This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

win32, is most likely more than this [Closed]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i havent been able to find any traces of trend micro, so i believe it worked thanks for all your help do you want me to run one last scan for you to look at?
. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 1/24/2008 5:37:01 PM System Uptime: 6/4/2012 3:20:30 PM (82 hours ago) . Motherboard: Dell Inc. | | 0NX907 Processor: Intel® Core™2 Duo CPU T5270 @ 1.40GHz | Microprocessor | 1396/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 72 GiB total, 34.279 GiB free. D: is CDROM () E: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP387: 4/17/2012 2:03:25 AM - System Checkpoint RP388: 4/17/2012 10:00:27 AM - Software Distribution Service 3.0 RP389: 4/17/2012 4:22:46 PM - Software Distribution Service 3.0 RP390: 4/17/2012 11:28:20 PM - Software Distribution Service 3.0 RP391: 4/18/2012 10:00:26 AM - Software Distribution Service 3.0 RP392: 4/18/2012 11:56:45 PM - Software Distribution Service 3.0 RP393: 4/19/2012 10:00:25 AM - Software Distribution Service 3.0 RP394: 4/20/2012 1:04:59 AM - Software Distribution Service 3.0 RP395: 4/20/2012 10:00:19 AM - Software Distribution Service 3.0 RP396: 4/21/2012 10:46:33 AM - System Checkpoint RP397: 4/22/2012 12:04:00 AM - Software Distribution Service 3.0 RP398: 4/22/2012 1:59:30 AM - Software Distribution Service 3.0 RP399: 4/23/2012 2:56:13 AM - System Checkpoint RP400: 4/23/2012 7:47:06 AM - Software Distribution Service 3.0 RP401: 4/24/2012 7:50:36 AM - Software Distribution Service 3.0 RP402: 4/25/2012 7:50:07 AM - Software Distribution Service 3.0 RP403: 4/25/2012 11:19:37 PM - Removed Kaspersky Internet Security 2010. RP404: 4/26/2012 11:14:54 PM - Software Distribution Service 3.0 RP405: 4/27/2012 11:51:52 PM - System Checkpoint RP406: 4/28/2012 1:58:52 PM - Software Distribution Service 3.0 RP407: 4/29/2012 2:16:23 AM - Software Distribution Service 3.0 RP408: 4/29/2012 10:00:19 AM - Software Distribution Service 3.0 RP409: 4/30/2012 8:02:20 AM - Software Distribution Service 3.0 RP410: 4/30/2012 10:00:19 AM - Software Distribution Service 3.0 RP411: 5/1/2012 10:00:19 AM - Software Distribution Service 3.0 RP412: 5/2/2012 10:57:04 AM - System Checkpoint RP413: 5/2/2012 1:37:09 PM - Software Distribution Service 3.0 RP414: 5/3/2012 1:36:50 PM - Software Distribution Service 3.0 RP415: 5/4/2012 3:42:57 PM - Software Distribution Service 3.0 RP416: 5/5/2012 3:41:44 PM - Software Distribution Service 3.0 RP417: 5/6/2012 2:05:09 AM - Software Distribution Service 3.0 RP418: 5/6/2012 3:42:19 PM - Software Distribution Service 3.0 RP419: 5/7/2012 9:38:18 AM - Removed Java™ 6 Update 18 RP420: 5/7/2012 9:39:36 AM - Installed Java™ 6 Update 32 RP421: 5/7/2012 3:42:15 PM - Software Distribution Service 3.0 RP422: 5/8/2012 3:41:55 PM - Software Distribution Service 3.0 RP423: 5/9/2012 3:41:56 PM - Software Distribution Service 3.0 RP424: 5/10/2012 4:06:41 PM - System Checkpoint RP425: 5/11/2012 7:41:44 AM - Software Distribution Service 3.0 RP426: 5/12/2012 7:46:27 AM - System Checkpoint RP427: 5/12/2012 10:00:20 AM - Software Distribution Service 3.0 RP428: 5/12/2012 10:38:23 AM - Software Distribution Service 3.0 RP429: 5/13/2012 2:07:13 AM - Software Distribution Service 3.0 RP430: 5/14/2012 2:34:32 AM - System Checkpoint RP431: 5/14/2012 8:41:07 AM - Software Distribution Service 3.0 RP432: 5/15/2012 8:40:03 AM - Software Distribution Service 3.0 RP433: 5/16/2012 8:48:06 AM - System Checkpoint RP434: 5/16/2012 10:57:47 PM - Software Distribution Service 3.0 RP435: 5/17/2012 10:54:59 PM - Software Distribution Service 3.0 RP436: 5/18/2012 10:55:34 PM - Software Distribution Service 3.0 RP437: 5/20/2012 9:44:32 AM - System Checkpoint RP438: 5/21/2012 8:42:02 AM - Software Distribution Service 3.0 RP439: 5/21/2012 10:00:17 AM - Software Distribution Service 3.0 RP440: 5/22/2012 8:42:17 AM - Software Distribution Service 3.0 RP441: 5/22/2012 10:00:18 AM - Software Distribution Service 3.0 RP442: 5/23/2012 9:30:10 AM - Software Distribution Service 3.0 RP443: 5/25/2012 10:37:01 AM - System Checkpoint RP444: 5/26/2012 1:50:29 AM - Installed HiJackThis RP445: 5/26/2012 9:50:56 AM - Software Distribution Service 3.0 RP446: 5/27/2012 1:35:12 AM - Software Distribution Service 3.0 RP447: 5/28/2012 2:28:41 AM - System Checkpoint RP448: 5/29/2012 1:11:31 AM - Software Distribution Service 3.0 RP449: 5/30/2012 1:15:18 AM - System Checkpoint RP450: 5/30/2012 4:10:22 PM - Software Distribution Service 3.0 RP451: 5/31/2012 10:34:49 AM - Removed Java™ 6 Update 32 RP452: 5/31/2012 10:35:45 AM - Installed Java™ 6 Update 32 RP453: 5/31/2012 4:10:29 PM - Software Distribution Service 3.0 RP454: 6/1/2012 4:11:28 PM - Software Distribution Service 3.0 RP455: 6/2/2012 4:10:34 PM - Software Distribution Service 3.0 RP456: 6/3/2012 1:50:44 AM - Software Distribution Service 3.0 RP457: 6/3/2012 4:10:04 PM - Software Distribution Service 3.0 RP458: 6/4/2012 10:00:17 AM - Software Distribution Service 3.0 RP459: 6/5/2012 9:59:24 AM - Software Distribution Service 3.0 RP460: 6/6/2012 10:29:30 AM - System Checkpoint RP461: 6/6/2012 3:32:12 PM - Software Distribution Service 3.0 RP462: 6/7/2012 3:31:31 PM - Software Distribution Service 3.0 . ==== Installed Programs ====================== . Adobe Flash Player 10 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 8.1.3 Adobe Shockwave Player 11.5 America Online (Choose which version to remove) Apple Application Support Apple Mobile Device Support Apple Software Update Bonjour Broadcom Management Programs Browser Address Error Redirector CCleaner Compatibility Pack for the 2007 Office system Conexant HDA D330 MDC V.92 Modem Content Transfer Corel WordPerfect Suite 8 Dell Network Assistant Dell Support Center (Support Software) Dell Touchpad Digital Line Detect ESET Online Scanner v3 Google Desktop Google Earth Google Toolbar for Internet Explorer Google Update Helper Google Updater HiJackThis HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB954550-v5) Intel® Graphics Media Accelerator Driver Intel® PROSet/Wireless Software IntelliSonic Speech Enhancement iTunes J2SE Runtime Environment 5.0 Update 6 Java Auto Updater Java™ 6 Update 32 Malwarebytes Anti-Malware version 1.61.0.1400 mCore mDrWiFi MediaDirect mHlpDell Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2656353) Microsoft .NET Framework 1.1 Security Update (KB2656370) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft National Language Support Downlevel APIs Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Security Client Microsoft Security Essentials Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Works mIWA mLogView mMHouse MobileMe Control Panel Modem Diagnostic Tool Mozilla Firefox 12.0 (x86 en-US) Mozilla Maintenance Service mPfMgr mPfWiz mProSafe mSCfg mSSO MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6.0 Parser (KB933579) mWlsSafe mWMI mZConfig NetWaiting OpenOffice.org 3.2 OutlookAddinSetup QuickSet QuickTime RealPlayer Basic Safari SearchAssist Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Windows Internet Explorer 7 (KB2544521) Security Update for Windows Internet Explorer 7 (KB2675157) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB2647516) Security Update for Windows Internet Explorer 8 (KB2675157) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB923689) Sonic Activation Module SPBBC 32bit Startup Manager 2.4.2 Trend Micro AntiVirus Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Internet Explorer 7 (KB980182) Update for Windows Internet Explorer 8 (KB2598845) Update for Windows XP (KB2718704) WebFldrs XP Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 . ==== Event Viewer Messages From Past Week ======== . 6/4/2012 10:18:16 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SASKUTIL . ==== End Of File =========================== . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_32 Run by [removed] at 1:16:16 on 2012-06-08 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.256 [GMT -5:00] . AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF} AV: Trend Micro AntiVirus *Disabled/Updated* {7D2296BC-32CC-4519-917E-52E652474AF5} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Dell Network Assistant\hnm_svc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\lxdncoms.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe C:\Program Files\Trend Micro\BM\TMBMSRV.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Safari\Safari.exe C:\Program Files\Safari\Apple Application Support\WebKit2WebProcess.exe C:\Program Files\Safari\Safari.exe . ============== Pseudo HJT Report =============== . uStart Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2080117 uInternet Settings,ProxyOverride = *.local BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe" mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe mRun: [ECenter] c:\dell\e-center\EULALauncher.exe mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [ContentTransferWMDetector.exe] c:\program files\sony\content transfer\ContentTransferWMDetector.exe mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Chessmaster%20Challenge/Images/stg_drm.ocx DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Chessmaster%20Challenge/Images/armhelper.ocx DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll TCP: DhcpNameServer = 192.168.254.254 TCP: Interfaces\{1F271E44-2309-470A-B663-509A80ACACB2} : DhcpNameServer = 192.168.254.254 SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\temp\application data\mozilla\firefox\profiles\8is70qn8.default\ FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.1601.7122\npCIDetect13.dll FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_235.dll FF - plugin: c:\windows\system32\npdeployJava1.dll FF - plugin: c:\windows\system32\npptools.dll . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 171064] R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service –> c:\windows\system32\lxdncoms.exe -service [?] R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2009-1-15 52240] R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-2-18 36368] S1 SASKUTIL;SASKUTIL;\??\c:\program files\superantispyware\saskutil.sys –> c:\program files\superantispyware\SASKUTIL.sys [?] S2 gupdate1c9e997644d890a;Google Update Service (gupdate1c9e997644d890a);c:\program files\google\update\GoogleUpdate.exe [2009-6-10 133104] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-17 257696] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-1-16 29744] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-6-10 133104] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-28 129976] S3 tmproxy;Trend Micro Proxy Service;c:\program files\trend micro\internet security\TmProxy.exe [2009-1-15 648456] . =============== Created Last 30 ================ . 2012-06-07 20:31:34 6737808 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fa49a2f6-0fbd-4308-9085-150acbea736f}\mpengine.dll 2012-06-06 20:32:15 6737808 ——w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2012-06-04 23:34:29 ——– d—–w- c:\documents and settings\temp\local settings\application data\Trend Micro 2012-05-31 15:36:19 73728 —-a-w- c:\windows\system32\javacpl.cpl 2012-05-29 23:03:15 ——– d-s—w- C:\ComboFix 2012-05-28 20:58:18 ——– d—–w- c:\program files\ESET 2012-05-28 05:49:27 ——– d-sha-r- C:\cmdcons 2012-05-28 05:45:58 98816 —-a-w- c:\windows\sed.exe 2012-05-28 05:45:58 518144 —-a-w- c:\windows\SWREG.exe 2012-05-28 05:45:58 256000 —-a-w- c:\windows\PEV.exe 2012-05-28 05:45:58 208896 —-a-w- c:\windows\MBR.exe 2012-05-27 00:54:33 ——– d—–w- c:\documents and settings\temp\application data\Malwarebytes 2012-05-27 00:52:35 ——– d—–w- C:\TDSSKiller_Quarantine 2012-05-26 06:50:34 388096 —-a-r- c:\documents and settings\temp\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2012-05-26 05:27:29 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-05-26 05:27:29 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-05-25 14:34:16 ——– d—–w- c:\documents and settings\temp\local settings\application data\PackageAware 2012-05-23 14:05:37 ——– d—–w- c:\program files\iPod 2012-05-23 14:05:28 ——– d—–w- c:\program files\iTunes 2012-05-23 13:47:39 ——– d—–w- c:\program files\Bonjour . ==================== Find3M ==================== . 2012-05-31 13:22:09 599040 —-a-w- c:\windows\system32\crypt32.dll 2012-05-27 00:53:33 96512 —-a-w- c:\windows\system32\drivers\atapi.sys 2012-05-10 13:06:19 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-05-10 13:06:18 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-05-07 14:39:53 476960 —-a-w- c:\windows\system32\npdeployJava1.dll 2012-05-07 14:39:52 472864 —-a-w- c:\windows\system32\deployJava1.dll 2012-04-19 01:56:30 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2012-04-19 01:56:30 69632 —-a-w- c:\windows\system32\QuickTime.qts 2012-04-11 13:14:41 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-04-11 13:12:06 1862272 —-a-w- c:\windows\system32\win32k.sys 2012-04-11 12:35:51 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-03-21 01:44:12 171064 —-a-w- c:\windows\system32\drivers\MpFilter.sys . ============= FINISH: 1:18:45.64 ===============
Looks pretty good. I am going to remove the rest of TrendMicro that is sitting there though.

Please delete the current version of Combofix.exe from your desktop and download a new version from here to your desktop.

Disable your AntiVirus and AntiSpyware applications.

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\temp\application data\mozilla\firefox\profiles\8is70qn8.default\
    FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
    
    Folder::
    c:\documents and settings\temp\local settings\application data\Trend Micro
    
    File::
    c:\windows\system32\drivers\tmevtmgr.sys
    c:\windows\system32\drivers\tmpreflt.sys
    c:\program files\trend micro\internet security\TmProxy.exe
    
    Driver::
    tmevtmgr
    tmpreflt
    tmproxy
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
———

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI