This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE Hijacked [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When my son clicks on his IE icon he gets XP Antispyware 2012 Firewall alert. It says there is malware and spyware and viruses detected. It asks to activate XP Antispyware 2012 (recommended) or No, continue unprotected (Not recommended). When clicking yes it wants money. When you click no it does not allow IE to open to a web page. I have attached a Hijackthis log below. Thank you in advance for any and all assistance!!



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:00:11 PM, on 12/13/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17103)
Boot mode: Normal

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\ibmpmsvc.exe
C:\WINXP\system32\Ati2evxx.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\S24EvMon.exe
C:\WINXP\system32\spoolsv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINXP\system32\RegSrvc.exe
C:\WINXP\system32\svchost.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINXP\system32\TpKmpSVC.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Configuresoft\CSI Remote Client\CSIRemoteCSvc.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\WINXP\TEMP\YM7D57.EXE
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINXP\system32\Ati2evxx.exe
C:\WINXP\Explorer.EXE
C:\WINXP\system32\RunDll32.exe
C:\WINXP\AGRSMMSG.exe
C:\WINXP\system32\taskswitch.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINXP\system32\dla\tfswctrl.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\NPDTray.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\ctfmon.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\cms.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Administrator\Desktop\Scott.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.Chr-Hansen.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://jsonline.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.Chr-Hansen.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.Chr-Hansen.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Chr. Hansen
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINXP\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINXP\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINXP\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINXP\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [CoolSwitch] C:\WINXP\system32\taskswitch.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [NPDTray] C:\PROGRA~1\ThinkPad\UTILIT~1\NPDTray.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [dla] C:\WINXP\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINXP\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINXP\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.addictinggames.com/sports-games/streetsesh.jsp"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: VPN Client.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to AMV Converter… - C:\Program Files\MP3 Player Utilities 4.19\AMVConverter\grab.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINXP\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINXP\system32\browseui.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINXP\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Configuresoft ECM Remote Client (CSIRemoteC) - Configuresoft, Inc. - C:\Program Files\Configuresoft\CSI Remote Client\CSIRemoteCSvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINXP\system32\ibmpmsvc.exe
O23 - Service: iPassConnectEngine - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPassPeriodicUpdateApp - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
O23 - Service: iPassPeriodicUpdateService - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINXP\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINXP\system32\S24EvMon.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINXP\system32\TpKmpSVC.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: VNC Server (winvnc) - AT&T Research Labs Cambridge - C:\Program Files\ORL\VNC\WinVNC.exe

–
End of file - 11150 bytes
:welcome:

Yep, do not pay these thieves for a bogus program, you would be giving your credit card number to cyber thieves.

Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
Thanks, Ken! Log posted below. Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7622 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 12/15/2011 6:05:06 PM mbam-log-2011-12-15 (18-05-06).txt Scan type: Quick scan Objects scanned: 171424 Time elapsed: 10 minute(s), 52 second(s) Memory Processes Infected: 1 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 2 Registry Data Items Infected: 4 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: c:\documents and settings\administrator\local settings\application data\cms.exe (Trojan.ExeShell.Gen) -> 4040 -> Unloaded process successfully. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{AEB04B5E-C981-47a9-B847-33EE4C92F6B9} (PUP.Magoo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AEB04B5E-C981-47a9-B847-33EE4C92F6B9} (PUP.Magoo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{02F0243C-2E71-4A1A-A790-6C30888119D0} (PUP.Magoo) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Value: (default) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Value: ForceClassicControlPanel -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Administrator\Local Settings\Application Data\cms.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\documents and settings\administrator\local settings\application data\cms.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully.
:thumbup:


Lets check a bit further


Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]






Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-15 21:28:31 —————————– 21:28:31.356 OS Version: Windows 5.1.2600 Service Pack 3 21:28:31.356 Number of processors: 1 586 0x905 21:28:31.356 ComputerName: USLT0112 UserName: 21:28:31.767 Initialize success 21:28:58.726 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 21:28:58.726 Disk 0 Vendor: FUJITSU_MHT2040AH 006C Size: 34728MB BusType: 3 21:29:00.749 Disk 0 MBR read successfully 21:29:00.749 Disk 0 MBR scan 21:29:00.749 Disk 0 Windows XP default MBR code 21:29:00.749 Disk 0 scanning sectors +71120896 21:29:00.829 Disk 0 scanning C:\WINXP\system32\drivers 21:29:15.750 Service scanning 21:29:17.663 Modules scanning 21:29:25.464 Disk 0 trace - called modules: 21:29:25.494 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 21:29:25.494 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a22bab8] 21:29:25.504 3 CLASSPNP.SYS[f7647fd7] -> nt!IofCallDriver -> \Device\00000084[0x8a1c13b8] 21:29:25.504 5 ACPI.sys[f750e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a207d98] 21:29:25.835 Scan finished successfully 21:30:06.503 Disk 0 MBR has been saved successfully to "E:\MBR.dat" 21:30:06.653 The log file has been saved successfully to "E:\aswMBR.txt" . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.5730.13 Run by [removed] at 21:30:29 on 2011-12-15 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1279.816 [GMT -6:00] . FW: Trend Micro OfficeScan Enterprise Client Firewall *Disabled* . ============== Running Processes =============== . C:\WINXP\system32\ibmpmsvc.exe C:\WINXP\system32\Ati2evxx.exe C:\WINXP\system32\svchost -k DcomLaunch svchost.exe C:\WINXP\System32\svchost.exe -k netsvcs C:\WINXP\system32\S24EvMon.exe svchost.exe svchost.exe C:\WINXP\system32\spoolsv.exe C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe C:\WINXP\system32\RegSrvc.exe C:\WINXP\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe C:\WINXP\system32\TpKmpSVC.exe C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe C:\Program Files\ORL\VNC\WinVNC.exe C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe C:\Program Files\Configuresoft\CSI Remote Client\CSIRemoteCSvc.exe C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe c:\program files\lenovo\system update\suservice.exe C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe C:\WINXP\TEMP\MP3A96.EXE C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe C:\WINXP\System32\svchost.exe -k HTTPFilter C:\WINXP\system32\1XConfig.exe C:\WINXP\system32\Ati2evxx.exe C:\WINXP\Explorer.EXE . ============== Pseudo HJT Report =============== . uStart Page = hxxp://jsonline.com/ uWindow Title = Windows Internet Explorer provided by Chr. Hansen uDefault_Page_URL = hxxp://www.Chr-Hansen.com mDefault_Page_URL = hxxp://www.Chr-Hansen.com mStart Page = hxxp://www.Chr-Hansen.com uInternet Settings,ProxyOverride = ;*.local mSearchAssistant = hxxp://www.google.com/ie_rsearch.html mCustomizeSearch = hxxp://www.google.com/ie_rsearch.html BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\winxp\system32\dla\tfswshx.dll uRun: [ctfmon.exe] c:\winxp\system32\ctfmon.exe uRunOnce: [Shockwave Updater] c:\winxp\system32\adobe\shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.addictinggames.com/sports-games/streetsesh.jsp" mRun: [IMJPMIG8.1] "c:\winxp\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [PHIME2002ASync] c:\winxp\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\winxp\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [WinVNC] "c:\program files\orl\vnc\WinVNC.exe" -servicehelper mRun: [OfficeScanNT Monitor] "c:\program files\trend micro\officescan client\pccntmon.exe" -HideWindow mRun: [CoolSwitch] c:\winxp\system32\taskswitch.exe mRun: [TPHOTKEY] c:\progra~1\lenovo\pkgmgr\hotkey\TPHKMGR.exe mRun: [BMMGAG] RunDll32 c:\progra~1\thinkpad\utilit~1\pwrmonit.dll,StartPwrMonitor mRun: [BMMLREF] c:\program files\thinkpad\utilities\BMMLREF.EXE mRun: [BMMMONWND] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatInfEx.dll,BMMAutonomicMonitor mRun: [BLOG] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog mRun: [TPKMAPHELPER] c:\program files\thinkpad\utilities\TpKmapAp.exe -helper mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe mRun: [NPDTray] c:\progra~1\thinkpad\utilit~1\NPDTray.exe mRun: [TP4EX] tp4ex.exe mRun: [dla] c:\winxp\system32\dla\tfswctrl.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [TVT Scheduler Proxy] c:\program files\common files\lenovo\scheduler\scheduler_proxy.exe mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\winxp\installer\{24c67b54-0718-445e-b663-3138d9246bd1}\Icon3E5562ED7.ico mPolicies-explorer: NoStrCmpLogical = 1 (0x1) IE: Add to AMV Converter… - c:\program files\mp3 player utilities 4.19\amvconverter\grab.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_01\bin\npjpi150_01.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL LSP: mswsock.dll DPF: Microsoft XML Parser for Java - file://c:\winxp\java\classes\xmldso.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {32505657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab DPF: {41F17733-B041-4099-A042-B518BB6A408C} - hxxp://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{15C3EA8A-758D-4266-972E-F24EA14B1FF9} : DhcpNameServer = [removed] [removed] Notify: ACNotify - ACNotify.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: tpfnf2 - notifyf2.dll Notify: tphotkey - tphklock.dll LSA: Notification Packages = scecli ACGina . ============= SERVICES / DRIVERS =============== . R1 TPPWR;TPPWR;c:\winxp\system32\drivers\TPPWR.SYS [2008-12-22 16384] R2 CSIRemoteC;Configuresoft ECM Remote Client;c:\program files\configuresoft\csi remote client\CSIRemoteCSvc.exe [2006-4-25 102400] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-12-15 366152] R2 OfcPfwSvc;OfficeScanNT Personal Firewall;c:\program files\trend micro\officescan client\OfcPfwSvc.exe [2006-8-9 233552] R2 TmFilter;Trend Micro Filter;c:\program files\trend micro\officescan client\tmxpflt.sys [2005-11-9 205328] R2 TmPreFilter;Trend Micro PreFilter;c:\program files\trend micro\officescan client\tmpreflt.sys [2005-11-9 36368] R3 MBAMProtector;MBAMProtector;c:\winxp\system32\drivers\mbam.sys [2011-12-15 22216] S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\winxp\system32\drivers\mbamswissarmy.sys –> c:\winxp\system32\drivers\mbamswissarmy.sys [?] . =============== File Associations =============== . .exe=n1m . =============== Created Last 30 ================ . 2011-12-15 23:51:47 ——– d—–w- c:\documents and settings\administrator\application data\Malwarebytes 2011-12-15 23:51:36 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2011-12-15 23:51:33 22216 —-a-w- c:\winxp\system32\drivers\mbam.sys 2011-12-15 23:51:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-12-14 01:19:27 ——– d—–w- c:\winxp\system32\appmgmt 2011-12-01 22:40:10 ——– d—–w- c:\program files\DictionaryBossEI . ==================== Find3M ==================== . 2011-10-10 14:22:41 692736 —-a-w- c:\winxp\system32\inetcomm.dll 2011-09-28 07:06:50 599040 —-a-w- c:\winxp\system32\crypt32.dll 2011-09-26 17:41:20 611328 —-a-w- c:\winxp\system32\uiautomationcore.dll 2011-09-26 17:41:20 220160 —-a-w- c:\winxp\system32\oleacc.dll 2011-09-26 17:41:14 20480 —-a-w- c:\winxp\system32\oleaccrc.dll . ============= FINISH: 21:31:28.42 ===============

Attachments:

Hi,

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
Ok, Ken…..I ran the program. It took a little over an hour to complete but I then never saw an option for a "list of found threats" or "export to text file". When the scan finished running there was only a "Finish" button. (I've attached a screen shot of what I saw.) When I hit the finish button the program just closed. Did I do something wrong? Did I miss something? Also, for what it's worth, when I go to my Start button to fire up a program (Notepad, for instance) I get the "Open with" dialog box. Sigh.
Did you notice if it found threats or no threats where found. Looking over your logs lets do this

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Ken….it popped up a couple of dialog boxes explaining that there was a particularly nasty rootkit virus hidden and instructed that it may take some time. The program ran well. Log below….




ComboFix 11-12-16.03 - Administrator 12/16/2011 19:04:47.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1279.859 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: Trend Micro OfficeScan Enterprise Client Firewall *Disabled* {8DCD034B-D3BC-4798-A8C5-B48C06E24D6A}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\globalwinst\WINDOWS
c:\program files\DictionaryBossEI
c:\program files\TelevisionFanatic
c:\program files\TelevisionFanatic\bar\Message\COMMON\8_step1.gif
c:\program files\TelevisionFanatic\bar\Message\COMMON\index.htm
c:\program files\TelevisionFanatic\bar\Message\COMMON\rebut4b.htm
c:\program files\TelevisionFanatic\bar\Message\COMMON\shield.png
c:\program files\TelevisionFanaticEI
c:\winxp\$NtUninstallKB25698$
c:\winxp\$NtUninstallKB25698$\1305225646\@
c:\winxp\$NtUninstallKB25698$\1305225646\bckfg.tmp
c:\winxp\$NtUninstallKB25698$\1305225646\cfg.ini
c:\winxp\$NtUninstallKB25698$\1305225646\Desktop.ini
c:\winxp\$NtUninstallKB25698$\1305225646\keywords
c:\winxp\$NtUninstallKB25698$\1305225646\kwrd.dll
c:\winxp\$NtUninstallKB25698$\1305225646\L\izotaeda
c:\winxp\$NtUninstallKB25698$\1305225646\lsflt7.ver
c:\winxp\$NtUninstallKB25698$\1305225646\U\00000001.@
c:\winxp\$NtUninstallKB25698$\1305225646\U\00000002.@
c:\winxp\$NtUninstallKB25698$\1305225646\U\00000004.@
c:\winxp\$NtUninstallKB25698$\1305225646\U\80000000.@
c:\winxp\$NtUninstallKB25698$\1305225646\U\80000004.@
c:\winxp\$NtUninstallKB25698$\1305225646\U\80000032.@
c:\winxp\$NtUninstallKB25698$\4114919432
c:\winxp\CSC\d6
c:\winxp\system32\PowerToyReadme.htm
.
.
((((((((((((((((((((((((( Files Created from 2011-11-17 to 2011-12-17 )))))))))))))))))))))))))))))))
.
.
2011-12-16 21:59 . 2011-12-16 21:59 ——– d—–w- c:\program files\ESET
2011-12-15 23:51 . 2011-12-15 23:51 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2011-12-15 23:51 . 2011-12-15 23:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-15 23:51 . 2011-12-15 23:51 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-15 23:51 . 2011-08-31 23:00 22216 —-a-w- c:\winxp\system32\drivers\mbam.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:22 . 2008-12-22 17:03 692736 —-a-w- c:\winxp\system32\inetcomm.dll
2011-09-28 07:06 . 2008-12-22 19:47 599040 —-a-w- c:\winxp\system32\crypt32.dll
2011-09-26 17:41 . 2008-12-22 19:47 220160 —-a-w- c:\winxp\system32\oleacc.dll
2011-09-26 17:41 . 2008-07-30 01:59 611328 —-a-w- c:\winxp\system32\uiautomationcore.dll
2011-09-26 17:41 . 2008-12-22 19:47 20480 —-a-w- c:\winxp\system32\oleaccrc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\winxp\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\winxp\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\winxp\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"AGRSMMSG"="AGRSMMSG.exe" [2003-02-14 88107]
"WinVNC"="c:\program files\ORL\VNC\WinVNC.exe" [2001-03-16 208896]
"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2006-02-07 356352]
"CoolSwitch"="c:\winxp\system32\taskswitch.exe" [2002-03-19 45632]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-10-02 94208]
"BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2005-04-19 110592]
"BMMLREF"="c:\program files\ThinkPad\Utilities\BMMLREF.EXE" [2005-04-19 20480]
"BMMMONWND"="c:\progra~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2005-04-19 396288]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-04-19 208896]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-04 897024]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2008-06-05 242976]
"NPDTray"="c:\progra~1\ThinkPad\UTILIT~1\NPDTray.exe" [2005-05-17 221184]
"TP4EX"="tp4ex.exe" [2002-09-04 53248]
"dla"="c:\winxp\system32\dla\tfswctrl.exe" [2003-10-22 114741]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-08-21 487424]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-08-16 425984]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-08-16 143360]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2007-02-07 344064]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-06-24 126976]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-06-24 561152]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-22 734872]
VPN Client.lnk - c:\winxp\Installer\{24C67B54-0718-445E-B663-3138D9246BD1}\Icon3E5562ED7.ico [2008-12-22 6144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Taskman"=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-06 04:45 28672 —-a-w- c:\winxp\system32\notifyf2.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-12-01 01:16 24576 —-a-w- c:\winxp\system32\tphklock.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R1 TPPWR;TPPWR;c:\winxp\system32\drivers\TPPWR.SYS [12/22/2008 11:23 AM 16384]
R2 CSIRemoteC;Configuresoft ECM Remote Client;c:\program files\Configuresoft\CSI Remote Client\CSIRemoteCSvc.exe [4/25/2006 4:40 PM 102400]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/15/2011 5:51 PM 366152]
R2 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\tmxpflt.sys [11/9/2005 12:34 PM 205328]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\tmpreflt.sys [11/9/2005 12:34 PM 36368]
R3 MBAMProtector;MBAMProtector;c:\winxp\system32\drivers\mbam.sys [12/15/2011 5:51 PM 22216]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\winxp\system32\drivers\mbamswissarmy.sys –> c:\winxp\system32\drivers\mbamswissarmy.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - IPFILTERDRIVER
.
Contents of the 'Scheduled Tasks' folder
.
2008-12-26 c:\winxp\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2008-12-22 23:38]
.
2011-12-17 c:\winxp\Tasks\User_Feed_Synchronization-{69B9586A-FB0B-483B-8BA1-7E33D09EF9B3}.job
- c:\winxp\system32\msfeedssync.exe [2007-08-13 23:36]
.
2011-12-17 c:\winxp\Tasks\User_Feed_Synchronization-{DACB6900-9B63-4709-9D33-6E8C737E5AA1}.job
- c:\winxp\system32\msfeedssync.exe [2007-08-13 23:36]
.
2011-12-17 c:\winxp\Tasks\WGASetup.job
- c:\winxp\system32\KB905474\wgasetup.exe [2009-12-25 04:18]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://jsonline.com/
mStart Page = hxxp://www.Chr-Hansen.com
uInternet Settings,ProxyOverride = ;*.local
IE: Add to AMV Converter… - c:\program files\MP3 Player Utilities 4.19\AMVConverter\grab.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
DPF: Microsoft XML Parser for Java - file://c:\winxp\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
.
Notify-ACNotify - ACNotify.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-16 19:14
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-583907252-789336058-1060284298-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c5,8e,c8,c1,e1,b9,8a,47,97,96,c7,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c5,8e,c8,c1,e1,b9,8a,47,97,96,c7,\
.
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1272)
c:\winxp\system32\tvt_gina.dll
c:\program files\ThinkPad\ConnectUtilities\ACGina.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACON.dll
c:\winxp\system32\WININET.dll
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgr.dll
c:\program files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll
c:\program files\ThinkPad\ConnectUtilities\ACTurinSupport.dll
c:\program files\ThinkPad\ConnectUtilities\AcSmBiosHelper.dll
c:\program files\ThinkPad\ConnectUtilities\AcAdaptersInfo.dll
c:\program files\ThinkPad\ConnectUtilities\Res\US\ACGinaRes.dll
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\winxp\system32\Ati2evxx.dll
c:\winxp\system32\tphklock.dll
.
- - - - - - - > 'explorer.exe'(1964)
c:\winxp\system32\WININET.dll
c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll
c:\winxp\system32\IEFRAME.dll
.
———————— Other Running Processes ————————
.
c:\winxp\system32\ibmpmsvc.exe
c:\winxp\system32\Ati2evxx.exe
c:\winxp\system32\S24EvMon.exe
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
c:\program files\Trend Micro\OfficeScan Client\ntrtscan.exe
c:\winxp\system32\RegSrvc.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\program files\Trend Micro\OfficeScan Client\tmlisten.exe
c:\winxp\system32\TpKmpSVC.exe
c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
c:\program files\lenovo\system update\suservice.exe
c:\winxp\system32\wbem\unsecapp.exe
c:\program files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
c:\winxp\TEMP\HC4EE2.EXE
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\winxp\system32\1XConfig.exe
c:\winxp\system32\Ati2evxx.exe
c:\winxp\AGRSMMSG.exe
c:\winxp\system32\RunDll32.exe
c:\program files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-12-16 19:18:58 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-17 01:18
.
Pre-Run: 17,644,081,152 bytes free
Post-Run: 17,852,383,232 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINXP
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINXP="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 32E957E6AEEE57C98EDE984A331577B8
After a quick test drive it appears to be running MUCH better now. Obviously no false popups asking for money. Quick on the internet. All windows based programs seem to be working well. Were you able to tell what game my son was playing/authorized when the added junk was downloaded? I saw some "Televison fanatic" and "Dictionary something-or-another" on the IE bar at the top when he was experiencing problems. I would assume this was packaged with some other game or something that he downloaded and the problems began??
Good Morning,

c:\program files\TelevisionFanatic <—Combofix removed this also, its a site and Program to stay away from.



This also was on your logs, another site to stay away from

O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINXP\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.addictinggames.com/sports-games/streetsesh.jsp"


Glad things are back to normal, kids, you gotta love im, have 4 myself but they all think there immune to this stuff

Any other issues ?
All seems to be well. I think he visits addictinggames web site quite often to play stuff…..I'll have to keep him outta there. Once again, thanks to Whatthetech (Tom Coyote), my hide has been saved. I really appreciate it! I'd really like to give back and am seriously considering the classroom to become a helper here. My only concern is in the summertime I am quite active outdoors with my kids and I'm not sure I could dedicate as much time as required then. Any thoughts?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI