Solved

Manual removal of troj_agent.allo

Posted on 2009-05-05
7
873 Views
Last Modified: 2012-05-06
Does anyone know how to manually remove the troj_agent.allo virus? I have tried everything and been all over the internet trying to find out. My niece got it on her laptop and I can't find a way to get rid of it. The internet keeps pointing me at all sorts of virus programs (none of which have gotten rid of it).. So if anyone knows the secret to removing this thing I would love to hear it.

Tried already:
Trend Micro: finds it quarantines it and then it is right back
Turned off system restore
Tried running trend micro in safe mode
The virus seems to block all contact with trend micro Windows update and most other virus software sites.
0
Comment
Question by:Anjinsan5
7 Comments
 
LVL 2

Expert Comment

by:FatManc
ID: 24310048
Hi,

Please download and install Malwarebytes AntiMalware...

http://www.malwarebytes.org/mbam.php

And update the software. Do not run it at this time.

Boot to safe mode in Windows (f8 when machine is booting) THEN run a quick scan whilst in safe mode. It should find and remove the virus.

If not, then run ComboFix (also in safe mode)

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

These two tools should go some way to removing any nasties left on your machine

Hope this helps
John


0
 
LVL 47

Accepted Solution

by:
rpggamergirl earned 500 total points
ID: 24311277
Anjinsan5,
Run Combofix in normal mode, unless the pc only boots in safe mode. And please attach the logfile here as some bad files may still be needed to be removed using CF script function.
 

FatManc,
Why are you suggesting combofix to be run in Safe Mode???
Combofix is designed to be run in normal mode so it should be run in that mode unless pc doesn't boot normally.
0
 
LVL 2

Expert Comment

by:FatManc
ID: 24313069
I was assuming that it wouldn't boot properly due to the re-infection. In some cases I have had more success with ComboFix in safe more.

Anjinsan5 - please run ComboFix in whichever mode the PC will run normally in.
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 

Author Comment

by:Anjinsan5
ID: 24322207
Thanks you guys. Combofix seems to have done the trick.

Here is the log file:


ComboFix 09-05-05.03 - Administrator 05/06/2009 23:49.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1023.719 [GMT -4:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated)
FW: Trend Micro Personal Firewall *disabled*

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Local Settings\Temp\atl80.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\150\SfEnAv.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\150\SfEnVSMs.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\150\SfEnVSRs.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\151\SfEnAs.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\151\SfEnBehv.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\151\SfEnVSMs.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\151\SfEnVSRs.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\152\SfEnFw.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\152\SfEnFwLc.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\152\SfEnFwNl.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\152\SfEnFwRl.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\152\SfEnFwSs.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\153\SfEnCp.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\153\SfEnCpAs.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\153\SfEnCpP3.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\153\SfEnCpPd.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\153\SfEnCpPh.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\153\SfEnCpSp.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\153\SfEnCpUf.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\153\SfEnCpWm.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\154\SfEnMc.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\154\SfEnMcHn.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\154\SfEnMcTs.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Enforce\32bit\154\SfEnMcVa.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x00000004\BPMNT.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x00000004\vsapi32.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x00000010\tmpreflt.sys
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x00000010\tmxpflt.sys
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x00000010\VsapiNT.sys
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x14000000\tmufeng.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x21000800\vstlib32.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22000010\ssapi32.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22000040\tmactmon.sys
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22000040\tmcomm.sys
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22000040\tmevtmgr.sys
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22000080\TMBMSRV.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22000080\tmcomeng.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22000080\tmtap.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22000080\tmufeng.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22001000\ncfg.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22001000\tm_cfw.sys
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22004000\TMLWF.sys
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22004000\tmlwfins.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22004000\TMWFP.sys
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22004000\tmwfpins.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22010000\tdiins.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22010000\tmtdi.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\32bit\[u]0[/u]x22010000\tmtdi.sys
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Engine\Share\[u]0[/u]x21080000\tsc.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\atl80.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\GENKEY32.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\HCcommon.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\libexpat.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\mfc80.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\mfc80u.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\mfcm80.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\mfcm80u.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\msvcm80.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\msvcp80.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\msvcr80.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfCtlCom.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfEnCm.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfFnProf.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfFnUtil.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfFnWSC.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfFnWTC.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfIfCom.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfIfDtCv.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfIfDtHd.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfIfEvMg.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfIfHttp.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfSvCoMg.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfSvEnHd.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfSvEvLg.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfSvLcMg.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfSvQuMg.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfSvTkSd.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfSvUiSv.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\SfSvUpMg.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\tismsi.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\tisspwiz.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\TISSuprt.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\TisWrapr.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\TMASmsi.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\TMBMCLI.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\Tmdshell.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\TmEngDrv.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\UfIfAvIm.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\UfLogUi.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\UfNavi.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\UfPack.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\UfSeAgnt.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\UfUpdUi.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\UfWSC.cpl
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\VBProp.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\vsapiins.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\32bit\146\wtclog.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\Share\146\Remove.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\Share\146\SfPxSt32.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\Share\146\TmDbg32.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\Share\146\TmUtyPPI.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Framework\Share\146\TSRemove.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\155\PccScan.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\156\PccSpy.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\157\PcDce.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\158\TmCfwApi.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\158\TmHash.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\158\TmPfw.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\158\TmPfwApi.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\158\TmPfwCtl.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\158\TmPfwHlp.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\158\TmPfwLog.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\158\TmPfwRul.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\158\tmwfpapi.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmcfScan.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmMsg.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmpeASpm.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmpeHosF.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmpePDP.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmpeUrlF.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmpeVS.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmphAim.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmphHttp.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmphIcq.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmphMsn.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmphPop3.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmphSMTP.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmphYmsg.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmProxy.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmProxy.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmpxCfg.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmpxHelp.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmsmHttp.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmsmIm.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\159\TmsmMail.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\161\SfFnAvIm.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\162\SfFnHttp.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\163\SfFnSvAg.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\165\HomeNet.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\165\NetBSrvr.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\165\tmdp.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\165\tmpp.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\171\clnrbin.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\32bit\171\PcHisCln.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\Share\157\PcDceLog.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\Share\160\ciuas32.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\Share\160\ciussi32.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\Share\160\Patch.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\Share\160\patchbld.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\Share\160\PATCHW32.DLL
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\Share\160\SfFnUp.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Function\Share\160\TmUpdate.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\HtmlView.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\Setup.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\tisprs32.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\common\win32\TMAS_AU.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\common\win32\TMAS_Hlp.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\common\win32\tmaseng.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\common\win32\TmasHlp.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OE\TMAS_OE.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OE\TMAS_OEA.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OE\TMAS_OEApi.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OE\TMAS_OEApiInit.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OE\TMAS_OEHook.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OE\TMAS_OEImp.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OE\TMAS_OEMon.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OE\TMAS_OEStore.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OE\TMAS_OEWab.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OL\Redemption.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OL\TMAS_OL.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OL\TMAS_OLA.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OL\TMAS_OLImp.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OL\TMAS_OLSentry.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\TMAS\OL\TMAS_OLShare.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Setup\VsapiTool\32bit\TVscan32.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Tools\32bit\libexpat.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Tools\32bit\ncfg.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Tools\32bit\TISSuprt.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Tools\32bit\TmDbg32.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Tools\32bit\TmEngDrv.dll
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Tools\32bit\TSRemove.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TIS1610_1063\Tools\32bit\vsapiins.exe
c:\documents and settings\Administrator\Local Settings\Temp\EZ_temp\Product\TrendMicro_TIS_16.1_1063_x32_T_0831212302.exe
c:\documents and settings\Administrator\Local Settings\Temp\is-FM96S.tmp\gtapi.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.exe
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1025.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1028.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1029.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1030.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1031.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1032.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1033.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1035.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1036.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1037.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1038.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1040.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1041.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1042.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1043.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1044.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1045.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1046.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1049.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1053.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.1055.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.2052.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.2070.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.3076.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\install.res.3082.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\mscoree.dll
c:\documents and settings\Administrator\Local Settings\Temp\IS17.tmp\unicows.dll
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\Arj.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\ArjPack.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\avlib.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\Avp1.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\AVP3Info.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\AvpMgr.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\avs.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\avspm.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\Base64.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\Base64P.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\btdisk.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\btimages.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\buffer.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\CAB.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\crpthlpr.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\deflate.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\dmap.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\dtreg.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\Explode.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\farbuffer.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\faristream.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\FsDrvPlg.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\FSSync.dll
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\HashCont.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\HashMD5.PPL
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\HCCMP.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\ichk2.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\iChkSA.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\ikave.dll
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\Inflate.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\IniFile.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\IWGen.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\kave.dll
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\klavsrch.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\kosglue-7.0.26.0.dll
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\L_llio.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\lha.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\lic60.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\LicMgr.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\MailMsg.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\mc.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\mdb.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\MDMAP.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\MemModSc.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\MemScan.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\minizip.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\MKavIO.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\msoe.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\msvcm80.dll
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\msvcp80.dll
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\msvcr80.dll
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\ndetect.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\nfio.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\NTFSstrm.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\ods.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\params.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\passdmap.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\prKernel.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\prLoader.dll
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\procmon.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\prremote.dll
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\prseqio.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\PrUpdate.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\PrUtil.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\Quantum.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\rar.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\ScanningProcess.exe
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\schedule.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\sfdb.PPL
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\StdComp.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\StEnum2.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\stored.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\superio.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\TempFile.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\thpimpl.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\Timer.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\tm.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\UnArj.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\UniArc.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\UnLZX.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\Unreduce.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\UNSHRINK.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\UnStored.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\WDiskIO.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\WinReg.ppl
c:\documents and settings\Administrator\Local Settings\Temp\jkos-Administrator\binaries\xorio.ppl
c:\documents and settings\Administrator\Local Settings\Temp\libexpat.dll
c:\documents and settings\Administrator\Local Settings\Temp\mfc80.dll
c:\documents and settings\Administrator\Local Settings\Temp\mfc80u.dll
c:\documents and settings\Administrator\Local Settings\Temp\mfcm80.dll
c:\documents and settings\Administrator\Local Settings\Temp\mfcm80u.dll
c:\documents and settings\Administrator\Local Settings\Temp\msvcm80.dll
c:\documents and settings\Administrator\Local Settings\Temp\msvcp80.dll
c:\documents and settings\Administrator\Local Settings\Temp\msvcr80.dll
c:\documents and settings\Administrator\Local Settings\Temp\nlsdl.dll
c:\documents and settings\Administrator\Local Settings\Temp\Oracle IRM Desktop EN 5.5.9.95.exe
c:\documents and settings\Administrator\Local Settings\Temp\Perflib_Perfdata__755.dat
c:\documents and settings\Administrator\Local Settings\Temp\set168.tmp
c:\documents and settings\Administrator\Local Settings\Temp\Set24.tmp
c:\documents and settings\Administrator\Local Settings\Temp\tismsi.dll.mui
c:\documents and settings\Administrator\Local Settings\Temp\TmDbg32.dll
c:\documents and settings\Administrator\Local Settings\Temp\ytb.exe
c:\windows\IE4 Error Log.txt
c:\windows\system32\drivers\gaopdxruiajduk.sys
c:\windows\system32\gaopdxcounter
c:\windows\system32\gaopdxplmfexrd.dll

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_gaopdxserv.sys


(((((((((((((((((((((((((   Files Created from 2009-04-07 to 2009-05-07  )))))))))))))))))))))))))))))))
.

2009-05-07 03:48 . 2009-05-07 03:48      --------      d-----w      c:\documents and settings\TEMP
2009-05-06 03:44 . 2009-05-06 03:44      --------      d-----w      c:\program files\XoftSpySE
2009-05-06 03:09 . 2009-05-06 03:09      --------      d-----w      c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-05-06 03:09 . 2009-04-06 19:32      15504      ----a-w      c:\windows\system32\drivers\mbam.sys
2009-05-06 03:09 . 2009-04-06 19:32      38496      ----a-w      c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-06 03:09 . 2009-05-06 03:09      --------      d-----w      c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-06 03:09 . 2009-05-07 03:07      --------      d-----w      c:\program files\Malwarebytes' Anti-Malware
2009-05-05 02:30 . 2009-05-05 02:27      50192      ----a-w      c:\windows\system32\drivers\tmactmon.sys
2009-05-05 02:30 . 2009-05-05 02:27      150032      ----a-w      c:\windows\system32\drivers\tmcomm.sys
2009-05-05 02:30 . 2009-05-05 02:27      50192      ----a-w      c:\windows\system32\drivers\tmevtmgr.sys
2009-05-05 02:29 . 2009-05-05 02:29      --------      d-----w      c:\documents and settings\All Users\Application Data\Trend Micro
2009-05-05 02:29 . 2009-05-05 02:30      --------      d-----w      c:\program files\Trend Micro
2009-05-05 02:27 . 2009-05-05 02:27      1195512      ----a-w      c:\windows\system32\drivers\vsapint.sys
2009-05-05 02:27 . 2009-05-05 02:27      335376      ----a-w      c:\windows\system32\drivers\TM_CFW.sys
2009-05-05 02:27 . 2009-05-05 02:27      36368      ----a-w      c:\windows\system32\drivers\tmpreflt.sys
2009-05-05 02:27 . 2009-05-05 02:27      80400      ----a-w      c:\windows\system32\drivers\tmtdi.sys
2009-05-05 02:27 . 2009-05-05 02:27      205328      ----a-w      c:\windows\system32\drivers\tmxpflt.sys
2009-05-04 12:37 . 2009-05-04 21:01      --------      d---a-w      c:\documents and settings\All Users\Application Data\TEMP
2009-05-04 02:21 . 2009-05-04 02:25      664      ----a-w      c:\windows\system32\d3d9caps.dat
2009-05-04 02:10 . 2009-05-04 02:10      410984      ----a-w      c:\windows\system32\deploytk.dll
2009-04-30 03:32 . 2009-04-30 03:32      0      ----a-w      c:\windows\nsreg.dat
2009-04-30 03:32 . 2009-04-30 03:32      --------      d-----w      c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-04-30 02:54 . 2009-04-30 02:54      --------      d-----w      c:\windows\system32\Service
2009-04-30 02:24 . 2009-04-30 02:24      --------      d-----w      c:\documents and settings\All Users\Application Data\MSN6
2009-04-30 02:24 . 2009-04-30 02:59      --------      d-----w      c:\documents and settings\Administrator\Application Data\MSN6
2009-04-25 03:26 . 2009-04-25 03:26      --------      d-----w      c:\documents and settings\Administrator\Local Settings\Application Data\Trend Micro
2009-04-25 03:26 . 2008-10-21 17:59      46456      ----a-r      c:\windows\system32\exitwx.exe
2009-04-25 02:35 . 2009-05-04 03:58      --------      d-----w      c:\documents and settings\Administrator\.housecall6.6

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-05 02:08 . 2004-01-14 00:41      --------      d--h--w      c:\program files\InstallShield Installation Information
2009-05-04 02:10 . 2004-01-14 18:12      --------      d-----w      c:\program files\Java
2009-04-30 02:23 . 2004-01-14 17:30      --------      d-----w      c:\program files\Toshiba
2009-04-25 04:49 . 2008-09-23 02:16      29224      ----a-w      c:\documents and settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 65536]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"NVIEW"="nview.dll" - c:\windows\system32\nview.dll [2003-12-10 856135]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-12-10 4866048]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2003-10-31 192512]
"00THotkey"="c:\windows\System32\[u]0[/u]0THotkey.exe" [2003-11-21 22:49 258048]
"DpUtil"="c:\program files\TOSHIBA\DualPointUtility\TEDTray.exe" [2003-11-12 159744]
"TosHKCW.exe"="c:\program files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [2002-09-09 49152]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2003-12-03 131072]
"TAudEffect"="c:\program files\Toshiba\TAudEffect\TAudEff.exe" [2003-12-26 208972]
"Pinger"="c:\toshiba\IVP\ISM\pinger.exe" [2005-03-17 151552]
"PRONoMgr.exe"="c:\program files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2003-12-10 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"sealmon.exe"="c:\program files\Oracle\Information Rights Management\Desktop\sealmon.exe" [2008-08-21 371000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-04 148888]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-05-05 995528]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2003-12-10 323584]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2003-04-18 88363]
"000StTHK"="000StTHK.exe" - c:\windows\system32\[u]0[/u]00StTHK.exe [2001-06-24 04:28 24576]
"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2003-12-15 278528]
"TFncKy"="TFncKy.exe" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2009-05-05 492808]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-4-19 64864]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2004-1-14 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2003-12-16 15:32      110592      ----a-w      c:\windows\System32\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"=

R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [5/4/2009 10:30 PM 50192]
R2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [5/4/2009 10:30 PM 497008]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [5/4/2009 10:27 PM 36368]
R2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [5/4/2009 10:30 PM 677128]
R3 TEchoCan;Toshiba Audio Effect;c:\windows\system32\drivers\TEchoCan.sys [1/14/2004 2:36 PM 28416]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [5/4/2009 10:27 PM 335376]
.
Contents of the 'Scheduled Tasks' folder

2009-05-07 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2009-04-29 13:28]

2009-05-07 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2009-04-29 13:28]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.toshiba.com
mStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.toshiba.com/
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\65tsvz1m.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-06 23:53
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...  

scanning hidden autostart entries ...

scanning hidden files ...  

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1016)
c:\windows\System32\LgNotify.dll
.
Completion time: 2009-05-07 23:55
ComboFix-quarantined-files.txt  2009-05-07 03:54

Pre-Run: 49,848,455,168 bytes free
Post-Run: 50,281,152,512 bytes free

459      --- E O F ---      2009-01-18 15:35
0
 
LVL 2

Expert Comment

by:FatManc
ID: 24333828
Are you saying the problem is fixed now as ComboFix seemed to have removed a lot of Malware?

If you're still having the issue, please let me know

Thanks
John
0
 
LVL 15

Expert Comment

by:xmachine
ID: 24635527
Hi,

1) Download & run CCleaner to clean your system (including registry) from junk files/registry keys

http://www.ccleaner.com/download

2) Download and run HijackThis portable and attach the log here for analysis
 (http://www.portableshare.com/downloads/HijackThis-Portable.html)

3) Download & run GMER (rootkit scanner) from (http://www2.gmer.net/gmer.zip)

Start GMER, select all options on the right side, after scanning is finished, click on save. Attach the log file here

4) Please download RootkitRevealer then extract it to C:\

(http://download.sysinternals.com/Files/RootkitRevealer.zip)

From CMD, type the following command:

C:\rootkitrevealer.exe -a c:\rootkit.log

Attach the log file here

5) Download & run Autorunsc (Command line version of Autoruns)

http://download.sysinternals.com/Files/Autoruns.zip

run the tool with all options from command line (CMD):

c:\autorunsc.exe -a -c -m -e -h -n -r -s -W > autoruns.txt

attach autoruns.txt for analysis

6) Download & run injecteddll

(http://www.nirsoft.net/utils/injecteddll.zip)

select all items, then click on the save button to export a log file, attach it here as well.

Symantec Certified Specialist
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

In every aspect, security is essential for your business, and for that matter you need to always keep an eye on it. The same can be said about your computer network system too. Your computer network is prone to various malware and security threats t…
Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now