My Trendmicro client showed, as a result of a scan, an infection:
C:\WINDOWS\msncomm.EXE BKDR_WEBDOOR.B
but couldn't clean it.
*********************
Logfile of HijackThis v1.99.1
Scan saved at 13:10:54, on 11/09/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\LogWatNT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\TFS Technology\TFS Desktop\system\sdlss.exe
C:\TNGSD\BIN\SDSERV.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Host Integration Server\system\ddmserv.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\TNGSD\BIN\TRIGGAG.EXE
C:\WINDOWS\system32\UStorSrv.exe
C:\Programmi\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\UMCSTUB.EXE
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TFS Technology\TFS Desktop\System\SDTray.exe
C:\Program Files\TFS Technology\TFS Desktop\System\winwatch.exe
C:\TNGSD\BIN\triggusr.exe
C:\Program Files\Trend Micro\OfficeScan Client\Pccntmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe
C:\SxpInst\sxplog32.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\WINDOWS\TEMP\CE332D.EXE
C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccnt.exe
C:\Documents and Settings\37341395\Desktop\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.intranet.tim.it
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Telecom Italia Mobile
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [TFS DesktopTray] "C:\Program Files\TFS Technology\TFS Desktop\\System\SDTray.exe"
O4 - HKLM\..\Run: [TFS WindowWatcher] "C:\Program Files\TFS Technology\TFS Desktop\\System\winwatch.exe"
O4 - HKLM\..\Run: [SDJobCheck] triggusr.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\Pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [FinePrint Dispatcher v4] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe
O4 - HKLM\..\Run: [Sxplog] C:\SxpInst\sxpstub.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: CLOCK.EXE
O4 - Startup: explorer.exe.lnk = C:\WINDOWS\explorer.exe
O4 - Startup: Posta TELECOM.lnk = C:\WINDOWS\ptop.vbs
O4 - Global Startup: Acroeula.lnk = C:\TMP_SWD\LAB\Acroeula.vbs
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: MapiProfiles.lnk = C:\WINDOWS\MapiProfileOF.vbs
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: proxy.vbs
O4 - Global Startup: SecurityBar.vbs
O4 - Global Startup: ZoneAlarm.lnk.disabled
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Cerca con Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Traduci parola in italiano - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Link a ritroso - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pagine simili - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Versione cache della pagina - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: @c:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @c:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\tfs technology\tfs desktop\system\mlr.dll
O10 - Unknown file in Winsock LSP: c:\program files\tfs technology\tfs desktop\system\mlr.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.intranet.tim.it
O15 - Trusted Zone: http://*.e2kasd00a
O15 - Trusted Zone: http://*.e2kasd00b
O15 - Trusted Zone: *.https
O15 - Trusted Zone: http://noiportal.telecomitalia.it
O15 - Trusted Zone: http://open.telecomitalia.it
O15 - Trusted Zone: http://tils.open.telecomitalia.it
O15 - Trusted Zone: http://asppc.rm.tim.it
O15 - Trusted Zone: http://asppcn.rm.tim.it
O15 - Trusted Zone: http://aspplo.rm.tim.it
O15 - Trusted Zone: http://asppne.rm.tim.it
O15 - Trusted Zone: http://asppno.rm.tim.it
O15 - Trusted Zone: http://aspps1.rm.tim.it
O15 - Trusted Zone: http://aspps2.rm.tim.it
O15 - Trusted Zone: http://ccrmweb.intranet.tim.it
O15 - Trusted Zone: http://crmccolws2.collaudo.tim.it
O15 - Trusted Zone: http://cunfunws2.rm.tim.it
O15 - Trusted Zone: http://dbr.rete.intranet.tim.it
O15 - Trusted Zone: http://dbrwdm.rete.intranet.tim.it
O15 - Trusted Zone: http://dwhvendite.pd.tim.it
O15 - Trusted Zone: http://ebillas3.pd.tim.it
O15 - Trusted Zone: http://egaindashboard.intranet.tim.it
O15 - Trusted Zone: http://egainsv.intranet.tim.it
O15 - Trusted Zone: http://helponline.intranet.tim.it
O15 - Trusted Zone: http://www.contim.tim.it
O15 - Trusted Zone: http://www.crmc.tim.it
O15 - Trusted Zone: http://www.intranet.tim.it
O15 - Trusted Zone: http://www-it.rm.tim.it
O15 - Trusted Zone: http://tils.open.telecomitalia.it (HKLM)
O15 - Trusted Zone: http://asppc.rm.tim.it (HKLM)
O15 - Trusted Zone: http://asppcn.rm.tim.it (HKLM)
O15 - Trusted Zone: http://aspplo.rm.tim.it (HKLM)
O15 - Trusted Zone: http://asppne.rm.tim.it (HKLM)
O15 - Trusted Zone: http://asppno.rm.tim.it (HKLM)
O15 - Trusted Zone: http://aspps1.rm.tim.it (HKLM)
O15 - Trusted Zone: http://aspps2.rm.tim.it (HKLM)
O15 - Trusted Zone: http://crmccolws2.collaudo.tim.it (HKLM)
O15 - Trusted Zone: http://dwhvendite.pd.tim.it (HKLM)
O15 - Trusted Zone: http://www.contim.tim.it (HKLM)
O15 - Trusted Zone: http://www.crmc.tim.it (HKLM)
O15 - Trusted Zone: http://www.intranet.tim.it (HKLM)
O15 - Trusted Zone: http://www-it.rm.tim.it (HKLM)
O15 - Trusted IP range: http://10.41.39.5
O15 - Trusted IP range: http://10.6.41.64
O15 - Trusted IP range: http://10.6.66.41
O15 - Trusted IP range: http://194.243.137.243
O15 - Trusted IP range: http://10.6.41.64
O15 - Trusted IP range: http://10.6.126.103
O15 - Trusted IP range: http://10.6.126.64
O15 - Trusted IP range: http://10.6.66.41
O15 - Trusted IP range: http://10.6.21.124
O15 - Trusted IP range: http://10.12.19.100
O15 - Trusted IP range: http://10.6.140.83
O15 - Trusted IP range: http://10.6.21.124
O15 - Trusted IP range: http://10.41.39.5 (HKLM)
O15 - Trusted IP range: http://10.6.41.64 (HKLM)
O15 - Trusted IP range: http://10.6.66.41 (HKLM)
O15 - Trusted IP range: http://194.243.137.243 (HKLM)
O15 - Trusted IP range: http://10.6.41.64 (HKLM)
O15 - Trusted IP range: http://10.6.126.103 (HKLM)
O15 - Trusted IP range: http://10.6.126.64 (HKLM)
O15 - Trusted IP range: http://10.6.66.41 (HKLM)
O15 - Trusted IP range: http://10.6.21.124 (HKLM)
O15 - Trusted IP range: http://10.12.19.100 (HKLM)
O15 - Trusted IP range: http://10.6.140.83 (HKLM)
O15 - Trusted IP range: http://10.6.21.124 (HKLM)
O16 - DPF: {11818680-FCF6-11D0-9808-0800092A4865} (FormFlow Form Control) - http://timweb.intran...ase/FormCtl.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {182DA930-985A-11D8-859C-0008C73AF774} (PortPiProj.PortPi) - http://dbrwdm.rete.i.../PortPiProj.CAB
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1154333532936
O16 - DPF: {85D6F6C1-97FE-11D1-86CC-080009B6ACE6} (JetForm Image Filter (GIF)) - http://timweb.intran...se/imagegif.cab
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f008.mail.lyc...ileUploader.cab
O16 - DPF: {CDDCFBB3-4D93-11D2-B1A9-00A0C9B742BE} (FormFlowScriptObject Class) - http://timweb.intran...criptobject.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?326
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = intranet.tim.it
O17 - HKLM\Software\..\Telephony: DomainName = intranet.tim.it
O17 - HKLM\System\CCS\Services\Tcpip\..\{1647719B-AE37-4248-9DE2-76E4CB905DCF}: NameServer = 10.6.80.48,10.6.80.47,10.41.35.48,10.41.35.47
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = intranet.tim.it
O17 - HKLM\System\CS3\Services\Tcpip\..\{1647719B-AE37-4248-9DE2-76E4CB905DCF}: NameServer = 10.6.80.48,10.6.80.47,10.41.35.48,10.41.35.47
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = intranet.tim.it
O17 - HKLM\System\CS4\Services\Tcpip\..\{1647719B-AE37-4248-9DE2-76E4CB905DCF}: NameServer = 10.6.80.48,10.6.80.47,10.41.35.48,10.41.35.47
O17 - HKLM\System\CS5\Services\Tcpip\Parameters: Domain = intranet.tim.it
O17 - HKLM\System\CS5\Services\Tcpip\..\{1647719B-AE37-4248-9DE2-76E4CB905DCF}: NameServer = 10.6.80.48,10.6.80.47,10.41.35.48,10.41.35.47
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Asset Management Agent (AmoAgent) - Computer Associates International, Inc. - C:\WINDOWS\UMCSTUB.EXE
O23 - Service: Event Log Watch (LogWatch) - Unknown owner - C:\WINDOWS\LogWatNT.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Desktop Security Server (SDLss) - TFS Technology. - C:\Program Files\TFS Technology\TFS Desktop\\system\sdlss.exe
O23 - Service: Unicenter Software Delivery (SDService) - Computer Associates International, Inc. - C:\TNGSD\BIN\SDSERV.EXE
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
**************************
I expect any suggestion to get rid of the treath.
Thank u very much.