seem to go away.
While typing this message IE Opened with EliteTool Bar.
Just got a pop up soon after.. Keep getting Pop Ups Now



Logfile of HijackThis v1.98.2
Scan saved at 3:28:12 AM, on 12/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvzcl32.exe
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097456561584
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab







Log for VX2.BetterInternet File Finder (msg126)

Files Found—

Additional Files—

Keys Under Notify—
crypt32chain
cryptnet
cscdll
policies
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
wlballoon


Guardian Key— is called:

User Agent String—
iebar



Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
12/13/2004 03:48 PM 226,292 Hgperman.dll
12/13/2004 01:18 PM 225,583 wgnsta.dll
12/12/2004 07:36 PM 225,583 j6j60g1se6.dll
12/12/2004 07:35 PM 223,039 o266lcjs1fo6.dll
12/12/2004 06:06 PM 225,046 o6nslg5716.dll
12/12/2004 05:57 AM 223,120 mmsign32.dll
12/12/2004 05:26 AM 223,078 sne.dll
12/12/2004 04:00 AM 223,834 o6ns0g57e6.dll
12/12/2004 03:19 AM 223,381 fp0o03d3e.dll
12/06/2004 11:06 PM 223,078 kddmac.dll
12/05/2004 08:06 AM 225,244 nzmsdba.dll
12/05/2004 01:18 AM 225,653 cmcdll.dll
12/05/2004 01:00 AM 225,244 kmdsl.dll
12/04/2004 06:47 PM 224,570 jBvart.dll
12/04/2004 06:24 PM 222,891 sarobj.dll
12/04/2004 06:21 PM 225,559 igetcplc.dll
12/04/2004 07:56 AM 224,976 fZultrep.dll
12/03/2004 10:50 PM 224,804 irr6l59s1.dll
12/03/2004 10:34 PM 223,825 slrrun.dll
12/03/2004 09:27 PM 225,842 mliavi32.dll
12/03/2004 08:29 PM 222,952 csusapi.dll
12/03/2004 12:35 AM 223,561 wgigest.dll
12/02/2004 10:24 PM 224,098 dawsock.dll
12/02/2004 08:33 PM 224,098 dgrgui.dll
12/02/2004 05:33 PM 224,354 f22mlcf11f2.dll
10/09/2004 09:53 PM Microsoft
25 File(s) 5,609,705 bytes
2 Dir(s) 29,475,491,840 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
10/09/2004 06:15 PM 488 logonui.exe.manifest
10/09/2004 06:15 PM 488 WindowsLogon.manifest
10/09/2004 06:14 PM 749 nwc.cpl.manifest
10/09/2004 06:14 PM 749 sapi.cpl.manifest
10/09/2004 06:14 PM 749 ncpa.cpl.manifest
10/09/2004 06:14 PM 749 wuaucpl.cpl.manifest
10/09/2004 06:14 PM 749 cdplayer.exe.manifest
7 File(s) 4,721 bytes
1 Dir(s) 29,475,491,840 bytes free

———- Files Named "Guard" ————-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32


——— Temp Files in System32 Directory ——–

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

07/16/2003 03:25 PM 2,577 CONFIG.TMP
1 File(s) 2,577 bytes
0 Dir(s) 29,475,491,840 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"iebar"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\policies]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\e2202cfmgf2a2.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————


ok, looking better. We'll deal with kalvsys, it is part of elitebar. Since it has been almost a day, please post fresh logs so we can deal with what is running at this time. If we can keep this moving along then we may be able to get it cleaned up tonight.
:)
Logfile of HijackThis v1.98.2
Scan saved at 9:20:15 PM, on 12/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvzcl32.exe
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097456561584
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab





Log for VX2.BetterInternet File Finder (msg126)

Files Found—

Additional Files—

Keys Under Notify—
crypt32chain
cryptnet
cscdll
policies
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
wlballoon


Guardian Key— is called:

User Agent String—
iebar











Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
12/13/2004 03:48 PM 226,292 Hgperman.dll
12/13/2004 01:18 PM 225,583 wgnsta.dll
12/12/2004 07:36 PM 225,583 j6j60g1se6.dll
12/12/2004 07:35 PM 223,039 o266lcjs1fo6.dll
12/12/2004 06:06 PM 225,046 o6nslg5716.dll
12/12/2004 05:57 AM 223,120 mmsign32.dll
12/12/2004 05:26 AM 223,078 sne.dll
12/12/2004 04:00 AM 223,834 o6ns0g57e6.dll
12/12/2004 03:19 AM 223,381 fp0o03d3e.dll
12/06/2004 11:06 PM 223,078 kddmac.dll
12/05/2004 08:06 AM 225,244 nzmsdba.dll
12/05/2004 01:18 AM 225,653 cmcdll.dll
12/05/2004 01:00 AM 225,244 kmdsl.dll
12/04/2004 06:47 PM 224,570 jBvart.dll
12/04/2004 06:24 PM 222,891 sarobj.dll
12/04/2004 06:21 PM 225,559 igetcplc.dll
12/04/2004 07:56 AM 224,976 fZultrep.dll
12/03/2004 10:50 PM 224,804 irr6l59s1.dll
12/03/2004 10:34 PM 223,825 slrrun.dll
12/03/2004 09:27 PM 225,842 mliavi32.dll
12/03/2004 08:29 PM 222,952 csusapi.dll
12/03/2004 12:35 AM 223,561 wgigest.dll
12/02/2004 10:24 PM 224,098 dawsock.dll
12/02/2004 08:33 PM 224,098 dgrgui.dll
12/02/2004 05:33 PM 224,354 f22mlcf11f2.dll
10/09/2004 09:53 PM Microsoft
25 File(s) 5,609,705 bytes
2 Dir(s) 28,929,581,056 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
10/09/2004 06:15 PM 488 logonui.exe.manifest
10/09/2004 06:15 PM 488 WindowsLogon.manifest
10/09/2004 06:14 PM 749 nwc.cpl.manifest
10/09/2004 06:14 PM 749 sapi.cpl.manifest
10/09/2004 06:14 PM 749 ncpa.cpl.manifest
10/09/2004 06:14 PM 749 wuaucpl.cpl.manifest
10/09/2004 06:14 PM 749 cdplayer.exe.manifest
7 File(s) 4,721 bytes
1 Dir(s) 28,929,581,056 bytes free

———- Files Named "Guard" ————-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32


——— Temp Files in System32 Directory ——–

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

07/16/2003 03:25 PM 2,577 CONFIG.TMP
1 File(s) 2,577 bytes
0 Dir(s) 28,929,581,056 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"iebar"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\policies]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\e2202cfmgf2a2.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————


Run killbox for these, no dummy file this time just the delete on reboot option.

c:\windows\system32\dllcache\Hgperman.dll
c:\windows\system32\dllcache\wgnsta.dll
c:\windows\system32\dllcache\j6j60g1se6.dll
c:\windows\system32\dllcache\o266lcjs1fo6.dll
c:\windows\system32\dllcache\o6nslg5716.dll
c:\windows\system32\dllcache\mmsign32.dll
c:\windows\system32\dllcache\sne.dll
c:\windows\system32\dllcache\o6ns0g57e6.dll
c:\windows\system32\dllcache\fp0o03d3e.dll
c:\windows\system32\dllcache\kddmac.dll
c:\windows\system32\dllcache\nzmsdba.dll
c:\windows\system32\dllcache\cmcdll.dll
c:\windows\system32\dllcache\kmdsl.dll
c:\windows\system32\dllcache\jBvart.dll
c:\windows\system32\dllcache\sarobj.dll
c:\windows\system32\dllcache\igetcplc.dll
c:\windows\system32\dllcache\fZultrep.dll
c:\windows\system32\dllcache\irr6l59s1.dll
c:\windows\system32\dllcache\slrrun.dll
c:\windows\system32\dllcache\mliavi32.dll
c:\windows\system32\dllcache\csusapi.dll
c:\windows\system32\dllcache\wgigest.dll
c:\windows\system32\dllcache\dawsock.dll
c:\windows\system32\dllcache\dgrgui.dll
c:\windows\system32\dllcache\f22mlcf11f2.dll
C:\windows\system32\kalvzcl32.exe
C:\WINDOWS\EliteToolBar <

Accept the reboot option after you paste the EliteToolBar folder in.

Copy the following to a notepad document, name it fix-2.reg and save it to your desktop.
REGEDIT4
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\policies]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"iebar"=-

Double click fix-2.reg to run it after you have returned from the killbox reboot.

Tick the following lines for fixing in hijackthis, make sure all other programs are shut down.
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvzcl32.exe

Did you set these? If not, tick them for fixing also.
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

Click fix checked, after it finishes then reboot and post fresh logs.
i haven't told you this yet but when i run Find.bat i get 2 errors saying, But i just hit ignore and the log still comes up.

C:\Windows\System32\cmd.exe
C:\Windows\System32\AUTOEXEC.NT. The System File is Not Suitable for Running MS-DOS and Microsoft Windows Applications. Choose Close to Terminate the Application.






Logfile of HijackThis v1.98.2
Scan saved at 10:08:08 PM, on 12/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvzcl32.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097456561584
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab







Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
12/13/2004 03:48 PM 226,292 Hgperman.dll
12/13/2004 01:18 PM 225,583 wgnsta.dll
12/12/2004 07:36 PM 225,583 j6j60g1se6.dll
12/12/2004 07:35 PM 223,039 o266lcjs1fo6.dll
12/12/2004 06:06 PM 225,046 o6nslg5716.dll
12/12/2004 05:57 AM 223,120 mmsign32.dll
12/12/2004 05:26 AM 223,078 sne.dll
12/12/2004 04:00 AM 223,834 o6ns0g57e6.dll
12/12/2004 03:19 AM 223,381 fp0o03d3e.dll
12/06/2004 11:06 PM 223,078 kddmac.dll
12/05/2004 08:06 AM 225,244 nzmsdba.dll
12/05/2004 01:18 AM 225,653 cmcdll.dll
12/05/2004 01:00 AM 225,244 kmdsl.dll
12/04/2004 06:47 PM 224,570 jBvart.dll
12/04/2004 06:24 PM 222,891 sarobj.dll
12/04/2004 06:21 PM 225,559 igetcplc.dll
12/04/2004 07:56 AM 224,976 fZultrep.dll
12/03/2004 10:50 PM 224,804 irr6l59s1.dll
12/03/2004 10:34 PM 223,825 slrrun.dll
12/03/2004 09:27 PM 225,842 mliavi32.dll
12/03/2004 08:29 PM 222,952 csusapi.dll
12/03/2004 12:35 AM 223,561 wgigest.dll
12/02/2004 10:24 PM 224,098 dawsock.dll
12/02/2004 08:33 PM 224,098 dgrgui.dll
12/02/2004 05:33 PM 224,354 f22mlcf11f2.dll
10/09/2004 09:53 PM Microsoft
25 File(s) 5,609,705 bytes
2 Dir(s) 28,927,479,808 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
10/09/2004 06:15 PM 488 logonui.exe.manifest
10/09/2004 06:15 PM 488 WindowsLogon.manifest
10/09/2004 06:14 PM 749 nwc.cpl.manifest
10/09/2004 06:14 PM 749 sapi.cpl.manifest
10/09/2004 06:14 PM 749 ncpa.cpl.manifest
10/09/2004 06:14 PM 749 wuaucpl.cpl.manifest
10/09/2004 06:14 PM 749 cdplayer.exe.manifest
7 File(s) 4,721 bytes
1 Dir(s) 28,927,479,808 bytes free

———- Files Named "Guard" ————-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32


——— Temp Files in System32 Directory ——–

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

07/16/2003 03:25 PM 2,577 CONFIG.TMP
1 File(s) 2,577 bytes
0 Dir(s) 28,927,479,808 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"iebar"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\policies]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\e2202cfmgf2a2.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————


















Log for VX2.BetterInternet File Finder (msg126)

Files Found—

Additional Files—

Keys Under Notify—
crypt32chain
cryptnet
cscdll
policies
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
wlballoon


Guardian Key— is called:

User Agent String—
iebar
yes but if i do a install over the previous copy the computer screws up and i get a blue screen and gotta format, happened twice.. so i rather not do that.. but yes i got a dell windows xp cd
That is a restore CD. I am not recommending a reinstall or a repair install. There is a tool on the windows cd called recovery console, it is not on manufacturer cds as far as I know. Elitebar is giving us a hard time.

The next step will be to run a couple of scanners and see if they can clean things up. Lets try a-squared first. It is free and worth keeping around.

Download it from:
http://www.download.com/3000-2239-10262215…page&tag;=button
Install it, update it.
Next, boot into safe mode (tap as the computer boots and select "Safe Mode" from the choices, you don't want networking).
Do a full system scan with a-squared then ad-aware. When they finish, double click the fix-2.reg file and answer yes to add it to the registry.

Run HijackThis and tick the elitebar entries and the kalvsys line, click "fix checked".

Reboot normally and post fresh logs. I would like a log from an additonal tool called dll compare, you can get it at the following link.
http://downloads.subratam.org/DllCompare.exe
Follow the steps in blue that it gives when you run it.

Post all the logs. You can wait until tomorrow evening if you like as I am going to bed now.

We are making progress, we'll have to plug away some more to get it all. :)
Aight man thanks for all the help so far, i really "REALLY" appreciate it.
Never could of got this far on my own.

Here are the logs.

* DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________

C:\WINDOWS\SYSTEM32\cmcdll.dll Sun Dec 5 2004 1:18:04a ..S.R 225,653 220.36 K
C:\WINDOWS\SYSTEM32\csusapi.dll Fri Dec 3 2004 8:29:52p ..S.R 222,952 217.73 K
C:\WINDOWS\SYSTEM32\dawsock.dll Thu Dec 2 2004 10:24:32p ..S.R 224,098 218.84 K
C:\WINDOWS\SYSTEM32\dgrgui.dll Thu Dec 2 2004 8:33:08p ..S.R 224,098 218.84 K
C:\WINDOWS\SYSTEM32\f22mlc~1.dll Thu Dec 2 2004 5:33:04p ..S.R 224,354 219.09 K
C:\WINDOWS\SYSTEM32\fp0o03~1.dll Sun Dec 12 2004 3:19:52a ..S.R 223,381 218.14 K
C:\WINDOWS\SYSTEM32\fzultrep.dll Sat Dec 4 2004 7:56:40a ..S.R 224,976 219.70 K
C:\WINDOWS\SYSTEM32\hgperman.dll Mon Dec 13 2004 3:48:40p ..S.R 226,292 220.99 K
C:\WINDOWS\SYSTEM32\igetcplc.dll Sat Dec 4 2004 6:21:08p ..S.R 225,559 220.27 K
C:\WINDOWS\SYSTEM32\irr6l5~1.dll Fri Dec 3 2004 10:50:12p ..S.R 224,804 219.54 K
C:\WINDOWS\SYSTEM32\j6j60g~1.dll Sun Dec 12 2004 7:36:14p ..S.R 225,583 220.29 K
C:\WINDOWS\SYSTEM32\jbvart.dll Sat Dec 4 2004 6:47:26p ..S.R 224,570 219.30 K
C:\WINDOWS\SYSTEM32\kddmac.dll Mon Dec 6 2004 11:06:58p ..S.R 223,078 217.85 K
C:\WINDOWS\SYSTEM32\kmdsl.dll Sun Dec 5 2004 1:00:30a ..S.R 225,244 219.96 K
C:\WINDOWS\SYSTEM32\mliavi32.dll Fri Dec 3 2004 9:27:28p ..S.R 225,842 220.55 K
C:\WINDOWS\SYSTEM32\mmsign32.dll Sun Dec 12 2004 5:57:14a ..S.R 223,120 217.89 K
C:\WINDOWS\SYSTEM32\nzmsdba.dll Sun Dec 5 2004 8:07:00a ..S.R 225,244 219.96 K
C:\WINDOWS\SYSTEM32\o266lc~1.dll Sun Dec 12 2004 7:35:14p ..S.R 223,039 217.81 K
C:\WINDOWS\SYSTEM32\o6ns0g~1.dll Sun Dec 12 2004 4:00:28a ..S.R 223,834 218.59 K
C:\WINDOWS\SYSTEM32\o6nslg~1.dll Sun Dec 12 2004 6:06:14p ..S.R 225,046 219.77 K
C:\WINDOWS\SYSTEM32\sarobj.dll Sat Dec 4 2004 6:24:16p ..S.R 222,891 217.66 K
C:\WINDOWS\SYSTEM32\slrrun.dll Fri Dec 3 2004 10:34:04p ..S.R 223,825 218.58 K
C:\WINDOWS\SYSTEM32\sne.dll Sun Dec 12 2004 5:26:02a ..S.R 223,078 217.85 K
C:\WINDOWS\SYSTEM32\wgigest.dll Fri Dec 3 2004 12:36:00a ..S.R 223,561 218.32 K
C:\WINDOWS\SYSTEM32\wgnsta.dll Mon Dec 13 2004 1:18:56p ..S.R 225,583 220.29 K
________________________________________________

1,276 items found: 1,276 files (25 H/S), 0 directories.
Total of file sizes: 265,438,995 bytes 253.14 M

Administrator Account = True

——————–End log———————




Logfile of HijackThis v1.98.2
Scan saved at 12:23:46 AM, on 12/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097456561584
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab






Log for VX2.BetterInternet File Finder (msg126)

Files Found—

Additional Files—

Keys Under Notify—
crypt32chain
cryptnet
cscdll
policies
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
wlballoon


Guardian Key— is called:

User Agent String—
iebar







Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
12/13/2004 03:48 PM 226,292 Hgperman.dll
12/13/2004 01:18 PM 225,583 wgnsta.dll
12/12/2004 07:36 PM 225,583 j6j60g1se6.dll
12/12/2004 07:35 PM 223,039 o266lcjs1fo6.dll
12/12/2004 06:06 PM 225,046 o6nslg5716.dll
12/12/2004 05:57 AM 223,120 mmsign32.dll
12/12/2004 05:26 AM 223,078 sne.dll
12/12/2004 04:00 AM 223,834 o6ns0g57e6.dll
12/12/2004 03:19 AM 223,381 fp0o03d3e.dll
12/06/2004 11:06 PM 223,078 kddmac.dll
12/05/2004 08:06 AM 225,244 nzmsdba.dll
12/05/2004 01:18 AM 225,653 cmcdll.dll
12/05/2004 01:00 AM 225,244 kmdsl.dll
12/04/2004 06:47 PM 224,570 jBvart.dll
12/04/2004 06:24 PM 222,891 sarobj.dll
12/04/2004 06:21 PM 225,559 igetcplc.dll
12/04/2004 07:56 AM 224,976 fZultrep.dll
12/03/2004 10:50 PM 224,804 irr6l59s1.dll
12/03/2004 10:34 PM 223,825 slrrun.dll
12/03/2004 09:27 PM 225,842 mliavi32.dll
12/03/2004 08:29 PM 222,952 csusapi.dll
12/03/2004 12:35 AM 223,561 wgigest.dll
12/02/2004 10:24 PM 224,098 dawsock.dll
12/02/2004 08:33 PM 224,098 dgrgui.dll
12/02/2004 05:33 PM 224,354 f22mlcf11f2.dll
10/09/2004 09:53 PM Microsoft
25 File(s) 5,609,705 bytes
2 Dir(s) 28,928,835,584 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
10/09/2004 06:15 PM 488 logonui.exe.manifest
10/09/2004 06:15 PM 488 WindowsLogon.manifest
10/09/2004 06:14 PM 749 nwc.cpl.manifest
10/09/2004 06:14 PM 749 sapi.cpl.manifest
10/09/2004 06:14 PM 749 ncpa.cpl.manifest
10/09/2004 06:14 PM 749 wuaucpl.cpl.manifest
10/09/2004 06:14 PM 749 cdplayer.exe.manifest
7 File(s) 4,721 bytes
1 Dir(s) 28,928,835,584 bytes free

———- Files Named "Guard" ————-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32


——— Temp Files in System32 Directory ——–

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

07/16/2003 03:25 PM 2,577 CONFIG.TMP
1 File(s) 2,577 bytes
0 Dir(s) 28,928,835,584 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"iebar"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\policies]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\e2202cfmgf2a2.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————


C:\WINDOWS\SYSTEM32\
cmcdll.dll Sun Dec 5 2004 1:18:04a ..S.R 225,653 220.36 K
csusapi.dll Fri Dec 3 2004 8:29:52p ..S.R 222,952 217.73 K
dawsock.dll Thu Dec 2 2004 10:24:32p ..S.R 224,098 218.84 K
dgrgui.dll Thu Dec 2 2004 8:33:08p ..S.R 224,098 218.84 K
f22mlc~1.dll Thu Dec 2 2004 5:33:04p ..S.R 224,354 219.09 K
fp0o03~1.dll Sun Dec 12 2004 3:19:52a ..S.R 223,381 218.14 K
fzultrep.dll Sat Dec 4 2004 7:56:40a ..S.R 224,976 219.70 K
hgperman.dll Mon Dec 13 2004 3:48:40p ..S.R 226,292 220.99 K
igetcplc.dll Sat Dec 4 2004 6:21:08p ..S.R 225,559 220.27 K
irr6l5~1.dll Fri Dec 3 2004 10:50:12p ..S.R 224,804 219.54 K
j6j60g~1.dll Sun Dec 12 2004 7:36:14p ..S.R 225,583 220.29 K
jbvart.dll Sat Dec 4 2004 6:47:26p ..S.R 224,570 219.30 K
kddmac.dll Mon Dec 6 2004 11:06:58p ..S.R 223,078 217.85 K
kmdsl.dll Sun Dec 5 2004 1:00:30a ..S.R 225,244 219.96 K
mliavi32.dll Fri Dec 3 2004 9:27:28p ..S.R 225,842 220.55 K
mmsign32.dll Sun Dec 12 2004 5:57:14a ..S.R 223,120 217.89 K
nzmsdba.dll Sun Dec 5 2004 8:07:00a ..S.R 225,244 219.96 K
o266lc~1.dll Sun Dec 12 2004 7:35:14p ..S.R 223,039 217.81 K
o6ns0g~1.dll Sun Dec 12 2004 4:00:28a ..S.R 223,834 218.59 K
o6nslg~1.dll Sun Dec 12 2004 6:06:14p ..S.R 225,046 219.77 K
sarobj.dll Sat Dec 4 2004 6:24:16p ..S.R 222,891 217.66 K
slrrun.dll Fri Dec 3 2004 10:34:04p ..S.R 223,825 218.58 K
sne.dll Sun Dec 12 2004 5:26:02a ..S.R 223,078 217.85 K
wgigest.dll Fri Dec 3 2004 12:36:00a ..S.R 223,561 218.32 K
wgnsta.dll Mon Dec 13 2004 1:18:56p ..S.R 225,583 220.29 K

25 items found: 25 files, 0 directories.
Total of file sizes: 5,609,705 bytes 5.35 M

It looks like the SearchMiracle bho, toolbar and exe is gone. :) Post a fresh set of logs so we know what is going on right now. I'll get back to you shortly after you post them.
Logfile of HijackThis v1.98.2
Scan saved at 11:19:27 PM, on 12/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\BitTornado\btdownloadgui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097456561584
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab




Log for VX2.BetterInternet File Finder (msg126)

Files Found—

Additional Files—

Keys Under Notify—
crypt32chain
cryptnet
cscdll
policies
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
wlballoon


Guardian Key— is called:

User Agent String—





Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
12/13/2004 03:48 PM 226,292 Hgperman.dll
12/13/2004 01:18 PM 225,583 wgnsta.dll
12/12/2004 07:36 PM 225,583 j6j60g1se6.dll
12/12/2004 07:35 PM 223,039 o266lcjs1fo6.dll
12/12/2004 06:06 PM 225,046 o6nslg5716.dll
12/12/2004 05:57 AM 223,120 mmsign32.dll
12/12/2004 05:26 AM 223,078 sne.dll
12/12/2004 04:00 AM 223,834 o6ns0g57e6.dll
12/12/2004 03:19 AM 223,381 fp0o03d3e.dll
12/06/2004 11:06 PM 223,078 kddmac.dll
12/05/2004 08:06 AM 225,244 nzmsdba.dll
12/05/2004 01:18 AM 225,653 cmcdll.dll
12/05/2004 01:00 AM 225,244 kmdsl.dll
12/04/2004 06:47 PM 224,570 jBvart.dll
12/04/2004 06:24 PM 222,891 sarobj.dll
12/04/2004 06:21 PM 225,559 igetcplc.dll
12/04/2004 07:56 AM 224,976 fZultrep.dll
12/03/2004 10:50 PM 224,804 irr6l59s1.dll
12/03/2004 10:34 PM 223,825 slrrun.dll
12/03/2004 09:27 PM 225,842 mliavi32.dll
12/03/2004 08:29 PM 222,952 csusapi.dll
12/03/2004 12:35 AM 223,561 wgigest.dll
12/02/2004 10:24 PM 224,098 dawsock.dll
12/02/2004 08:33 PM 224,098 dgrgui.dll
12/02/2004 05:33 PM 224,354 f22mlcf11f2.dll
10/09/2004 09:53 PM Microsoft
25 File(s) 5,609,705 bytes
2 Dir(s) 26,258,477,056 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
10/09/2004 06:15 PM 488 logonui.exe.manifest
10/09/2004 06:15 PM 488 WindowsLogon.manifest
10/09/2004 06:14 PM 749 nwc.cpl.manifest
10/09/2004 06:14 PM 749 sapi.cpl.manifest
10/09/2004 06:14 PM 749 ncpa.cpl.manifest
10/09/2004 06:14 PM 749 wuaucpl.cpl.manifest
10/09/2004 06:14 PM 749 cdplayer.exe.manifest
7 File(s) 4,721 bytes
1 Dir(s) 26,258,477,056 bytes free

———- Files Named "Guard" ————-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32


——— Temp Files in System32 Directory ——–

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

07/16/2003 03:25 PM 2,577 CONFIG.TMP
1 File(s) 2,577 bytes
0 Dir(s) 26,258,477,056 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"iebar"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\policies]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\e2202cfmgf2a2.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————


C:\WINDOWS\SYSTEM32\
cmcdll.dll Sun Dec 5 2004 1:18:04a ..S.R 225,653 220.36 K
csusapi.dll Fri Dec 3 2004 8:29:52p ..S.R 222,952 217.73 K
dawsock.dll Thu Dec 2 2004 10:24:32p ..S.R 224,098 218.84 K
dgrgui.dll Thu Dec 2 2004 8:33:08p ..S.R 224,098 218.84 K
f22mlc~1.dll Thu Dec 2 2004 5:33:04p ..S.R 224,354 219.09 K
fp0o03~1.dll Sun Dec 12 2004 3:19:52a ..S.R 223,381 218.14 K
fzultrep.dll Sat Dec 4 2004 7:56:40a ..S.R 224,976 219.70 K
hgperman.dll Mon Dec 13 2004 3:48:40p ..S.R 226,292 220.99 K
igetcplc.dll Sat Dec 4 2004 6:21:08p ..S.R 225,559 220.27 K
irr6l5~1.dll Fri Dec 3 2004 10:50:12p ..S.R 224,804 219.54 K
j6j60g~1.dll Sun Dec 12 2004 7:36:14p ..S.R 225,583 220.29 K
jbvart.dll Sat Dec 4 2004 6:47:26p ..S.R 224,570 219.30 K
kddmac.dll Mon Dec 6 2004 11:06:58p ..S.R 223,078 217.85 K
kmdsl.dll Sun Dec 5 2004 1:00:30a ..S.R 225,244 219.96 K
mliavi32.dll Fri Dec 3 2004 9:27:28p ..S.R 225,842 220.55 K
mmsign32.dll Sun Dec 12 2004 5:57:14a ..S.R 223,120 217.89 K
nzmsdba.dll Sun Dec 5 2004 8:07:00a ..S.R 225,244 219.96 K
o266lc~1.dll Sun Dec 12 2004 7:35:14p ..S.R 223,039 217.81 K
o6ns0g~1.dll Sun Dec 12 2004 4:00:28a ..S.R 223,834 218.59 K
o6nslg~1.dll Sun Dec 12 2004 6:06:14p ..S.R 225,046 219.77 K
sarobj.dll Sat Dec 4 2004 6:24:16p ..S.R 222,891 217.66 K
slrrun.dll Fri Dec 3 2004 10:34:04p ..S.R 223,825 218.58 K
sne.dll Sun Dec 12 2004 5:26:02a ..S.R 223,078 217.85 K
wgigest.dll Fri Dec 3 2004 12:36:00a ..S.R 223,561 218.32 K
wgnsta.dll Mon Dec 13 2004 1:18:56p ..S.R 225,583 220.29 K

25 items found: 25 files, 0 directories.
Total of file sizes: 5,609,705 bytes 5.35 M

First, I would like you to check a file.
Navigate to:
C:\Windows\System32\Restore\filelist.xml
First, make a copy of the file to your desktop as a safety precaution.
Right click that file and choose Open With > Notepad
Inside you will find lines like the following.
%windir%\system.ini
The and tags mark the beginning and end of a record, respectively.
Look through that file for any of the file names in the list below and if you see them then remove their record which includes the tags. Let us know if you found any in there.

Copy the following to a notepad document, name it fix-3.reg and save it to your desktop. Well use it later.
REGEDIT4
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\policies]

Ok, back to the killbox now :)

Run Pocket Killbox
First go to Tools > Delete Temp Files
After you do that:
Select the "Delete on Reboot" option.
For each of the files listed below:
1. Make sure Delte on Reboot is selected
2. Paste the path in the Full Path of File to Delete box.
3. Click to check mark the Use Dummy box
4. Click the red highlighted X button and say yes to the first prompt
5. Answer No to the "Reboot Now?" prompt.
Do these steps for all files in the following list:

c:\windows\system32\dllcache\Hgperman.dll
c:\windows\system32\dllcache\wgnsta.dll
c:\windows\system32\dllcache\j6j60g1se6.dll
c:\windows\system32\dllcache\o266lcjs1fo6.dll
c:\windows\system32\dllcache\o6nslg5716.dll
c:\windows\system32\dllcache\mmsign32.dll
c:\windows\system32\dllcache\sne.dll
c:\windows\system32\dllcache\o6ns0g57e6.dll
c:\windows\system32\dllcache\fp0o03d3e.dll
c:\windows\system32\dllcache\kddmac.dll
c:\windows\system32\dllcache\nzmsdba.dll
c:\windows\system32\dllcache\cmcdll.dll
c:\windows\system32\dllcache\kmdsl.dll
c:\windows\system32\dllcache\jBvart.dll
c:\windows\system32\dllcache\sarobj.dll
c:\windows\system32\dllcache\igetcplc.dll
c:\windows\system32\dllcache\fZultrep.dll
c:\windows\system32\dllcache\irr6l59s1.dll
c:\windows\system32\dllcache\slrrun.dll
c:\windows\system32\dllcache\mliavi32.dll
c:\windows\system32\dllcache\csusapi.dll
c:\windows\system32\dllcache\wgigest.dll
c:\windows\system32\dllcache\dawsock.dll
c:\windows\system32\dllcache\dgrgui.dll
c:\windows\system32\dllcache\f22mlcf11f2.dll
c:\windows\system32\cmcdll.dll
c:\windows\system32\csusapi.dll
c:\windows\system32\dawsock.dll
c:\windows\system32\dgrgui.dll
c:\windows\system32\f22mlc~1.dll
c:\windows\system32\fp0o03~1.dll
c:\windows\system32\fzultrep.dll
c:\windows\system32\hgperman.dll
c:\windows\system32\igetcplc.dll
c:\windows\system32\irr6l5~1.dll
c:\windows\system32\j6j60g~1.dll
c:\windows\system32\jbvart.dll
c:\windows\system32\kddmac.dll
c:\windows\system32\kmdsl.dll
c:\windows\system32\mliavi32.dll
c:\windows\system32\mmsign32.dll
c:\windows\system32\nzmsdba.dll
c:\windows\system32\o266lc~1.dll
c:\windows\system32\o6ns0g~1.dll
c:\windows\system32\o6nslg~1.dll
c:\windows\system32\sarobj.dll
c:\windows\system32\slrrun.dll
c:\windows\system32\sne.dll
c:\windows\system32\wgigest.dll
c:\windows\system32\wgnsta.dll


After you paste the last file in then accept the reboot option.

Run VX2Finder, click the "find VX2" button. When it finishes, click the "User Agent" button.

Double Click fix-3.reg to add it to the registry.

Reboot

Post fresh logs from HijackThis, VX2Finder, Find_All and dllcompare along with what you found in filelist.xml.
Didn't really understand the first step, and you can't use "Use Dummy" on killbox under "delete on reboot" on the version i have(dont know if thats normal). I Only can use it on Replace on reboot.
Logfile of HijackThis v1.98.2
Scan saved at 1:33:54 AM, on 12/18/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097456561584
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab









Log for VX2.BetterInternet File Finder (msg126)

Files Found—

Additional Files—

Keys Under Notify—
crypt32chain
cryptnet
cscdll
policies
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
wlballoon


Guardian Key— is called:

User Agent String—












Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
12/12/2004 05:57 AM 223,120 mmsign32.dll
10/09/2004 09:53 PM Microsoft
1 File(s) 223,120 bytes
2 Dir(s) 26,096,644,096 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

12/13/2004 03:50 PM dllcache
10/09/2004 06:15 PM 488 logonui.exe.manifest
10/09/2004 06:15 PM 488 WindowsLogon.manifest
10/09/2004 06:14 PM 749 nwc.cpl.manifest
10/09/2004 06:14 PM 749 sapi.cpl.manifest
10/09/2004 06:14 PM 749 ncpa.cpl.manifest
10/09/2004 06:14 PM 749 wuaucpl.cpl.manifest
10/09/2004 06:14 PM 749 cdplayer.exe.manifest
7 File(s) 4,721 bytes
1 Dir(s) 26,096,644,096 bytes free

———- Files Named "Guard" ————-

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32


——— Temp Files in System32 Directory ——–

Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE

Directory of C:\WINDOWS\System32

07/16/2003 03:25 PM 2,577 CONFIG.TMP
1 File(s) 2,577 bytes
0 Dir(s) 26,096,644,096 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\policies]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\e2202cfmgf2a2.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————


C:\WINDOWS\SYSTEM32\
mmsign32.dll Sun Dec 12 2004 5:57:14a ..S.R 223,120 217.89 K

1 item found: 1 file, 0 directories.
Total of file sizes: 223,120 bytes 217.89 K











* DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________

C:\WINDOWS\SYSTEM32\mmsign32.dll Sun Dec 12 2004 5:57:14a ..S.R 223,120 217.89 K
________________________________________________

1,250 items found: 1,250 files (1 H/S), 0 directories.
Total of file sizes: 259,937,722 bytes 247.89 M

Administrator Account = True

——————–End log———————

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI