Nokturnal
Ok here it is, i got an error with the recycling bin file but it still seems to work
C:\windows\system32\kalvzcl32.exe won't seem to go away.
While typing this message IE Opened with EliteTool Bar.
Just got a pop up soon after.. Keep getting Pop Ups Now
Logfile of HijackThis v1.98.2
Scan saved at 3:28:12 AM, on 12/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvzcl32.exe
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097456561584
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
Log for VX2.BetterInternet File Finder (msg126)
Files Found—
Additional Files—
Keys Under Notify—
crypt32chain
cryptnet
cscdll
policies
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
wlballoon
Guardian Key— is called:
User Agent String—
iebar
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
——- System Files in System32 Directory ——-
Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE
Directory of C:\WINDOWS\System32
12/13/2004 03:50 PM dllcache
12/13/2004 03:48 PM 226,292 Hgperman.dll
12/13/2004 01:18 PM 225,583 wgnsta.dll
12/12/2004 07:36 PM 225,583 j6j60g1se6.dll
12/12/2004 07:35 PM 223,039 o266lcjs1fo6.dll
12/12/2004 06:06 PM 225,046 o6nslg5716.dll
12/12/2004 05:57 AM 223,120 mmsign32.dll
12/12/2004 05:26 AM 223,078 sne.dll
12/12/2004 04:00 AM 223,834 o6ns0g57e6.dll
12/12/2004 03:19 AM 223,381 fp0o03d3e.dll
12/06/2004 11:06 PM 223,078 kddmac.dll
12/05/2004 08:06 AM 225,244 nzmsdba.dll
12/05/2004 01:18 AM 225,653 cmcdll.dll
12/05/2004 01:00 AM 225,244 kmdsl.dll
12/04/2004 06:47 PM 224,570 jBvart.dll
12/04/2004 06:24 PM 222,891 sarobj.dll
12/04/2004 06:21 PM 225,559 igetcplc.dll
12/04/2004 07:56 AM 224,976 fZultrep.dll
12/03/2004 10:50 PM 224,804 irr6l59s1.dll
12/03/2004 10:34 PM 223,825 slrrun.dll
12/03/2004 09:27 PM 225,842 mliavi32.dll
12/03/2004 08:29 PM 222,952 csusapi.dll
12/03/2004 12:35 AM 223,561 wgigest.dll
12/02/2004 10:24 PM 224,098 dawsock.dll
12/02/2004 08:33 PM 224,098 dgrgui.dll
12/02/2004 05:33 PM 224,354 f22mlcf11f2.dll
10/09/2004 09:53 PM Microsoft
25 File(s) 5,609,705 bytes
2 Dir(s) 29,475,491,840 bytes free
——- Hidden Files in System32 Directory ——-
Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE
Directory of C:\WINDOWS\System32
12/13/2004 03:50 PM dllcache
10/09/2004 06:15 PM 488 logonui.exe.manifest
10/09/2004 06:15 PM 488 WindowsLogon.manifest
10/09/2004 06:14 PM 749 nwc.cpl.manifest
10/09/2004 06:14 PM 749 sapi.cpl.manifest
10/09/2004 06:14 PM 749 ncpa.cpl.manifest
10/09/2004 06:14 PM 749 wuaucpl.cpl.manifest
10/09/2004 06:14 PM 749 cdplayer.exe.manifest
7 File(s) 4,721 bytes
1 Dir(s) 29,475,491,840 bytes free
———- Files Named "Guard" ————-
Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE
Directory of C:\WINDOWS\System32
——— Temp Files in System32 Directory ——–
Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE
Directory of C:\WINDOWS\System32
07/16/2003 03:25 PM 2,577 CONFIG.TMP
1 File(s) 2,577 bytes
0 Dir(s) 29,475,491,840 bytes free
—————- User Agent ————
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"iebar"=""
———— Keys Under Notify ————
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\policies]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\e2202cfmgf2a2.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
—————- Xfind Results —————–
————– Locate.com Results —————
C:\windows\system32\kalvzcl32.exe won't seem to go away.
While typing this message IE Opened with EliteTool Bar.
Just got a pop up soon after.. Keep getting Pop Ups Now
Logfile of HijackThis v1.98.2
Scan saved at 3:28:12 AM, on 12/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvzcl32.exe
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097456561584
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
Log for VX2.BetterInternet File Finder (msg126)
Files Found—
Additional Files—
Keys Under Notify—
crypt32chain
cryptnet
cscdll
policies
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
wlballoon
Guardian Key— is called:
User Agent String—
iebar
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
——- System Files in System32 Directory ——-
Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE
Directory of C:\WINDOWS\System32
12/13/2004 03:50 PM dllcache
12/13/2004 03:48 PM 226,292 Hgperman.dll
12/13/2004 01:18 PM 225,583 wgnsta.dll
12/12/2004 07:36 PM 225,583 j6j60g1se6.dll
12/12/2004 07:35 PM 223,039 o266lcjs1fo6.dll
12/12/2004 06:06 PM 225,046 o6nslg5716.dll
12/12/2004 05:57 AM 223,120 mmsign32.dll
12/12/2004 05:26 AM 223,078 sne.dll
12/12/2004 04:00 AM 223,834 o6ns0g57e6.dll
12/12/2004 03:19 AM 223,381 fp0o03d3e.dll
12/06/2004 11:06 PM 223,078 kddmac.dll
12/05/2004 08:06 AM 225,244 nzmsdba.dll
12/05/2004 01:18 AM 225,653 cmcdll.dll
12/05/2004 01:00 AM 225,244 kmdsl.dll
12/04/2004 06:47 PM 224,570 jBvart.dll
12/04/2004 06:24 PM 222,891 sarobj.dll
12/04/2004 06:21 PM 225,559 igetcplc.dll
12/04/2004 07:56 AM 224,976 fZultrep.dll
12/03/2004 10:50 PM 224,804 irr6l59s1.dll
12/03/2004 10:34 PM 223,825 slrrun.dll
12/03/2004 09:27 PM 225,842 mliavi32.dll
12/03/2004 08:29 PM 222,952 csusapi.dll
12/03/2004 12:35 AM 223,561 wgigest.dll
12/02/2004 10:24 PM 224,098 dawsock.dll
12/02/2004 08:33 PM 224,098 dgrgui.dll
12/02/2004 05:33 PM 224,354 f22mlcf11f2.dll
10/09/2004 09:53 PM Microsoft
25 File(s) 5,609,705 bytes
2 Dir(s) 29,475,491,840 bytes free
——- Hidden Files in System32 Directory ——-
Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE
Directory of C:\WINDOWS\System32
12/13/2004 03:50 PM dllcache
10/09/2004 06:15 PM 488 logonui.exe.manifest
10/09/2004 06:15 PM 488 WindowsLogon.manifest
10/09/2004 06:14 PM 749 nwc.cpl.manifest
10/09/2004 06:14 PM 749 sapi.cpl.manifest
10/09/2004 06:14 PM 749 ncpa.cpl.manifest
10/09/2004 06:14 PM 749 wuaucpl.cpl.manifest
10/09/2004 06:14 PM 749 cdplayer.exe.manifest
7 File(s) 4,721 bytes
1 Dir(s) 29,475,491,840 bytes free
———- Files Named "Guard" ————-
Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE
Directory of C:\WINDOWS\System32
——— Temp Files in System32 Directory ——–
Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE
Directory of C:\WINDOWS\System32
07/16/2003 03:25 PM 2,577 CONFIG.TMP
1 File(s) 2,577 bytes
0 Dir(s) 29,475,491,840 bytes free
—————- User Agent ————
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"iebar"=""
———— Keys Under Notify ————
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\policies]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\e2202cfmgf2a2.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
—————- Xfind Results —————–
————– Locate.com Results —————