Hijacked Internet Explorer[INACTIVE]


Recommended Posts

One of the computers in our office keeps getting referred to other sites. I did the Trend Micro System Cleaner scan which showed we had 2 viruses:

C:\WINDOWS\system32\geede.dll [Cryp_Tap]

C:\WINDOWS\system32\ljjhfgf.dll [TROJ_VUNDO.APW]

but was told they couldn't be cleaned. Checked back on TM website which said to delete the files. When tried to delete, go message they couldn't be deleted because they were in use, although no other programs running.

Yesterday puchased Uniblue Office Suite, ran RegistryBooster2, SpeedUpMyPC and SpyEraser. Deleted everything that was recommended. Then tried to delete files above, but they were no longer there.

Went back in to Internet Explorer and bad sites still popped up, so I placed them in restricted sites. The sites showed up in the address bar, but no images appeared.

This morning when we checked Internet email, sites still popped up but no images.

I went back to Trend Micro and downloaded HijackThis and did a scan. In following the directions to join this community when I clicked submit, the following restricted sites came up again but with all the images

After clicking the UPLOAD button to send the log file, a new window opened:

Then I got a message that my upload failed - "You are not permitted to upload this type of file. File is pasted below:

__________________________________

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 10:57:52 AM, on 2/27/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

c:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Program Files\Trend Micro\Security Server\PCCSRV\web\service\ofcservice.exe

C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe

C:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exe

C:\Program Files\Trend Micro\Security Server\PCCSRV\Web\Service\DbServer.exe

C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\TEMP\DME41A.EXE

C:\WINDOWS\Mixer.exe

C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe

C:\Program Files\Uniblue\PowerSuite\PowerSuite.exe

C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe

C:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\ApacheMonitor.exe

C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon

O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup

O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe

O4 - HKLM\..\Run: [bM43a7bf1d] Rundll32.exe "C:\WINDOWS\system32\jfcguvhf.dll",s

O4 - HKLM\..\Run: [40948c81] rundll32.exe "C:\WINDOWS\system32\aggsxuxi.dll",b

O4 - HKCU\..\Run: [uniblue PowerSuite] C:\Program Files\Uniblue\PowerSuite\PowerSuite.exe

O4 - HKCU\..\Run: [uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: Monitor Apache Servers.lnk = Apache2\bin\ApacheMonitor.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} (Encrypt Class) - https://ocm102.ocm.local:4343/SMB/console/h...root/AtxEnc.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1124916610360

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1158512581908

O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab

O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - https://yourconferencing.webex.com/client/T...bex/ieatgpc.cab

O16 - DPF: {E78DE03F-DC83-40DB-B590-8FD80BE5F7C8} (Security Server Management Console) - https://ocm102.ocm.local:4343/SMB/console/h.../AtxConsole.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = OCM.local

O17 - HKLM\Software\..\Telephony: DomainName = OCM.local

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = OCM.local

O23 - Service: Apache2 - Apache Software Foundation - c:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe

O23 - Service: Trend Micro Security Server Master Service (ofcservice) - Trend Micro Inc. - C:\Program Files\Trend Micro\Security Server\PCCSRV\web\service\ofcservice.exe

O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe

--

End of file - 5117 bytes

_________________________________________

When I clicked button to preview post, another website popped up:

Please help - I'm desperate!

Thanks

Edited by Rorschach112
Removed live links
Link to post
Share on other sites

Hello

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  1. Please, never rename Combofix unless instructed.
  2. Close any open browsers.
  3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------


  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

-----------------------------------------------------------

[*]Double click on combofix.exe & follow the prompts.

[*]When finished, it will produce a report for you.

[*]Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

Link to post
Share on other sites
Hello

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  1. Please, never rename Combofix unless instructed.
  2. Close any open browsers.
  3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------


  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

-----------------------------------------------------------

[*]Double click on combofix.exe & follow the prompts.

[*]When finished, it will produce a report for you.

[*]Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

Thanks! The logs are pasted below:

ComboFix 08-02-25.3 - paulettee 2008-02-27 16:54:01.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.279 [GMT -7:00]

Running from: C:\Documents and Settings\paulettee.OCM.000\Desktop\ComboFix.exe

* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

C:\WINDOWS\cookies.ini

C:\WINDOWS\system32\aggsxuxi.dll

C:\WINDOWS\system32\boktpdhe.ini

C:\WINDOWS\system32\edeeg.ini

C:\WINDOWS\system32\edeeg.ini2

C:\WINDOWS\system32\epmijjrh.dll

C:\WINDOWS\system32\ewpynhvn.ini

C:\WINDOWS\system32\geede.dll

C:\WINDOWS\system32\imvvrmqj.ini

C:\WINDOWS\system32\issnnwho.dll

C:\WINDOWS\system32\ixuxsgga.ini

C:\WINDOWS\system32\jfcguvhf.dll

C:\WINDOWS\system32\kctxheyx.dll

C:\WINDOWS\system32\kqpgqxmo.dll

C:\WINDOWS\system32\liuorgcr.ini

C:\WINDOWS\system32\ljjhfgf.dll

C:\WINDOWS\system32\lsyruhau.dll

C:\WINDOWS\system32\mcrh.tmp

C:\WINDOWS\system32\mnieeceu.ini

C:\WINDOWS\system32\ndvpjrjo.dll

C:\WINDOWS\system32\ngojpfif.dll

C:\WINDOWS\system32\ojrjpvdn.ini

C:\WINDOWS\system32\qofxnlay.dll

C:\WINDOWS\system32\qsidwion.dll

C:\WINDOWS\system32\rcgrouil.dll

C:\WINDOWS\system32\sngxeonc.dll

C:\WINDOWS\system32\uahurysl.ini

.

((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-28 )))))))))))))))))))))))))))))))

.

2008-02-26 14:15 . 2008-02-27 14:15 99,346 --a------ C:\WINDOWS\BM43a7bf1d.xml

2008-02-26 14:15 . 2008-02-27 16:54 21 --a------ C:\WINDOWS\pskt.ini

2008-02-22 17:40 . 2008-02-25 12:48 <DIR> d-------- C:\Program Files\Uniblue

2008-02-22 17:40 . 2008-02-26 08:56 <DIR> d-------- C:\Documents and Settings\paulettee.OCM.000\Application Data\Uniblue

2008-02-22 17:40 . 2008-02-22 17:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue

2008-02-20 15:06 . 2008-02-26 09:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft

2008-01-29 15:13 . 2008-01-29 15:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Winferno

2008-01-28 11:24 . 2008-01-28 11:24 324,316 --a------ C:\WINDOWS\system32\TmEncryptTemp.006

2008-01-28 11:24 . 2008-01-28 11:24 324,316 --a------ C:\WINDOWS\system32\TmEncryptTemp.005

2008-01-28 11:24 . 2008-01-28 11:24 324,316 --a------ C:\WINDOWS\system32\TmEncryptTemp.004

2008-01-28 11:24 . 2008-01-28 11:24 324,316 --a------ C:\WINDOWS\system32\TmEncryptTemp.003

2008-01-28 11:24 . 2008-01-28 11:24 324,316 --a------ C:\WINDOWS\system32\TmEncryptTemp.002

2008-01-28 11:19 . 2008-01-28 11:19 39,040 --a------ C:\WINDOWS\system32\TmEncryptTemp.001

2008-01-28 11:19 . 2008-01-28 11:19 39,040 --a------ C:\WINDOWS\system32\TmEncryptTemp.000

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-02-27 17:57 --------- d-----w C:\Program Files\Trend Micro

2008-02-26 16:50 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard

2008-02-23 00:29 --------- d-----w C:\Program Files\Microsoft AntiSpyware

2008-01-30 20:15 --------- d-----w C:\Program Files\Yahoo!

2008-01-30 19:50 --------- d-----w C:\Program Files\palmOne

2008-01-24 10:02 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2

2008-01-08 23:05 --------- d-----w C:\Program Files\MSECache

2006-09-25 18:02 64,160 -c--a-w C:\Documents and Settings\paulettee.OCM.000\Application Data\GDIPFONTCACHEV1.DAT

2005-09-22 18:38 64,160 -c--a-w C:\Documents and Settings\paulettee\Application Data\GDIPFONTCACHEV1.DAT

2005-09-22 18:38 64,160 -c--a-w C:\Documents and Settings\paulettee.OCM\Application Data\GDIPFONTCACHEV1.DAT

2005-09-09 23:04 63,000 -c--a-w C:\Documents and Settings\tinat\Application Data\GDIPFONTCACHEV1.DAT

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Uniblue PowerSuite"="C:\Program Files\Uniblue\PowerSuite\PowerSuite.exe" [2008-01-29 09:20 3202832]

"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2008-01-29 09:20 1885464]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-04 00:56 143360]

"C-Media Mixer"="Mixer.exe" [2003-04-06 02:39 1818624 C:\WINDOWS\mixer.exe]

"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2005-11-02 22:32 372813]

"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-12-06 09:01 196608]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

Monitor Apache Servers.lnk - C:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\ApacheMonitor.exe [2005-04-16 13:26:08 41042]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"NoWelcomeScreen"= 1 (0x1)

[HKLM\~\startupfolder\C:^Documents and Settings^paulettee.OCM.000^Start Menu^Programs^Startup^palmOne Registration.lnk]

backup=C:\WINDOWS\pss\palmOne Registration.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"1798:UDP"= 1798:UDP:Windows Media Format SDK (iexplore.exe)

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

.

Contents of the 'Scheduled Tasks' folder

"2008-02-27 16:00:00 C:\WINDOWS\Tasks\rpc.job"

- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe

"2008-02-25 17:09:28 C:\WINDOWS\Tasks\Uniblue SpyEraser Nag.job"

- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe

"2008-02-25 17:00:59 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"

- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe

.

**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-02-27 17:05:15

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

c:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Program Files\Trend Micro\Security Server\PCCSRV\web\service\ofcservice.exe

C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe

C:\WINDOWS\system32\wdfmgr.exe

C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe

C:\Program Files\Trend Micro\Security Server\PCCSRV\Web\Service\DbServer.exe

C:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exe

C:\WINDOWS\TEMP\YI12A3.EXE

C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe

.

**************************************************************************

.

Completion time: 2008-02-27 17:08:40 - machine was rebooted

ComboFix-quarantined-files.txt 2008-02-28 00:08:30

.

2008-02-14 10:25:47 --- E O F ---

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 17:11, on 2008-02-27

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

c:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Program Files\Trend Micro\Security Server\PCCSRV\web\service\ofcservice.exe

C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe

C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe

C:\Program Files\Trend Micro\Security Server\PCCSRV\Web\Service\DbServer.exe

C:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\TEMP\YI12A3.EXE

C:\WINDOWS\Mixer.exe

C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe

C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe

C:\Program Files\Uniblue\PowerSuite\PowerSuite.exe

C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\ApacheMonitor.exe

C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon

O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup

O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe

O4 - HKCU\..\Run: [uniblue PowerSuite] C:\Program Files\Uniblue\PowerSuite\PowerSuite.exe

O4 - HKCU\..\Run: [uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: Monitor Apache Servers.lnk = Apache2\bin\ApacheMonitor.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} (Encrypt Class) - https://ocm102.ocm.local:4343/SMB/console/h...root/AtxEnc.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1124916610360

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1158512581908

O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab

O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - https://yourconferencing.webex.com/client/T...bex/ieatgpc.cab

O16 - DPF: {E78DE03F-DC83-40DB-B590-8FD80BE5F7C8} (Security Server Management Console) - https://ocm102.ocm.local:4343/SMB/console/h.../AtxConsole.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = OCM.local

O17 - HKLM\Software\..\Telephony: DomainName = OCM.local

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = OCM.local

O23 - Service: Apache2 - Apache Software Foundation - c:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe

O23 - Service: Trend Micro Security Server Master Service (ofcservice) - Trend Micro Inc. - C:\Program Files\Trend Micro\Security Server\PCCSRV\web\service\ofcservice.exe

O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe

--

End of file - 4946 bytes

Becky @OCM

Link to post
Share on other sites

Hello

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

File::

C:\WINDOWS\system32\TmEncryptTemp.006

C:\WINDOWS\system32\TmEncryptTemp.005

C:\WINDOWS\system32\TmEncryptTemp.004

C:\WINDOWS\system32\TmEncryptTemp.003

C:\WINDOWS\system32\TmEncryptTemp.002

C:\WINDOWS\system32\TmEncryptTemp.001

C:\WINDOWS\system32\TmEncryptTemp.000

Save this as CFScript.txt, in the same location as ComboFix.exe

Combo-Do.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:

Do not mouseclick combofix's window whilst it's running. That may cause it to stall

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan. Check all the boxes and click Start Scan
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Reboot and post a new HijackThis log and tell me how your PC is running

Link to post
Share on other sites
Guest
This topic is now closed to further replies.