OCM Posted February 27, 2008 Report Share Posted February 27, 2008 (edited) One of the computers in our office keeps getting referred to other sites. I did the Trend Micro System Cleaner scan which showed we had 2 viruses:C:\WINDOWS\system32\geede.dll [Cryp_Tap]C:\WINDOWS\system32\ljjhfgf.dll [TROJ_VUNDO.APW]but was told they couldn't be cleaned. Checked back on TM website which said to delete the files. When tried to delete, go message they couldn't be deleted because they were in use, although no other programs running.Yesterday puchased Uniblue Office Suite, ran RegistryBooster2, SpeedUpMyPC and SpyEraser. Deleted everything that was recommended. Then tried to delete files above, but they were no longer there.Went back in to Internet Explorer and bad sites still popped up, so I placed them in restricted sites. The sites showed up in the address bar, but no images appeared.This morning when we checked Internet email, sites still popped up but no images.I went back to Trend Micro and downloaded HijackThis and did a scan. In following the directions to join this community when I clicked submit, the following restricted sites came up again but with all the imagesAfter clicking the UPLOAD button to send the log file, a new window opened:Then I got a message that my upload failed - "You are not permitted to upload this type of file. File is pasted below:__________________________________Logfile of Trend Micro HijackThis v2.0.2Scan saved at 10:57:52 AM, on 2/27/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exec:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\Program Files\Trend Micro\Security Server\PCCSRV\web\service\ofcservice.exeC:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exeC:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exeC:\Program Files\Trend Micro\Security Server\PCCSRV\Web\Service\DbServer.exeC:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\TEMP\DME41A.EXEC:\WINDOWS\Mixer.exeC:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exeC:\Program Files\Uniblue\PowerSuite\PowerSuite.exeC:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exeC:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\ApacheMonitor.exeC:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exeC:\WINDOWS\system32\rundll32.exeC:\WINDOWS\explorer.exeC:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXEC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logonO4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startupO4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindowO4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exeO4 - HKLM\..\Run: [bM43a7bf1d] Rundll32.exe "C:\WINDOWS\system32\jfcguvhf.dll",sO4 - HKLM\..\Run: [40948c81] rundll32.exe "C:\WINDOWS\system32\aggsxuxi.dll",bO4 - HKCU\..\Run: [uniblue PowerSuite] C:\Program Files\Uniblue\PowerSuite\PowerSuite.exeO4 - HKCU\..\Run: [uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /SO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - Global Startup: Monitor Apache Servers.lnk = Apache2\bin\ApacheMonitor.exeO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} (Encrypt Class) - https://ocm102.ocm.local:4343/SMB/console/h...root/AtxEnc.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1124916610360O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1158512581908O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cabO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - https://yourconferencing.webex.com/client/T...bex/ieatgpc.cabO16 - DPF: {E78DE03F-DC83-40DB-B590-8FD80BE5F7C8} (Security Server Management Console) - https://ocm102.ocm.local:4343/SMB/console/h.../AtxConsole.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = OCM.localO17 - HKLM\Software\..\Telephony: DomainName = OCM.localO17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = OCM.localO23 - Service: Apache2 - Apache Software Foundation - c:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exeO23 - Service: Trend Micro Security Server Master Service (ofcservice) - Trend Micro Inc. - C:\Program Files\Trend Micro\Security Server\PCCSRV\web\service\ofcservice.exeO23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe--End of file - 5117 bytes_________________________________________When I clicked button to preview post, another website popped up:Please help - I'm desperate!Thanks Edited February 27, 2008 by Rorschach112 Removed live links Link to post Share on other sites
Rorschach112 Posted February 27, 2008 Report Share Posted February 27, 2008 HelloPlease download ComboFix from Here or Here to your Desktop.**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**Please, never rename Combofix unless instructed.Close any open browsers.Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.-----------------------------------------------------------Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.-----------------------------------------------------------Close any open browsers.WARNING: Combofix will disconnect your machine from the Internet as soon as it startsPlease do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.If there is no internet connection after running Combofix, then restart your computer to restore back your connection.-----------------------------------------------------------[*]Double click on combofix.exe & follow the prompts.[*]When finished, it will produce a report for you. [*]Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall** Link to post Share on other sites
OCM Posted February 27, 2008 Author Report Share Posted February 27, 2008 HelloPlease download ComboFix from Here or Here to your Desktop.**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**Please, never rename Combofix unless instructed.Close any open browsers.Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.-----------------------------------------------------------Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.-----------------------------------------------------------Close any open browsers.WARNING: Combofix will disconnect your machine from the Internet as soon as it startsPlease do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.If there is no internet connection after running Combofix, then restart your computer to restore back your connection.-----------------------------------------------------------[*]Double click on combofix.exe & follow the prompts.[*]When finished, it will produce a report for you. [*]Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**Thanks! The logs are pasted below:ComboFix 08-02-25.3 - paulettee 2008-02-27 16:54:01.1 - NTFSx86Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.279 [GMT -7:00]Running from: C:\Documents and Settings\paulettee.OCM.000\Desktop\ComboFix.exe * Created a new restore pointWARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).C:\WINDOWS\cookies.iniC:\WINDOWS\system32\aggsxuxi.dllC:\WINDOWS\system32\boktpdhe.iniC:\WINDOWS\system32\edeeg.iniC:\WINDOWS\system32\edeeg.ini2C:\WINDOWS\system32\epmijjrh.dllC:\WINDOWS\system32\ewpynhvn.iniC:\WINDOWS\system32\geede.dllC:\WINDOWS\system32\imvvrmqj.iniC:\WINDOWS\system32\issnnwho.dllC:\WINDOWS\system32\ixuxsgga.iniC:\WINDOWS\system32\jfcguvhf.dllC:\WINDOWS\system32\kctxheyx.dllC:\WINDOWS\system32\kqpgqxmo.dllC:\WINDOWS\system32\liuorgcr.iniC:\WINDOWS\system32\ljjhfgf.dllC:\WINDOWS\system32\lsyruhau.dllC:\WINDOWS\system32\mcrh.tmpC:\WINDOWS\system32\mnieeceu.iniC:\WINDOWS\system32\ndvpjrjo.dllC:\WINDOWS\system32\ngojpfif.dllC:\WINDOWS\system32\ojrjpvdn.iniC:\WINDOWS\system32\qofxnlay.dllC:\WINDOWS\system32\qsidwion.dllC:\WINDOWS\system32\rcgrouil.dllC:\WINDOWS\system32\sngxeonc.dllC:\WINDOWS\system32\uahurysl.ini.((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-28 ))))))))))))))))))))))))))))))).2008-02-26 14:15 . 2008-02-27 14:15 99,346 --a------ C:\WINDOWS\BM43a7bf1d.xml2008-02-26 14:15 . 2008-02-27 16:54 21 --a------ C:\WINDOWS\pskt.ini2008-02-22 17:40 . 2008-02-25 12:48 <DIR> d-------- C:\Program Files\Uniblue2008-02-22 17:40 . 2008-02-26 08:56 <DIR> d-------- C:\Documents and Settings\paulettee.OCM.000\Application Data\Uniblue2008-02-22 17:40 . 2008-02-22 17:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue2008-02-20 15:06 . 2008-02-26 09:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft2008-01-29 15:13 . 2008-01-29 15:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Winferno2008-01-28 11:24 . 2008-01-28 11:24 324,316 --a------ C:\WINDOWS\system32\TmEncryptTemp.0062008-01-28 11:24 . 2008-01-28 11:24 324,316 --a------ C:\WINDOWS\system32\TmEncryptTemp.0052008-01-28 11:24 . 2008-01-28 11:24 324,316 --a------ C:\WINDOWS\system32\TmEncryptTemp.0042008-01-28 11:24 . 2008-01-28 11:24 324,316 --a------ C:\WINDOWS\system32\TmEncryptTemp.0032008-01-28 11:24 . 2008-01-28 11:24 324,316 --a------ C:\WINDOWS\system32\TmEncryptTemp.0022008-01-28 11:19 . 2008-01-28 11:19 39,040 --a------ C:\WINDOWS\system32\TmEncryptTemp.0012008-01-28 11:19 . 2008-01-28 11:19 39,040 --a------ C:\WINDOWS\system32\TmEncryptTemp.000.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2008-02-27 17:57 --------- d-----w C:\Program Files\Trend Micro2008-02-26 16:50 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard2008-02-23 00:29 --------- d-----w C:\Program Files\Microsoft AntiSpyware2008-01-30 20:15 --------- d-----w C:\Program Files\Yahoo!2008-01-30 19:50 --------- d-----w C:\Program Files\palmOne2008-01-24 10:02 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.22008-01-08 23:05 --------- d-----w C:\Program Files\MSECache2006-09-25 18:02 64,160 -c--a-w C:\Documents and Settings\paulettee.OCM.000\Application Data\GDIPFONTCACHEV1.DAT2005-09-22 18:38 64,160 -c--a-w C:\Documents and Settings\paulettee\Application Data\GDIPFONTCACHEV1.DAT2005-09-22 18:38 64,160 -c--a-w C:\Documents and Settings\paulettee.OCM\Application Data\GDIPFONTCACHEV1.DAT2005-09-09 23:04 63,000 -c--a-w C:\Documents and Settings\tinat\Application Data\GDIPFONTCACHEV1.DAT.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Uniblue PowerSuite"="C:\Program Files\Uniblue\PowerSuite\PowerSuite.exe" [2008-01-29 09:20 3202832]"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2008-01-29 09:20 1885464]"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-04 00:56 143360]"C-Media Mixer"="Mixer.exe" [2003-04-06 02:39 1818624 C:\WINDOWS\mixer.exe]"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2005-11-02 22:32 372813]"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-12-06 09:01 196608]C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor Apache Servers.lnk - C:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\ApacheMonitor.exe [2005-04-16 13:26:08 41042][HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]"NoWelcomeScreen"= 1 (0x1)[HKLM\~\startupfolder\C:^Documents and Settings^paulettee.OCM.000^Start Menu^Programs^Startup^palmOne Registration.lnk]backup=C:\WINDOWS\pss\palmOne Registration.lnkStartup[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"=[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"1798:UDP"= 1798:UDP:Windows Media Format SDK (iexplore.exe)"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009.Contents of the 'Scheduled Tasks' folder"2008-02-27 16:00:00 C:\WINDOWS\Tasks\rpc.job"- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe"2008-02-25 17:09:28 C:\WINDOWS\Tasks\Uniblue SpyEraser Nag.job"- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe"2008-02-25 17:00:59 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe.**************************************************************************catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2008-02-27 17:05:15Windows 5.1.2600 Service Pack 2 NTFSscanning hidden processes ... scanning hidden autostart entries ...scanning hidden files ... scan completed successfully hidden files: 0 **************************************************************************.------------------------ Other Running Processes ------------------------.c:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\Program Files\Trend Micro\Security Server\PCCSRV\web\service\ofcservice.exeC:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exeC:\WINDOWS\system32\wdfmgr.exeC:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exeC:\Program Files\Trend Micro\Security Server\PCCSRV\Web\Service\DbServer.exeC:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exeC:\WINDOWS\TEMP\YI12A3.EXEC:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe.**************************************************************************.Completion time: 2008-02-27 17:08:40 - machine was rebootedComboFix-quarantined-files.txt 2008-02-28 00:08:30.2008-02-14 10:25:47 --- E O F --- Logfile of Trend Micro HijackThis v2.0.2Scan saved at 17:11, on 2008-02-27Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exec:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\Program Files\Trend Micro\Security Server\PCCSRV\web\service\ofcservice.exeC:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exeC:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exeC:\Program Files\Trend Micro\Security Server\PCCSRV\Web\Service\DbServer.exeC:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\TEMP\YI12A3.EXEC:\WINDOWS\Mixer.exeC:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exeC:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exeC:\Program Files\Uniblue\PowerSuite\PowerSuite.exeC:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\ApacheMonitor.exeC:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exeC:\WINDOWS\explorer.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logonO4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startupO4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindowO4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exeO4 - HKCU\..\Run: [uniblue PowerSuite] C:\Program Files\Uniblue\PowerSuite\PowerSuite.exeO4 - HKCU\..\Run: [uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /SO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - Global Startup: Monitor Apache Servers.lnk = Apache2\bin\ApacheMonitor.exeO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} (Encrypt Class) - https://ocm102.ocm.local:4343/SMB/console/h...root/AtxEnc.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1124916610360O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1158512581908O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cabO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - https://yourconferencing.webex.com/client/T...bex/ieatgpc.cabO16 - DPF: {E78DE03F-DC83-40DB-B590-8FD80BE5F7C8} (Security Server Management Console) - https://ocm102.ocm.local:4343/SMB/console/h.../AtxConsole.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = OCM.localO17 - HKLM\Software\..\Telephony: DomainName = OCM.localO17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = OCM.localO23 - Service: Apache2 - Apache Software Foundation - c:\Program Files\Trend Micro\Security Server\PCCSRV\Apache2\bin\Apache.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exeO23 - Service: Trend Micro Security Server Master Service (ofcservice) - Trend Micro Inc. - C:\Program Files\Trend Micro\Security Server\PCCSRV\web\service\ofcservice.exeO23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe--End of file - 4946 bytesBecky @OCM Link to post Share on other sites
Rorschach112 Posted February 27, 2008 Report Share Posted February 27, 2008 Hello1. Close any open browsers.2. Open notepad and copy/paste the text in the quotebox below into it:File::C:\WINDOWS\system32\TmEncryptTemp.006C:\WINDOWS\system32\TmEncryptTemp.005C:\WINDOWS\system32\TmEncryptTemp.004C:\WINDOWS\system32\TmEncryptTemp.003C:\WINDOWS\system32\TmEncryptTemp.002C:\WINDOWS\system32\TmEncryptTemp.001C:\WINDOWS\system32\TmEncryptTemp.000Save this as CFScript.txt, in the same location as ComboFix.exeRefering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at "C:\ComboFix.txt"Note:Do not mouseclick combofix's window whilst it's running. That may cause it to stall1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis. Please download Malwarebytes' Anti-Malware from Here or HereDouble Click mbam-setup.exe to install the application.Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.If an update is found, it will download and install the latest version.Once the program has loaded, select "Perform Full Scan", then click Scan. Check all the boxes and click Start ScanThe scan may take some time to finish,so please be patient.When the scan is complete, click OK, then Show Results to view the results.Make sure that everything is checked, and click Remove Selected.When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.Copy&Paste the entire report in your next reply.Extra Note:If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.Reboot and post a new HijackThis log and tell me how your PC is running Link to post Share on other sites
Recommended Posts