Unsolved
This post is more than 5 years old
1 Rookie
•
15 Posts
0
1989
April 18th, 2009 11:00
Redirect to "res://C:\WINDOWS\system32\shdoclc.dll/navcancl.htm" when browsing sites
Sorry to bother, but I seem to have the same problem once again. When I browse some sites I get directed to "res://C:\WINDOWS\system32\shdoclc.dll/navcancl.htm" . Bugbatter helped me fixed this issue 2 weeks ago, but it seems the problem has arisen once again =(
Here is my HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:34:05 PM, on 4/18/2009
Platform: Windows XP SP3, v.3264 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\lgiftpzwr\atisvc_cwnzcpub.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
C:\WINDOWS\system32\lgiftpzwr\atisvc_cwnzcpub.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\lexpps.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\PlatformDependent\ProToolbarComm.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
O4 - HKUS\S-1-5-19\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1233429897340
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1236475747453
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O23 - Service: atisvc_cwnzcpub - Unknown owner - C:\WINDOWS\system32\lgiftpzwr\atisvc_cwnzcpub.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Security Activity Dashboard Service - Trend Micro Inc. - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
--
End of file - 9405 bytes


Bugbatter
4 Apprentice
•
20.5K Posts
0
April 18th, 2009 15:00
It looks as if the malware has returned. I'm not sure if it is coming from a site you may have revisited or whether it did not completely leave the first time. We'll have to run a more powerful tool. Please visit this webpage for download links, and instructions for running ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
" * Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log for further review.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
* Additional information on A/V control HERE. * ComboFix is not intended for use with servers.
jthamara
1 Rookie
•
15 Posts
0
April 18th, 2009 15:00
When i try to run ComboFix, it brings up a warning message saying that it has detected Norton Internet Security still active. However, i currenly have trend micro at the moment and it is disabled. I had Norton a couple of months ago, but i replaced it with trend micro. Is Norton still installed? If so, how do i disable it?
Bugbatter
4 Apprentice
•
20.5K Posts
0
April 18th, 2009 17:00
Apparently Norton was not completely removed. Did you use Add/Remove and follow with the removal tool? If not please run it now.
http://www.majorgeeks.com/Norton_Removal_Tool_SymNRT_d4749.html
jthamara
1 Rookie
•
15 Posts
0
April 18th, 2009 18:00
I ran the Norton Removal tool and was able to run ComboFix as well. However, Windows Security Alerts says that it doesnt detect a virus program on my computer, even though Trend Micro was turned back on after ComboFix was finished. What should i do about that?
ComboFix log:
ComboFix 09-04-19.01 - Joseph 04/18/2009 19:20.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.211 [GMT -5:00]
Running from: c:\documents and settings\Joseph\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
AV: Trend Micro Internet Security Pro *On-access scanning disabled* (Updated)
FW: Trend Micro Personal Firewall *disabled*
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-03-19 to 2009-04-19 )))))))))))))))))))))))))))))))
.
2009-04-18 16:05 . 2009-04-18 22:29 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-18 03:04 . 2009-04-18 03:12 -------- d-----w c:\windows\system32\lgiftpzwr
2009-04-13 22:42 . 2009-04-13 22:41 73728 ----a-w c:\windows\system32\javacpl.cpl
2009-04-13 20:16 . 2009-04-13 20:16 -------- d-----w c:\documents and settings\Joseph\Application Data\Malwarebytes
2009-04-13 20:16 . 2009-04-06 20:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-13 20:16 . 2009-04-06 20:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-13 20:16 . 2009-04-13 20:16 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-09 01:42 . 2008-03-14 18:14 52736 ----a-w c:\windows\system32\sqlcecompact30.dll
2009-04-09 01:42 . 2008-03-14 18:14 525824 ----a-w c:\windows\system32\sqlceqp30.dll
2009-04-09 01:42 . 2008-03-14 18:14 287232 ----a-w c:\windows\system32\sqlceca30.dll
2009-04-09 01:42 . 2008-03-14 18:14 284672 ----a-w c:\windows\system32\sqlcese30.dll
2009-04-09 01:42 . 2008-03-14 18:14 133120 ----a-w c:\windows\system32\sqlceoledb30.dll
2009-04-09 01:42 . 2008-03-14 18:14 129536 ----a-w c:\windows\system32\sqlceer30EN.dll
2009-04-09 01:42 . 2008-03-14 18:14 44544 ----a-w c:\windows\system32\sqlceme30.dll
2009-04-08 02:20 . 2009-04-08 02:20 -------- d-----w c:\documents and settings\Joseph\Local Settings\Application Data\Identities
2009-03-20 18:15 . 2009-03-28 00:12 256 ----a-w c:\windows\system32\pool.bin
2009-03-20 18:14 . 2009-03-20 18:14 -------- d-----w c:\documents and settings\Joseph\Application Data\Research In Motion
2009-03-20 18:14 . 2009-03-20 18:14 256 ----a-w c:\documents and settings\Joseph\pool.bin
2009-03-20 17:59 . 2009-03-20 17:59 -------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
2009-03-20 17:59 . 2009-03-20 17:59 -------- d-----w c:\documents and settings\All Users\Application Data\Sonic
2009-03-20 17:55 . 2009-03-20 17:55 -------- d-----w c:\documents and settings\All Users\Application Data\Roxio
2009-03-20 17:25 . 2007-01-18 16:24 26496 ----a-r c:\windows\system32\drivers\RimSerial.sys
2009-03-20 17:16 . 2009-03-20 17:16 -------- d-sh--w c:\windows\ftpcache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-18 23:24 . 2009-03-06 15:56 77824 ----a-w c:\windows\system32\kdfapi.dll
2009-04-18 23:24 . 2009-03-06 15:56 192512 ----a-w c:\windows\system32\kdfvmgr.exe
2009-04-18 23:24 . 2009-03-06 15:56 53248 ----a-w c:\windows\system32\Kdfhok.dll
2009-04-18 23:24 . 2009-03-06 15:56 387288 ----a-w c:\windows\system32\kdfmgr.exe
2009-04-18 22:29 . 2009-04-18 16:04 -------- d-----w c:\program files\SpywareBlaster
2009-04-18 17:23 . 2009-04-18 17:23 -------- d-----w c:\program files\CCleaner
2009-04-18 02:55 . 2009-02-13 13:17 13696 ----a-w c:\windows\system32\drivers\wpsnuio.sys
2009-04-17 03:37 . 2009-02-15 00:07 34 ----a-w c:\documents and settings\Joseph\jagex_runescape_preferences.dat
2009-04-13 22:50 . 2009-02-17 00:16 -------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-04-13 22:41 . 2009-02-14 21:07 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-13 22:41 . 2009-04-13 22:41 -------- d-----w c:\program files\Java
2009-04-13 21:52 . 2009-04-13 21:32 6134 ----a-w C:\avenger.txt
2009-04-13 20:16 . 2009-04-13 20:16 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-12 22:23 . 2009-03-06 15:46 -------- d-----w c:\program files\Trend Micro
2009-04-02 23:08 . 2009-03-06 15:48 50192 ----a-w c:\windows\system32\drivers\tmactmon.sys
2009-04-02 23:08 . 2009-03-06 15:48 50192 ----a-w c:\windows\system32\drivers\tmevtmgr.sys
2009-04-02 23:08 . 2009-03-06 15:48 153104 ----a-w c:\windows\system32\drivers\tmcomm.sys
2009-03-20 18:30 . 2009-03-20 17:46 -------- d-----w c:\program files\Common Files\Research In Motion
2009-03-20 18:21 . 2009-01-31 19:02 83704 ----a-w c:\documents and settings\Joseph\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-20 17:57 . 2009-03-20 17:55 -------- d-----w c:\program files\Common Files\Roxio Shared
2009-03-20 17:56 . 2009-03-20 17:55 -------- d-----w c:\program files\Roxio
2009-03-20 17:55 . 2009-03-20 17:55 -------- d-----w c:\program files\Common Files\Sonic Shared
2009-03-20 17:55 . 2009-01-31 18:37 -------- d-----w c:\program files\Common Files\InstallShield
2009-03-20 17:46 . 2009-03-20 17:46 -------- d-----w c:\program files\Research In Motion
2009-03-20 14:43 . 2009-03-06 15:56 475872 ----a-w c:\windows\system32\kdfinj.dll
2009-03-13 03:44 . 2009-03-13 03:44 -------- d-----w c:\program files\MSECache
2009-03-13 00:31 . 2009-01-31 19:54 -------- d-----w c:\program files\Common Files\Adobe
2009-03-12 03:29 . 2009-03-11 04:46 -------- d-----w c:\documents and settings\Joseph\Application Data\LimeWire
2009-03-07 20:42 . 2009-03-07 20:42 -------- d-----w c:\program files\Common Files\INCA Shared
2009-03-07 20:34 . 2009-03-07 20:34 -------- d-----w c:\program files\Subagames
2009-03-07 15:22 . 2009-02-11 05:14 -------- d-----w c:\program files\DivX
2009-03-06 16:04 . 2009-03-06 15:47 -------- d-----w c:\documents and settings\All Users\Application Data\Trend Micro
2009-03-06 16:00 . 2009-02-06 02:00 -------- d-----w c:\documents and settings\All Users\Application Data\NortonInstaller
2009-03-06 15:43 . 2009-02-06 02:02 -------- d-----w c:\documents and settings\All Users\Application Data\Norton
2009-03-06 03:49 . 2009-01-31 21:15 -------- d-----w c:\program files\Lexmark X6100 Series
2009-03-06 02:17 . 2008-08-14 17:23 36368 ----a-w c:\windows\system32\drivers\tmpreflt.sys
2009-03-06 02:17 . 2008-08-14 17:23 205328 ----a-w c:\windows\system32\drivers\tmxpflt.sys
2009-03-06 02:17 . 2008-08-14 17:23 1195512 ----a-w c:\windows\system32\drivers\vsapint.sys
2009-03-03 23:12 . 2008-08-14 17:23 80400 ----a-w c:\windows\system32\drivers\tmtdi.sys
2009-03-03 09:08 . 2008-08-14 17:23 335376 ----a-w c:\windows\system32\drivers\TM_CFW.sys
2009-02-28 18:02 . 2009-02-28 18:02 -------- d-----w c:\documents and settings\All Users\Application Data\Pure Networks
2009-02-27 12:58 . 2009-01-31 22:31 -------- d-----w c:\documents and settings\All Users\Application Data\America's Army Deploy Client
2009-02-27 12:58 . 2009-01-31 22:31 -------- d-----w c:\program files\America's Army Deploy Client
2009-02-27 04:23 . 2009-01-31 19:28 -------- d-----w c:\program files\InterVideo
2009-02-27 04:23 . 2009-01-31 19:28 -------- d-----w c:\program files\Common Files\InterVideo
2009-02-24 00:09 . 2009-02-24 00:09 -------- d-----w c:\program files\SystemRequirementsLab
2009-02-24 00:09 . 2009-02-24 00:09 -------- d-----w c:\documents and settings\Joseph\Application Data\SystemRequirementsLab
2009-02-17 00:16 . 2009-02-17 00:15 391 ---ha-w C:\IPH.PH
2009-02-06 01:20 . 2009-02-06 01:20 996 ----a-w C:\net_save.dna
2009-01-31 18:58 . 2009-01-31 18:31 71627 ----a-w c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-01-31 18:53 . 2002-09-03 16:50 250048 --sha-r C:\ntldr
2009-01-31 18:31 . 2009-01-31 18:31 558142 ----a-w c:\windows\java\Packages\NHBPFBXN.ZIP
2009-01-31 18:31 . 2009-01-31 18:31 2678 ----a-w c:\windows\java\Packages\Data\GOB35R5Z.DAT
2009-01-31 18:31 . 2009-01-31 18:31 2678 ----a-w c:\windows\java\Packages\Data\N1JT3BB9.DAT
2009-01-31 18:31 . 2009-01-31 18:31 155995 ----a-w c:\windows\java\Packages\VDVLRHBR.ZIP
2009-01-31 18:31 . 2009-01-31 18:31 2678 ----a-w c:\windows\java\Packages\Data\O1NVL3JF.DAT
2009-01-31 18:31 . 2009-01-31 18:31 2678 ----a-w c:\windows\java\Packages\Data\N75ZX7LZ.DAT
2009-01-31 18:31 . 2009-01-31 18:31 2678 ----a-w c:\windows\java\Packages\Data\9JFDZNP7.DAT
2009-01-31 18:29 . 2009-01-31 18:29 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-04-18 03:2009-02-13 13:17 04:56 . c:\program files\mozilla firefox\components\1268145.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2007-12-01 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-31 68856]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2008-08-14 497008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-10-06 5058560]
"Lexmark X6100 Series"="c:\program files\Lexmark X6100 Series\lxbfbmgr.exe" [2003-09-23 57344]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-04-01 995528]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-13 148888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2008-08-14 497008]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
backup=c:\windows\pss\Ralink Wireless Utility.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2009-04-02 50192]
R2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [2009-04-01 497008]
R2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2009-03-06 36368]
R2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2009-04-01 677128]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-02-17 2736890]
S2 atisvc_cwnzcpub;atisvc_cwnzcpub;c:\windows\system32\lgiftpzwr\atisvc_cwnzcpub.exe [2009-04-18 456812]
S2 Security Activity Dashboard Service;Security Activity Dashboard Service;c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe [2008-08-14 181584]
S3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\DRIVERS\TM_CFW.sys [2009-03-03 335376]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ebfed018-1d81-11de-90c5-0007e9d8ca36}]
\Shell\AutoRun\command - setupSNK.exe
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://cnn.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title = Windows Internet Explorer provided by Comcast
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Joseph\Application Data\Mozilla\Firefox\Profiles\9bbovppi.default\
FF - component: c:\program files\Mozilla Firefox\components\1268145.dll
FF - component: c:\program files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFTMUFEHelper.dll
FF - component: c:\program files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFToolbarComm.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-18 19:22
Windows 5.1.2600 Service Pack 3, v.3264 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1659004503-606747145-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1844)
c:\windows\system32\lgiftpzwr\mcie_pnanhvhbq.dll
c:\windows\system32\lgiftpzwr\mca_iebsicpfb.dll
c:\windows\system32\lgiftpzwr\mcapp_wlwbnczwg.dll
c:\windows\system32\lgiftpzwr\AWTKernel32_maimhlre.dll
c:\windows\system32\lgiftpzwr\ATIDLL_soomslvai.dll
c:\windows\system32\lgiftpzwr\mcsc_rbbetciig.dll
c:\windows\system32\lgiftpzwr\mcy_ovvjoxdyo.dll
c:\windows\system32\lgiftpzwr\mcmsg_wqthfuyqa.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2009-04-19 19:24
ComboFix-quarantined-files.txt 2009-04-19 00:24
Pre-Run: 44,507,357,184 bytes free
Post-Run: 44,531,077,120 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
203 --- E O F --- 2009-04-15 11:37
And Heres the HijackThis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:39:42 PM, on 4/18/2009
Platform: Windows XP SP3, v.3264 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\lgiftpzwr\atisvc_cwnzcpub.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\WINDOWS\system32\lgiftpzwr\atisvc_cwnzcpub.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\lexpps.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1233429897340
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1236475747453
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O23 - Service: atisvc_cwnzcpub - Unknown owner - C:\WINDOWS\system32\lgiftpzwr\atisvc_cwnzcpub.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Security Activity Dashboard Service - Trend Micro Inc. - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
--
End of file - 9025 bytes
Bugbatter
4 Apprentice
•
20.5K Posts
0
April 18th, 2009 19:00
It appears that there may be conflicts on there because you also have AVG on that computer.
If you are using Trend Micro Internet Security for anti-virus, please remove AVG and follow with the removal tool.
http://www.avg.com/download-tools
Save the file to your desktop. Close all programs before running the Removal Tool
It looks as if that malware was created today.
Disconnect from the internet....pull the plug!
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray.
Otherwise, they may interfere with running ComboFix.
Open Notepad and copy/paste the following text between the lines below.
Do not copy the dotted lines.
** Make sure you copy/paste ALL the text at once. Do not try to edit extra spaces.
It will copy correctly to Notepad if you highlight and copy as is.
-----------------------------------------------------------------------------------
Folder::
c:\windows\system32\lgiftpzwr
Driver::
atisvc_cwnzcpub
npggsvc
----------------------------------------------------------------------------
Save this as CFScript.txt
Referring to the picture above, drag CFScript into ComboFix.exe
You will be prompted to run Combofix again.
Follow the same instructions you did before for running ComboFix.
CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.
When finished, a log is produced here: C:\ComboFix.txt
In your next reply, please post that log along with a new HijackThis log.
Let me know how things are running.
jthamara
1 Rookie
•
15 Posts
0
April 18th, 2009 21:00
I disabled Trend Micro and ran ComboFix, however after ComboFix restarted the computer, Trend Micro restarted and prompted whether it should allow some program to continue running. Then after a while ComboFix, stopped and opened up a blank notepad but said it couldnt locate something. So I'm pasting the log that was under C:\ . Hopefully nothing in the computer messed up :( Plz let me know if theres anything messed up and what i need to do to fix it.
ComboFix Log:
ComboFix 09-04-19.01 - Joseph 04/18/2009 21:35.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.259 [GMT -5:00]
Running from: c:\documents and settings\Joseph\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Joseph\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
AV: Trend Micro Internet Security Pro *On-access scanning disabled* (Updated)
FW: Trend Micro Personal Firewall *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\lgiftpzwr
c:\windows\system32\lgiftpzwr\AES256.dll
c:\windows\system32\lgiftpzwr\ATIDLL_soomslvai.dll
c:\windows\system32\lgiftpzwr\ATIDLL64_ktbadeypu.dll
c:\windows\system32\lgiftpzwr\atisvc_cwnzcpub.exe
c:\windows\system32\lgiftpzwr\AWTKernel32_maimhlre.dll
c:\windows\system32\lgiftpzwr\Cache\S-1-5-21-1659004503-606747145-839522115-1004\Default\588_11569500_1.cdf
c:\windows\system32\lgiftpzwr\ccp_arjcmpxyi.dll
c:\windows\system32\lgiftpzwr\Config.dat
c:\windows\system32\lgiftpzwr\database.sdf
c:\windows\system32\lgiftpzwr\Director_weaypkkf.dll
c:\windows\system32\lgiftpzwr\dprx_xvducfbgt.dll
c:\windows\system32\lgiftpzwr\ffe_iebsicpfb.dll
c:\windows\system32\lgiftpzwr\ffe3_phatcauws.dll
c:\windows\system32\lgiftpzwr\LiteUnzip.dll
c:\windows\system32\lgiftpzwr\mca_iebsicpfb.dll
c:\windows\system32\lgiftpzwr\mcapp_wlwbnczwg.dll
c:\windows\system32\lgiftpzwr\mcff_nqqjcgvib.dll
c:\windows\system32\lgiftpzwr\mcie_pnanhvhbq.dll
c:\windows\system32\lgiftpzwr\mck_mhqgfcase.dll
c:\windows\system32\lgiftpzwr\mclmd_rictfdnqb.dll
c:\windows\system32\lgiftpzwr\mcmsg_wqthfuyqa.dll
c:\windows\system32\lgiftpzwr\mco_jkeojwgyj.dll
c:\windows\system32\lgiftpzwr\mcoexp_fpbrtkis.dll
c:\windows\system32\lgiftpzwr\mcsc_rbbetciig.dll
c:\windows\system32\lgiftpzwr\mcy_ovvjoxdyo.dll
c:\windows\system32\lgiftpzwr\proxy.dll
c:\windows\system32\lgiftpzwr\Settings.dat
c:\windows\system32\lgiftpzwr\Settings1083603.dat
c:\windows\system32\lgiftpzwr\svcsetup.exe
c:\windows\system32\lgiftpzwr\ve.dll
c:\windows\system32\lgiftpzwr\WindowsAccessBridge.dll
c:\windows\system32\lgiftpzwr\wpsapi-vista.dll
c:\windows\system32\lgiftpzwr\wpsapi-xp.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ATISVC_CWNZCPUB
-------\Service_atisvc_cwnzcpub
-------\Service_npggsvc
((((((((((((((((((((((((( Files Created from 2009-03-19 to 2009-04-19 )))))))))))))))))))))))))))))))
.
2009-04-18 16:05 . 2009-04-18 22:29 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-13 22:42 . 2009-04-13 22:41 73728 ----a-w c:\windows\system32\javacpl.cpl
2009-04-13 20:16 . 2009-04-13 20:16 -------- d-----w c:\documents and settings\Joseph\Application Data\Malwarebytes
2009-04-13 20:16 . 2009-04-06 20:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-13 20:16 . 2009-04-06 20:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-13 20:16 . 2009-04-13 20:16 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-09 01:42 . 2008-03-14 18:14 52736 ----a-w c:\windows\system32\sqlcecompact30.dll
2009-04-09 01:42 . 2008-03-14 18:14 525824 ----a-w c:\windows\system32\sqlceqp30.dll
2009-04-09 01:42 . 2008-03-14 18:14 287232 ----a-w c:\windows\system32\sqlceca30.dll
2009-04-09 01:42 . 2008-03-14 18:14 284672 ----a-w c:\windows\system32\sqlcese30.dll
2009-04-09 01:42 . 2008-03-14 18:14 133120 ----a-w c:\windows\system32\sqlceoledb30.dll
2009-04-09 01:42 . 2008-03-14 18:14 129536 ----a-w c:\windows\system32\sqlceer30EN.dll
2009-04-09 01:42 . 2008-03-14 18:14 44544 ----a-w c:\windows\system32\sqlceme30.dll
2009-04-08 02:20 . 2009-04-08 02:20 -------- d-----w c:\documents and settings\Joseph\Local Settings\Application Data\Identities
2009-03-20 18:15 . 2009-03-28 00:12 256 ----a-w c:\windows\system32\pool.bin
2009-03-20 18:14 . 2009-03-20 18:14 -------- d-----w c:\documents and settings\Joseph\Application Data\Research In Motion
2009-03-20 18:14 . 2009-03-20 18:14 256 ----a-w c:\documents and settings\Joseph\pool.bin
2009-03-20 17:59 . 2009-03-20 17:59 -------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
2009-03-20 17:59 . 2009-03-20 17:59 -------- d-----w c:\documents and settings\All Users\Application Data\Sonic
2009-03-20 17:55 . 2009-03-20 17:55 -------- d-----w c:\documents and settings\All Users\Application Data\Roxio
2009-03-20 17:25 . 2007-01-18 16:24 26496 ----a-r c:\windows\system32\drivers\RimSerial.sys
2009-03-20 17:16 . 2009-03-20 17:16 -------- d-sh--w c:\windows\ftpcache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-18 23:24 . 2009-03-06 15:56 77824 ----a-w c:\windows\system32\kdfapi.dll
2009-04-18 23:24 . 2009-03-06 15:56 192512 ----a-w c:\windows\system32\kdfvmgr.exe
2009-04-18 23:24 . 2009-03-06 15:56 53248 ----a-w c:\windows\system32\Kdfhok.dll
2009-04-18 23:24 . 2009-03-06 15:56 387288 ----a-w c:\windows\system32\kdfmgr.exe
2009-04-18 22:29 . 2009-04-18 16:04 -------- d-----w c:\program files\SpywareBlaster
2009-04-18 17:23 . 2009-04-18 17:23 -------- d-----w c:\program files\CCleaner
2009-04-18 02:55 . 2009-02-13 13:17 13696 ----a-w c:\windows\system32\drivers\wpsnuio.sys
2009-04-17 03:37 . 2009-02-15 00:07 34 ----a-w c:\documents and settings\Joseph\jagex_runescape_preferences.dat
2009-04-13 22:50 . 2009-02-17 00:16 -------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-04-13 22:41 . 2009-02-14 21:07 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-13 22:41 . 2009-04-13 22:41 -------- d-----w c:\program files\Java
2009-04-13 21:52 . 2009-04-13 21:32 6134 ----a-w C:\avenger.txt
2009-04-13 20:16 . 2009-04-13 20:16 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-12 22:23 . 2009-03-06 15:46 -------- d-----w c:\program files\Trend Micro
2009-04-02 23:08 . 2009-03-06 15:48 50192 ----a-w c:\windows\system32\drivers\tmactmon.sys
2009-04-02 23:08 . 2009-03-06 15:48 50192 ----a-w c:\windows\system32\drivers\tmevtmgr.sys
2009-04-02 23:08 . 2009-03-06 15:48 153104 ----a-w c:\windows\system32\drivers\tmcomm.sys
2009-03-20 18:30 . 2009-03-20 17:46 -------- d-----w c:\program files\Common Files\Research In Motion
2009-03-20 18:21 . 2009-01-31 19:02 83704 ----a-w c:\documents and settings\Joseph\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-20 17:57 . 2009-03-20 17:55 -------- d-----w c:\program files\Common Files\Roxio Shared
2009-03-20 17:56 . 2009-03-20 17:55 -------- d-----w c:\program files\Roxio
2009-03-20 17:55 . 2009-03-20 17:55 -------- d-----w c:\program files\Common Files\Sonic Shared
2009-03-20 17:55 . 2009-01-31 18:37 -------- d-----w c:\program files\Common Files\InstallShield
2009-03-20 17:46 . 2009-03-20 17:46 -------- d-----w c:\program files\Research In Motion
2009-03-20 14:43 . 2009-03-06 15:56 475872 ----a-w c:\windows\system32\kdfinj.dll
2009-03-13 03:44 . 2009-03-13 03:44 -------- d-----w c:\program files\MSECache
2009-03-13 00:31 . 2009-01-31 19:54 -------- d-----w c:\program files\Common Files\Adobe
2009-03-12 03:29 . 2009-03-11 04:46 -------- d-----w c:\documents and settings\Joseph\Application Data\LimeWire
2009-03-07 20:42 . 2009-03-07 20:42 -------- d-----w c:\program files\Common Files\INCA Shared
2009-03-07 20:34 . 2009-03-07 20:34 -------- d-----w c:\program files\Subagames
2009-03-07 15:22 . 2009-02-11 05:14 -------- d-----w c:\program files\DivX
2009-03-06 16:04 . 2009-03-06 15:47 -------- d-----w c:\documents and settings\All Users\Application Data\Trend Micro
2009-03-06 16:00 . 2009-02-06 02:00 -------- d-----w c:\documents and settings\All Users\Application Data\NortonInstaller
2009-03-06 15:43 . 2009-02-06 02:02 -------- d-----w c:\documents and settings\All Users\Application Data\Norton
2009-03-06 03:49 . 2009-01-31 21:15 -------- d-----w c:\program files\Lexmark X6100 Series
2009-03-06 02:17 . 2008-08-14 17:23 36368 ----a-w c:\windows\system32\drivers\tmpreflt.sys
2009-03-06 02:17 . 2008-08-14 17:23 205328 ----a-w c:\windows\system32\drivers\tmxpflt.sys
2009-03-06 02:17 . 2008-08-14 17:23 1195512 ----a-w c:\windows\system32\drivers\vsapint.sys
2009-03-03 23:12 . 2008-08-14 17:23 80400 ----a-w c:\windows\system32\drivers\tmtdi.sys
2009-03-03 09:08 . 2008-08-14 17:23 335376 ----a-w c:\windows\system32\drivers\TM_CFW.sys
2009-02-28 18:02 . 2009-02-28 18:02 -------- d-----w c:\documents and settings\All Users\Application Data\Pure Networks
2009-02-27 12:58 . 2009-01-31 22:31 -------- d-----w c:\documents and settings\All Users\Application Data\America's Army Deploy Client
2009-02-27 12:58 . 2009-01-31 22:31 -------- d-----w c:\program files\America's Army Deploy Client
2009-02-27 04:23 . 2009-01-31 19:28 -------- d-----w c:\program files\InterVideo
2009-02-27 04:23 . 2009-01-31 19:28 -------- d-----w c:\program files\Common Files\InterVideo
2009-02-24 00:09 . 2009-02-24 00:09 -------- d-----w c:\program files\SystemRequirementsLab
2009-02-24 00:09 . 2009-02-24 00:09 -------- d-----w c:\documents and settings\Joseph\Application Data\SystemRequirementsLab
2009-02-17 00:16 . 2009-02-17 00:15 391 ---ha-w C:\IPH.PH
2009-02-06 01:20 . 2009-02-06 01:20 996 ----a-w C:\net_save.dna
2009-01-31 18:58 . 2009-01-31 18:31 71627 ----a-w c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-01-31 18:53 . 2002-09-03 16:50 250048 --sha-r C:\ntldr
2009-01-31 18:31 . 2009-01-31 18:31 558142 ----a-w c:\windows\java\Packages\NHBPFBXN.ZIP
2009-01-31 18:31 . 2009-01-31 18:31 2678 ----a-w c:\windows\java\Packages\Data\GOB35R5Z.DAT
2009-01-31 18:31 . 2009-01-31 18:31 2678 ----a-w c:\windows\java\Packages\Data\N1JT3BB9.DAT
2009-01-31 18:31 . 2009-01-31 18:31 155995 ----a-w c:\windows\java\Packages\VDVLRHBR.ZIP
2009-01-31 18:31 . 2009-01-31 18:31 2678 ----a-w c:\windows\java\Packages\Data\O1NVL3JF.DAT
2009-01-31 18:31 . 2009-01-31 18:31 2678 ----a-w c:\windows\java\Packages\Data\N75ZX7LZ.DAT
2009-01-31 18:31 . 2009-01-31 18:31 2678 ----a-w c:\windows\java\Packages\Data\9JFDZNP7.DAT
2009-01-31 18:29 . 2009-01-31 18:29 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-04-18 03:2009-02-13 13:17 04:56 . c:\program files\mozilla firefox\components\1268145.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-04-19_00.22.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-19 02:40 . 2009-04-19 02:40 16384 c:\windows\Temp\Perflib_Perfdata_148.dat
+ 2009-01-31 18:34 . 2009-04-19 00:37 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-01-31 18:34 . 2009-04-19 00:16 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-31 18:34 . 2009-04-19 00:37 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-01-31 18:34 . 2009-04-19 00:16 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2007-12-01 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-31 68856]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2008-08-14 497008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-10-06 5058560]
"Lexmark X6100 Series"="c:\program files\Lexmark X6100 Series\lxbfbmgr.exe" [2003-09-23 57344]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-04-01 995528]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-13 148888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2008-08-14 497008]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
backup=c:\windows\pss\Ralink Wireless Utility.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
S2 Security Activity Dashboard Service;Security Activity Dashboard Service;c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe [2008-08-14 181584]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2009-04-02 50192]
S2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [2009-04-01 497008]
S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2009-03-06 36368]
S2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2009-04-01 677128]
S3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\DRIVERS\TM_CFW.sys [2009-03-03 335376]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ebfed018-1d81-11de-90c5-0007e9d8ca36}]
\Shell\AutoRun\command - setupSNK.exe
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://cnn.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title = Windows Internet Explorer provided by Comcast
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Joseph\Application Data\Mozilla\Firefox\Profiles\9bbovppi.default\
FF - component: c:\program files\Mozilla Firefox\components\1268145.dll
FF - component: c:\program files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFTMUFEHelper.dll
FF - component: c:\program files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFToolbarComm.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-18 21:41
Windows 5.1.2600 Service Pack 3, v.3264 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\atisvc_cwnzcpub]
"ImagePath"="c:\windows\system32\lgiftpzwr\atisvc_cwnzcpub.exe"
--
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1659004503-606747145-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3604)
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Trend Micro\BM\TMBMSRV.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Lexmark X6100 Series\lxbfbmon.exe
c:\program files\Trend Micro\Internet Security\SfCtlCom.exe
c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
c:\combofix\hidec.exe
c:\program files\Trend Micro\TrendSecure\TSCFCommander.exe
c:\combofix\Catchme.tmp
.
**************************************************************************
.
Completion time: 2009-04-19 21:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-19 02:45
ComboFix2.txt 2009-04-19 00:24
Pre-Run: 44,521,033,728 bytes free
Post-Run: 44,427,075,584 bytes free
262 --- E O F --- 2009-04-15 11:37
HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:10:01 PM, on 4/18/2009
Platform: Windows XP SP3, v.3264 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\PlatformDependent\ProToolbarComm.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1233429897340
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1236475747453
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Security Activity Dashboard Service - Trend Micro Inc. - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
--
End of file - 8722 bytes
Bugbatter
4 Apprentice
•
20.5K Posts
0
April 18th, 2009 23:00
Trend Micro restarted and prompted whether it should allow some program to continue running. Then after a while ComboFix, stopped and opened up a blank notepad but said it couldnt locate something
Those are rather non-specific messages, so I have no idea what that program was or what ComboFix couldn't find. Your logs look okay.
Please run HijackThis and place a checkmark next to the following:
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
Close all other windows and click "Fix Checked". Close HijackThis.
Please delete this file:
C:\avenger.txt
Reboot.
Try the computer online by going to a few SAFE sites. Any browser problems? If everything is back to normal we'll remove ComboFix and its files.
jthamara
1 Rookie
•
15 Posts
0
April 19th, 2009 12:00
The popup messages from TrendMicro were probably nothing to worry about. Fixed the thing in Hijack and CNN and yahoo are now working thanks =)
Bugbatter
4 Apprentice
•
20.5K Posts
0
April 19th, 2009 13:00
It's time for some housekeeping.
Because the tools we used to scan the computer, as well as tools to delete files and folders, are no longer needed, they should be removed, along with the folders created by these tools.
* Click Start then Run
Copy and paste next command in the field:
ComboFix /u
Make sure there's a space between Combofix and / Then hit enter.
This will remove ComboFix, run some cleanup procedures, and flush System Restore, thus creating a clean Restore Point.
You already have my prevention tips from your other thread, so I won't include those this time.