This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Mal hifrm removal help

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello and thank you in advance for your time and help,

I have been infected for a week or so by a virus called Mal Hifrm and the infected file is: C:\Users\Ed\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\different file name each time\i[1].htm

My anti-virus program (TREND) detects it near daily but says it cannot quarantine or remove it. Malwarebytes was recommended as the tool to remove it, so I've downloaded, updated and ran MalWarebytes many times but the virus is still there. The results show my computer is clean, but I know that is not the case, as Trend Micro warns me multiples times per day that I am infected. I use ATF-Cleaner to empty the temp files, but still the warnings recur. I have been manually erasing the specified temp files in the Content.IE5 folder, but still the warning recur. I tried to erase the entire Content.IE5 folder but can't seem to do so. I am using Windows Vista.

Any suggestions on how to get rid of Mal Hifrm?

Here is a copy of the HijackThis log I just ran.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:47:46 AM, on 8/19/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\Maxtor\MANAGE~1\OneTouch.exe
C:\Windows\Explorer.EXE
C:\Program Files\Retrospect\Retrospect Express HD 2.0\RetroExpress.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\aol\1180220016\ee\aolsoftware.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE
C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\RETROS~1\RETROS~1.0\RetroExpress.exe /h
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1\AOL.EXE" -b
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/…can8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: dlcx_device - - C:\Windows\system32\dlcxcoms.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\Utils\SyncServices.exe
O23 - Service: Retrospect Express HD Helper (RetroExp Helper) - EMC Corporation - C:\Program Files\Retrospect\Retrospect Express HD 2.0\rthlpsvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - EMC Corporation - C:\Program Files\Retrospect\Retrospect Express HD 2.0\retrorun.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

–
End of file - 6581 bytes
[external image: Posted Image]

1. These tools MUST be run from the executable. (.exe)
2. With Admin Rights (Right click, choose "Run as Administrator") every time you run them


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Hello, Thank you so much for responding to my post with further directions. I was away all weekend, but have just got back home and followed your instructions. I have run the ATF Cleaner and emptied about 350Mb of stuff with it. Then I disabled my Trend Micro and the AdAware programs and ran the ComboFix application. Below is the log from the ComboFix program which I ran a few minutes ago. Also, my pc seems to be running much faster now, and Trend Micro, which I turned back on after the ComboFix process, has not flashed any warnings about Mal hifrm yet. Please take a look at the ComboFix Log below. Thank you in advance for your time and attention, I look forward to reading what next steps I need to take. Edward ComboFix 09-08-24.05 - Ed 08/24/2009 16:49.1.2 - NTFSx86 Microsoft® Windows Vista™ Business 6.0.6001.1.1252.1.1033.18.2046.1233 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5} SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Trend Micro Internet Security *enabled* (Updated) {003DD9A8-02A6-43CF-81BA-5D403CAD001E} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-918056312-2952985149-2686913973-500 c:\recycler\S-1-5-21-989950530-2701354910-514727013-1005 c:\recycler\S-1-5-21-989950530-2701354910-514727013-500 c:\users\Ed\AppData\Roaming\inst.exe c:\windows\emMON.exe c:\windows\Installer\2009391.msi c:\windows\Installer\54f83.msi c:\windows\system32\mfc45.dll . ((((((((((((((((((((((((( Files Created from 2009-07-24 to 2009-08-24 ))))))))))))))))))))))))))))))) . 2009-08-24 20:54 . 2009-08-24 20:54 ——– d—–w- c:\users\Ed\AppData\Local\temp 2009-08-24 20:54 . 2009-08-24 20:54 ——– d—–w- c:\users\Default\AppData\Local\temp 2009-08-24 20:54 . 2009-08-24 20:54 ——– d—–w- c:\users\Administrator.Ed-PC\AppData\Local\temp 2009-08-19 23:15 . 2009-08-19 23:16 ——– d—–w- c:\program files\QuickTime 2009-08-19 17:57 . 2009-03-08 11:32 72704 —-a-w- c:\windows\system32\admparse.dll 2009-08-19 17:56 . 2009-06-15 15:24 175104 —-a-w- c:\windows\system32\wdigest.dll 2009-08-19 17:56 . 2009-06-15 15:23 1256448 —-a-w- c:\windows\system32\lsasrv.dll 2009-08-19 17:56 . 2009-06-15 15:22 213504 —-a-w- c:\windows\system32\msv1_0.dll 2009-08-19 17:56 . 2009-06-15 15:21 499712 —-a-w- c:\windows\system32\kerberos.dll 2009-08-19 17:56 . 2009-06-15 18:20 439896 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2009-08-19 17:56 . 2009-06-15 15:24 72704 —-a-w- c:\windows\system32\secur32.dll 2009-08-19 17:56 . 2009-06-15 15:24 270848 —-a-w- c:\windows\system32\schannel.dll 2009-08-19 17:56 . 2009-06-15 12:57 9728 —-a-w- c:\windows\system32\lsass.exe 2009-08-19 02:55 . 2009-08-19 02:55 ——– d—–w- c:\users\Ed\AppData\Roaming\Malwarebytes 2009-08-19 02:54 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-19 02:54 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-08-19 02:54 . 2009-08-19 02:55 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2009-08-13 03:32 . 2009-08-13 03:32 ——– d—–w- c:\windows\BDOSCAN8 2009-08-13 03:05 . 2009-08-13 03:07 ——– d—–w- c:\users\Ed\.housecall6.6 2009-08-12 09:48 . 2009-07-17 14:35 71680 —-a-w- c:\windows\system32\atl.dll 2009-08-12 09:48 . 2009-06-10 12:12 160256 —-a-w- c:\windows\system32\wkssvc.dll 2009-08-12 09:48 . 2009-06-04 12:34 2066432 —-a-w- c:\windows\system32\mstscax.dll 2009-08-12 09:48 . 2009-06-10 12:07 91136 —-a-w- c:\windows\system32\avifil32.dll 2009-08-12 09:48 . 2009-07-14 13:00 313344 —-a-w- c:\windows\system32\wmpdxm.dll 2009-08-12 09:48 . 2009-07-14 12:58 7680 —-a-w- c:\windows\system32\spwmp.dll 2009-08-12 09:48 . 2009-07-14 12:59 4096 —-a-w- c:\windows\system32\dxmasf.dll 2009-08-12 09:48 . 2009-07-14 10:59 8147456 —-a-w- c:\windows\system32\wmploc.DLL 2009-08-04 22:28 . 2009-08-04 22:28 ——– d—–w- c:\program files\Common Files\DivX Shared 2009-08-03 00:31 . 2009-08-04 09:59 ——– d—–w- c:\program files\NOS 2009-08-03 00:11 . 2009-08-03 00:11 ——– d—–w- c:\users\Ed\AppData\Roaming\KodakCredentialStore 2009-08-03 00:10 . 2009-08-03 10:11 ——– d—–w- c:\users\Ed\AppData\Local\KodakGallery 2009-08-03 00:09 . 2009-08-03 00:09 ——– d—–w- c:\users\Ed\AppData\Roaming\Skinux 2009-08-03 00:04 . 2009-08-03 00:04 ——– d—–w- c:\program files\Common Files\Kodak 2009-08-03 00:01 . 2009-08-03 00:01 ——– d—–w- c:\program files\Kodak 2009-07-31 03:42 . 2009-05-22 05:02 225296 —-a-w- c:\windows\system32\drivers\tmxpflt.sys 2009-07-31 03:42 . 2009-05-22 05:00 36368 —-a-w- c:\windows\system32\drivers\tmpreflt.sys 2009-07-31 03:42 . 2009-05-22 04:45 1220120 —-a-w- c:\windows\system32\drivers\vsapint.sys 2009-07-30 17:43 . 2009-06-15 15:24 156672 —-a-w- c:\windows\system32\t2embed.dll 2009-07-30 17:43 . 2009-06-15 15:20 72704 —-a-w- c:\windows\system32\fontsub.dll 2009-07-30 17:43 . 2009-06-15 15:20 10240 —-a-w- c:\windows\system32\dciman32.dll 2009-07-30 17:43 . 2009-06-15 12:52 289792 —-a-w- c:\windows\system32\atmfd.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-08-24 20:39 . 2007-06-02 00:14 ——– d—–w- c:\program files\Dl_cats 2009-08-21 23:20 . 2007-05-26 10:39 ——– d—–w- c:\users\Ed\AppData\Roaming\uTorrent 2009-08-15 16:07 . 2007-05-26 22:55 ——– d—–w- c:\program files\Viewpoint 2009-08-13 07:04 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail 2009-08-04 22:28 . 2008-07-13 13:43 ——– d—–w- c:\program files\DivX 2009-07-31 07:14 . 2008-03-10 04:32 ——– d—–w- c:\program files\Microsoft Silverlight 2009-07-30 20:24 . 2008-02-06 22:37 ——– d—–w- c:\program files\MagicISO 2009-07-21 21:52 . 2009-08-19 17:59 915456 —-a-w- c:\windows\system32\wininet.dll 2009-07-21 21:47 . 2009-08-19 17:59 109056 —-a-w- c:\windows\system32\iesysprep.dll 2009-07-21 21:47 . 2009-08-19 17:59 71680 —-a-w- c:\windows\system32\iesetup.dll 2009-07-21 20:13 . 2009-08-19 17:59 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2009-07-13 15:37 . 2007-12-20 00:28 102408 —-a-w- c:\users\Administrator.Ed-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2009-06-13 00:50 . 2009-06-13 00:50 1878984 —-a-w- c:\users\Ed\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe 2009-06-02 01:16 . 2009-04-07 02:41 15688 —-a-w- c:\windows\system32\lsdelete.exe 2009-05-31 16:09 . 2007-05-26 07:48 102408 —-a-w- c:\users\Ed\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032] "msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "DLCXCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496] "RetroExpress"="c:\progra~1\RETROS~1\RETROS~1.0\RetroExpress.exe" [2007-01-22 9385504] "UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-01-31 1398024] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-30 520024] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableInstallerDetection"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Kodak EasyShare software.lnk backup=c:\windows\pss\Kodak EasyShare software.lnk.CommonStartup backupExtension=.CommonStartup [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe "AOL Fast Start"="c:\program files\AOL 9.0a\AOL.EXE" -b "MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" "HostManager"=c:\program files\Common Files\AOL\1180220016\ee\AOLSoftware.exe "Windows Mobile Device Center"=c:\windows\WindowsMobile\wmdc.exe "WD Button Manager"=WDBtnMgr.exe "mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{6D3BD8CE-9E17-4B48-88CE-09A723BF4921}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{C13FA3BD-2771-4C73-AA2A-65C369EAD167}"= UDP:c:\program files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer "{9FAC5F93-0D6F-47A2-B011-471D0600A771}"= TCP:c:\program files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer "{0348C78C-9E41-4481-BE63-244FFE5BF161}"= UDP:c:\program files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service "{A38E1EF4-9233-43D1-A63E-5CF650DA0F40}"= TCP:c:\program files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service "{795CE53D-C185-416D-9532-CB06F348F371}"= UDP:c:\program files\Common Files\aol\1180220016\ee\aolsoftware.exe:AOL Shared Components "{A0520BBB-7280-4A86-9581-428A6AB7061F}"= TCP:c:\program files\Common Files\aol\1180220016\ee\aolsoftware.exe:AOL Shared Components "{213DB630-9875-45A8-BE98-59547780A6CA}"= UDP:c:\program files\AOL 9.0\waol.exe:AOL "{BE1E7F19-B640-4C39-BDE8-900708AD63EC}"= TCP:c:\program files\AOL 9.0\waol.exe:AOL "{99C41304-E6C7-4F89-B8D0-C2D6FA8E92A0}"= UDP:c:\program files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed "{5020D5D5-B449-4496-8021-DE405B2C22D8}"= TCP:c:\program files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed "{1D936F70-DD93-4052-B8DD-9176054E8531}"= UDP:c:\program files\Common Files\aol\Loader\aolload.exe:AOL Loader "{0B3BA55B-EEC1-4D97-ACF2-C7E6D4999D8D}"= TCP:c:\program files\Common Files\aol\Loader\aolload.exe:AOL Loader "{A3FC5CBC-FDF2-4B64-B565-849647D6D641}"= UDP:c:\program files\Common Files\aol\System Information\sinf.exe:AOL System Information "{D9038000-43FB-457E-AEF1-918E9C1ACCA5}"= TCP:c:\program files\Common Files\aol\System Information\sinf.exe:AOL System Information "{3BF5638C-905E-4676-8600-E6B389C07AE4}"= UDP:c:\program files\Pinnacle\MediaCenter\Settings.exe:Settings.exe "{A3CD580E-C01C-464C-B694-D70A7D4C690D}"= TCP:c:\program files\Pinnacle\MediaCenter\Settings.exe:Settings.exe "{169EA706-E398-4D3F-952E-D2E47FD66CC4}"= UDP:c:\program files\Pinnacle\MediaCenter\PMC.exe:Pmc.exe "{20D258EA-A357-4C24-8614-D5116486C6BE}"= TCP:c:\program files\Pinnacle\MediaCenter\PMC.exe:Pmc.exe "{0E60CBBB-E521-4EE6-B38D-AE4F37B5CCF9}"= UDP:c:\program files\Pinnacle\MediaCenter\PMSInstallInit.exe:PMSInstallInit.exe "{69CFACC5-500A-4C17-9988-081088A30255}"= TCP:c:\program files\Pinnacle\MediaCenter\PMSInstallInit.exe:PMSInstallInit.exe "{FACE9F75-F37A-4A6D-A21C-6A15AA76BD2C}"= UDP:c:\windows\System32\dlcxcoms.exe:Lexmark Communications System "{2BE84858-1E02-4A08-B211-81556FE68F64}"= TCP:c:\windows\System32\dlcxcoms.exe:Lexmark Communications System "{61CA4FFE-9BCC-4BD6-8E5D-A187525A3E7E}"= UDP:c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor "{DA627C25-AA8D-414D-8ECD-E8EECEB787AD}"= TCP:c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor "{08AE6220-8D58-478C-BCBD-30D44F156B16}"= UDP:c:\program files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center "{B5337AA4-4E8A-48AD-93FD-7BF35F8CB99B}"= TCP:c:\program files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center "{5B04971B-D2D9-4F1E-9DDE-947F7409B5E0}"= UDP:c:\program files\AOL 9.0a\waol.exe:AOL "{FBF28CD5-450F-4ED2-BF81-DB36B256F304}"= TCP:c:\program files\AOL 9.0a\waol.exe:AOL "{5C8C72E2-3AE5-4191-84FE-7E2A1E391730}"= UDP:c:\program files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer "{23D8B9A2-78E5-4D84-A507-9AB8672A2F97}"= TCP:c:\program files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer "{B50AE509-BD89-4530-B74A-549288F1EEDE}"= UDP:c:\program files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service "{D6D2EF35-CF68-4193-875B-DFF3A0B34CB5}"= TCP:c:\program files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service "{1B81A6AB-5605-4472-B7F9-18C0E9AC6F90}"= UDP:c:\program files\Common Files\aol\1180220016\ee\aolsoftware.exe:AOL Shared Components "{29AAD373-B49F-4E9D-A231-77D717CEDF81}"= TCP:c:\program files\Common Files\aol\1180220016\ee\aolsoftware.exe:AOL Shared Components "{D778C041-D3A9-45C8-B094-3EBEF3AF19F4}"= UDP:c:\program files\AOL 9.1\waol.exe:AOL "{CC38F09C-6E22-4C8D-9080-93BCC34C3A67}"= TCP:c:\program files\AOL 9.1\waol.exe:AOL "{9E861A71-8A0E-4AF0-8E72-157ACCE8B419}"= UDP:c:\program files\Common Files\aol\Loader\aolload.exe:AOL Loader "{D5AB7266-ABCD-4DE0-9B3A-00659A03BD25}"= TCP:c:\program files\Common Files\aol\Loader\aolload.exe:AOL Loader "{F0C89F6B-4FCF-4C13-9377-F83AE0DE1558}"= UDP:c:\program files\Common Files\aol\System Information\sinf.exe:AOL System Information "{9E7E5C08-A0A9-462E-832C-29649377E3D8}"= TCP:c:\program files\Common Files\aol\System Information\sinf.exe:AOL System Information "{63226177-ACFA-409E-BF8D-4D775789131A}"= UDP:c:\program files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL "{70C281EC-27D0-4521-8EFE-75132C75EA87}"= TCP:c:\program files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL "{4E6FC3DD-146B-49EF-8BA3-E66B433F9513}"= UDP:c:\program files\TurboTax\Deluxe 2007\32bit\ttax.exe:TurboTax "{FD15B6D2-A027-491C-A055-4E34BC662087}"= TCP:c:\program files\TurboTax\Deluxe 2007\32bit\ttax.exe:TurboTax "{BF82E7A7-151C-4584-BA4E-93BDA22FB1AF}"= UDP:c:\program files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:TurboTax Update Manager "{14A5F351-68D0-4A48-A15C-353E81272EA3}"= TCP:c:\program files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:TurboTax Update Manager "TCP Query User{5754B721-0660-4A3F-86B0-766C74C6E29D}c:\\users\\ed\\documents\\miscellany\\torrents\\utorrent.exe"= UDP:c:\users\ed\documents\miscellany\torrents\utorrent.exe:utorrent.exe "UDP Query User{185B03FA-4E92-463D-8709-630239F44A5E}c:\\users\\ed\\documents\\miscellany\\torrents\\utorrent.exe"= TCP:c:\users\ed\documents\miscellany\torrents\utorrent.exe:utorrent.exe "{12A83BDB-B613-435D-B9EB-369B4507FCBC}"= UDP:c:\program files\2K Games\Firaxis Games\Sid Meier's Civilization IV Colonization\Colonization.exe:Sid Meier's Civilization IV Colonization "{4970CDCB-2B5E-4013-B387-B6F1506C3498}"= TCP:c:\program files\2K Games\Firaxis Games\Sid Meier's Civilization IV Colonization\Colonization.exe:Sid Meier's Civilization IV Colonization "{BAF86D92-8E82-4EF7-A6FD-EE3BE429C30B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In) "{5F49CA42-DA02-4ABC-864F-6C339C14DCC7}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In) "{420ECECF-5554-49ED-A160-F723A20463C2}"= UDP:c:\program files\AIM6\aim6.exe:AIM "{3ED63C4C-3CC3-4AFD-9EDC-6DB9E9E8D83C}"= TCP:c:\program files\AIM6\aim6.exe:AIM [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [4/27/2009 9:17 PM 64160] R1 ElRawDisk;ElRawDisk;c:\windows\System32\drivers\elrawdsk.sys [9/8/2008 10:01 PM 12800] R1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\System32\drivers\tmlwf.sys [2/15/2008 11:39 PM 141840] R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service –> c:\windows\system32\dlcxcoms.exe -service [?] R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 6:45 AM 13088] R2 tmpreflt;tmpreflt;c:\windows\System32\drivers\tmpreflt.sys [7/30/2009 11:42 PM 36368] R2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\System32\drivers\tmwfp.sys [2/15/2008 11:39 PM 234512] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456] S2 tmevtmgr;tmevtmgr;c:\windows\System32\drivers\tmevtmgr.sys [2/15/2008 11:39 PM 52624] S3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~2\TmPfw.exe [6/12/2008 8:23 AM 488768] S3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [6/12/2008 8:23 AM 648456] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr bthsvcs REG_MULTI_SZ BthServ [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-08-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 01:17] 2009-08-24 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-04-07 04:37] 2009-08-24 c:\windows\Tasks\User_Feed_Synchronization-{48CC167D-682B-48B6-97F0-6FB5452223D4}.job - c:\windows\system32\msfeedssync.exe [2009-08-19 20:13] . - - - - ORPHANS REMOVED - - - - HKCU-Run-Aim6 - (no file) . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ig?hl=en&source;=iglk IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 Trusted Zone: turbotax.com DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab FF - ProfilePath - FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ —- FIREFOX POLICIES —- c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); . . ——- File Associations ——- . VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … HKLM\Software\Microsoft\Windows\CurrentVersion\Run DLCXCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_USERS\S-1-5-21-2541251621-127953674-580709905-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:7a,21,95,75,a9,80,7a,8b,f7,de,b0,0d,5c,69,da,a9,6c,e1,9d,e1,6b,69,ff, e7,a4,38,0b,af,57,ff,07,51,29,db,32,a3,70,7d,40,2f,a7,27,b3,b7,5e,ad,96,5b,\ "??"=hex:af,35,e6,37,84,8d,94,50,14,8b,cf,3d,b2,c5,26,62 [HKEY_USERS\S-1-5-21-2541251621-127953674-580709905-1000\Software\SecuROM\License information*] "datasecu"=hex:df,c5,32,bf,71,e0,84,6d,91,a2,87,45,f0,99,4b,00,66,b8,2e,64,e1, 07,47,15,35,c7,6a,e3,f1,f5,fc,9d,6d,9b,b8,fa,c6,4d,b0,0c,08,69,98,c0,3a,09,\ "rkeysecu"=hex:c7,43,24,f3,e3,ea,83,1d,cd,35,c0,48,e7,53,63,a8 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\Windows\\system32\\OLE32.DLL" "cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,54,84,02,67,15, 4e,f6,fb,c8,28,51,af,b0,29,a3,98,db,09,59,df,a3,97,41,24,e2,63,26,f1,3f,c8,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\Windows\\system32\\OLE32.DLL" "bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,3b,86,20,49,36, 0a,88,62,71,3b,04,66,8b,46,0d,96,b5,08,4d,20,63,d6,f0,a3,6a,9c,d6,61,af,45,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\Windows\\system32\\OLE32.DLL" "2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,d9,bb,d7,31,cc, 55,13,6b,25,da,ec,7e,55,20,c9,26,94,1b,ac,aa,a2,67,56,1a,ff,7c,85,e0,43,d4,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\Windows\\system32\\OLE32.DLL" "2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,08,b3,fd,9e,13, a6,e2,1c,3e,1e,9e,e0,57,5a,93,61,4f,82,98,8d,07,af,6d,f9,86,8c,21,01,be,91,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\Windows\\system32\\OLE32.DLL" "caaeda5fd7a9ed7697d9686d4b818472"=hex:e9,02,6c,fa,fb,1d,47,57,6c,ea,1c,ae,ef, b7,b7,22,cd,44,cd,b9,a6,33,6c,cd,f3,d6,7c,8a,f6,90,aa,98,f5,1d,4d,73,a8,13,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\Windows\\system32\\OLE32.DLL" "a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,6f,02,55,fd,23, 22,d0,2e,b0,18,ed,a7,3f,8d,37,a4,e8,ba,1c,a8,60,99,ad,2d,df,20,58,62,78,6b,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\Windows\\system32\\OLE32.DLL" "4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,3e,1e,a0,44,d4, 47,0d,c8,31,77,e1,ba,b1,f8,68,02,6e,10,20,97,4b,55,a1,12,fb,a7,78,e6,12,2f,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\Windows\\system32\\OLE32.DLL" "1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,12,1e,07,9a,0b, 72,27,9f,83,6c,56,8b,a0,85,96,ab,db,5a,87,aa,a5,26,7d,b2,01,3a,48,fc,e8,04,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\Windows\\system32\\OLE32.DLL" "1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,93,a8,2b,af,b0, 2d,a2,14,51,fa,6e,91,28,9e,14,cc,d1,b5,b1,15,59,b9,2c,73,f6,0f,4e,58,98,5b,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\Windows\\system32\\OLE32.DLL" "f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,4d,5a,0d,b4,02, fc,14,06,b1,cd,45,5a,a8,c4,f8,b9,d8,f4,a7,07,55,ca,2a,ca,3d,ce,ea,26,2d,45,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\Windows\\system32\\OLE32.DLL" "fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,eb,20,b6,f9,aa, 10,4c,c5,e3,0e,66,d5,eb,bc,2f,6b,d2,25,29,35,48,58,14,82,2a,b7,cc,b5,b9,7f,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\Windows\\system32\\OLE32.DLL" "8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,f8,9b,ab,b5,77, b7,65,20,fa,ea,66,7f,d4,3b,6b,70,15,95,df,91,5f,10,46,0a,6c,43,2d,1e,aa,22,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2009-08-24 16:58 ComboFix-quarantined-files.txt 2009-08-24 20:58 Pre-Run: 8,844,324,864 bytes free Post-Run: 10,532,212,736 bytes free 389 — E O F — 2009-08-19 18:00
Well, Just when I thought I may be free of the Mal Hifrm, the Trend Micro warning just started up again. Please help me get rid of this. Thank you!

Well,

Just when I thought I may be free of the Mal Hifrm, the Trend Micro warning just started up again. Please help me get rid of this.

Thank you!

Where is it showing that it found it?
System Restore?
Qoobox?
It always says it's found in: C:\Users\Ed\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3V91VN6I\ Of course the temp file in the Content.IE5 folder, in this case 3V91VN6I, is different each time. I have to close out AOL and Explorer processes through the task manager, then I delete the contents of the specified file. I tried to delete the Content.IE5 folder entirely, but am not allowed that function by the pc. Please help, this has been going on for weeks now, and I see others on this forum have been suffering the same problem. Thanks! Ed
Those are temp files from the internet.
What websites are you going to?

ATF cleaner will remove them.

Set you IE settings:

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
I will set the Explorer options as you recommend. However, I am not visiting any new sites. And I think this is a worm, judging from other posts on this site. Your colleagues seem to think it's a lot more serious than just a temp. int. file. Are you sure it's not a worm?
You didn't answer my question about what sites you're visiting to get those infected temp files.

You do understand where the Temporary Internet Files\Content.IE5 files are coming from, right?

http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Note: You will need to use Internet explorer for this scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is unticked, and the option Scan unwanted applications is checked
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.
Thanks for your continues help. I certainly do understand that temp int. files go in the Content.IE5 folder. I visit too many sites to know which one triggered the Trend Micro Mal Hifrm warning. I ran ESET scan as you instructed and there were no infected files found. The log is: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK Did I do something wrong? Should I rerun it? Thanks once again!

Thanks for your continues help.

I certainly do understand that temp int. files go in the Content.IE5 folder.

I visit too many sites to know which one triggered the Trend Micro Mal Hifrm warning.

I ran ESET scan as you instructed and there were no infected files found.

The log is:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK

Did I do something wrong? Should I rerun it?

Thanks once again!

If it didn't find any infections then I'd say your pc is clean.
You'll always get temp files and cookies when you visit websites.

You can run this one if you want.

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


After that click on Security level then choose Customize then click on the tab that says Heuristic Analyzer then choose Enable Deep rootkit search then choose ok.
Then choose OK again then you are back to the main screen.

  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left un-neutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

Hi, Thanks for recommending Kaspersky Scan. I just finished it and it did find a worm (virus), please see below. Detected ——– Status Object —— —— deleted: virus Worm.Win32.AutoRun.ek File: C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\1408.tmp//CryptFF.b I deleted this file. Would you recommend I take any other actions? Thanks again, Ed
I suggest you do this now.

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    To be on the safe side, I would also change all my passwords.


    Here's my usual all clean post

    Log looks good :D


    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.


I would suggest you read How to Prevent Malware:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI