
05-15-2012 01:25 AM - edited 05-15-2012 01:31 AM
Hi Guys,
Having a bit of a nightmare getting rid of the above. TrendMicro keeps finding and quarantining and the cleaning files and prompting restart and yet it keeps coming back. Have followed the instructions on the main TrendMicro encyclopedia but didn't find the registry entries (not that know exactly what I'm looking for):
http://about-threats.trendmicro.com/Malware.aspx?l
Have ran SpyBot and that found 1 trojan and cleaned it, currently in process of running MalwareBytes program, waiting on results although whilst scan in progress, keeps saying "successfully blocked potentially malicious outgoing connection" so I'm assuming something is still running and trying to connect to net. I've disconnected from internet in meantime. I have access to a second computer on diff network so can download any utilities to this and transfer to infected machine with USB. Any help would be greatly appreciated.
Thanks
Terry
Solved! Go to Solution.
05-15-2012 01:32 AM
Welcome aboard! ![]()
lets get to it
Download OTL to your Desktop.
http://www.geekstogo.com/forum/files/file/398-otl-
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
consrv.dll
explorer.exe
netbt.sys
atapi.sys
volsnap.sys
redbook.sys
lsi_sas.sys
lsi_scsi.sys
cdrom*
tcpip.sys
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic
C:\Windows\assembly\tmp\U\*.* /s
C:\Program Files\Common Files\ComObjects\*.* /s
CREATERESTOREPOINT
NEXT
Download aswmbr.exe ( 1.8mb ) to your desktop.
http://public.avast.com/~gmerek/aswMBR.htm
Double click the aswMBR.exe to run it Click the "Scan" button to start scan.

Click the [Scan] button to start scan

On completion of the scan click [Save log], save it to your desktop and post in your next reply.
05-15-2012 03:08 AM
Hi MK,
Here are the logs
Thanks
Terry
05-15-2012 08:51 AM
Anyone out there who can help or is Malwarekiller a lone ranger when it comes to fighting the above?
Thanks
Terry
05-15-2012 09:22 AM - edited 05-15-2012 09:23 AM
Hi sorry for late response...
Download ComboFix from the any of the locations given in this website:


05-15-2012 10:56 AM - edited 05-15-2012 11:40 AM
Hi Mk,
Thanks for getting back to me. I know you want all current security off before run ComboFix but it is IMPOSSIBLE to completely remove TrendMicro OfficeScan. I have ran the uninstall and then restarted machine. As far as Add/Remove programs and Start Menu Entries and Startup items in MSCONFIG are concerned, it is gone but ComboFix keeps saying that it is still running. So....I ran ComboFix anyway, said that has infected TCP/IP Stack, really difficult to remove blah blah, then done its stuff, restarted, done a load of processes and then said reboot machine again...except it didn't. It got stuck on that screen for about an hour. I ended up manually rebooting (I know it says you shouldn't but literally it was stuck. Wasn't even seeing a lit up "working" light on my PC). Then it came up and generated a log. A copy of which I've attached here.
Thanks in advance
Terry
05-16-2012 12:14 AM
Alright! combofix got the most of it.
delete the current version of combofix from desktop and download a new one and run it and attach the log.
05-16-2012 12:43 AM
Hi MK,
Re-ran combofix as advised, didn't get the warning about rootkit being present that is difficult to remove etc (so that's a good sign). However, once CF had ran the processes, before it generated a report, I got windows error boxes, the ones that say "This program has encountered an error and had to close, click to send error report to windows" blah blah
The programs that encountered errors were:
Realtek HD Audio
PDF Sentry
The Realtek box closed itself eventually wheras the PDF sentry would not close until I clicked the "Debug" option. Clicking "Don't send error report" kept making a windows error noise
Log attached
Thanks
Terry
05-16-2012 01:16 AM
As an addition step it's recommended that you download other free anti-malware software from the list below and run a full system scan :
05-16-2012 01:18 AM
Ok thanks
If they come up clean, am I in the all clear?! ![]()
Thanks
Terry
Copyright (c) 1989-2012 Trend Micro Incorporated. All rights reserved.
