This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Having Problems With Spyware

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry for taking so long to get back. Please post a new findit log as well as a hijackthis log. I will be out of town for the next week but will ask someone to watch for your response.
Sorry I haven't posted in a while, but I figured I'd give you the new logs before Christmas Day.

Logfile of HijackThis v1.99.0
Scan saved at 10:12:29 AM, on 12/24/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
D:\common files\Symantec Shared\ccSetMgr.exe
D:\common files\Symantec Shared\SNDSrvc.exe
D:\common files\Symantec Shared\SPBBC\SPBBCSvc.exe
D:\common files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\CTsvcCDA.exe
d:\cox anti-spy\app\CurtainsSysSvcNt.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\svchost.exe
D:\common files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\MsPMSPSv.exe
D:\common files\Symantec Shared\ccApp.exe
D:\common files\Real\Update_OB\evntsvc.exe
D:\WCAT\wcat.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
D:\Superadblocker\SAdBlock.exe
C:\Documents and Settings\Duane Berger\Application Data\csoo.exe
D:\Adobe Acrobat v 5.0\Distillr\AcroTray.exe
D:\ZoneAlarm\zapro.exe
D:\Superadblocker\SABSVC.EXE
C:\WINNT\System32\devldr32.exe
D:\Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
G:\apps\HijackThis.exe

O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - D:\Superadblocker\SABBHO.DLL
O2 - BHO: AuthBHO.cBHO - {A4D90779-6CB2-4752-83C2-A2AB4D9A672D} - D:\cox anti-spy\app\AuthBHO.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - D:\Panicware\Pop-Up Stopper Pro\popuppro.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - D:\cox anti-spy\app\AuthBHO.dll
O4 - HKLM\..\Run: [ccApp] "D:\common files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] D:\common files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKCU\..\Run: [WatchCat] D:\WCAT\wcat.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [AntiPopUp] D:\AntiPopUp\AntiPopUp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SuperAdBlocker] D:\Superadblocker\SAdBlock.exe
O4 - HKCU\..\Run: [Oeas] C:\Documents and Settings\Duane Berger\Application Data\csoo.exe
O4 - Global Startup: Acrobat Assistant.lnk = D:\Adobe Acrobat v 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\OfficeXP\Office10\OSA.EXE
O4 - Global Startup: strings.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = D:\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\OfficeXP\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\AIM95\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mpg: D:\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .qcp: D:\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1099505939921
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/deleon/1…n/GoogleNav.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - D:\common files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - D:\common files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - D:\common files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: Curtains for Windows System Service - Authentium, Inc. - d:\cox anti-spy\app\CurtainsSysSvcNt.exe
O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Super Ad Blocker Service - SuperAdBlocker.com - D:\Superadblocker\SABSVC.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - D:\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - D:\common files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc - Symantec Corporation - D:\common files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: STOPzilla Local Service - Unknown - D:\STOPzilla!\szntsvc.exe (file missing)
O23 - Service: StyleXPService - Unknown - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - D:\common files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe

———————————————————————————————–
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/14/2004 05:38 PM dllcache
0 File(s) 0 bytes
1 Dir(s) 3,291,848,704 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/24/2004 09:41 AM 124 vsconfig.xml
12/14/2004 05:38 PM dllcache
04/13/2003 10:36 PM 4,212 zllictbl.dat
03/05/2003 12:26 AM 488 logonui.exe.manifest
03/05/2003 12:26 AM 488 WindowsLogon.manifest
03/05/2003 12:26 AM 749 wuaucpl.cpl.manifest
03/05/2003 12:26 AM 749 nwc.cpl.manifest
03/05/2003 12:26 AM 749 sapi.cpl.manifest
03/05/2003 12:26 AM 749 cdplayer.exe.manifest
03/05/2003 12:26 AM 749 ncpa.cpl.manifest
03/06/2002 06:29 PM GroupPolicy
03/06/2002 06:23 PM 21,692 folder.htt
10 File(s) 30,749 bytes
2 Dir(s) 3,291,848,704 bytes free

———- Files Named "Guard" ————-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32


——— Temp Files in System32 Directory ——–

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

09/23/2002 03:10 PM 544,256 SET1B.tmp
12/07/1999 06:00 AM 2,577 CONFIG.TMP
05/07/1999 01:00 AM 140,288 ~GLH0005.TMP
05/05/1999 09:22 PM 63,760 mpg2splt.ax.tmp
08/09/1998 07:07 AM 118,784 ~GLH000d.TMP
5 File(s) 869,665 bytes
0 Dir(s) 3,291,848,704 bytes free

—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{48F6B995-E9BE-41DA-AEA9-7F63F27EEE59}"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCD]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINNT\\system32\\ir04l5dq1.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


—————- Xfind Results —————–


————– Locate.com Results —————
————————————————————————————————-
Siggy told me to download the newest version of FindIT, but it didn't want to work right so I just used the version I had.
Here ya go man. Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. Find.bat is running from: G:\apps\FINDIT2\Find It NT-2K-XP ——- System Files in System32 Directory ——- Volume in drive C is ROOT Volume Serial Number is 08F3-2F9B Directory of C:\WINNT\System32 12/24/2004 10:39 AM dllcache 0 File(s) 0 bytes 1 Dir(s) 2,790,109,184 bytes free ——- Hidden Files in System32 Directory ——- Volume in drive C is ROOT Volume Serial Number is 08F3-2F9B Directory of C:\WINNT\System32 01/08/2005 01:55 PM 124 vsconfig.xml 12/24/2004 10:39 AM dllcache 04/13/2003 10:36 PM 4,212 zllictbl.dat 03/05/2003 12:26 AM 488 logonui.exe.manifest 03/05/2003 12:26 AM 488 WindowsLogon.manifest 03/05/2003 12:26 AM 749 wuaucpl.cpl.manifest 03/05/2003 12:26 AM 749 nwc.cpl.manifest 03/05/2003 12:26 AM 749 sapi.cpl.manifest 03/05/2003 12:26 AM 749 cdplayer.exe.manifest 03/05/2003 12:26 AM 749 ncpa.cpl.manifest 03/06/2002 06:29 PM GroupPolicy 03/06/2002 06:23 PM 21,692 folder.htt 10 File(s) 30,749 bytes 2 Dir(s) 2,790,105,088 bytes free ———— Files Named "Guard" ————— Volume in drive C is ROOT Volume Serial Number is 08F3-2F9B Directory of C:\WINNT\System32 —— Temp Files in System32 Directory —— Volume in drive C is ROOT Volume Serial Number is 08F3-2F9B Directory of C:\WINNT\System32 09/23/2002 03:10 PM 544,256 SET1B.tmp 12/07/1999 06:00 AM 2,577 CONFIG.TMP 05/07/1999 01:00 AM 140,288 ~GLH0005.TMP 05/05/1999 09:22 PM 63,760 mpg2splt.ax.tmp 08/09/1998 07:07 AM 118,784 ~GLH000d.TMP 5 File(s) 869,665 bytes 0 Dir(s) 2,790,105,088 bytes free —————— User Agent —————- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wi ndows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{48F6B995-E9BE-41DA-AEA9-7F63F27EEE59}"="" ————- Keys Under Notify ————- REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCD] "Asynchronous"=dword:00000000 "DllName"="C:\\WINNT\\system32\\ir04l5dq1.dll" "Impersonate"=dword:00000000 "Logon"="WinLogon" "Logoff"="WinLogoff" "Shutdown"="WinShutdown" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 ————- Locate.com Results ————- ——– Strings.exe Qoologic Results ——– ——— Strings.exe Aspack Results ——— ————– HKLM Run Key —————- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ccApp"="\"D:\\common files\\Symantec Shared\\ccApp.exe\"" "TkBellExe"="D:\\common files\\Real\\Update_OB\\evntsvc.exe -osboot" "mswspl"="C:\\DOCUME~1\\DUANEB~1\\LOCALS~1\\Temp\\searchbarcash.exe"
WE seem to be missing each other a bit here. I will be onloine Sunday at about noon EST. If you can post a new findit log and hijackthis log then it would be great.
Sorry I didn't catch you yesterday, but here's the latest and greatest

Logfile of HijackThis v1.99.0
Scan saved at 7:48:27 PM, on 1/10/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINNT\system32\logonui.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
D:\common files\Symantec Shared\ccSetMgr.exe
D:\common files\Symantec Shared\SNDSrvc.exe
D:\common files\Symantec Shared\ccApp.exe
D:\common files\Real\Update_OB\evntsvc.exe
D:\WCAT\wcat.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
D:\common files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Documents and Settings\Duane Berger\Application Data\csoo.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
D:\common files\Symantec Shared\ccEvtMgr.exe
D:\ZoneAlarm\zapro.exe
C:\WINNT\System32\CTsvcCDA.exe
d:\cox anti-spy\app\CurtainsSysSvcNt.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\svchost.exe
D:\common files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\MsPMSPSv.exe
D:\Superadblocker\SABSVC.EXE
C:\WINNT\System32\devldr32.exe
D:\Firefox\firefox.exe
G:\apps\HijackThis.exe

O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - D:\Superadblocker\SABBHO.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AuthBHO.cBHO - {A4D90779-6CB2-4752-83C2-A2AB4D9A672D} - D:\cox anti-spy\app\AuthBHO.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - D:\Panicware\Pop-Up Stopper Pro\popuppro.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - D:\cox anti-spy\app\AuthBHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ccApp] "D:\common files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] D:\common files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [mswspl] C:\DOCUME~1\DUANEB~1\LOCALS~1\Temp\searchbarcash.exe
O4 - HKCU\..\Run: [WatchCat] D:\WCAT\wcat.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [AntiPopUp] D:\AntiPopUp\AntiPopUp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SuperAdBlocker] D:\Superadblocker\SAdBlock.exe
O4 - HKCU\..\Run: [Oeas] C:\Documents and Settings\Duane Berger\Application Data\csoo.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\OfficeXP\Office10\OSA.EXE
O4 - Global Startup: strings.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = D:\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\OfficeXP\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\AIM95\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mpg: D:\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .qcp: D:\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1099505939921
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/deleon/1…n/GoogleNav.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - D:\common files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - D:\common files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - D:\common files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: Curtains for Windows System Service - Authentium, Inc. - d:\cox anti-spy\app\CurtainsSysSvcNt.exe
O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Super Ad Blocker Service - SuperAdBlocker.com - D:\Superadblocker\SABSVC.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - D:\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - D:\common files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc - Symantec Corporation - D:\common files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: STOPzilla Local Service - Unknown - D:\STOPzilla!\szntsvc.exe (file missing)
O23 - Service: StyleXPService - Unknown - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - D:\common files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe

————————————————————————————————

Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

Find.bat is running from: G:\apps\FINDIT2\Find It NT-2K-XP

——- System Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

12/24/2004 10:39 AM dllcache
0 File(s) 0 bytes
1 Dir(s) 2,756,829,184 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

01/10/2005 01:54 PM 124 vsconfig.xml
12/24/2004 10:39 AM dllcache
04/13/2003 10:36 PM 4,212 zllictbl.dat
03/05/2003 12:26 AM 488 logonui.exe.manifest
03/05/2003 12:26 AM 488 WindowsLogon.manifest
03/05/2003 12:26 AM 749 wuaucpl.cpl.manifest
03/05/2003 12:26 AM 749 nwc.cpl.manifest
03/05/2003 12:26 AM 749 sapi.cpl.manifest
03/05/2003 12:26 AM 749 cdplayer.exe.manifest
03/05/2003 12:26 AM 749 ncpa.cpl.manifest
03/06/2002 06:29 PM GroupPolicy
03/06/2002 06:23 PM 21,692 folder.htt
10 File(s) 30,749 bytes
2 Dir(s) 2,756,825,088 bytes free

———— Files Named "Guard" —————

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32


—— Temp Files in System32 Directory ——

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

09/23/2002 03:10 PM 544,256 SET1B.tmp
12/07/1999 06:00 AM 2,577 CONFIG.TMP
05/07/1999 01:00 AM 140,288 ~GLH0005.TMP
05/05/1999 09:22 PM 63,760 mpg2splt.ax.tmp
08/09/1998 07:07 AM 118,784 ~GLH000d.TMP
5 File(s) 869,665 bytes
0 Dir(s) 2,756,825,088 bytes free

—————— User Agent —————-

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{48F6B995-E9BE-41DA-AEA9-7F63F27EEE59}"=""


————- Keys Under Notify ————-

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCD]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINNT\\system32\\ir04l5dq1.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


————- Locate.com Results ————-

——– Strings.exe Qoologic Results ——–


——— Strings.exe Aspack Results ———


————– HKLM Run Key —————-

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="\"D:\\common files\\Symantec Shared\\ccApp.exe\""
"TkBellExe"="D:\\common files\\Real\\Update_OB\\evntsvc.exe -osboot"
"mswspl"="C:\\DOCUME~1\\DUANEB~1\\LOCALS~1\\Temp\\searchbarcash.exe"



Click here to download ServiceFilter, a little script by rand1038 that reveals potential unauthorised running services in your system. Download, unzip and double-click ServiceFilter.vbs (you may need to enable your antivirus program to run the file). This script will create a text file named Post_This.txt in the same folder as the script itself has been saved - copy and paste the contents of Post_This.txt in your next reply here.

Then a new findit log also please.
Here's the logs you've requested: The script did not recognize the services listed below. This does not mean that they are a problem. To copy the entire contents of this document for posting: At the top of this window click "Edit" then "Select All" Next click "Edit" again then "Copy" Now right click in the forum post box then click "Paste" ######################################## ServiceFilter 1.1 by rand1038 Microsoft Windows XP Professional Version: 5.1.2600 Jan 12, 2005 8:19:24 PM ===> Begin Service Listing <=== Unknown Service #1 Service Name: ccEvtMgr Display Name: Symantec Event Manager Start Mode: Auto Start Name: LocalSystem Description: Symantec Event … Service Type: Own Process Path: d:\common files\symantec shared\ccevtmgr.exe State: Running Process ID: 972 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Unknown Service #2 Service Name: ccPwdSvc Display Name: Symantec Password Validation Start Mode: Manual Start Name: LocalSystem Description: Symantec Password Validation … Service Type: Own Process Path: "d:\common files\symantec shared\ccpwdsvc.exe" State: Stopped Process ID: 0 Started: False Exit Code: 1077 Accept Pause: False Accept Stop: False Unknown Service # 3 Service Name: CurtainsSysSvc Display Name: Curtains for Windows System Service Start Mode: Auto Start Name: LocalSystem Description: … Service Type: Own Process Path: d:\cox anti-spy\app\curtainssyssvcnt.exe State: Running Process ID: 1736 Started: True Exit Code: 0 Accept Pause: False Accept Stop: False Unknown Service #4 Service Name: GhostStartService Display Name: GhostStartService Start Mode: Auto Start Name: LocalSystem Description: Background service to allow Norton Ghost to perform priviledged … Service Type: Own Process Path: d:\norton~1\norton~2\ghosts~2.exe State: Running Process ID: 1788 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Unknown Service #5 Service Name: navapsvc Display Name: Norton AntiVirus Auto Protect Service Start Mode: Auto Start Name: LocalSystem Description: Handles Norton AntiVirus Auto-Protect … Service Type: Own Process Path: "d:\norton systemworks\norton antivirus\navapsvc.exe" State: Running Process ID: 1820 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Unknown Service #6 Service Name: NProtectService Display Name: Norton Unerase Protection Start Mode: Auto Start Name: LocalSystem Description: … Service Type: Own Process Path: "d:\norton systemworks\norton utilities\nprotect.exe" State: Running Process ID: 1892 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Unknown Service # 7 Service Name: SABSVC Display Name: Super Ad Blocker Service Start Mode: Manual Start Name: LocalSystem Description: Super Ad Blocker Service - This service must be running for spyware/adware … Service Type: Own Process Path: d:\superadblocker\sabsvc.exe State: Stopped Process ID: 0 Started: False Exit Code: 1077 Accept Pause: False Accept Stop: False Unknown Service #8 Service Name: SBService Display Name: ScriptBlocking Service Start Mode: Auto Start Name: LocalSystem Description: … Service Type: Own Process Path: d:\common~1\symant~1\script~1\sbserv.exe State: Stopped Process ID: 0 Started: False Exit Code: 0 Accept Pause: False Accept Stop: False Unknown Service #9 Service Name: SNDSrvc Display Name: Symantec Network Drivers Service Start Mode: Auto Start Name: LocalSystem Description: Symantec Network Drivers … Service Type: Own Process Path: d:\common files\symantec shared\sndsrvc.exe State: Running Process ID: 996 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Unknown Service # 10 Service Name: STOPzilla Local Service Display Name: STOPzilla Local Service Start Mode: Auto Start Name: LocalSystem Description: … Service Type: Own Process Path: d:\stopzilla!\szntsvc.exe /service "stopzilla local service" State: Stopped Process ID: 0 Started: False Exit Code: 0 Accept Pause: False Accept Stop: False Unknown Service #11 Service Name: SwPrv Display Name: MS Software Shadow Copy Provider Start Mode: Manual Start Name: LocalSystem Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this … Service Type: Own Process Path: c:\winnt\system32\dllhost.exe /processid:{3ff7482a-d6f1-49d4-a9ad-7bad0651777e} State: Stopped Process ID: 0 Started: False Exit Code: 1077 Accept Pause: False Accept Stop: False Unknown Service # 12 Service Name: UtilMan Display Name: Utility Manager Start Mode: Manual Start Name: LocalSystem Description: Starts and configures accessibility tools from one … Service Type: Own Process Path: c:\winnt\system32\utilman.exe State: Stopped Process ID: 0 Started: False Exit Code: 1077 Accept Pause: False Accept Stop: False —> End Service Listing <— There are 92 Win32 services on this machine. 12 were unrecognized. Script Execution Time: 8.578125 seconds. ————————————————————————————————– Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. Find.bat is running from: G:\apps\FINDIT2\Find It NT-2K-XP ——- System Files in System32 Directory ——- Volume in drive C is ROOT Volume Serial Number is 08F3-2F9B Directory of C:\WINNT\System32 01/12/2005 07:28 PM dllcache 01/11/2005 06:00 PM 32 {41EBD602-5F8E-488A-89C7-1950C824730A}.dat 01/11/2005 05:42 PM 32 {952E6322-2186-476E-BF6C-4DE176337D26}.dat 01/11/2005 05:40 PM 32 {EE622A92-EDB7-4ED8-8262-F60DC5989714}.dat 01/11/2005 05:40 PM 32 {297DD1DF-C034-423D-B35F-EA4B5587B5BA}.dat 01/11/2005 05:40 PM 32 {1ED60785-7758-4C43-97E0-576BF84B12B0}.dat 01/11/2005 05:37 PM 32 {A3CB91D1-220F-4F6E-90D7-F546D3771778}.dat 6 File(s) 192 bytes 1 Dir(s) 5,790,416,896 bytes free ——- Hidden Files in System32 Directory ——- Volume in drive C is ROOT Volume Serial Number is 08F3-2F9B Directory of C:\WINNT\System32 01/12/2005 07:28 PM dllcache 01/12/2005 07:28 PM 124 vsconfig.xml 01/11/2005 06:00 PM 32 {41EBD602-5F8E-488A-89C7-1950C824730A}.dat 01/11/2005 05:42 PM 32 {952E6322-2186-476E-BF6C-4DE176337D26}.dat 01/11/2005 05:40 PM 32 {EE622A92-EDB7-4ED8-8262-F60DC5989714}.dat 01/11/2005 05:40 PM 32 {297DD1DF-C034-423D-B35F-EA4B5587B5BA}.dat 01/11/2005 05:40 PM 32 {1ED60785-7758-4C43-97E0-576BF84B12B0}.dat 01/11/2005 05:37 PM 32 {A3CB91D1-220F-4F6E-90D7-F546D3771778}.dat 04/13/2003 10:36 PM 4,212 zllictbl.dat 03/05/2003 12:26 AM 488 WindowsLogon.manifest 03/05/2003 12:26 AM 488 logonui.exe.manifest 03/05/2003 12:26 AM 749 sapi.cpl.manifest 03/05/2003 12:26 AM 749 nwc.cpl.manifest 03/05/2003 12:26 AM 749 cdplayer.exe.manifest 03/05/2003 12:26 AM 749 wuaucpl.cpl.manifest 03/05/2003 12:26 AM 749 ncpa.cpl.manifest 03/06/2002 06:29 PM GroupPolicy 03/06/2002 06:23 PM 21,692 folder.htt 16 File(s) 30,941 bytes 2 Dir(s) 5,790,412,800 bytes free ———— Files Named "Guard" ————— Volume in drive C is ROOT Volume Serial Number is 08F3-2F9B Directory of C:\WINNT\System32 —— Temp Files in System32 Directory —— Volume in drive C is ROOT Volume Serial Number is 08F3-2F9B Directory of C:\WINNT\System32 09/23/2002 03:10 PM 544,256 SET1B.tmp 12/07/1999 06:00 AM 2,577 CONFIG.TMP 05/07/1999 01:00 AM 140,288 ~GLH0005.TMP 05/05/1999 09:22 PM 63,760 mpg2splt.ax.tmp 08/09/1998 07:07 AM 118,784 ~GLH000d.TMP 5 File(s) 869,665 bytes 0 Dir(s) 5,790,412,800 bytes free —————— User Agent —————- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{48F6B995-E9BE-41DA-AEA9-7F63F27EEE59}"="" ————- Keys Under Notify ————- REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCD] "Asynchronous"=dword:00000000 "DllName"="C:\\WINNT\\system32\\ir04l5dq1.dll" "Impersonate"=dword:00000000 "Logon"="WinLogon" "Logoff"="WinLogoff" "Shutdown"="WinShutdown" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 ————- Locate.com Results ————- ——– Strings.exe Qoologic Results ——– ——— Strings.exe Aspack Results ——— ————– HKLM Run Key —————- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TkBellExe"="D:\\common files\\Real\\Update_OB\\evntsvc.exe -osboot" "mswspl"="C:\\DOCUME~1\\DUANEB~1\\LOCALS~1\\Temp\\searchbarcash.exe" "ccApp"="D:\\common files\\Symantec Shared\\ccApp.exe" "GhostStartTrayApp"="D:\\Norton SystemWorks\\Norton Ghost\\GhostStartTrayApp.exe" 
Here's the dll log: * DLLCompare Log version(1.0.0.127) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ O^E says: "There were no files found :)" ________________________________________________ 1,371 items found: 1,371 files, 0 directories. Total of file sizes: 259,737,628 bytes 247.70 M Administrator Account = True ——————–End log———————
Here's the newest logs:

Logfile of HijackThis v1.99.0
Scan saved at 9:48:10 PM, on 1/17/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINNT\system32\spoolsv.exe
D:\common files\Symantec Shared\ccEvtMgr.exe
D:\common files\Symantec Shared\SNDSrvc.exe
C:\WINNT\Explorer.EXE
D:\common files\Real\Update_OB\evntsvc.exe
D:\common files\Symantec Shared\ccApp.exe
D:\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
D:\WCAT\wcat.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\Duane Berger\Application Data\csoo.exe
C:\Program Files\SpyKiller\spykiller.exe
C:\Program Files\BestPopUpKiller\BestPopupKiller.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
D:\ZoneAlarm\zapro.exe
C:\WINNT\System32\CTsvcCDA.exe
d:\cox anti-spy\app\CurtainsSysSvcNt.exe
D:\NORTON~1\NORTON~2\GHOSTS~2.EXE
D:\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
D:\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\System32\devldr32.exe
C:\Program Files\Messenger\msmsgs.exe
D:\AIM95\aim.exe
D:\Firefox\firefox.exe
G:\apps\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AuthBHO.cBHO - {A4D90779-6CB2-4752-83C2-A2AB4D9A672D} - D:\cox anti-spy\app\AuthBHO.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {D714A94F-123A-45CC-8F03-040BCAF82AD6} - C:\WINNT\Downloaded Program Files\SbCIe02a.dll
O3 - Toolbar: (no name) - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - D:\cox anti-spy\app\AuthBHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TkBellExe] D:\common files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [ccApp] D:\common files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] D:\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKCU\..\Run: [WatchCat] D:\WCAT\wcat.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [AntiPopUp] D:\AntiPopUp\AntiPopUp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SuperAdBlocker] D:\Superadblocker\SAdBlock.exe
O4 - HKCU\..\Run: [Oeas] C:\Documents and Settings\Duane Berger\Application Data\csoo.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\OfficeXP\Office10\OSA.EXE
O4 - Global Startup: strings.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = D:\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\OfficeXP\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINNT\Downloaded Program Files\SbCIe02a.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\AIM95\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mpg: D:\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .qcp: D:\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1099505939921
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/deleon/1…n/GoogleNav.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - D:\common files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - D:\common files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: Curtains for Windows System Service - Authentium, Inc. - d:\cox anti-spy\app\CurtainsSysSvcNt.exe
O23 - Service: GhostStartService - Symantec Corporation - D:\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - D:\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - D:\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Super Ad Blocker Service - Unknown - D:\Superadblocker\SABSVC.EXE (file missing)
O23 - Service: ScriptBlocking Service - Symantec Corporation - D:\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - D:\common files\Symantec Shared\SNDSrvc.exe
O23 - Service: STOPzilla Local Service - Unknown - D:\STOPzilla!\szntsvc.exe (file missing)
O23 - Service: StyleXPService - Unknown - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe

————————————————————————————————–\
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

Find.bat is running from: G:\apps\FINDIT2\Find It NT-2K-XP

——- System Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

01/17/2005 01:45 PM dllcache
01/11/2005 06:00 PM 32 {41EBD602-5F8E-488A-89C7-1950C824730A}.dat
01/11/2005 05:42 PM 32 {952E6322-2186-476E-BF6C-4DE176337D26}.dat
01/11/2005 05:40 PM 32 {EE622A92-EDB7-4ED8-8262-F60DC5989714}.dat
01/11/2005 05:40 PM 32 {297DD1DF-C034-423D-B35F-EA4B5587B5BA}.dat
01/11/2005 05:40 PM 32 {1ED60785-7758-4C43-97E0-576BF84B12B0}.dat
01/11/2005 05:37 PM 32 {A3CB91D1-220F-4F6E-90D7-F546D3771778}.dat
6 File(s) 192 bytes
1 Dir(s) 5,698,301,952 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

01/17/2005 01:45 PM dllcache
01/17/2005 01:09 PM 124 vsconfig.xml
01/11/2005 06:00 PM 32 {41EBD602-5F8E-488A-89C7-1950C824730A}.dat
01/11/2005 05:42 PM 32 {952E6322-2186-476E-BF6C-4DE176337D26}.dat
01/11/2005 05:40 PM 32 {EE622A92-EDB7-4ED8-8262-F60DC5989714}.dat
01/11/2005 05:40 PM 32 {297DD1DF-C034-423D-B35F-EA4B5587B5BA}.dat
01/11/2005 05:40 PM 32 {1ED60785-7758-4C43-97E0-576BF84B12B0}.dat
01/11/2005 05:37 PM 32 {A3CB91D1-220F-4F6E-90D7-F546D3771778}.dat
04/13/2003 10:36 PM 4,212 zllictbl.dat
03/05/2003 12:26 AM 488 WindowsLogon.manifest
03/05/2003 12:26 AM 488 logonui.exe.manifest
03/05/2003 12:26 AM 749 sapi.cpl.manifest
03/05/2003 12:26 AM 749 nwc.cpl.manifest
03/05/2003 12:26 AM 749 cdplayer.exe.manifest
03/05/2003 12:26 AM 749 wuaucpl.cpl.manifest
03/05/2003 12:26 AM 749 ncpa.cpl.manifest
03/06/2002 06:29 PM GroupPolicy
03/06/2002 06:23 PM 21,692 folder.htt
16 File(s) 30,941 bytes
2 Dir(s) 5,698,297,856 bytes free

———— Files Named "Guard" —————

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32


—— Temp Files in System32 Directory ——

Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B

Directory of C:\WINNT\System32

09/23/2002 03:10 PM 544,256 SET1B.tmp
12/07/1999 06:00 AM 2,577 CONFIG.TMP
05/07/1999 01:00 AM 140,288 ~GLH0005.TMP
05/05/1999 09:22 PM 63,760 mpg2splt.ax.tmp
08/09/1998 07:07 AM 118,784 ~GLH000d.TMP
5 File(s) 869,665 bytes
0 Dir(s) 5,698,297,856 bytes free

—————— User Agent —————-

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{48F6B995-E9BE-41DA-AEA9-7F63F27EEE59}"=""


————- Keys Under Notify ————-

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCD]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINNT\\system32\\ir04l5dq1.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


————- Locate.com Results ————-

C:\WINNT\SYSTEM32\
vsconfig.xml Mon Jan 17 2005 1:09:24p A..H. 124 0.12 K
{1ed60~1.dat Tue Jan 11 2005 5:40:56p A.SH. 32 0.03 K
{297dd~1.dat Tue Jan 11 2005 5:40:56p A.SH. 32 0.03 K
{41ebd~1.dat Tue Jan 11 2005 6:00:42p A.SH. 32 0.03 K
{952e6~1.dat Tue Jan 11 2005 5:42:48p A.SH. 32 0.03 K
{a3cb9~1.dat Tue Jan 11 2005 5:37:42p A.SH. 32 0.03 K
{ee622~1.dat Tue Jan 11 2005 5:40:56p A.SH. 32 0.03 K

7 items found: 7 files, 0 directories.
Total of file sizes: 316 bytes 0.31 K

——– Strings.exe Qoologic Results ——–


——— Strings.exe Aspack Results ———


————– HKLM Run Key —————-

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="D:\\common files\\Real\\Update_OB\\evntsvc.exe -osboot"
"ccApp"="D:\\common files\\Symantec Shared\\ccApp.exe"
"GhostStartTrayApp"="D:\\Norton SystemWorks\\Norton Ghost\\GhostStartTrayApp.exe"
Almost done. Please disable teatimer instructions here >>>> http://russelltexas.com/malware/teatimer.htm

Then boot to safe mode scan with hijackthis and put a check beside these lines

O3 - Toolbar: (no name) - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - (no file)

O4 - HKCU\..\Run: [Oeas] C:\Documents and Settings\Duane Berger\Application Data\csoo.exe

O4 - Global Startup: strings.exe

Then while still in safe mode delete this file if present

C:\Documents and Settings\Duane Berger\Application Data\csoo.exe

Then reboot to normal mode, how is it running after the reboot?

New log please.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI