Unsolved
This post is more than 5 years old
4 Posts
0
4308
March 7th, 2010 10:00
Need help with Hijack this file pls
Hi, I'm new to this forum. Would someone please assist me with this Hijack this log? Trend found TROJ Gen.MZ40L8 Thanks A
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:37:27 PM, on 3/7/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Internet Explorer\IEUser.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files (x86)\Dell\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Unknown owner - C:\Windows\system32\AERTSr64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)
--
End of file - 6837 bytes


VivaSpain
3 Posts
0
March 7th, 2010 18:00
Hi Andrea,
I'm using WinXP SP3 - Trend Office Scan - Firefox/Chrome and I think the problem is a false positive of Office Scan. My antivirus should have updated recently (as well as yours) and in my computer and in another one where I also use Office Scan (where nothing has been installed recently), are appearing TROJ_Gen.MZ40L8 detections since yesterday (not before), in my case when I use CCleaner to clean Firefox and Chrome's cache.
Any new opinions are wellcome.
Thanks.
Rick412
11 Posts
0
March 7th, 2010 20:00
Using XP-SP3. Trend Micro PC-cillin Internet Security Notification reported it detected Troj_Gen.MZ40L8 in C:\Program Files\Trend Micro\Internet Security 12\VSS5117V.107. It didn't, however take any action.
Andreamagic
4 Posts
0
March 8th, 2010 11:00
Yes, it said that it quarantined the file then there was no file in the quarantined area to delete. There was a file in users/local/temp ~DF8AE3.tmp but it could not be deleted . Do you see any problems with the Hi jack this log? Thanks A
Andreamagic
4 Posts
0
March 8th, 2010 11:00
Thx, but there is the matter of an undeletable file. Do you know about the Hi Jack this log?
Bugbatter
4 Apprentice
•
20.5K Posts
0
March 8th, 2010 13:00
Hi Andrea,
While we appreciate their trying to assist, the members who replied are not on the list of trained helpers at the top of this forum, so they may not be aware that HijackThis does not give an accurate output log for Vista 64-bit systems. Before we run additional diagnostic tools, I am wondering if this may be a false positive. Please update Trend Micro, reboot, and run another scan. Is that problem still showing up?
If so, you could also get a second opinion from an online virus scan by Kaspersky from HERE.
2. At the next window Select Update. Allow the Database to update.
Note: If prompted to run or update your Java, then follow the prompts to do so. Kaspersky requires Java to run.
3. Once the Database has finished, under the Scan icon Select My Computer to start the scan. The scan may take a few minutes to complete.
4. Select Scan Report.
5. If any threats were found they will appear in the report
6. Select "Save error report as"
Then in the file name just type in kaspersky
Under "save as type" select text .txt
Save it to your Desktop.
Copy and post the results of the Kaspersky Online scan. If no threats were found then report that as well.
VivaSpain
3 Posts
0
March 8th, 2010 15:00
Hello,
I'm really sorry for not being a top member (I really registered only to help Andrea). Anyway I gave support faster than you, Bugbatter ;-)
I used the famous MS-Windows statement: Do_nothing_loop (); to solve the problem.
Today, Office Scan updated and TROJ_Gen.MZ40L8 disappeared from both computers mysteriously (though I expected). I didn't see that Andrea used HijackThis to make the report, I simply used logic to say it's a false positive (and I reaffirm). Anyway I can make mistakes like everyone else, so a second opinion from an online virus scan is a good idea (bet it will not appear anything like TROJ_Gen.MZ40L8, hehe).
Good luck.
Bugbatter
4 Apprentice
•
20.5K Posts
0
March 8th, 2010 16:00
Hi, VivaSpain,
Generally, our goal is not to see who gives "faster support". We take those who have been waiting the longest or those with the most severe problems that need prompt attention (for obvious reasons). At other times, we need to wait for a specialist to handle the issue.Feel free to share on Dell Community. It doesn't matter whether you are new or a regular poster. The only forum that is slightly different is this one because it is preferred that those helping have training as discussed in the announcement at the top of the forum: Please Read This Before Posting On the Malware Removal Forum
You probably missed the log in the first post and also missed reading that announcement because you came in via Most Recent Posts. We are hoping that option will be omitted when Dell upgrades the forums in the future. Thank you for your input, though. Yes, I agree that it is most likely a FP.
VivaSpain
3 Posts
1
March 8th, 2010 17:00
OMG, you are true, I beg your pardon. I really didn't read "Please Read This Before Posting On the Malware Removal Forum", because I simply came in searching on Google: TROJ_Gen.MZ40L8
If you see, there are only two links: a Danish web page and ours: "Need help with Hijack this file pls", so It was difficult to reach the former link.
Bye.
Bugbatter
4 Apprentice
•
20.5K Posts
0
March 8th, 2010 19:00
Understood. :emotion-1:
Andreamagic
4 Posts
0
March 16th, 2010 23:00
Thanks BB, I have been away. It must have been a false positive because both the file and the warnings are gone. I followed your instruction with Please update Trend Micro, reboot, and run another scan. Is that problem still showing up? At first it did then later on it went away. I usually do that but it was ineffective at first, so Trend must have come up with an eventual correction to the issue. I loaded malware bytes instead of Kaspersky because I didn't want to use the Java or update as there has been known problems with that. Both trend and malware bytes report no threats on the computer. Thanks for your help. Did you notice any issues with the Hijack log and could you clarify about the inaccuracy? Thx A
Bugbatter
4 Apprentice
•
20.5K Posts
0
March 17th, 2010 01:00
Glad to hear that you solved the problem and that threats are no longer reported.
That is correct. Some websites require you to use Java in order to use them, but because of vulnerabilities it needs to be kept updated. HijackThis was written way before Vista 64-bit. Therefore, it does not display that operating system's registry as it should, and cannot be used for diagnostic purposes.The issue has been resolved, so this thread is now closed.
Everyone else who is having a similar issue, please begin a New Message at the top of the forum.