Question

Can't get rid of this Trojan, acts like a VX2

Asked by: JonSh

I've spent over 10 hours trying to defeat this trojan.  I can't.  I'm not even going to detail what I've tried - cause it hasn't worked and I'm tired :)

So, I've saved the Hijackthis log file analysis at http://www.hijackthis.de/logfiles/0fe8b55fe92937bafa019fec6a6d132c.html

And here is the output from VX2 Finder:
Log for VX2.BetterInternet File Finder (msg126)

Files Found---
 
Additional Files---
 
Keys Under Notify---
crypt32chain
cryptnet
cscdll
Extensions
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
wlballoon


Guardian Key--- is called:

User Agent String---
{B0A2FCFA-BC60-4BF9-A1EA-700D852A042D}
=========End Of Log================

Okay, all you experts....help! :)

Jon

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2004-12-02 at 11:22:42ID21228139
Tags

trojan

Topic

Networking Security Vulnerabilities

Participating Experts
5
Points
500
Comments
39

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. trojans
    Tell me about trojans and where can I find or download good programs to remove them.
  2. Trojans
    Can A trojan infect the MBR? If so will repartitioning get rid of it?
  3. trojan horse
    hello how can I remove trojan horse in C;\windows\system 32\winlogon.exe. thank you
  4. Remove trojan
    Anyone know how to get rid of trojan-spy.htm from computer running Windows XP?

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: SheharyaarSaahilPosted on 2004-12-02 at 11:32:41ID: 12729391

Hello JonSh =)

There is an addon of Adaware called Vx2 Cleaner.... have you installed and run it >> http://www.lavasoftusa.com/software/addons/vx2cleaner.shtml
Is System Restore turned off ?? Have you run all the tools in safemode ??
Have you run this tool yet in safemode >> http://www.downloads.subratam.org/VX2Finder.exe ??

In your log file, these entries are required to be fixed,

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\system32\kapsar.exe
O4 - Global Startup: lgkvgt.exe

Have you fixed them and deleted those kapsar.exe and lgkvgt.exe files manually from the system ??

 

by: JonShPosted on 2004-12-02 at 12:05:13ID: 12729715

SheharyaarSaahil,

Yes, I have run the VX2 Add-on for Ad-Aware.  It finds nothing.
System Restore is Turned Off
Um, I don't think I have run all the tools in safe mode.
I have done the fixes many times, and I thought I had deleted those files but perhaps not.

What you are sayign is making sense to me, but I've missed this boat a lot of times.  Would you write this up as a procedure for me to follow?  Also, should I be deleting the 2 htm files ast well?





 

by: SheharyaarSaahilPosted on 2004-12-02 at 12:27:04ID: 12729933

ok let me try..... here goes...... :)

First use msconfig to untick unwanted progrmas as described here >> http://netsquirrel.com/msconfig/
Then make sure that you have these latest edition of tools and install and update them,

AdAware ==> http://www.spychecker.com/program/adaware.html
SpyBot  ==> http://www.spychecker.com/program/spybot.html
CoolWebShredder ==> http://www.softpedia.com/public/cat/10/17/10-17-150.shtml
About:Buster ==> http://www.snapfiles.com/get/aboutbuster.html
Vx2 Removal Tool ==> http://www.downloads.subratam.org/VX2Finder.exe
Stinger ==> http://vil.nai.com/vil/stinger

Then Disable System Restore >> WinME\XP >> http://www.pchell.com/virus/systemrestore.shtml
Then Disable the Messenger Service if its running >> http://www.itc.virginia.edu/desktop/docs/messagepopup/
Then run hijackthis scan, close all the explorer windows, disconnect from the intenret and fix the above lines which i mentioned, now dont do anything else and restart your system and boot it in safemode now!

1. Login as Administrator
2. Run your av scan and stinger and delete anything they find
3. Run the Spyware Removal tools one by one and delete everything they detect
4. Then goto My Computer>Tools>Folder Options>View and turn on the feature of Show Hidden Files
5. Goto C:\Documents and Settings\your username\Local Settings\Temp and delete all files present here
6. Goto C:\Documents and Settings\your username\Local Settings\Temporary Internet Files, and delete the folder of ContentIE
7. Goto C:\Documents and Settings\your username\Cookies, and delete all cookies present here
(ofcourse im assuming that u have already saved all the login passwords for ur websites :)
8. Goto C:\Windows\Temp and delete all files present here
9. Dont delete those html files, but delete the two exe ones, i.e kapsar.exe and lgkvgt.exe
10. Reboot back in Normal Mode and check if problems are gone or not

Post Back and Good Luck :)

 

by: mwnnjPosted on 2004-12-02 at 23:42:29ID: 12733681

Hi JohnSH,
regarding to the very suggestions of shehar,
install Pest Patrol from:
http://www.pestpatrol.com/Products/PestPatrolHE/Single_User_Evaluation.asp
make this settings:
Pest patrol > options > Where to Search :
 check : all files ;
 check : scanning method : thorough ,
 check : scan shell tree options > show hidden and show files .
Pest patrol > options > What to search for - and then check all the items-all!
Pest patrol > options > What to exclude : wtere must be only the recycle folder and system volume information nothing mere!
Pest patrol > options > Automatic scans !!!
 check : scan on boot --> your boot partition
 check : PPMemCheck Memory Scan > Invoke on boot
 check : CookiePatrol > Invoke on boot
 check : PPcontrol > Invoke on boot
 check : KeyPatrol > Invoke on boot
you can check also the right click option for folders too...
check in the main menue to scan all hard drives .... update the pest patrol.
install winpatrtol from:
http://www.winpatrol.com/winpatrol.html

Have you done everything ,restart your PC as normal and delete everything that the two programs detect....
ONLY AS A SUGGESTION!!! :
I would recommend that you install also Antivir Personal edition as antiviral program with the following settings:
on both scanner and virus watcher:
at the search section/tab:
-for boot sectors :check the two options
-for the data search :check all files
-for priority check :high
at the search subtab - archves:select all archive types
at the repair section:
-check :delete with prompt
at the unwanted program tab:
-check all
at the heuristic tab:
-select:enable mcro virus heuristic
-select:win32 file heuristic enabled and then detction level high
at the drag&drop tab:
-select:scan subfolders
at the miscellaneous tab:
-select: interruption allowed
-check the option for load the guard at system start
-check the option lload the guard via the control program
-enable:check for old virus definition files(7 days)
go to options and make: save setting...
this settings you must make to the main program and the virus guard too,,,
to start the virus guard menue -double click on the Antivir icon in the system tray=>options=>configure,,,
but you must first disable your recent virus scanner to install the antivir personal if you wish-i am very happy with this program....
hope this additional info could help!
CHEERS

 

by: blue_zeePosted on 2004-12-03 at 00:23:10ID: 12733828


Worth a try:

http://downloads.subratam.org/VX2Finder(126).exe
The latest Look2Me Fix

 

by: blue_zeePosted on 2004-12-03 at 00:23:59ID: 12733834


New Version for L2M is out and it is autoupdating to Msg126. If the user has "old L2M" VX2Finder will do the job, but it is better we run this tool first now, as because we know L2M autoupdates.

Zee

 

by: JonShPosted on 2004-12-03 at 00:46:25ID: 12733937

Interim update:....I followed SheharyaarSahill's protocol, it almost worked....but I can't get rid of this kaspar thingie.  I searched the internet for "kaspar"+"trojan" and a lot came up, but only in eastern european languages.  

Anyone ever seen this kaspar.exe?

 

by: SheharyaarSaahilPosted on 2004-12-03 at 08:42:04ID: 12737604

why you cannot et rid of it, whne you try to delete it from safemode, what error do you get ??
or does it come back after deleting, if yes then did you remove its entries from regedit also ??

 

by: JonShPosted on 2004-12-03 at 10:16:29ID: 12738656

it hides in safemode.  i think it is changing filenames around.  I can always find either kaspar.exe or lgkvgt.exe or lsp.dll, but never all 3.  I've even tried it in safemode with command line so the explorer shell doesn't get loaded (I think).

This variant is very very tricky, the only VX2 that ever sees it is ad-aware.  The only good thing about this so far is that I'm pulling my hair out which is getting rid of my bald spot......

oh, yeah, I've removed the entries from regedit, and from hijackthis, and from msconfig........arrrgh!  many times now....

 

by: SheharyaarSaahilPosted on 2004-12-03 at 10:21:52ID: 12738711

Jon can you see any "ShopatHomeSelect Agent" in your Add Remove Programs....... or any other suspisious software ??

 

by: JonShPosted on 2004-12-03 at 10:33:56ID: 12738819

Yes, and I got rid of those a while back.  But I just saw something interesting.  I got the machine to a point that tested on hijack as a "clean" machine.  Then, I plugged the LAN cable back in and all of a sudden I get this popup from RUNDLL as follows:

An exception occurred while trying to run ""C:\WINDOWS\system32\rzgsvc.dll",UMonitor"

now I get this when I run Hijackthis:

http://www.hijackthis.de/logfiles/ea32713abf6d41f499e80b3591472168.html

so whatever this thing is, it is network aware......

 

by: SheharyaarSaahilPosted on 2004-12-03 at 11:00:18ID: 12739046

Download Killbox from here >> http://www.downloads.subratam.org/KillBox.zip
using it, try to tell it to remove three files,

C:\WINDOWS\system32\rzgsvc.dll
C:\WINDOWS\system32\kapsar.exe
lgkvgt.exe

now restart and check if still these files are reappearing ??

 

by: mwnnjPosted on 2004-12-03 at 13:20:54ID: 12740352

Hi Jon,
i read the postings and as a suggestion i'll recommend to you that you install theese two programs :
PestPatrol and Winpatrol(as above)
you can remove all found entries but if there is a program module hidden inside the explorer.exe for an instance,you can't see this malware even with the best registry program,,,
so why i recomment theese scanners to ,cuz there are startup scanners and they are active during your start up,,,if you can disable the starting up module,among the startup of your system ,there could be a way that you stop the results from it:kaspar.exe and this silly .dll,,,
just try them and post your reply!
check out your antivirus program:make the highest protection,update it and make scan...
Good luck!

 

by: JonShPosted on 2004-12-03 at 13:32:32ID: 12740472

the dll name appears to be random, changes after every boot....I let it sit connected to the internet for 90 minutes, undisturbed, the damm thing filled up the computer with another 15-20 pieces of ad-ware...Elite Toolbar, VBouncer, etceteras...this is some serious sh*t happening to this machine.....

....I'm this close to formatting the drive and starting clean.......

....Going to try Pest Patrol next, I guess,  in maximum modes.......

 

by: SheharyaarSaahilPosted on 2004-12-03 at 13:39:30ID: 12740547

its not your fault..... its the new variant of Vx2 which is spreading across.... many people are having it with no definate solution yet...... =\

 

by: mwnnjPosted on 2004-12-03 at 14:00:51ID: 12740751

Hi Jon ,
don't give up!Formatting is the dullest thing and the virus wins,,,
I have written to you for Pest patrol adjustement,please make the settings as above,
for winpatrol you don't need any furthur setting except,,,
why don't you clean your winsock settings and then lock the host file with winn patrol or spybot ,this could also´help(the trojan connects to a speciffic site isn't it...)
Do you have a firewall if not instal the new Kerio Personal or ZoneAlarm - this could block the internet-connectivity of the trojan ...
if you want make also screen shots of what you found,delete and rapair(Printscreen[Gadwin]is a good one);ONLY if you wish!


Good luck!

 

by: JonShPosted on 2004-12-03 at 15:12:18ID: 12741295

Okay, I'm currently Pest and Win patrolling, let's see if this stuff can get everything at once :)...once I've done a full sweep, I'm going to reboot and see what it finds on boot-up....

 

by: blue_zeePosted on 2004-12-03 at 15:39:01ID: 12741400

As posted above:

http://downloads.subratam.org/VX2Finder(126).exe

Don't click the link because the (...) break it.

Copy it and paste to your browser address bar.

Zee

 

by: JonShPosted on 2004-12-03 at 19:07:23ID: 12742070

Thankx blue_zee....I've been using it since the beginning of this issue, it finds no files.  Sorry I didn't mention that earlier.

 

by: JonShPosted on 2004-12-04 at 09:43:57ID: 12744807

Update:  Using Pest Patrol and Winpatrol, still not much help.  This Trojan is a bad-a$$; it is even blocking startup scans.  I've got a massively multiadware headache at thispoint.....

 

by: blue_zeePosted on 2004-12-04 at 10:04:41ID: 12744867


Have a go with the PeperFix:

http://downloads.subratam.org/PeperFix.exe

 

by: blue_zeePosted on 2004-12-04 at 10:06:57ID: 12744880


And considering the trouble you're facing, why not format and reinstall from scratch?

I know it will be a pain gettimg all those Windows Updates, etc. etc., but you will end up with a clean and lean machine.

Zee

 

by: SheharyaarSaahilPosted on 2004-12-04 at 10:06:58ID: 12744881

the log doesn't show a peper trojan infection,,, it clearly shows a Vx2 infection..... and its a new variant that is spreading :-\

 

by: SheharyaarSaahilPosted on 2004-12-04 at 10:09:30ID: 12744892

JonSh..... just confirm one thing...... are these processes running in safemode also ??

 

by: blue_zeePosted on 2004-12-04 at 10:10:12ID: 12744894


The link to the log shows an empty page...

And throw it all available tools just to see if any work (even a little).

Zee

 

by: SheharyaarSaahilPosted on 2004-12-04 at 10:11:24ID: 12744897

yeah its now a blank page..... i looked at it many times before...... there was not a single sign of peper trojan :)

 

by: JonShPosted on 2004-12-04 at 12:13:05ID: 12745263

Sheharyaar, yeah, they run in safe-mode too.  Whoever crafted this crafted a beauty.  Blue_zee, I'm on the way to formatting the box, we just took a software inventory......sigh :)

 

by: SheharyaarSaahilPosted on 2004-12-04 at 12:32:38ID: 12745316

hmmm can i ask a last question if you dont mind =\
when you goto Start>Run>regedit and navigate to the following key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows

in the right pane you will find an AppInit_DLLs entry, when you right click it and click Modify, what is the value data written here ??

 

by: JonShPosted on 2004-12-04 at 15:51:36ID: 12746059

Okay, the damm adware wins.  I just formatted the drive and am now building a better mousetrap.  Any suggestions as to how I might divide up the points?

 

by: blue_zeePosted on 2004-12-04 at 16:26:17ID: 12746144


No problems here if you want to ask for a refund at Community Support:

http://www.experts-exchange.com/Community_Support/

I honestly don't believe that suggesting a format and reinstall could be an accepted answer to this question.

Cheers and good luck!

Zee

 

by: JonShPosted on 2004-12-04 at 23:07:39ID: 12747104

Well, I give us all a "C", including myself....we failed, and the patient died :)  So, I split it up among answers that streched my mind technically, showed me something I hadn't considered,  or answers that made me a little better about failing :)

Much thanx, folks!  Jon

 

by: SheharyaarSaahilPosted on 2004-12-05 at 10:03:10ID: 12749022

hmmmmm new infections disappoint us like this... but ONLY when they are new.... im sure that this variant also gonna have some removal tool out there..... just give it some days.... :)

 

by: Joel_SiskoPosted on 2004-12-06 at 16:56:04ID: 12759948

JonSh,

I feel your pain, I am still dealing with same thing. Its a nasty one to say the least, and to address blue_zee yes format c: sometimes just provides a sense of relief. I have spent since Thanksgiving trying to resolve from what it seems the same issues. I have stayed with it because it entered thru a door (port 135) that was opened by one of my vendors applications. Needless to say the potential for my clients to get this is very high. So I figured going thru the pain today will pay off when my clients get this.

Just  few things that happened to me when I was hit:

Google toolbar and popup blocker disabled
Reycycle bin icon always showed full, oped folder nothing, right click asked to delete 9 files?
Certian keys on keyboard were remapped
Host file, unlocked
NAV disabled
Spybot disabled certian things, but not completely, enough not to casue attention
Right click possible culprit, it would disappear
Process running in safe mode
Randomly create a dll upon winlogin and logout, also dll name is random containing numbers a letters
provide new key in Notify of Winlogin which appeared to look like a normal name such as Restart, Startup, Stillimage with newly created dll registered already
host of pop-ups even with opera and firefox using their stuff
cpu cycles just kill system after a while
turned restore feature backon disks
populate temp directories with links
turned feature on folders to hide hidden files

From what I can tell is that two files seem to be at the root at least for me, pkpbpp.exe and klkikk.exe

My next step is to use a linux LiveCD distro to boot up in RAM and delete all files on HD past a certian date.

 

by: blue_zeePosted on 2004-12-07 at 00:19:01ID: 12761618


Ouch!!

 

by: Joel_SiskoPosted on 2004-12-07 at 00:41:54ID: 12761750

Thing that actually scares me is that what is next? A friend and I have talked about the entire collapse of the Internet infrastructure in the next 3 years (running bet we started 5 years ago). This was based more upon the downsizing and outsourcing of IT, aslo companies stretching systems original intent well beyond its means. I am starting to rethink that "what is next" a little ole piece of software written in C+ will bring the Internet down even sooner.


 

 

by: rossfingalPosted on 2004-12-07 at 12:27:07ID: 12767935

Hi!

This Vx2 variant is being worked on - mixed success.
2 or more randomly named dll's - that change on reboot.
A hidden file in system32 named guard.tmp
Causes things deleted to be immediately deleted and not sent
to the recycle bin.
Messes with a user's ability to print anything.
Some success using DLLCompare and PocketKillbox to find all the dll's
Trys to connect to {www.a-d-w-a-r-e.com} or something simliar
One user had success dealing with it using Recovery Console - link here:
{http://computercops.biz/postp381429.html#381429}
Don't know yet if this fix works all the time, though.
{Zupe} over at SWI has written a batch file to try to help find the bad dll's -
http://www.dslreports.com/r0/download/725998~d44d0289add36c04c2a05ef54e5a84f2/FindIt.zip
Check the warning about it also showing valid files!!
Here's a link to a post where he's using it -
http://www.dslreports.com/forum/remark,12023321~mode=flat
Sheeesh!!! - what will they come up with next!?!

Regards

RF

 

by: Joel_SiskoPosted on 2004-12-07 at 14:07:03ID: 12768822

Looks like what I have, here is the link to my ongoing post here at EE:

http://www.experts-exchange.com/Applications/Viruses/Q_21226919.html

I believe that the dll's are created at each login and logout and shutdown, this is how it even happens during safe mode since I have been logging in. This is supported by the fact I have two new dlls each day at least on system. The key under HKLM\Software\Microsoft\WINNT\Currentversion\Winlogin\notify shows values for WinLogin, WinLogout, Shutdown.

Also I just noticed that all the other keys that are normally in the Notify have neen delted (not by me) so this Vx2 variant is self mutating and smart enough to delte keys over time. Aslo there are several more new .exe running I have not seen before in the process list.

Today when I booted my software from various companies were no longer registered including Spysubtract, TrendMicro and XP Pro!!!!!

I have a copy of Knoppix, which I have been informed can write and read to NTFS without a hitch. My plan later is to boot Knoppix off CD and have a good old time delting.

The main key with this variant is to get as quick as possible, rebooting and log on/off the sytem the least amount of times possible. The best would be a bootable floppy/CD with a batch program to delete suspect files based on time, size and naming convention.


I hope this provides some insight to anyone who may have this on their system. I will report back if using Knoppix approach works or does not.

Joel_Sisko

 

by: mwnnjPosted on 2004-12-07 at 17:15:28ID: 12769857

Hi JonSh,thanks for the given points and damn sorry that we couldn't solve the problem...
Good luck with the new system,,,a good firewall and antiviral system will prevent you from having theese troubles again,so if you wish keep on patrolling :) with the right settings on each program!
All the best!

Joel_Sisko,

it's true that knoppix has the experimental captive system:
http://www.jankratochvil.net/project/captive/ , which gives the chance to be written on NTFS5 system,the win Pro partitions,but it's still experimental, so pay attention!
I can give you a suggestion ,that you use the ERD Commander,it's very expensive ,but does a good work -in case of overwriting or deleting files from all kind of ntfs-partitions...
CHEERS

 

by: rossfingalPosted on 2004-12-07 at 20:25:42ID: 12770597

One other thing - fixes have to be done offline - no Internet connection
And, when you attempt to perform a "fix" -
no reboot (unless you're at the point with "KillBox")
What an agravating thing this is!
ARRGGHHHH!!!

As allways...

RF

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...