This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help With Hijack This Log

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I followed a link a friend sent to me a few days ago and since then, I've been having pop-ups at an amazing frequency. I have Ad Aware on my laptop (and have had it since I got the laptop) but it didn't stop this. I have now installed Ad Aware Plus and am runnign Ad Watch, but Ad Watch is not stopping all the pop-ups either. I've scanned with Ad Aware about a dozen times and it hasn't helped much - it finds and removes threats - every time but pop-ups keep happening. Anyway, here is my Hijack This log - I'm not very good at this, but it doesn't look good even to me. I'd appreciate any help anyone can give me with this. I can't believe how quickly it got nuked, it's a brand new laptop and now I can't turn it on without pop-ups every minute.

Logfile of HijackThis v1.98.2
Scan saved at 6:19:24 PM, on 12/10/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSD.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\WINDOWS\jagxgwoo.exe
C:\Program Files\SED\SED.exe
C:\WINDOWS\system32\perprovi.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\mpldle.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Pook\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.128.126:8888
R3 - Default URLSearchHook is missing
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSD.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AVManager] "C:\Program Files\Wistron\AVManager\AVManager.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [C:\WINDOWS\jagxgwoo.exe] C:\WINDOWS\jagxgwoo.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [wFsW37j] perprovi.exe
O4 - HKLM\..\Run: [180ax] c:\windows\temp\180ax.exe
O4 - HKLM\..\Run: [nwzilub] C:\WINDOWS\nwzilub.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ho36RXHpU] mpldle.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.shockwave.com/content/feedingfr…outLauncher.cab
Hello welcome to the forum.

Please put your HijackThis in it's own folder, (I create a new folder in C:\ named HJT).
You can do a Right Click on any open area on the desktop, New> Folder, then rename the folder HJT.

Go to where your HijackThis is and Right Click on HijackThis.exe, select Cut, then open the new folder you just created (HJT) Right Click in the folder and select paste.

The reason we do this is Hijackthis creates backup files just in case you'd need to restore one and we'll be cleaning out the temp files.


Please do all the steps in the order they are listed

Uninstall Virtumundo from control panel >> add remove program if listed there

Reboot

Download LSPfix here: http://www.cexx.org/lspfix.htm

Start the program and then check the I know what I'm doing box.

Move all instances of calsp.dll and aklsp.dll (and nothing else), to the Remove pane.
Click the Finish Button and reboot.

Find and delete the file c:\windows\system\calsp.dll
Find and delete the file c:\windows\system\aklsp.dll

1. Open My Computer
2. Right click on your hard drive that you wish to clean (C drive, for example)
3. In the context menu that opens, select properties
4. Under the general tab you should select Disk Cleanup
5. Windows will scan your drive which will take a few seconds/minutes
6. A box will display the various files you can remove.
Check all boxes except compress old files
7. Click OK and windows will comply.


Restart your computer.

Reboot and "copy/paste" a new log file into this thread.
Thanks for the help -

So far so good - there was no Virtumundo listed in the add/remove programs to uninstall, though. Still getting pop-ups at this point, though the frequency seems to have decreased. Here is the new log file.

Logfile of HijackThis v1.98.2
Scan saved at 12:09:39 AM, on 12/11/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSD.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\jagxgwoo.exe
C:\Program Files\SED\SED.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Pook\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.128.126:8888
R3 - Default URLSearchHook is missing
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSD.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AVManager] "C:\Program Files\Wistron\AVManager\AVManager.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKLM\..\Run: [C:\WINDOWS\jagxgwoo.exe] C:\WINDOWS\jagxgwoo.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [180ax] c:\windows\temp\180ax.exe
O4 - HKLM\..\Run: [nwzilub] C:\WINDOWS\nwzilub.exe
O4 - HKLM\..\Run: [wFsW37j] perprovi.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ho36RXHpU] mpldle.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.shockwave.com/content/feedingfr…outLauncher.cab
Welcome back mbhinton.

Lets get rid of the easy ones, then we'll get to the real nasty 01's.


I suggest you do this:

Go to Add/Remove Programs and uninstall SED


Run Hijack This again and put a check by these.

R3 - Default URLSearchHook is missing
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [C:\WINDOWS\jagxgwoo.exe] C:\WINDOWS\jagxgwoo.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [180ax] c:\windows\temp\180ax.exe
O4 - HKLM\..\Run: [nwzilub] C:\WINDOWS\nwzilub.exe
O4 - HKLM\..\Run: [wFsW37j] perprovi.exe
O4 - HKCU\..\Run: [ho36RXHpU] mpldle.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL


Close ALL windows and browsers except HijackThis and click "Fix checked"

Restart in Safe Mode:
Restart your computer.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.

Search for these Files and delete them if still listed.

perprovi.exe
mpldle.exe

C:\WINDOWS\jagxgwoo.exe
C:\WINDOWS\nwzilub.exe

C:\Program Files\SED <–Delete Folder


Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Thanks again. I followed the instructions and checked the the items you listed, and they appeared to be removed and remained gone during the Safe reboot. However, when I rebooted again, Ad Watch (which I have set to load on startup) reported several registry modifications which were those items putting themselves back into the registry. It did not give me the choice it usually did to block the changes, it simply reported them. I was not connected to the Internet on startup, so it seems to me that something present on my computer is writing those items back to my registry during every startup. When I checked both the registry and a new Hijack This log, they were present again (as you can see below). However, I did notice that, even though the registry items were back, the files I deleted (the SED folder, jagxgwoo.exe, etc.) - the files referred to in the registry items - remain deleted.

I also posted the Ad Watch log below the HJT log, in case it could be helpful.

Logfile of HijackThis v1.98.2
Scan saved at 10:45:55 AM, on 12/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSD.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HJT\HijackThis.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.128.126:8888
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSD.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AVManager] "C:\Program Files\Wistron\AVManager\AVManager.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKLM\..\Run: [C:\WINDOWS\jagxgwoo.exe] C:\WINDOWS\jagxgwoo.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [wFsW37j] perprovi.exe
O4 - HKLM\..\Run: [180ax] c:\windows\temp\180ax.exe
O4 - HKLM\..\Run: [nwzilub] C:\WINDOWS\nwzilub.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ho36RXHpU] mpldle.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab






Ad-Watch Logfile, exported on 12/12/2004
Total number of events:13
===============================================
12/12/2004 12:06:30 AM - Definitions file SE1R21 03.12.2004 loaded successfully.
Build:SE1R21 03.12.2004
Total Signatures :34553
Target Families :625
Target Categories :6
CSI data Size :39236

File Size :1292266

===============================================
12/12/2004 12:06:30 AM - User preferences file loaded.
Ad-Watch preference file loaded.
Applying user settings
C:\Documents and Settings\Pook\Application Data\Lavasoft\Ad-Aware\awsettings.awc
Initialization complete.




===============================================
12/12/2004 12:06:30 AM - Sites file loaded.
Sites file loaded successfully.
C:\PROGRA~1\Lavasoft\AD-AWA~1\sites.txt
Total entries : 3231





===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\Main
Value:Search Page
Data:http://ie.search.msn.com
New Data:http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch



===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Internet Explorer\Main
Value:Search Page
Data:http://ie.search.msn.com
New Data:http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch



===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Internet Explorer\Search
Value:SearchAssistant
Data:http://ie.search.msn.com
New Data:http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm



===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Windows\CurrentVersion\Run
Value:ho36RXHpU
Data:mpldle.exe
New Data:



===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Windows\CurrentVersion\Run
Value:C:\WINDOWS\jagxgwoo.exe
Data:C:\WINDOWS\jagxgwoo.exe
New Data:



===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Internet Explorer\Search
Value:CustomizeSearch
Data:http://ie.search.msn.com
New Data:http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm



===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Windows\CurrentVersion\Run
Value:SESync
Data:"C:\Program Files\SED\SED.exe"
New Data:



===============================================
12/12/2004 12:06:31 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Windows\CurrentVersion\Run
Value:wFsW37j
Data:perprovi.exe
New Data:



===============================================
12/12/2004 12:06:31 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Windows\CurrentVersion\Run
Value:180ax
Data:c:\windows\temp\180ax.exe
New Data:



===============================================
12/12/2004 12:06:31 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Windows\CurrentVersion\Run
Value:nwzilub
Data:C:\WINDOWS\nwzilub.exe
New Data:



===============================================
Remove Ad Watch. You can re-install it later. This will stop the fix.



First, enable the viewing of Hidden Files and Folders as follows:
-At your Desktop, go to Start>My Computer
-Select the Tools menu and then Folder Options
-After the new window appears select the View tab
-Select: Display the contents of system folders
-Under the Hidden files and folders section select: Show hidden files and folders
-Remove the checkmark from Hide file extensions for known file types
-Remove the checkmark from Hide protected operating system files (Recommended)
-Press the Apply button
Click OK

Now, right click the Start button on the Desktop
-Select: Explore from the menu
-In the left pane, look for the C: drive (or Local Disk C:}
Below the C: drive, look for [+]WINDOWS, and click on the [+] to expand/open
-Under WINDOWS, you should find the System32 folder.
-Select/highlight the System32 folder
-In the right pane, all the contents of System32 folder appear
-Scroll down the right pane and look for the following file: guard.tmp
-If found, right click the file, and select: Properties
Post back the date Created

Now, let's find the files that are making this beast prevail.
Please do the following:

Download Find_It.zip:
http://www.dslreports.com/r0/download/7259…84f2/FindIt.zip
Unzip its contents to its own folder
Open the folder and double click on Find.bat (File with a gear symbol)
Ignore any File not found messages
It runs for a minute, and produces a log
Please copy and paste the log on your next response.

Download VX2Finder(126).exe:
http://downloads.subratam.org/VX2Finder(126).exe
Save the program in its own folder.
Run VX2Finder(126).exe
Select: Click to Find VX2.Betterinternet
When the scan is done, select the Make Log
It will open the log in Notepad.
Copy and paste the log to on your response.

Also, download KillBox.zip (Removal Tool #15) from here:
http://www.subratam.org/?page=removal
Place it in a folder on your Desktop.
Do not run it yet.

Will wait for the Find_It log, and the VX2Finder log, as well as the information requested for guard.tmp. Also include a new HijackThis log in your reply, since we need to have all the information as current as possible.

After providing the logs requested, please do not reboot or shutdown/restart the computer. Just leave it on. If you restart, any information provided may change, and we are back to square one.
Ad Watch removed. There is no guard.tmp file in the system32 folder or in any other folder (I did a search just in case). Find_It Log: Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. ——- System Files in System32 Directory ——- Volume in drive C has no label. Volume Serial Number is 98B1-0CF2 Directory of C:\WINDOWS\System32 12/12/2004 05:28 PM 223,455 dbkquoui.dll 12/12/2004 05:28 PM 224,916 en64l1jq1.dll 12/12/2004 05:07 PM 224,976 en2ql1f51.dll 12/12/2004 12:05 AM 223,455 enn6l15s1.dll 12/11/2004 11:21 PM 223,071 mirapi.dll 12/11/2004 11:11 PM 224,908 ttext.dll 12/11/2004 10:34 PM 224,337 gltuname.dll 12/11/2004 08:21 PM 223,683 lFngwrbk.dll 12/11/2004 08:18 PM 222,956 wpsdmoe.dll 12/11/2004 07:44 PM 224,892 uzrlbva.dll 12/10/2004 08:13 PM 225,013 kwdes.dll 12/10/2004 12:56 PM 222,990 n6n60g5se6.dll 12/10/2004 11:46 AM 225,013 pdrfproc.dll 12/10/2004 11:37 AM 225,070 o4840elqehqe0.dll 12/08/2004 08:00 AM dllcache 03/02/2004 12:35 PM Microsoft 14 File(s) 3,138,735 bytes 2 Dir(s) 25,907,277,824 bytes free ——- Hidden Files in System32 Directory ——- Volume in drive C has no label. Volume Serial Number is 98B1-0CF2 Directory of C:\WINDOWS\System32 12/08/2004 08:00 AM dllcache 03/02/2004 12:23 PM 488 logonui.exe.manifest 03/02/2004 12:23 PM 488 WindowsLogon.manifest 03/02/2004 12:23 PM 749 nwc.cpl.manifest 03/02/2004 12:23 PM 749 sapi.cpl.manifest 03/02/2004 12:23 PM 749 ncpa.cpl.manifest 03/02/2004 12:23 PM 749 wuaucpl.cpl.manifest 03/02/2004 12:23 PM 749 cdplayer.exe.manifest 7 File(s) 4,721 bytes 1 Dir(s) 25,907,277,824 bytes free ———- Files Named "Guard" ————- Volume in drive C has no label. Volume Serial Number is 98B1-0CF2 Directory of C:\WINDOWS\System32 ——— Temp Files in System32 Directory ——– Volume in drive C has no label. Volume Serial Number is 98B1-0CF2 Directory of C:\WINDOWS\System32 12/09/2004 12:47 PM 263,012 pzvbha.xml.tmp 03/31/2003 06:00 AM 2,577 CONFIG.TMP 2 File(s) 265,589 bytes 0 Dir(s) 25,907,277,824 bytes free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{C79B4EAD-F4CF-4C78-B70D-5C82DD90B30F}"="" ———— Keys Under Notify ———— REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls] "Asynchronous"=dword:00000000 "DllName"="C:\\WINDOWS\\system32\\enn6l15s1.dll" "Impersonate"=dword:00000000 "Logon"="WinLogon" "Logoff"="WinLogoff" "Shutdown"="WinShutdown" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Sebring] "Logoff"="SebringUserLogoff" "Logon"="SebringUserLogon" "Impersonate"=dword:00000000 "Dllname"="C:\\WINDOWS\\System32\\LgNotify.dll" "Asynchronous"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 —————- Xfind Results —————– C:\WINDOWS\System32\DBKQUOUI.DLL +++ File read error ————– Locate.com Results ————— C:\WINDOWS\SYSTEM32\ dbkquoui.dll Sun Dec 12 2004 5:28:08p ..S.R 223,455 218.21 K en2ql1~1.dll Sun Dec 12 2004 5:07:56p ..S.R 224,976 219.70 K en64l1~1.dll Sun Dec 12 2004 5:28:08p ..S.R 224,916 219.64 K enn6l1~1.dll Sun Dec 12 2004 12:05:32a ..S.R 223,455 218.21 K gltuname.dll Sat Dec 11 2004 10:34:34p ..S.R 224,337 219.08 K kwdes.dll Fri Dec 10 2004 8:13:06p ..S.R 225,013 219.74 K lfngwrbk.dll Sat Dec 11 2004 8:21:06p ..S.R 223,683 218.44 K mirapi.dll Sat Dec 11 2004 11:21:40p ..S.R 223,071 217.84 K n6n60g~1.dll Fri Dec 10 2004 12:56:10p ..S.R 222,990 217.76 K o4840e~1.dll Fri Dec 10 2004 11:37:12a ..S.R 225,070 219.79 K pdrfproc.dll Fri Dec 10 2004 11:46:14a ..S.R 225,013 219.74 K ttext.dll Sat Dec 11 2004 11:11:14p ..S.R 224,908 219.64 K uzrlbva.dll Sat Dec 11 2004 7:44:36p ..S.R 224,892 219.62 K wpsdmoe.dll Sat Dec 11 2004 8:18:10p ..S.R 222,956 217.73 K 14 items found: 14 files, 0 directories. Total of file sizes: 3,138,735 bytes 2.99 M  VX2 Log: Log for VX2.BetterInternet File Finder (msg126) Files Found— Additional Files— Keys Under Notify— crypt32chain cryptnet cscdll Nls ScCertProp Schedule sclgntfy Sebring SensLogn termsrv wlballoon Guardian Key— is called: User Agent String— {C79B4EAD-F4CF-4C78-B70D-5C82DD90B30F} I have downloaded Killbox but have not run it, and I will not restart.
Sorry, I forgot to post the Hijack This log:

Logfile of HijackThis v1.98.2
Scan saved at 5:43:38 PM, on 12/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSD.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\HJT\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.128.126:8888
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSD.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AVManager] "C:\Program Files\Wistron\AVManager\AVManager.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [180ax] c:\windows\temp\180ax.exe
O4 - HKLM\..\Run: [C:\WINDOWS\jagxgwoo.exe] C:\WINDOWS\jagxgwoo.exe
O4 - HKLM\..\Run: [nwzilub] C:\WINDOWS\nwzilub.exe
O4 - HKLM\..\Run: [wFsW37j] perprovi.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ho36RXHpU] mpldle.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
If you have not rebooted or shutdown/restarted, proceed as follows:

First, Disconnect from the Internet!!

(Please copy these instructions to NotePad for copy/paste use, since you will be off the Internet.)
____
Next, launch Notepad, and copy/paste all the blue REGEDIT below to it
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{C79B4EAD-F4CF-4C78-B70D-5C82DD90B30F}"=-

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls]



Back on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.
____
Now, extract KillBox (downloaded earlier) from the zip file and double-click on KillBox.exe to run it.

In the main screen of Pocket KillBox, go to Tools in the top menu bar, and select: Delete Temp Files.

Back at the main screen of KillBox, select the option: Delete on Reboot

In the Full Path of File to Delete box, copy and paste this entry:
C:\\WINDOWS\\system32\\enn6l15s1.dll
Press the button with a red circle and a white X.
When asked if you would like to Reboot, select No.

Do the same as above for each of the files that follow, and select No when asked to reboot!

C:\WINDOWS\System32\DBKQUOUI.DLL
C:\WINDOWS\System32\dbkquoui.dll
C:\WINDOWS\System32\en64l1jq1.dll
C:\WINDOWS\System32\en2ql1f51.dll
C:\WINDOWS\System32\enn6l15s1.dll
C:\WINDOWS\System32\mirapi.dll
C:\WINDOWS\System32\ttext.dll
C:\WINDOWS\System32\gltuname.dll
C:\WINDOWS\System32\lFngwrbk.dll
C:\WINDOWS\System32\wpsdmoe.dll
C:\WINDOWS\System32\uzrlbva.dll
C:\WINDOWS\System32\kwdes.dll
C:\WINDOWS\System32\n6n60g5se6.dll
C:\WINDOWS\System32\pdrfproc.dll
C:\WINDOWS\System32\o4840elqehqe0.dll


Finally, in the Full Path of File to Delete, copy and paste the following:
C:\WINDOWS\System32\guard.tmp
Press the button with a red circle and a white X.
When asked to Reboot, select Yes!!
____
Make sure all windows are closed before proceeding to run HijackThis and Scan. Fix the following by placing a check in the appropriate box and selecting Fix Checked:

O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [180ax] c:\windows\temp\180ax.exe
O4 - HKLM\..\Run: [C:\WINDOWS\jagxgwoo.exe] C:\WINDOWS\jagxgwoo.exe
O4 - HKLM\..\Run: [nwzilub] C:\WINDOWS\nwzilub.exe
O4 - HKLM\..\Run: [wFsW37j] perprovi.exe
O4 - HKCU\..\Run: [ho36RXHpU] mpldle.exe


Use Add/Remove Programs and uninstall SED

Open C:\perprovi.exe<–Delete File
Open C:\mpldle.exe <–Delete
Open C:\WINDOWS\jagxgwoo.exe <–Delete File
Open C:\WINDOWS\nwzilub.exe <–Delete File

Reboot the computer.

Since this intruder may alter the Hosts file, download the Hoster to restore the file:
http://members.aol.com/toadbee/hoster.zip
Select: Restore Original Hosts
Click OK and exit Hoster.
____
Next, download AdAware SE from the following link:
http://www.majorgeeks.com/download506.html
-Use the: 'Check for Updates Now' option and download the latest reference files
-Use the Start button, and on the next window, select: Perform Full System Scan
-Please deselect: Search for negligible risk entries
When the scan completes, select: Show Logfile
Copy/paste the complete log file, which may take 2-3 consecutive posts to this topic.

Also, check the Recycle Bin to see if it works properly. A side effect of VX2 is to sometimes damage the Recycle Bin operation.
Create an blank Notepad file on the Desktop: right click the Desktop, select New>Text Document
Right click the text document and delete it.
When a file is deleted, it should ask if you want to send it to Recycle Bin.
Does it ask if you want to send the file to the Recycle Bin, or, does the file just get deleted?

Post back what it does.

When done with all of the above, close all windows and browsers, run HijackThis, Scan, post a new HijackThis log, and a new Find_It log.

If you encounter any problems with the steps above, please describe them.
When I deleted the text file from the desktop, it did ask for confirmation to send it to the recycle bin. AdAware Scan: Ad-Aware SE Build 1.05 Logfile Created on:Sunday, December 12, 2004 8:57:41 PM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R22 13.12.2004 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hijacker.TopConverting(TAC index:5):1 total references Tracking Cookie(TAC index:3):51 total references VirtualBouncer(TAC index:5):1 total references VX2(TAC index:10):4 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Ad-Aware SE Settings =========================== Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 12-12-2004 8:57:41 PM - Scan started. (Full System Scan) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] FilePath : \SystemRoot\System32\ ProcessID : 580 ThreadCreationTime : 12-13-2004 2:51:24 AM BasePriority : Normal #:2 [winlogon.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 668 ThreadCreationTime : 12-13-2004 2:51:27 AM BasePriority : High #:3 [services.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 712 ThreadCreationTime : 12-13-2004 2:51:27 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe #:4 [lsass.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 724 ThreadCreationTime : 12-13-2004 2:51:27 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:5 [ati2evxx.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 868 ThreadCreationTime : 12-13-2004 2:51:27 AM BasePriority : Normal #:6 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 884 ThreadCreationTime : 12-13-2004 2:51:27 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:7 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1008 ThreadCreationTime : 12-13-2004 2:51:28 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [s24evmon.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1056 ThreadCreationTime : 12-13-2004 2:51:28 AM BasePriority : Normal FileVersion : 8, 0, 0, 161 ProductVersion : 8, 0, 0, 161 ProductName : Mobile Unit Support Service CompanyName : Intel Corporation FileDescription : Event Monitor - Supports driver extensions to NIC Driver for wireless adapters. InternalName : S24EvMon LegalCopyright : Copyright © 2001 - 2003 Intel Corporation, 1997 - 2001 Symbol Technologies, Inc. Portions Copyright © MIT OriginalFilename : S24EvMon.exe #:9 [ccsetmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1448 ThreadCreationTime : 12-13-2004 2:51:29 AM BasePriority : Normal FileVersion : 103.0.1.26 ProductVersion : 103.0.1.26 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Settings Manager Service InternalName : ccSetMgr LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccSetMgr.exe #:10 [sndsrvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1460 ThreadCreationTime : 12-13-2004 2:51:29 AM BasePriority : Normal FileVersion : 5.4.3.11 ProductVersion : 5.4 ProductName : Symantec Security Drivers CompanyName : Symantec Corporation FileDescription : Network Driver Service InternalName : SndSrvc LegalCopyright : Copyright 2002, 2003, 2004 Symantec Corporation OriginalFilename : SndSrvc.exe #:11 [spbbcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\SPBBC\ ProcessID : 1472 ThreadCreationTime : 12-13-2004 2:51:29 AM BasePriority : Normal FileVersion : 1,0,1,47 ProductVersion : 1,0,1,47 ProductName : SPBBC CompanyName : Symantec Corporation FileDescription : SPBBC Service InternalName : SPBBCSvc LegalCopyright : Copyright © 2004 Symantec Corporation. All rights reserved. OriginalFilename : SPBBCSvc.exe #:12 [ccevtmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1540 ThreadCreationTime : 12-13-2004 2:51:31 AM BasePriority : Normal FileVersion : 103.0.1.26 ProductVersion : 103.0.1.26 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Event Manager Service InternalName : ccEvtMgr LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccEvtMgr.exe #:13 [brsvc01a.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1668 ThreadCreationTime : 12-13-2004 2:51:31 AM BasePriority : Normal FileVersion : 1, 0, 0, 3 ProductVersion : 1, 0, 0, 3 ProductName : brother Industries Ltd brsvc01a CompanyName : brother Industries Ltd FileDescription : brsvc01a InternalName : brsvc01a LegalCopyright : Copyright © Brother Industries, Ltd 2001 OriginalFilename : brsvc01a.exe #:14 [brss01a.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1684 ThreadCreationTime : 12-13-2004 2:51:31 AM BasePriority : Normal FileVersion : 1.004 ProductVersion : 1, 0, 0, 4 ProductName : brother Industries Ltd brss01a.exe CompanyName : brother Industries Ltd FileDescription : brss01a.exe InternalName : brss01a.exe LegalCopyright : Copyright ? 2001 OriginalFilename : brss01a.exe Comments : Brsplproc XP wrapper #:15 [spoolsv.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1692 ThreadCreationTime : 12-13-2004 2:51:31 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe #:16 [mdm.exe] FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\ ProcessID : 1884 ThreadCreationTime : 12-13-2004 2:51:31 AM BasePriority : Normal FileVersion : 7.00.9466 ProductVersion : 7.00.9466 ProductName : Microsoft® Visual Studio .NET CompanyName : Microsoft Corporation FileDescription : Machine Debug Manager InternalName : mdm.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : mdm.exe #:17 [npfmntor.exe] FilePath : C:\Program Files\Norton AntiVirus\IWP\ ProcessID : 1916 ThreadCreationTime : 12-13-2004 2:51:31 AM BasePriority : Normal FileVersion : 11.0.2.4 ProductVersion : 11.0.2 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Firewall Install Monitor InternalName : NPFMonitor LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved. OriginalFilename : NPFMonitor.EXE #:18 [nprotect.exe] FilePath : C:\Program Files\Norton AntiVirus\AdvTools\ ProcessID : 1944 ThreadCreationTime : 12-13-2004 2:51:31 AM BasePriority : Normal FileVersion : 16.00.0.22 ProductVersion : 16.00.0.22 ProductName : Norton Utilities CompanyName : Symantec Corporation FileDescription : Norton Protection Status InternalName : NPROTECT LegalCopyright : Copyright © 2003 Symantec Corporation LegalTrademarks : Norton Utilities OriginalFilename : NPROTECT.EXE #:19 [regsrvc.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 2004 ThreadCreationTime : 12-13-2004 2:51:31 AM BasePriority : Normal FileVersion : 8, 0, 0, 161 ProductVersion : 8, 0, 0, 161 ProductName : RegSrvc Module CompanyName : Intel Corporation FileDescription : RegSrvc Module InternalName : RegSrvc LegalCopyright : Copyright © 2002 - 2003 Intel Corporation OriginalFilename : RegSrvc.EXE #:20 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 188 ThreadCreationTime : 12-13-2004 2:51:31 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:21 [symlcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\ ProcessID : 204 ThreadCreationTime : 12-13-2004 2:51:31 AM BasePriority : Normal FileVersion : 1, 8, 54, 478 ProductVersion : 1, 8, 54, 478 ProductName : Symantec Core Component CompanyName : Symantec Corporation FileDescription : Symantec Core Component InternalName : symlcsvc LegalCopyright : Copyright © 2003 OriginalFilename : symlcsvc.exe #:22 [zcfgsvc.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 436 ThreadCreationTime : 12-13-2004 2:51:46 AM BasePriority : Normal FileVersion : 8, 0, 0, 161 ProductVersion : 8, 0, 0, 161 ProductName : ZeroCfgSvc Application CompanyName : Intel Corporation FileDescription : ZeroCfgSvc MFC Application InternalName : ZeroCfgSvc LegalCopyright : Copyright © 2002 - 2003 Intel Corporation OriginalFilename : ZeroCfgSvc.EXE #:23 [explorer.exe] FilePath : C:\WINDOWS\ ProcessID : 1380 ThreadCreationTime : 12-13-2004 2:51:46 AM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE #:24 [1xconfig.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 2060 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 8, 0, 0, 161 ProductVersion : 8, 0, 0, 161 ProductName : 8021XConfig Module CompanyName : Intel FileDescription : 8021XConfig Module InternalName : 8021XConfig LegalCopyright : Copyright 2003 OriginalFilename : 1XConfig.EXE Comments : Wrapper for MH. (Service COM) #:25 [atiptaxx.exe] FilePath : C:\Program Files\ATI Technologies\ATI Control Panel\ ProcessID : 2064 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 6.14.10.5037 ProductVersion : 6.14.10.5037 ProductName : ATI Desktop Component CompanyName : ATI Technologies, Inc. FileDescription : ATI Desktop Control Panel InternalName : Atiptaxx.exe LegalCopyright : Copyright © 1998-2002 ATI Technologies Inc. OriginalFilename : Atiptaxx.exe #:26 [launchap.exe] FilePath : C:\Program Files\Launch Manager\ ProcessID : 2088 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 1, 0, 0, 3 ProductVersion : 1, 0, 0, 3 ProductName : LaunchAp Application FileDescription : LaunchAp MFC Application InternalName : LaunchAp LegalCopyright : Copyright © 2001 OriginalFilename : LaunchAp.EXE #:27 [hotkeyapp.exe] FilePath : C:\Program Files\Launch Manager\ ProcessID : 2096 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 1, 0, 5, 4 ProductVersion : 1, 0, 5, 4 ProductName : Wistron HotkeyApp CompanyName : Wistron FileDescription : HotkeyApp InternalName : HotkeyApp LegalCopyright : Copyright c 2002 OriginalFilename : HotkeyApp.exe #:28 [osd.exe] FilePath : C:\Program Files\Launch Manager\ ProcessID : 2136 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 1, 0, 0, 3 ProductVersion : 1, 0, 0, 3 ProductName : On Screen Display CompanyName : Wistron FileDescription : On Screen Display InternalName : OSD LegalCopyright : Copyright c 2002 OriginalFilename : OSD.exe #:29 [wbutton.exe] FilePath : C:\Program Files\Launch Manager\ ProcessID : 2148 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 1, 0, 3, 7 ProductVersion : 1, 0, 3, 7 ProductName : WButton Application FileDescription : WButton MFC Application InternalName : WButton LegalCopyright : Copyright © 2001 OriginalFilename : WButton.EXE #:30 [avmanager.exe] FilePath : C:\Program Files\Wistron\AVManager\ ProcessID : 2160 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 1, 1, 0, 6 ProductVersion : 1, 1, 0, 6 ProductName : Wistron AVManager CompanyName : Wistron Corporation FileDescription : AVManager InternalName : AVManager LegalCopyright : Copyright c 2002 OriginalFilename : AVManager.exe #:31 [agrsmmsg.exe] FilePath : C:\WINDOWS\ ProcessID : 2168 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 2.1.31 2.1.31 06/27/2003 08:53:31 ProductVersion : 2.1.31 2.1.31 06/27/2003 08:53:31 ProductName : Agere SoftModem Messaging Applet CompanyName : Agere Systems FileDescription : SoftModem Messaging Applet InternalName : smdmstat.exe LegalCopyright : Copyright © Agere Systems 1998-2000 OriginalFilename : smdmstat.exe #:32 [syntplpr.exe] FilePath : C:\Program Files\Synaptics\SynTP\ ProcessID : 2176 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 7.6.1 25Jul03 ProductVersion : 7.6.1 25Jul03 ProductName : Progressive Touch CompanyName : Synaptics, Inc. FileDescription : TouchPad Driver Helper Application InternalName : SynTPLpr LegalCopyright : Copyright © Synaptics, Inc. 1996-2003 OriginalFilename : SynTPLpr.exe #:33 [syntpenh.exe] FilePath : C:\Program Files\Synaptics\SynTP\ ProcessID : 2184 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 7.6.1 25Jul03 ProductVersion : 7.6.1 25Jul03 ProductName : Progressive Touch CompanyName : Synaptics, Inc. FileDescription : Synaptics TouchPad Enhancements InternalName : Scrolleroo LegalCopyright : Copyright © Synaptics, Inc. 1996-2003 OriginalFilename : SynTPEnh.exe #:34 [pptd40nt.exe] FilePath : C:\Program Files\Scansoft\PaperPort\ ProcessID : 2252 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 8.10 ProductVersion : 8.10 ProductName : PaperPort CompanyName : ScanSoft, Inc. FileDescription : PaperPort Print to Desktop for NT InternalName : PPTD40NT LegalCopyright : Copyright © 1993-2001 Scansoft Inc. OriginalFilename : PPTD40NT.EXE #:35 [ccapp.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 2344 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 103.0.1.26 ProductVersion : 103.0.1.26 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec User Session InternalName : ccApp LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccApp.exe #:36 [em_exec.exe] FilePath : C:\Program Files\Logitech\MouseWare\system\ ProcessID : 2408 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 9.80.019 ProductVersion : 9.80.019 ProductName : MouseWare CompanyName : Logitech Inc. FileDescription : Logitech Events Handler Application InternalName : Em_Exec LegalCopyright : © 1987-2004 Logitech. All rights reserved. LegalTrademarks : Logitech® and MouseWare® are registered trademarks of Logitech Inc. OriginalFilename : Em_Exec.exe Comments : Created by the MouseWare team #:37 [ctfmon.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 2416 ThreadCreationTime : 12-13-2004 2:51:47 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : CTF Loader InternalName : CTFMON LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : CTFMON.EXE #:38 [wuauclt.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 3528 ThreadCreationTime : 12-13-2004 2:52:18 AM BasePriority : Normal FileVersion : 5.4.3790.2182 built by: srv03_rtm(ntvbl04) ProductVersion : 5.4.3790.2182 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Automatic Updates InternalName : wuauclt.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : wuauclt.exe #:39 [winword.exe] FilePath : C:\Program Files\Microsoft Office\OFFICE11\ ProcessID : 1804 ThreadCreationTime : 12-13-2004 2:53:35 AM BasePriority : Normal #:40 [iexplore.exe] FilePath : C:\Program Files\Internet Explorer\ ProcessID : 408 ThreadCreationTime : 12-13-2004 2:54:12 AM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE #:41 [navapsvc.exe] FilePath : C:\Program Files\Norton AntiVirus\ ProcessID : 416 ThreadCreationTime : 12-13-2004 2:54:50 AM BasePriority : Normal FileVersion : 11.0.2.4 ProductVersion : 11.0.2 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Auto-Protect Service InternalName : NAVAPSVC LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved. OriginalFilename : NAVAPSVC.EXE #:42 [msmsgs.exe] FilePath : C:\Program Files\Messenger\ ProcessID : 3764 ThreadCreationTime : 12-13-2004 2:56:50 AM BasePriority : Normal FileVersion : 4.7.3000 ProductVersion : Version 4.7.3000 ProductName : Messenger CompanyName : Microsoft Corporation FileDescription : Windows Messenger InternalName : msmsgs LegalCopyright : Copyright © Microsoft Corporation 2004 LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries. OriginalFilename : msmsgs.exe #:43 [ad-aware.exe] FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\ ProcessID : 3132 ThreadCreationTime : 12-13-2004 2:57:14 AM BasePriority : Normal FileVersion : 6.2.0.206 ProductVersion : VI.Second Edition ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@centrport[1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 12-31-2029 6:00:00 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 12-5-2019 9:55:06 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed]-sys[1].txt Category : Data Miner Comment : Hits:3 Value : Cookie:[removed]/ Expires : 1-1-2038 2:00:00 AM LastSync : Hits:3 UseCount : 0 Hits : 3 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@fortunecity[1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 12-31-2010 6:00:00 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@trafic[1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 1-11-2037 8:00:00 AM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:15 Value : Cookie:[removed]/ Expires : 11-15-2024 4:31:22 PM LastSync : Hits:15 UseCount : 0 Hits : 15 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@mediaplex[1].txt Category : Data Miner Comment : Hits:23 Value : Cookie:[removed]/ Expires : 6-21-2009 6:00:00 PM LastSync : Hits:23 UseCount : 0 Hits : 23 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:45 Value : Cookie:[removed]/ Expires : 11-14-2005 7:58:26 PM LastSync : Hits:45 UseCount : 0 Hits : 45 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@valueclick[3].txt Category : Data Miner Comment : Hits:3 Value : Cookie:[removed]/ Expires : 12-2-2029 7:53:12 AM LastSync : Hits:3 UseCount : 0 Hits : 3 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@questionmarket[1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 1-28-2006 11:15:58 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@2o7[1].txt Category : Data Miner Comment : Hits:84 Value : Cookie:[removed]/ Expires : 12-6-2009 6:22:24 PM LastSync : Hits:84 UseCount : 0 Hits : 84 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@cgi-bin[1].txt Category : Data Miner Comment : Hits:2 Value : Cookie:[removed]/cgi-bin Expires : 1-18-2009 5:00:00 PM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@serving-sys[2].txt Category : Data Miner Comment : Hits:23 Value : Cookie:[removed]/ Expires : 12-31-2037 11:00:00 PM LastSync : Hits:23 UseCount : 0 Hits : 23 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@bfast[2].txt Category : Data Miner Comment : Hits:2 Value : Cookie:[removed]/ Expires : 11-24-2024 9:51:58 AM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@advertising[2].txt Category : Data Miner Comment : Hits:84 Value : Cookie:[removed]/ Expires : 12-7-2009 7:36:02 AM LastSync : Hits:84 UseCount : 0 Hits : 84 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@realmedia[2].txt Category : Data Miner Comment : Hits:15 Value : Cookie:[removed]/ Expires : 12-31-2010 6:00:00 PM LastSync : Hits:15 UseCount : 0 Hits : 15 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@zedo[2].txt Category : Data Miner Comment : Hits:12 Value : Cookie:[removed]/ Expires : 11-13-2014 11:35:24 AM LastSync : Hits:12 UseCount : 0 Hits : 12 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@doubleclick[1].txt Category : Data Miner Comment : Hits:51 Value : Cookie:[removed]/ Expires : 11-12-2007 9:05:24 AM LastSync : Hits:51 UseCount : 0 Hits : 51 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@hitbox[2].txt Category : Data Miner Comment : Hits:99 Value : Cookie:[removed]/ Expires : 12-2-2005 9:24:52 PM LastSync : Hits:99 UseCount : 0 Hits : 99 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@trafficmp[2].txt Category : Data Miner Comment : Hits:17 Value : Cookie:[removed]/ Expires : 11-12-2005 9:18:06 AM LastSync : Hits:17 UseCount : 0 Hits : 17 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:38 Value : Cookie:[removed]/ Expires : 12-8-2005 8:19:40 AM LastSync : Hits:38 UseCount : 0 Hits : 38 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@tribalfusion[2].txt Category : Data Miner Comment : Hits:2 Value : Cookie:[removed]/ Expires : 12-31-2037 6:00:00 PM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:63 Value : Cookie:[removed]/ Expires : 12-20-2004 4:32:08 PM LastSync : Hits:63 UseCount : 0 Hits : 63 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@adrevolver[1].txt Category : Data Miner Comment : Hits:3 Value : Cookie:[removed]/adrevolver/ Expires : 9-3-2007 4:50:22 PM LastSync : Hits:3 UseCount : 0 Hits : 3 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@excite[2].txt Category : Data Miner Comment : Hits:2 Value : Cookie:[removed]/ Expires : 11-15-2014 8:10:02 PM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@fastclick[1].txt Category : Data Miner Comment : Hits:25 Value : Cookie:[removed]/ Expires : 11-2-2006 11:22:16 PM LastSync : Hits:25 UseCount : 0 Hits : 25 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][2].txt Category : Data Miner Comment : Hits:2 Value : Cookie:[removed]/ Expires : 11-18-2005 9:09:32 PM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@targetnet[2].txt Category : Data Miner Comment : Hits:6 Value : Cookie:[removed]/ Expires : 5-17-2033 9:33:20 PM LastSync : Hits:6 UseCount : 0 Hits : 6 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@cgi-bin[2].txt Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/cgi-bin Expires : 2-27-2015 6:00:00 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][2].txt Category : Data Miner Comment : Hits:14 Value : Cookie:[removed]/ Expires : 12-31-2009 6:00:00 PM LastSync : Hits:14 UseCount : 0 Hits : 14 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 12-4-2008 9:36:48 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@gator[1].txt Category : Data Miner Comment : Hits:19 Value : Cookie:[removed]/ Expires : 2-6-2005 7:45:58 PM LastSync : Hits:19 UseCount : 0 Hits : 19 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@adtech[2].txt Category : Data Miner Comment : Hits:4 Value : Cookie:[removed]/ Expires : 11-10-2014 6:29:02 PM LastSync : Hits:4 UseCount : 0 Hits : 4 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 12-5-2004 11:34:30 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][2].txt Category : Data Miner Comment : Hits:68 Value : Cookie:[removed]/ Expires : 1-7-2005 7:36:02 AM LastSync : Hits:68 UseCount : 0 Hits : 68 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 2-28-2007 6:00:00 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@statcounter[2].txt Category : Data Miner Comment : Hits:2 Value : Cookie:[removed]/ Expires : 11-18-2009 3:41:44 PM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 12-5-2019 10:01:08 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@atdmt[1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 12-11-2009 6:00:00 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@casalemedia[2].txt Category : Data Miner Comment : Hits:18 Value : Cookie:[removed]/ Expires : 11-23-2005 2:33:26 PM LastSync : Hits:18 UseCount : 0 Hits : 18 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@bluestreak[2].txt Category : Data Miner Comment : Hits:19 Value : Cookie:[removed]/ Expires : 12-5-2014 1:02:28 PM LastSync : Hits:19 UseCount : 0 Hits : 19 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][2].txt Category : Data Miner Comment : Hits:2 Value : Cookie:[removed]/ Expires : 12-30-2037 10:00:00 AM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@valueclick[1].txt Category : Data Miner Comment : Hits:9 Value : Cookie:[removed]/ Expires : 11-6-2029 11:21:34 PM LastSync : Hits:9 UseCount : 0 Hits : 9 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@edge.ru4[2].txt Category : Data Miner Comment : Hits:12 Value : Cookie:[removed]/ Expires : 2-4-2005 10:26:28 AM LastSync : Hits:12 UseCount : 0 Hits : 12 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][2].txt Category : Data Miner Comment : Hits:34 Value : Cookie:[removed]/ Expires : 11-20-2005 3:00:40 PM LastSync : Hits:34 UseCount : 0 Hits : 34 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 11-12-2005 6:29:04 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@domainsponsor[1].txt Category : Data Miner Comment : Hits:3 Value : Cookie:[removed]/ Expires : 12-5-2004 11:34:30 PM LastSync : Hits:3 UseCount : 0 Hits : 3 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@maxserving[1].txt Category : Data Miner Comment : Hits:23 Value : Cookie:[removed]/ Expires : 11-22-2014 9:48:56 AM LastSync : Hits:23 UseCount : 0 Hits : 23 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:3 Value : Cookie:[removed]/ Expires : 12-2-2005 9:24:52 PM LastSync : Hits:3 UseCount : 0 Hits : 3 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@dcsgcxwngpifwznfzlmv83o6w_5w4m[1].txt Category : Data Miner Comment : Hits:4 Value : Cookie:[removed]/dcsgcxwngpifwznfzlmv83o6w_5w4m Expires : 11-24-2014 2:36:10 PM LastSync : Hits:4 UseCount : 0 Hits : 4 Tracking Cookie Object Recognized! Type : IECache Entry Data : pook@0[2].txt Category : Data Miner Comment : Hits:2 Value : Cookie:[removed]/HTM/573/0 Expires : 11-30-2005 9:19:48 AM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 51 Objects found so far: 51 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hijacker.TopConverting Object Recognized! Type : File Data : loader2[1].ocx Category : Malware Comment : Object : C:\Documents and Settings\Pook\Local Settings\Temporary Internet Files\Content.IE5\OHEZ4P6N\ FileVersion : 1, 0, 0, 21 ProductVersion : 1, 0, 0, 21 ProductName : loader2 ActiveX Control Module FileDescription : loader2 ActiveX Control Module InternalName : loader2 LegalCopyright : Copyright © 2004 OriginalFilename : loader2.OCX VX2 Object Recognized! Type : File Data : A0002477.dll Category : Malware Comment : Object : C:\System Volume Information\_restore{C3489E41-E17E-4363-8020-5EDEB417559C}\RP21\ VX2 Object Recognized! Type : File Data : A0002485.dll Category : Malware Comment : Object : C:\System Volume Information\_restore{C3489E41-E17E-4363-8020-5EDEB417559C}\RP21\ VirtualBouncer Object Recognized! Type : File Data : A0002488.EXE Category : Malware Comment : Object : C:\System Volume Information\_restore{C3489E41-E17E-4363-8020-5EDEB417559C}\RP21\ VX2 Object Recognized! Type : File Data : A0002769.exe Category : Malware Comment : Object : C:\System Volume Information\_restore{C3489E41-E17E-4363-8020-5EDEB417559C}\RP22\ Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 56 Scanning Hosts file…… Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 1 entries scanned. New critical objects:0 Objects found so far: 56 Performing conditional scans… »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» VX2 Object Recognized! Type : RegValue Data : Category : Malware Comment : Rootkey : HKEY_CURRENT_USER Object : software\microsoft\internet explorer\toolbar\webbrowser Value : {0E5CBF21-D15F-11D0-8301-00AA005B4383} Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 1 Objects found so far: 57 9:05:40 PM Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:07:59.79 Objects scanned:138915 Objects identified:57 Objects ignored:0 New critical objects:57
Logfile of HijackThis v1.98.2
Scan saved at 9:29:38 PM, on 12/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSD.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\HJT\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.128.126:8888
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSD.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AVManager] "C:\Program Files\Wistron\AVManager\AVManager.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab





Find_It Log:


Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 98B1-0CF2

Directory of C:\WINDOWS\System32

12/08/2004 08:00 AM dllcache
03/02/2004 12:35 PM Microsoft
0 File(s) 0 bytes
2 Dir(s) 26,203,869,184 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 98B1-0CF2

Directory of C:\WINDOWS\System32

12/08/2004 08:00 AM dllcache
03/02/2004 12:23 PM 488 logonui.exe.manifest
03/02/2004 12:23 PM 488 WindowsLogon.manifest
03/02/2004 12:23 PM 749 nwc.cpl.manifest
03/02/2004 12:23 PM 749 sapi.cpl.manifest
03/02/2004 12:23 PM 749 ncpa.cpl.manifest
03/02/2004 12:23 PM 749 wuaucpl.cpl.manifest
03/02/2004 12:23 PM 749 cdplayer.exe.manifest
7 File(s) 4,721 bytes
1 Dir(s) 26,203,869,184 bytes free

———- Files Named "Guard" ————-

Volume in drive C has no label.
Volume Serial Number is 98B1-0CF2

Directory of C:\WINDOWS\System32

12/12/2004 08:42 PM 223,455 guard.tmp
1 File(s) 223,455 bytes
0 Dir(s) 26,203,869,184 bytes free

——— Temp Files in System32 Directory ——–

Volume in drive C has no label.
Volume Serial Number is 98B1-0CF2

Directory of C:\WINDOWS\System32

12/12/2004 08:42 PM 223,455 guard.tmp
12/09/2004 12:47 PM 263,012 pzvbha.xml.tmp
03/31/2003 06:00 AM 2,577 CONFIG.TMP
3 File(s) 489,044 bytes
0 Dir(s) 26,203,869,184 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{C79B4EAD-F4CF-4C78-B70D-5C82DD90B30F}"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\App Paths]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\en64l1jq1.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Sebring]
"Logoff"="SebringUserLogoff"
"Logon"="SebringUserLogon"
"Impersonate"=dword:00000000
"Dllname"="C:\\WINDOWS\\System32\\LgNotify.dll"
"Asynchronous"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————


No matches found.

If you have not rebooted or shutdown/restarted, proceed as follows:

First, Disconnect from the Internet!!

(Please copy these instructions to NotePad for copy/paste use, since you will be off the Internet.)
____
Next, launch Notepad, and copy/paste all the blue REGEDIT below to it
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{7573AB4A-C0D1-4BE2-9BE0-54451F6BC572}"=-

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\App Paths]



Back on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.
____
Now, extract KillBox (downloaded earlier) from the zip file and double-click on KillBox.exe to run it.

In the main screen of Pocket KillBox, go to Tools in the top menu bar, and select: Delete Temp Files.

Back at the main screen of KillBox, select the option: Delete on Reboot

In the Full Path of File to Delete box, copy and paste this entry:
C:\\WINDOWS\\system32\\en64l1jq1.dll
Press the button with a red circle and a white X.
When asked if you would like to Reboot, select No.

Finally, in the Full Path of File to Delete, copy and paste the following:
C:\WINDOWS\System32\guard.tmp
Press the button with a red circle and a white X.
When asked to Reboot, select Yes!!
____

1. Open My Computer
2. Right click on your hard drive that you wish to clean (C drive, for example)
3. In the context menu that opens, select properties
4. Under the general tab you should select Disk Cleanup
5. Windows will scan your drive which will take a few seconds/minutes
6. A box will display the various files you can remove.
Check all boxes except compress old files
7. Click OK and windows will comply.

Restart your computer.



post a new HijackThis log, and a new Find_It log.
Logfile of HijackThis v1.98.2
Scan saved at 10:34:45 PM, on 12/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSD.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HJT\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.128.126:8888
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSD.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AVManager] "C:\Program Files\Wistron\AVManager\AVManager.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab




Find It Log:

Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 98B1-0CF2

Directory of C:\WINDOWS\System32

12/08/2004 08:00 AM dllcache
03/02/2004 12:35 PM Microsoft
0 File(s) 0 bytes
2 Dir(s) 26,827,915,264 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C has no label.
Volume Serial Number is 98B1-0CF2

Directory of C:\WINDOWS\System32

12/08/2004 08:00 AM dllcache
03/02/2004 12:23 PM 488 logonui.exe.manifest
03/02/2004 12:23 PM 488 WindowsLogon.manifest
03/02/2004 12:23 PM 749 nwc.cpl.manifest
03/02/2004 12:23 PM 749 sapi.cpl.manifest
03/02/2004 12:23 PM 749 ncpa.cpl.manifest
03/02/2004 12:23 PM 749 wuaucpl.cpl.manifest
03/02/2004 12:23 PM 749 cdplayer.exe.manifest
7 File(s) 4,721 bytes
1 Dir(s) 26,827,915,264 bytes free

———- Files Named "Guard" ————-

Volume in drive C has no label.
Volume Serial Number is 98B1-0CF2

Directory of C:\WINDOWS\System32


——— Temp Files in System32 Directory ——–

Volume in drive C has no label.
Volume Serial Number is 98B1-0CF2

Directory of C:\WINDOWS\System32

12/09/2004 12:47 PM 263,012 pzvbha.xml.tmp
03/31/2003 06:00 AM 2,577 CONFIG.TMP
2 File(s) 265,589 bytes
0 Dir(s) 26,827,915,264 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{C79B4EAD-F4CF-4C78-B70D-5C82DD90B30F}"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Sebring]
"Logoff"="SebringUserLogoff"
"Logon"="SebringUserLogon"
"Impersonate"=dword:00000000
"Dllname"="C:\\WINDOWS\\System32\\LgNotify.dll"
"Asynchronous"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————


No matches found.

If you have not rebooted or shutdown/restarted, proceed as follows:

First, Disconnect from the Internet!!

(Please copy these instructions to NotePad for copy/paste use, since you will be off the Internet.)
____
Next, launch Notepad, and copy/paste all the blue REGEDIT below to it
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{7573AB4A-C0D1-4BE2-9BE0-54451F6BC572}"=-

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Sebring]


Back on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.
____
Now, double-click on KillBox.exe to run it.

In the main screen of Pocket KillBox, go to Tools in the top menu bar, and select: Delete Temp Files.

Back at the main screen of KillBox, select the option: Delete on Reboot

In the Full Path of File to Delete box, copy and paste this entry:
C:\\WINDOWS\\System32\\LgNotify.dll
Press the button with a red circle and a white X.
When asked if you would like to Reboot, select No.

Finally, in the Full Path of File to Delete, copy and paste the following:
C:\WINDOWS\System32\guard.tmp
Press the button with a red circle and a white X.
When asked to Reboot, select Yes!!
____

1. Open My Computer
2. Right click on your hard drive that you wish to clean (C drive, for example)
3. In the context menu that opens, select properties
4. Under the general tab you should select Disk Cleanup
5. Windows will scan your drive which will take a few seconds/minutes
6. A box will display the various files you can remove.
Check all boxes except compress old files
7. Click OK and windows will comply.

Restart your computer.



post a new HijackThis log, and a new Find_It log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI