nvaux32.dll, user32.dll deleted, Avast did but didn't exactly save me.

Hello.
As I was Cruisin the web, avast cought a virus/malware, “nvaux32.dll”,
So I sent it to the chest, then a second later it caught “kemnd”, both from the system32 folder, I hope I don’t need them.
I searched the registry for those and if I found anything I deleted it.
I think I did, can’t remember now ):=
So I immediately scanned with avast, then Windows Defender, then MalwareBytes, then liveonecare, then trendmicro free online.
nothing found.
So a day and a half goes by no reboot, then just sitting there on my desktop I luckily (I guess), seen a file pop on the desktop “a.exe” I scanned it avast said it was a virus/malware or something so I moved it to the chest, immediately another file “trz8d.tmp” popped on the desktop, same thing, then same thing “trz8e.tmp”, same thing then, “trz8f.tmp” then “trz90.tmp” then “trz91.tmp”.
That is all I have in the chect, I forget how I stopped this process, probably hit ctrl alt delete and found what ever it was and ended the task.
Then I go to my “msconfig” and I see something I do not recognize, but it might have been due to a bad shut down a couple days before, called,
“dumprep 0 -k” in the start up tab, the command was “%systemroot%\system32\dumprep 0 -k”.
OH I also use Ccleaner.
So I decide I need to restart my computer, EVEN after I searched for this"nvaux32.dll", and read about it, I found some info on it and checked all the files and changes it was supposed to make and all that, and did not find one single thing they listed, they being whoever was familiar and at the top of the list, like mcaffee norton bleeping computer and whoever else, I visisted about 4 or 5 sites.
SO I reboot, and the computer “bios” says memory decreased or something, and would not boot past the windows loading and logo screen, and would just be in a continous reboot loop.

I posted elsewhere at ms knowledgebase.
I tried and failed at everything from resetting cmos, changeing memory, and could not boot to anything including safe mode.
But I noticed a extremely quick flash sometimes at the end of the trying to boot process at the black windows loading logo screen, REALLY FAST! 1/60th of a second to be exact.
I had to use a digital camera at 60fps in video mode and a bunch of tried to catch it.
then played it back luckily You can go frame by frame because it only shows up in one frame.
saying on a blue screen, something about error (code of numbers here) unable to locate user32.dll the application failed try reinstalling the app and try again and all that sort of thing.
So I loaded my XP CD started the recovery console and searched the drive and there was no user32.dll, after some research and trial and error I used the cd and recovery console to replace the user32.dll and here I AM.
but don’t do these commands “%systemroot%\system32” garbage they have never worked for me.
I simply did what I know, used the expand like everywhere said, but instead of “% signs and system root” I just told it “c:\windows"system32” and I am up and running,
SO AVAST might have saved my hard drive, time will tell,
but did not really save me.
I unchecked that dumprep in msconfig, but I am not sure if I should just delete it from the registry or not.
AND I am not sure what to do at this point.
Dang that was long.

Looks like you have a worm/Backdoor trojan.

http://www.prevx.com/filenames/20878752371790299-X1/NVAUX322EDLL.html

http://www.greatis.com/appdata/d/n/nvaux32.dll.htm

http://www.virustotal.com/analisis/55623f6e6dc762db33a64226eaee290d

AhnLab-V3 2008.11.14.3 2008.11.14 Win-Trojan/Xema.variant
AntiVir 7.9.0.31 2008.11.14 TR/Crypt.XDR.Gen
Authentium 5.1.0.4 2008.11.14 W32/Dropper.gen8!Maximus
F-Prot 4.4.4.56 2008.11.14 W32/Dropper.gen8!Maximus
Microsoft 1.4104 2008.11.15 Worm:Win32/Mariofev.A
Prevx1 V2 2008.11.15 Malicious Software
SecureWeb-Gateway 6.7.6 2008.11.14 Trojan.Crypt.XDR.Gen
Sophos 4.35.0 2008.11.15 W32/MarioF-B

Hi there,
Yep, and so all those programs I listed, avast included, didn’t help or save me.
What do you suggest to make sure it is cleaned and gone ?.
And does not spring up something at a given day or time :slight_smile: or whatever else it may do.
AND is that “nvaux32.dll” something that downloaded silently, or something that I had already for a program or WinXP ?
I guess do I need that ?
and how to make sure the trojan is gone ?

Hi DADSGETNDOWN,

Search for this dll: jyjlt.dll and try to remove that in SafeMode with System Restore disabled,
Then the removal:
NVAUX32.DLL and detail of NVAUX32.DLL:

NVAUX32.DLL description :The filename NVAUX32.DLL was last seen on 11.15.2008, and it is considered unsafe. This threat is associated with the malware group w32/mariof-b. Threat name w32/mariof-b Filename [System32Root]\nvaux32.dll Filesize Unknown Last seen 11.15.2008 Status Known to RemoveIT Pro as unsafe. This file can perform following behavior. - Usualy created by unsafe process. - Registered as a Dynamic Link Library File. - Usualy have random filename and refers to many versions of a dynamic link library. - Can be injected/attached to the legitimate Windows process such as explorer.exe or other.

NVAUX32.DLL remove instruction

  1. Temporarily Disable System Restore, Reboot computer in SafeMode;

  2. Locate NVAUX32.DLL virus files and uninstall NVAUX32.DLL files program. Follow the screen step-by-step screen instructions to complete uninstallation of NVAUX32.DLL.

  3. Delete/Modify any values added to the registry related with NVAUX32.DLL,Exit registry editor and restart the computer;

4.Clean/delete all NVAUX32.DLLinfected file(s):NVAUX32.DLL and related,or rename NVAUX32.DLL virus files;

5.Please delete all your IE temp files with NVAUX32.DLL manually,run a whole scan with antivirus program ;

polonus

Hi polonus.
I did do all that before, not uninstall though, don’t see what to uninstall.
To bad Avast didn’t stop it.
I just searched the registry and my whole computer twice for each of
those 2 files, NVAUX32.DLL, jyjlt.dll, but did not find anything.
Also searched for mariof found nothing.
Now those files that I mentioned in the original post are in the chest, should I delete those ? or hang on to for a bit until I feel this is resolved ?
and Turning off system restore, doesn’t that delete all the system restores ?

What if I do a system restore to a day before this happened ?
OR should I even think about that ?
Computer seems to be running fine, for now.
Have not rebooted yet though…

It’s better to leave it in the chest for investigation.

First, do not delete, do no harm.