This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Having Problems With Spyware

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everyone. I'm new at this, so just bare with me. I just recently hooked my computer back up and got connected again. I've ran Ad-aware SE and I still keep finding things. Some items, mostly dll files, cannot be deleted through Ad-aware. I ran spybot S&D and still had problems. I also ran Nortons Antivirus and still. I'm getting sick and tired of all this crap that keeps slowing down my computer, so I did a little surfing. I ran across a article in pcworld and it recommended using Hijack This, so I figured I'd turn to you guys for help. Can someone help me out?

Logfile of HijackThis v1.97.7
Scan saved at 10:22:30 PM, on 12/16/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\spoolsv.exe
D:\common files\Symantec Shared\ccSetMgr.exe
D:\common files\Symantec Shared\SNDSrvc.exe
C:\WINNT\Explorer.EXE
D:\common files\Symantec Shared\SPBBC\SPBBCSvc.exe
D:\common files\Symantec Shared\ccEvtMgr.exe
D:\common files\Symantec Shared\ccApp.exe
D:\common files\Real\Update_OB\evntsvc.exe
D:\WCAT\wcat.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
D:\Adobe Acrobat v 5.0\Distillr\AcroTray.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\htghtt.exe
D:\ZoneAlarm\zapro.exe
D:\Popup killer for IE\PUKctrl.exe
C:\WINNT\System32\CTsvcCDA.exe
d:\cox anti-spy\app\CurtainsSysSvcNt.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\svchost.exe
D:\common files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\System32\devldr32.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Winzip\winzip32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\DUANEB~1\LOCALS~1\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.popupsearches.com/sidesearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.popupsearches.com/sidesearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: (no name) - {7E600446-2123-4CC9-A69D-7EEC55AB9956} - D:\Popup killer for IE\PUK.dll
O2 - BHO: (no name) - {A4D90779-6CB2-4752-83C2-A2AB4D9A672D} - D:\cox anti-spy\app\AuthBHO.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - D:\Panicware\Pop-Up Stopper Pro\popuppro.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - D:\cox anti-spy\app\AuthBHO.dll
O4 - HKLM\..\Run: [ccApp] "D:\common files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] D:\common files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\RunServices: [Default Browser] C:\WINNT\System32\iexplore.exe
O4 - HKCU\..\Run: [WatchCat] D:\WCAT\wcat.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [prrtect] C:\WINNT\System32\prrtect.exe
O4 - HKCU\..\Run: [AntiPopUp] D:\AntiPopUp\AntiPopUp.exe
O4 - Startup: Popup Killer.lnk = ?
O4 - Global Startup: Acrobat Assistant.lnk = D:\Adobe Acrobat v 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\OfficeXP\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = D:\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\OfficeXP\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O12 - Plugin for .mpg: D:\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .qcp: D:\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:\foo.mht!http://82.179.166.145/x15.chm::/trs15.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/05739892839593585005/netzip/RdxIE2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1099505939921
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/deleon/1…n/GoogleNav.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
Download LSPfix here:

http://www.cexx.org/LSPFix.exe

Save it to its own folder

To run it be sure you are NOT connected to the Internet.

Launch the application, and click the "I know what I'm doing" checkbox.

Check all instances of calsp.dll
(and nothing else), and move them to the "Remove" pane.
Then click Finish.

Please download and run Spybot Search & Destroy and AdAware. Then follow the instructions in the links below to run.

Spybot Tutorial

AdAware Tutorial



Please do an online scan,
Trend Micro http://housecall.trendmicro.com/housecall/start_corp.asp

Make sure that you choose "fix" or "clean".

Reboot and post a new HiJackThis log.
Here's the newest log. Sorry it took me a while.
Logfile of HijackThis v1.97.7
Scan saved at 10:28:16 AM, on 12/19/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINNT\system32\spoolsv.exe
D:\common files\Symantec Shared\ccSetMgr.exe
D:\common files\Symantec Shared\SNDSrvc.exe
D:\common files\Symantec Shared\SPBBC\SPBBCSvc.exe
D:\common files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
D:\common files\Symantec Shared\ccApp.exe
D:\common files\Real\Update_OB\evntsvc.exe
D:\WCAT\wcat.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
D:\AntiPopUp\AntiPopUp.exe
D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
D:\Adobe Acrobat v 5.0\Distillr\AcroTray.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\htghtt.exe
D:\ZoneAlarm\zapro.exe
C:\WINNT\System32\CTsvcCDA.exe
d:\cox anti-spy\app\CurtainsSysSvcNt.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\svchost.exe
D:\common files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\devldr32.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\System32\MsiExec.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\System32\wuauclt.exe
G:\apps\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.popupsearches.com/sidesearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.popupsearches.com/sidesearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - D:\Panicware\Pop-Up Stopper Pro\popuppro.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - D:\cox anti-spy\app\AuthBHO.dll
O4 - HKLM\..\Run: [ccApp] "D:\common files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] D:\common files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKCU\..\Run: [WatchCat] D:\WCAT\wcat.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [AntiPopUp] D:\AntiPopUp\AntiPopUp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Popup Killer.lnk = ?
O4 - Global Startup: Acrobat Assistant.lnk = D:\Adobe Acrobat v 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\OfficeXP\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = D:\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\OfficeXP\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .mpg: D:\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .qcp: D:\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:\foo.mht!http://82.179.166.145/x15.chm::/trs15.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/05739892839593585005/netzip/RdxIE2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1099505939921
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/deleon/1…n/GoogleNav.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
Please insure that all files are visable, tutorial here >>> http://www.xtra.co.nz/help/0,,4155-1916458,00.html

NEXT

Please download Vx2 Finder and safe it to its own folder. http://downloads.subratam.org/VX2Finder(126).exe
Run VX2Finder(126).exe
Select: Click to Find VX2.Betterinternet
When the scan is done, select the Make Log
Copy the log and post it.

NEXT

Download Find_It.zip:

It is at the bottom of the post

Unzip its contents to its own folder
Open the folder and double click on Find.bat (File with a gear symbol)
Ignore any File not found messages
It runs for a minute, and produces a log
Please copy and paste the log on your next response.

NEXT

Also, download KillBox.zip from the link below.
http://www.downloads.subratam.org/KillBox.exe
Place it in a folder on your Desktop.
Do not run it yet.

NEXT

Please look in your sytem32 folder and let me know if the below file is preset.

C:/Windoews/system32/guard.tmp

NEXT

Post all the logs and DO NOT REBOOT please.
Did exactly what you asked and this is what I've got Log for VX2.BetterInternet File Finder (msg126) Files Found— Additional Files— Keys Under Notify— crypt32chain cryptnet cscdll MSSYCLM ScCertProp Schedule sclgntfy SensLogn termsrv wlballoon Guardian Key— is called: User Agent String— {48F6B995-E9BE-41DA-AEA9-7F63F27EEE59} ————————————————————————————————- Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. ——- System Files in System32 Directory ——- Volume in drive C is ROOT Volume Serial Number is 08F3-2F9B Directory of C:\WINNT\System32 12/19/2004 12:50 PM 225,229 n46q0ej5eho.dll 12/19/2004 11:55 AM 224,665 f4l0le3m1h.dll 12/19/2004 12:28 AM 224,775 p4r40e9qeh.dll 12/15/2004 11:52 PM 225,680 wztdecod.dll 12/15/2004 06:58 PM 225,326 e002lado1d0c.dll 12/14/2004 05:38 PM dllcache 12/14/2004 04:06 PM 222,755 irr0l59m1.dll 11/30/2004 10:28 PM 225,083 FN20ENU.DLL 7 File(s) 1,573,513 bytes 1 Dir(s) 3,599,880,192 bytes free ——- Hidden Files in System32 Directory ——- Volume in drive C is ROOT Volume Serial Number is 08F3-2F9B Directory of C:\WINNT\System32 12/19/2004 12:51 PM 124 vsconfig.xml 12/14/2004 05:38 PM dllcache 04/13/2003 10:36 PM 4,212 zllictbl.dat 03/05/2003 12:26 AM 488 logonui.exe.manifest 03/05/2003 12:26 AM 488 WindowsLogon.manifest 03/05/2003 12:26 AM 749 wuaucpl.cpl.manifest 03/05/2003 12:26 AM 749 nwc.cpl.manifest 03/05/2003 12:26 AM 749 sapi.cpl.manifest 03/05/2003 12:26 AM 749 cdplayer.exe.manifest 03/05/2003 12:26 AM 749 ncpa.cpl.manifest 03/06/2002 06:29 PM GroupPolicy 03/06/2002 06:23 PM 21,692 folder.htt 10 File(s) 30,749 bytes 2 Dir(s) 3,599,880,192 bytes free ———- Files Named "Guard" ————- Volume in drive C is ROOT Volume Serial Number is 08F3-2F9B Directory of C:\WINNT\System32 12/19/2004 01:36 PM 224,665 guard.tmp 1 File(s) 224,665 bytes 0 Dir(s) 3,599,880,192 bytes free ——— Temp Files in System32 Directory ——– Volume in drive C is ROOT Volume Serial Number is 08F3-2F9B Directory of C:\WINNT\System32 12/19/2004 01:36 PM 224,665 guard.tmp 09/23/2002 03:10 PM 544,256 SET1B.tmp 12/07/1999 06:00 AM 2,577 CONFIG.TMP 05/07/1999 01:00 AM 140,288 ~GLH0005.TMP 05/05/1999 09:22 PM 63,760 mpg2splt.ax.tmp 08/09/1998 07:07 AM 118,784 ~GLH000d.TMP 6 File(s) 1,094,330 bytes 0 Dir(s) 3,599,880,192 bytes free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{48F6B995-E9BE-41DA-AEA9-7F63F27EEE59}"="" ———— Keys Under Notify ———— REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MSSYCLM] "Asynchronous"=dword:00000000 "DllName"="C:\\WINNT\\system32\\f4l0le3m1h.dll" "Impersonate"=dword:00000000 "Logon"="WinLogon" "Logoff"="WinLogoff" "Shutdown"="WinShutdown" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 —————- Xfind Results —————– ————– Locate.com Results —————  ———————————————————————————————— C:\WINNT\system32\guard.tmp is present
Sorry to double post, but also I did a full system with Norton's and found that I have adware called Qoolaid and I can't seem to get rid of it. There's also another file it found but I can't remember the exact name.
First, Disconnect from the Internet!!

(Please copy these instructions to NotePad for copy/paste use, since you will be off the Internet.)

Next, launch Notepad, and copy/paste all the blue REGEDIT below to it
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post

Platform]
"{48F6B995-E9BE-41DA-AEA9-7F63F27EEE59}"=""


[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MSSYCLM]



Now, extract KillBox (downloaded earlier) from the zip file and double-click on KillBox.exe to run it.

In the main screen of Pocket KillBox, go to Tools in the top menu bar, and select: Delete Temp Files.

Back at the main screen of KillBox, select the option: Delete on Reboot

In the Full Path of File to Delete box, copy and paste this entry:

C:\\WINNT\\system32\\f4l0le3m1h.dll

Press the button with a red circle and a white X.
When asked if you would like to Reboot, select No.

Do the same as above for each of the files that follow, and select No when asked to reboot!

C:\Windows\system32\n46q0ej5eho.dll

C:\Windows\system32\f4l0le3m1h.dll

C:\Windows\system32\p4r40e9qeh.dll

C:\Windows\system32\wztdecod.dll

C:\Windows\system32\e002lado1d0c.dll

C:\Windows\system32\irr0l59m1.dll

C:\Windows\system32\FN20ENU.DLL



Finally, in the Full Path of File to Delete, copy and paste the following:

C:\WINDOWS\System32\guard.tmp

Press the button with a red circle and a white X.
When asked to Reboot, select Yes!!

Make sure all windows are closed before proceeding to run HijackThis and Scan. Fix the following by placing a check in the appropriate box and selecting Fix Checked:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.popupsearches.com/sidesearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.popupsearches.com/sidesearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch

O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:\foo.mht!http://82.179.166.145/x15.chm::/trs15.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/05739892839593585005/netzip/RdxIE2.cab

Reboot the computer.

NEXT

Since this intruder may alter the Hosts file, download the Hoster to restore the file:
http://members.aol.com/toadbee/hoster.zip
Select: Restore Original Hosts
Click OK and exit Hoster.

Download AdAware SE from the following link:
http://www.majorgeeks.com/download506.html
-Use the: 'Check for Updates Now' option and download the latest reference files
-Use the Start button, and on the next window, select: Perform Full System Scan
-Press Next, and let Ad-aware scan the hard drive
-When finished, right-click the window with the entries, choose: Select All from the menu, and click Next.
-Once AdAware has removed the entries, close the program
Restart the computer

Also, check the Recycle Bin to see if it works properly. A side effect of VX2 is to sometimes damage the Recycle Bin operation.
Create an blank Notepad file on the Desktop: right click the Desktop, select New>Text Document
Right click the text document and delete it.
When a file is deleted, it should ask if you want to send it to Recycle Bin.
Does it ask if you want to send the file to the Recycle Bin, or, does the file just get deleted?
Post back what it does.

When done with all of the above, close all windows and browsers, run HijackThis, Scan, post a new HijackThis log, and a new Find_It log.

If you encounter any problems with the steps above, please describe them.
I didn't find these entries on hijack this to fix

O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
——————————————————————————————–

Here's the new log.

Logfile of HijackThis v1.97.7
Scan saved at 5:26:10 PM, on 12/19/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\spoolsv.exe
D:\common files\Symantec Shared\ccSetMgr.exe
D:\common files\Symantec Shared\SNDSrvc.exe
C:\WINNT\Explorer.EXE
D:\common files\Symantec Shared\SPBBC\SPBBCSvc.exe
D:\common files\Symantec Shared\ccEvtMgr.exe
D:\common files\Symantec Shared\ccApp.exe
D:\common files\Real\Update_OB\evntsvc.exe
D:\WCAT\wcat.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
D:\AntiPopUp\AntiPopUp.exe
D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
D:\Adobe Acrobat v 5.0\Distillr\AcroTray.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\htghtt.exe
D:\ZoneAlarm\zapro.exe
C:\WINNT\System32\CTsvcCDA.exe
d:\cox anti-spy\app\CurtainsSysSvcNt.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\System32\devldr32.exe
C:\WINNT\System32\svchost.exe
D:\common files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\System32\MsiExec.exe
C:\WINNT\System32\wuauclt.exe
G:\apps\HijackThis.exe

O2 - BHO: (no name) - {A4D90779-6CB2-4752-83C2-A2AB4D9A672D} - D:\cox anti-spy\app\AuthBHO.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - D:\Panicware\Pop-Up Stopper Pro\popuppro.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - D:\cox anti-spy\app\AuthBHO.dll
O4 - HKLM\..\Run: [ccApp] "D:\common files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] D:\common files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKCU\..\Run: [WatchCat] D:\WCAT\wcat.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [AntiPopUp] D:\AntiPopUp\AntiPopUp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Popup Killer.lnk = ?
O4 - Global Startup: Acrobat Assistant.lnk = D:\Adobe Acrobat v 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\OfficeXP\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = D:\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\OfficeXP\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .mpg: D:\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .qcp: D:\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1099505939921
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/deleon/1…n/GoogleNav.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab

———————————————————————————————-
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/19/2004 05:24 PM 225,610 ssmpapi.dll
12/19/2004 05:04 PM 224,665 hr0u05d9e.dll
12/19/2004 04:57 PM 225,610 hr4u05h9e.dll
12/19/2004 12:28 AM 224,775 p4r40e9qeh.dll
12/15/2004 11:52 PM 225,680 wztdecod.dll
12/15/2004 06:58 PM 225,326 e002lado1d0c.dll
12/14/2004 05:38 PM dllcache
12/14/2004 04:06 PM 222,755 irr0l59m1.dll
11/30/2004 10:28 PM 225,083 FN20ENU.DLL
8 File(s) 1,799,504 bytes
1 Dir(s) 3,579,330,560 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/19/2004 05:25 PM 124 vsconfig.xml
12/14/2004 05:38 PM dllcache
04/13/2003 10:36 PM 4,212 zllictbl.dat
03/05/2003 12:26 AM 488 logonui.exe.manifest
03/05/2003 12:26 AM 488 WindowsLogon.manifest
03/05/2003 12:26 AM 749 wuaucpl.cpl.manifest
03/05/2003 12:26 AM 749 nwc.cpl.manifest
03/05/2003 12:26 AM 749 sapi.cpl.manifest
03/05/2003 12:26 AM 749 cdplayer.exe.manifest
03/05/2003 12:26 AM 749 ncpa.cpl.manifest
03/06/2002 06:29 PM GroupPolicy
03/06/2002 06:23 PM 21,692 folder.htt
10 File(s) 30,749 bytes
2 Dir(s) 3,579,330,560 bytes free

———- Files Named "Guard" ————-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32


——— Temp Files in System32 Directory ——–

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

09/23/2002 03:10 PM 544,256 SET1B.tmp
12/07/1999 06:00 AM 2,577 CONFIG.TMP
05/07/1999 01:00 AM 140,288 ~GLH0005.TMP
05/05/1999 09:22 PM 63,760 mpg2splt.ax.tmp
08/09/1998 07:07 AM 118,784 ~GLH000d.TMP
5 File(s) 869,665 bytes
0 Dir(s) 3,579,330,560 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{48F6B995-E9BE-41DA-AEA9-7F63F27EEE59}"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ThemeManager]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINNT\\system32\\hr4u05h9e.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————


———————————————————————————————
The only problem with my recycle bin is it's showing 2 files left no matter how many times I empty it. Also when I ran ad-aware, there were some files that it couldn't delete.
First, Disconnect from the Internet!!

(Please copy these instructions to NotePad for copy/paste use, since you will be off the Internet.)

Next, launch Notepad, and copy/paste all the blue REGEDIT below to it
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{48F6B995-E9BE-41DA-AEA9-7F63F27EEE59}"=""

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ThemeManager]





Now, extract KillBox (downloaded earlier) from the zip file and double-click on KillBox.exe to run it.

UPDATED VERSION PLEASE USE THIS VERSION >>> http://www.downloads.subratam.org/KillBox.exe

In the main screen of Pocket KillBox, go to Tools in the top menu bar, and select: Delete Temp Files.

Back at the main screen of KillBox, select the option: Delete on Reboot

In the Full Path of File to Delete box, copy and paste this entry:

C:\\WINNT\\system32\\hr4u05h9e.dll

Press the button with a red circle and a white X.
When asked if you would like to Reboot, select No.

Do the same as above for each of the files that follow, and select No when asked to reboot!

C:\Windows\system32\ssmpapi.dll

C:\Windows\system32\hr0u05d9e.dll

C:\Windows\system32\hr4u05h9e.dll

C:\Windows\system32\p4r40e9qeh.dll

C:\Windows\system32\wztdecod.dll


C:\Windows\system32\e002lado1d0c.dll

C:\Windows\system32\irr0l59m1.dll

C:\Windows\system32\FN20ENU.DLL

Finally, in the Full Path of File to Delete, copy and paste the following:
C:\WINDOWS\System32\guard.tmp
Press the button with a red circle and a white X.
When asked to Reboot, select Yes!!


NEXT

Since this intruder may alter the Hosts file, download the Hoster to restore the file:
http://members.aol.com/toadbee/hoster.zip
Select: Restore Original Hosts
Click OK and exit Hoster.

Download AdAware SE from the following link:
http://www.majorgeeks.com/download506.html
-Use the: 'Check for Updates Now' option and download the latest reference files
-Use the Start button, and on the next window, select: Perform Full System Scan
-Press Next, and let Ad-aware scan the hard drive
-When finished, right-click the window with the entries, choose: Select All from the menu, and click Next.
-Once AdAware has removed the entries, close the program
Restart the computer

Also, check the Recycle Bin to see if it works properly. A side effect of VX2 is to sometimes damage the Recycle Bin operation.
Create an blank Notepad file on the Desktop: right click the Desktop, select New>Text Document
Right click the text document and delete it.
When a file is deleted, it should ask if you want to send it to Recycle Bin.
Does it ask if you want to send the file to the Recycle Bin, or, does the file just get deleted?
Post back what it does.

When done with all of the above, close all windows and browsers, run HijackThis, Scan, post a new HijackThis log, and a new Find_It log.

If you encounter any problems with the steps above, please describe them.
Here's the newest of both logs including problems I found

Logfile of HijackThis v1.97.7
Scan saved at 7:53:03 PM, on 12/20/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINNT\system32\spoolsv.exe
D:\common files\Symantec Shared\ccSetMgr.exe
D:\common files\Symantec Shared\SNDSrvc.exe
D:\common files\Symantec Shared\SPBBC\SPBBCSvc.exe
D:\common files\Symantec Shared\ccEvtMgr.exe
D:\common files\Symantec Shared\ccApp.exe
D:\WCAT\wcat.exe
D:\AntiPopUp\AntiPopUp.exe
D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
D:\ZoneAlarm\zapro.exe
C:\WINNT\System32\CTsvcCDA.exe
d:\cox anti-spy\app\CurtainsSysSvcNt.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\svchost.exe
D:\common files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\System32\devldr32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\explorer.exe
C:\WINNT\System32\wrawrr.exe
C:\WINNT\system32\notepad.exe
G:\apps\HijackThis.exe

O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - D:\Panicware\Pop-Up Stopper Pro\popuppro.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - D:\cox anti-spy\app\AuthBHO.dll
O4 - HKLM\..\Run: [ccApp] "D:\common files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] D:\common files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [Narrator] C:\WINNT\System32\wrawrr.exe
O4 - HKCU\..\Run: [WatchCat] D:\WCAT\wcat.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [AntiPopUp] D:\AntiPopUp\AntiPopUp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Popup Killer.lnk = ?
O4 - Global Startup: Acrobat Assistant.lnk = D:\Adobe Acrobat v 5.0\Distillr\AcroTray.exe
O4 - Global Startup: htghtt.exe
O4 - Global Startup: Microsoft Office.lnk = D:\OfficeXP\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = D:\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\OfficeXP\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .mpg: D:\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .qcp: D:\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1099505939921
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/deleon/1…n/GoogleNav.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
————————————————————————————————-
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/20/2004 07:22 PM 224,834 guard.tmp
12/20/2004 12:24 AM 224,665 m082lalo1dqc.dll
12/19/2004 12:28 AM 224,775 p4r40e9qeh.dll
12/15/2004 11:52 PM 225,680 wztdecod.dll
12/15/2004 06:58 PM 225,326 e002lado1d0c.dll
12/14/2004 05:38 PM dllcache
12/14/2004 04:06 PM 222,755 irr0l59m1.dll
11/30/2004 10:28 PM 225,083 FN20ENU.DLL
7 File(s) 1,573,118 bytes
1 Dir(s) 3,578,638,336 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/20/2004 10:26 AM 124 vsconfig.xml
12/14/2004 05:38 PM dllcache
04/13/2003 10:36 PM 4,212 zllictbl.dat
03/05/2003 12:26 AM 488 logonui.exe.manifest
03/05/2003 12:26 AM 488 WindowsLogon.manifest
03/05/2003 12:26 AM 749 wuaucpl.cpl.manifest
03/05/2003 12:26 AM 749 nwc.cpl.manifest
03/05/2003 12:26 AM 749 sapi.cpl.manifest
03/05/2003 12:26 AM 749 cdplayer.exe.manifest
03/05/2003 12:26 AM 749 ncpa.cpl.manifest
03/06/2002 06:29 PM GroupPolicy
03/06/2002 06:23 PM 21,692 folder.htt
10 File(s) 30,749 bytes
2 Dir(s) 3,578,638,336 bytes free

———- Files Named "Guard" ————-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/20/2004 07:22 PM 224,834 guard.tmp
1 File(s) 224,834 bytes
0 Dir(s) 3,578,638,336 bytes free

——— Temp Files in System32 Directory ——–

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/20/2004 07:22 PM 224,834 guard.tmp
09/23/2002 03:10 PM 544,256 SET1B.tmp
12/07/1999 06:00 AM 2,577 CONFIG.TMP
05/07/1999 01:00 AM 140,288 ~GLH0005.TMP
05/05/1999 09:22 PM 63,760 mpg2splt.ax.tmp
08/09/1998 07:07 AM 118,784 ~GLH000d.TMP
6 File(s) 1,094,499 bytes
0 Dir(s) 3,578,638,336 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{48F6B995-E9BE-41DA-AEA9-7F63F27EEE59}"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RunServices]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINNT\\system32\\lv6m09j1e.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————

————————————————————————————————
When I deleted the text file in the desktop, it did ask me if I wanted to delete it.
————————————————————————————————
The only problem I had in all of the process was when I deleted files in Ad-aware SE it said that certain files could not be deleted. These files were:
c:\\WINNT\system32\lv6m09j1e.dll
c:\\WINNT\system32\eprepp.dll which appeared numerous times.
I did the process all over except changing the directory to c:\\winnt. Also ad-aware allowed me to delete some of the files I mentioned in a previous post. I made a text file and it didn't send it to the recycle bin, it just asked if I'd like to delete it. Also this file, C:\WINNT\System32\wrawrr.exe showed up as adware when I ran Nortons. Here's the newest of logs.

Logfile of HijackThis v1.97.7
Scan saved at 11:37:10 AM, on 12/21/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINNT\system32\spoolsv.exe
D:\common files\Symantec Shared\ccSetMgr.exe
D:\common files\Symantec Shared\SNDSrvc.exe
D:\common files\Symantec Shared\SPBBC\SPBBCSvc.exe
D:\common files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\CTsvcCDA.exe
d:\cox anti-spy\app\CurtainsSysSvcNt.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
D:\common files\Symantec Shared\ccApp.exe
D:\WCAT\wcat.exe
D:\AntiPopUp\AntiPopUp.exe
C:\WINNT\System32\svchost.exe
D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
D:\Adobe Acrobat v 5.0\Distillr\AcroTray.exe
D:\common files\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\ZoneAlarm\zapro.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\System32\devldr32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\explorer.exe
C:\WINNT\System32\wrawrr.exe
G:\apps\HijackThis.exe

O2 - BHO: (no name) - {A4D90779-6CB2-4752-83C2-A2AB4D9A672D} - D:\cox anti-spy\app\AuthBHO.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - D:\Panicware\Pop-Up Stopper Pro\popuppro.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - D:\cox anti-spy\app\AuthBHO.dll
O4 - HKLM\..\Run: [ccApp] "D:\common files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] D:\common files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKCU\..\Run: [WatchCat] D:\WCAT\wcat.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [AntiPopUp] D:\AntiPopUp\AntiPopUp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Acrobat Assistant.lnk = D:\Adobe Acrobat v 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\OfficeXP\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = D:\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\OfficeXP\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .mpg: D:\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .qcp: D:\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1099505939921
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/deleon/1…n/GoogleNav.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
———————————————————————————————–

Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/21/2004 11:10 AM 224,834 guard.tmp
12/21/2004 11:06 AM 226,239 ir04l5dq1.dll
12/14/2004 05:38 PM dllcache
2 File(s) 451,073 bytes
1 Dir(s) 3,475,218,432 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/21/2004 11:09 AM 124 vsconfig.xml
12/14/2004 05:38 PM dllcache
04/13/2003 10:36 PM 4,212 zllictbl.dat
03/05/2003 12:26 AM 488 logonui.exe.manifest
03/05/2003 12:26 AM 488 WindowsLogon.manifest
03/05/2003 12:26 AM 749 wuaucpl.cpl.manifest
03/05/2003 12:26 AM 749 nwc.cpl.manifest
03/05/2003 12:26 AM 749 sapi.cpl.manifest
03/05/2003 12:26 AM 749 cdplayer.exe.manifest
03/05/2003 12:26 AM 749 ncpa.cpl.manifest
03/06/2002 06:29 PM GroupPolicy
03/06/2002 06:23 PM 21,692 folder.htt
10 File(s) 30,749 bytes
2 Dir(s) 3,475,218,432 bytes free

———- Files Named "Guard" ————-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/21/2004 11:10 AM 224,834 guard.tmp
1 File(s) 224,834 bytes
0 Dir(s) 3,475,218,432 bytes free

——— Temp Files in System32 Directory ——–

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/21/2004 11:10 AM 224,834 guard.tmp
09/23/2002 03:10 PM 544,256 SET1B.tmp
12/07/1999 06:00 AM 2,577 CONFIG.TMP
05/07/1999 01:00 AM 140,288 ~GLH0005.TMP
05/05/1999 09:22 PM 63,760 mpg2splt.ax.tmp
08/09/1998 07:07 AM 118,784 ~GLH000d.TMP
6 File(s) 1,094,499 bytes
0 Dir(s) 3,475,218,432 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{48F6B995-E9BE-41DA-AEA9-7F63F27EEE59}"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Group Policy]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINNT\\system32\\lv0m09d1e.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
Almost there

Now, extract KillBox (downloaded earlier) from the zip file and double-click on KillBox.exe to run it.

In the main screen of Pocket KillBox, go to Tools in the top menu bar, and select: Delete Temp Files.

Back at the main screen of KillBox, select the option: Delete on Reboot

In the Full Path of File to Delete box, copy and paste this entry:

C:\\WINNT\\system32\\lv0m09d1e.dll

Press the button with a red circle and a white X.
When asked if you would like to Reboot, select No.

Do the same as above for each of the files that follow, and select No when asked to reboot!

C:\WINNT\system32\ir04l5dq1.dll

C:\WINNT\system32\wrawrr.exe


Finally, in the Full Path of File to Delete, copy and paste the following:

C:\WINNT\system32\guard.tmp

Press the button with a red circle and a white X.
When asked to Reboot, select Yes!!

You need an updated version of hijackthis that you can get from here >>> http://www.majorgeeks.com/download3155.html

Please post a new fintit log and hijackthis log.

I am not sure if I gave you the latest findit file you can get it from here >>> http://www.thatcomputerguy.us/downloads/finditnt2000xp.zip
Here's the newest

Logfile of HijackThis v1.99.0
Scan saved at 1:52:11 PM, on 12/21/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
D:\common files\Symantec Shared\ccSetMgr.exe
D:\common files\Symantec Shared\SNDSrvc.exe
D:\common files\Symantec Shared\SPBBC\SPBBCSvc.exe
D:\common files\Symantec Shared\ccEvtMgr.exe
D:\common files\Symantec Shared\ccApp.exe
D:\common files\Real\Update_OB\evntsvc.exe
D:\WCAT\wcat.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
D:\AntiPopUp\AntiPopUp.exe
D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
D:\Adobe Acrobat v 5.0\Distillr\AcroTray.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\htghtt.exe
D:\ZoneAlarm\zapro.exe
C:\WINNT\System32\CTsvcCDA.exe
d:\cox anti-spy\app\CurtainsSysSvcNt.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\svchost.exe
D:\common files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\System32\MsiExec.exe
C:\WINNT\System32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\System32\devldr32.exe
C:\Program Files\Internet Explorer\iexplore.exe
G:\apps\HijackThis.exe

O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: AuthBHO.cBHO - {A4D90779-6CB2-4752-83C2-A2AB4D9A672D} - D:\cox anti-spy\app\AuthBHO.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - D:\Panicware\Pop-Up Stopper Pro\popuppro.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - D:\cox anti-spy\app\AuthBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] "D:\common files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] D:\common files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKCU\..\Run: [WatchCat] D:\WCAT\wcat.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [AntiPopUp] D:\AntiPopUp\AntiPopUp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Acrobat Assistant.lnk = D:\Adobe Acrobat v 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\OfficeXP\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = D:\ZoneAlarm\zapro.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\OfficeXP\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\AIM95\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mpg: D:\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .qcp: D:\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1099505939921
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/deleon/1…n/GoogleNav.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - D:\common files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - D:\common files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - D:\common files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: Curtains for Windows System Service - Authentium, Inc. - d:\cox anti-spy\app\CurtainsSysSvcNt.exe
O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - D:\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - D:\common files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc - Symantec Corporation - D:\common files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: STOPzilla Local Service - Unknown - D:\STOPzilla!\szntsvc.exe (file missing)
O23 - Service: StyleXPService - Unknown - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - D:\common files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe

——————————————————————————————–
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/14/2004 05:38 PM dllcache
0 File(s) 0 bytes
1 Dir(s) 3,450,163,200 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/21/2004 01:50 PM 124 vsconfig.xml
12/14/2004 05:38 PM dllcache
04/13/2003 10:36 PM 4,212 zllictbl.dat
03/05/2003 12:26 AM 488 logonui.exe.manifest
03/05/2003 12:26 AM 488 WindowsLogon.manifest
03/05/2003 12:26 AM 749 wuaucpl.cpl.manifest
03/05/2003 12:26 AM 749 nwc.cpl.manifest
03/05/2003 12:26 AM 749 sapi.cpl.manifest
03/05/2003 12:26 AM 749 cdplayer.exe.manifest
03/05/2003 12:26 AM 749 ncpa.cpl.manifest
03/06/2002 06:29 PM GroupPolicy
03/06/2002 06:23 PM 21,692 folder.htt
10 File(s) 30,749 bytes
2 Dir(s) 3,450,163,200 bytes free

———- Files Named "Guard" ————-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32


——— Temp Files in System32 Directory ——–

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

09/23/2002 03:10 PM 544,256 SET1B.tmp
12/07/1999 06:00 AM 2,577 CONFIG.TMP
05/07/1999 01:00 AM 140,288 ~GLH0005.TMP
05/05/1999 09:22 PM 63,760 mpg2splt.ax.tmp
08/09/1998 07:07 AM 118,784 ~GLH000d.TMP
5 File(s) 869,665 bytes
0 Dir(s) 3,450,163,200 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{48F6B995-E9BE-41DA-AEA9-7F63F27EEE59}"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCD]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINNT\\system32\\ir04l5dq1.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————


Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI