Dear professionals:
My PC has Trend Micro Office Scan installed but my PC was
still infected when I surfed the net. Thanks for Spybot S&D
most of spys are now removed, but there are still some problem:
1) I keep on having serveral pop up windows to install "Zango"
freeware and some ads.
2) Occasionally, my PC re-boots itself at start up or during
meantime of an application program.
3) Occasionally, the Trend Micro Office prompts to find trojan
or other virus. But it just found but couldn't kill.
Here is the logfile of HijackThis. Thanks for your kind help.
Logfile of HijackThis v1.99.1
Scan saved at 下午 05:04:34, on 2006/4/21
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\RealVNC\WinVNC\WinVNC.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\explorer.exe
C:\WINNT\TEMP\BLB78A.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\WINPENJR\win32\pphidpad.exe
C:\WINNT\ghost.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\Wireless\Client Manager\CMAGS.EXE
C:\WINNT\system32\conime.exe
C:\Program Files\Microsoft Office\Office\1028\msoffice.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\JF\Program\Hijack this\HijackThis.exe
F2 - REG:system.ini: Shell=explorer.exe C:\WINNT\system32\sxlntr.exe
F3 - REG:win.ini: load=C:\WINNT\system32\sxlntr.exe
F3 - REG:win.ini: run=C:\WINNT\system32\sxlntr.exe
O1 - Hosts: 85.249.139.66 socks.tempservice.org
O1 - Hosts: 85.249.139.66 socks.temphost.ws
O1 - Hosts: 85.249.139.66 j002_fljkdr.fgkfps.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O3 - Toolbar: 收音機(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [fwenc.exe] "C:\Program Files\CheckPoint\SecuRemote\bin\fwenc.exe"
O4 - HKLM\..\Run: [PPHIDPAD] C:\WINPENJR\win32\pphidpad.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [Sys_Run] C:\WINNT\ghost.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [RepServ Manager] C:\WINNT\system32\mpcsvc.exe
O4 - HKLM\..\Run: [RepServ Manager] C:\WINNT\system32\mpcsvc.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Rescue Autorun] C:\WINNT\winlogon.exe
O4 - HKLM\..\RunServices: [SystemTools] C:\WINNT\system32\kernels8.exe
O4 - HKLM\..\RunServices: [SystemTools] C:\WINNT\system32\kernels8.exe
O4 - HKLM\..\RunOnce: [Windows Rescue Autorun] C:\WINNT\winlogon.exe
O4 - HKLM\..\RunOnce: [Windows Rescue Autorun] C:\WINNT\winlogon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Malware Sweeper] C:\Program Files\MalwareSweeper.com\Malware Sweeper\MalSwep.exe /STARTUP
O4 - HKCU\..\Run: [RepServ Manager] C:\WINNT\system32\mpcsvc.exe
O4 - HKCU\..\Run: [Repair Service Manager] C:\WINNT\system32\mpcsvc.exe
O4 - HKCU\..\Run: [Windows Rescue Autorun] C:\WINNT\winlogon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Popup Control - {7947B27A-1FB6-4840-8A12-936EA221694F} - C:\Program Files\popup control\PopupControl.dll
O9 - Extra 'Tools' menuitem: Popup Control - {7947B27A-1FB6-4840-8A12-936EA221694F} - C:\Program Files\popup control\PopupControl.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm (file missing)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sme.gov.mo
O17 - HKLM\System\CCS\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: Domain = sme.gov.mo
O17 - HKLM\System\CCS\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: NameServer = 192.168.100.251
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sme.gov.mo
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = economia.gov.mo,sme.gov.mo
O17 - HKLM\System\CS1\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: Domain = sme.gov.mo
O17 - HKLM\System\CS1\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: NameServer = 192.168.100.251
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = sme.gov.mo
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = economia.gov.mo,sme.gov.mo
O17 - HKLM\System\CS2\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: Domain = sme.gov.mo
O17 - HKLM\System\CS2\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: NameServer = 192.168.100.251
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = sme.gov.mo
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = economia.gov.mo,sme.gov.mo
O17 - HKLM\System\CS3\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: Domain = sme.gov.mo
O17 - HKLM\System\CS3\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: NameServer = 192.168.100.251
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = economia.gov.mo,sme.gov.mo
O20 - Winlogon Notify: ckpNotify - C:\WINNT\SYSTEM32\ckpNotify.dll
O20 - Winlogon Notify: directpt - directpt.dll (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: OfficeScanNT 即時掃瞄 (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT 防火牆 (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -service (file missing)
My PC has Trend Micro Office Scan installed but my PC was
still infected when I surfed the net. Thanks for Spybot S&D
most of spys are now removed, but there are still some problem:
1) I keep on having serveral pop up windows to install "Zango"
freeware and some ads.
2) Occasionally, my PC re-boots itself at start up or during
meantime of an application program.
3) Occasionally, the Trend Micro Office prompts to find trojan
or other virus. But it just found but couldn't kill.
Here is the logfile of HijackThis. Thanks for your kind help.
Logfile of HijackThis v1.99.1
Scan saved at 下午 05:04:34, on 2006/4/21
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\RealVNC\WinVNC\WinVNC.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\explorer.exe
C:\WINNT\TEMP\BLB78A.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\WINPENJR\win32\pphidpad.exe
C:\WINNT\ghost.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\Wireless\Client Manager\CMAGS.EXE
C:\WINNT\system32\conime.exe
C:\Program Files\Microsoft Office\Office\1028\msoffice.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\JF\Program\Hijack this\HijackThis.exe
F2 - REG:system.ini: Shell=explorer.exe C:\WINNT\system32\sxlntr.exe
F3 - REG:win.ini: load=C:\WINNT\system32\sxlntr.exe
F3 - REG:win.ini: run=C:\WINNT\system32\sxlntr.exe
O1 - Hosts: 85.249.139.66 socks.tempservice.org
O1 - Hosts: 85.249.139.66 socks.temphost.ws
O1 - Hosts: 85.249.139.66 j002_fljkdr.fgkfps.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O3 - Toolbar: 收音機(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [fwenc.exe] "C:\Program Files\CheckPoint\SecuRemote\bin\fwenc.exe"
O4 - HKLM\..\Run: [PPHIDPAD] C:\WINPENJR\win32\pphidpad.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [Sys_Run] C:\WINNT\ghost.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [RepServ Manager] C:\WINNT\system32\mpcsvc.exe
O4 - HKLM\..\Run: [RepServ Manager] C:\WINNT\system32\mpcsvc.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Rescue Autorun] C:\WINNT\winlogon.exe
O4 - HKLM\..\RunServices: [SystemTools] C:\WINNT\system32\kernels8.exe
O4 - HKLM\..\RunServices: [SystemTools] C:\WINNT\system32\kernels8.exe
O4 - HKLM\..\RunOnce: [Windows Rescue Autorun] C:\WINNT\winlogon.exe
O4 - HKLM\..\RunOnce: [Windows Rescue Autorun] C:\WINNT\winlogon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Malware Sweeper] C:\Program Files\MalwareSweeper.com\Malware Sweeper\MalSwep.exe /STARTUP
O4 - HKCU\..\Run: [RepServ Manager] C:\WINNT\system32\mpcsvc.exe
O4 - HKCU\..\Run: [Repair Service Manager] C:\WINNT\system32\mpcsvc.exe
O4 - HKCU\..\Run: [Windows Rescue Autorun] C:\WINNT\winlogon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Popup Control - {7947B27A-1FB6-4840-8A12-936EA221694F} - C:\Program Files\popup control\PopupControl.dll
O9 - Extra 'Tools' menuitem: Popup Control - {7947B27A-1FB6-4840-8A12-936EA221694F} - C:\Program Files\popup control\PopupControl.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm (file missing)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sme.gov.mo
O17 - HKLM\System\CCS\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: Domain = sme.gov.mo
O17 - HKLM\System\CCS\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: NameServer = 192.168.100.251
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sme.gov.mo
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = economia.gov.mo,sme.gov.mo
O17 - HKLM\System\CS1\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: Domain = sme.gov.mo
O17 - HKLM\System\CS1\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: NameServer = 192.168.100.251
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = sme.gov.mo
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = economia.gov.mo,sme.gov.mo
O17 - HKLM\System\CS2\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: Domain = sme.gov.mo
O17 - HKLM\System\CS2\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: NameServer = 192.168.100.251
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = sme.gov.mo
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = economia.gov.mo,sme.gov.mo
O17 - HKLM\System\CS3\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: Domain = sme.gov.mo
O17 - HKLM\System\CS3\Services\Tcpip\..\{1295D087-BA82-4729-815A-5C51CE222AE4}: NameServer = 192.168.100.251
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = economia.gov.mo,sme.gov.mo
O20 - Winlogon Notify: ckpNotify - C:\WINNT\SYSTEM32\ckpNotify.dll
O20 - Winlogon Notify: directpt - directpt.dll (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: OfficeScanNT 即時掃瞄 (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT 防火牆 (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -service (file missing)