WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


Security Tool and maybe more malaware

4 posters

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
btw, at the beggining combofix says it has to download something and asking to have an internet connection working. That part fails. Because again my internet access is like blocked.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
here it is

ComboFix 09-11-05.01 - joe 2009-11-05 21:23.2.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.2.1036.18.1023.654 [GMT -5:00]
Lancé depuis: c:\documents and settings\joe\Bureau\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Outdated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
FW: Norton 360 *disabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}

AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
ADS - system32: deleted 142 bytes in 1 streams.

((((((((((((((((((((((((((((( Fichiers créés du 2009-10-06 au 2009-11-06 ))))))))))))))))))))))))))))))))))))
.

2009-11-05 03:34 . 2008-12-11 13:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-11-05 03:34 . 2009-08-24 19:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-11-05 03:34 . 2009-08-19 16:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-11-05 03:34 . 2009-11-05 03:35 -------- d-----w- c:\program files\Fichiers communs\PC Tools
2009-11-05 03:34 . 2008-12-10 16:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-11-05 03:34 . 2009-11-05 03:34 -------- d-----w- c:\documents and settings\joe\Application Data\PC Tools
2009-11-05 03:34 . 2009-11-05 03:34 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-11-04 17:34 . 2009-11-05 03:02 -------- d-----w- c:\program files\PC Tools AntiVirus
2009-11-03 04:26 . 2005-01-17 05:43 88576 ----a-w- c:\windows\system32\drivers\nvatabus.sys
2009-11-03 04:26 . 2008-04-13 18:40 96512 -c--a-w- c:\windows\system32\dllcache\atapi.sys
2009-11-03 04:26 . 2008-04-13 18:40 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-11-03 04:20 . 2009-11-03 04:20 -------- d-----w- c:\program files\Trend Micro
2009-11-03 03:53 . 2009-11-05 03:02 -------- d-----w- c:\program files\RegDefense
2009-11-03 03:48 . 2009-11-03 03:48 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2009-11-03 03:17 . 2009-11-03 03:17 -------- d-----w- c:\documents and settings\joe\Local Settings\Application Data\Mozilla
2009-11-03 02:39 . 2009-11-03 04:13 22016 ----a-w- c:\windows\system32\tdlwsp.dll
2009-11-02 23:19 . 2009-11-02 23:19 -------- d-----w- c:\documents and settings\joe\Application Data\Malwarebytes
2009-11-02 23:13 . 2009-11-06 02:12 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-28 05:28 . 2009-10-28 05:30 -------- d-----w- c:\program files\Windows Live Safety Center
2009-10-28 04:51 . 2009-10-28 04:51 -------- d-----w- c:\documents and settings\joe\Application Data\AVG8
2009-10-28 04:31 . 2009-06-30 14:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-10-23 07:32 . 2009-10-23 07:32 -------- d-----w- c:\documents and settings\joe\Application Data\SUPERAntiSpyware.com
2009-10-23 07:19 . 2008-11-26 16:08 131 ----a-w- c:\windows\IDB.zip
2009-10-23 07:19 . 2009-10-02 18:19 1152470 ----a-w- c:\windows\UDB.zip
2009-10-23 07:07 . 2009-10-28 04:22 -------- d-----w- c:\documents and settings\Malwarebytes' Anti-Malware
2009-10-23 07:07 . 2009-10-23 07:10 20949 ----a-w- c:\documents and settings\Malwarebytes' Anti-Malware\unins000.dat
2009-10-23 07:07 . 2009-10-23 07:10 -------- d-----w- c:\documents and settings\Malwarebytes' Anti-Malware\Languages
2009-10-23 06:50 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-23 06:50 . 2009-10-28 04:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-23 06:50 . 2009-10-23 06:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-23 06:50 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-23 05:40 . 2009-10-28 04:31 -------- d-----w- c:\program files\Panda Security
2009-10-23 05:37 . 2009-11-03 02:38 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-06 02:19 . 2006-02-04 17:22 -------- d-----w- c:\program files\Java
2009-11-06 02:15 . 2004-08-05 12:00 84874 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-06 02:15 . 2004-08-05 12:00 510656 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-06 02:08 . 2005-10-26 22:25 -------- d-----w- c:\program files\Steam
2009-11-06 00:04 . 2006-05-27 16:36 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000004-20021102}.dat
2009-11-06 00:04 . 2006-05-27 16:36 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000004-20021102}.dat
2009-10-28 05:18 . 2005-10-26 21:34 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2009-10-28 05:18 . 2005-10-26 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-28 05:13 . 2008-08-05 01:27 -------- d-----w- c:\program files\Norton 360
2009-10-23 07:31 . 2005-11-07 02:45 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2009-10-23 07:25 . 2009-10-28 04:17 8530 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Personal_32_1036.dat
2009-10-23 07:05 . 2007-12-25 22:22 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-30 18:58 . 2008-02-18 19:38 9576 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\CCMSLLUM.DLL
2009-09-22 02:58 . 2009-09-22 02:58 -------- d-----w- c:\program files\Cool MOV To WMV Converter
2009-09-11 23:18 . 2008-06-23 02:09 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000004-10001102}.dat
2009-09-11 23:18 . 2008-06-23 02:09 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000004-10001102}.dat
2009-09-11 14:18 . 2004-08-05 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 21:39 . 2009-03-21 00:01 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-07 05:39 . 2009-08-18 13:58 5 ----a-w- c:\windows\system32\SySAVI2WMV.dat
2009-09-07 05:01 . 2009-09-07 05:01 -------- d-----w- c:\program files\Windows Media Components
2009-09-04 21:04 . 2004-08-05 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 2004-08-05 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-27 08:34 . 2005-10-27 01:44 81504 ----a-w- c:\documents and settings\joe\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 08:01 . 2004-08-05 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 13:48 . 2009-08-18 13:48 34 ---ha-w- c:\windows\system32\Converter_sysquict.dat
1999-04-06 13:27 . 1999-04-06 13:27 99840 ----a-w- c:\program files\Fichiers communs\IRAABOUT.DLL
1998-12-09 03:53 . 1998-12-09 03:53 70144 ----a-w- c:\program files\Fichiers communs\IRAMDMTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 48640 ----a-w- c:\program files\Fichiers communs\IRALPTTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 31744 ----a-w- c:\program files\Fichiers communs\IRAWEBTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 186368 ----a-w- c:\program files\Fichiers communs\IRAREG.DLL
1998-12-09 03:53 . 1998-12-09 03:53 17920 ----a-w- c:\program files\Fichiers communs\IRASRIAL.DLL
.

((((((((((((((((((((((((((((( SnapShot@2009-11-03_04.41.32 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-05 12:00 . 2009-11-03 04:25 71374 c:\windows\system32\perfc009.dat
+ 2004-08-05 12:00 . 2009-11-06 02:15 71374 c:\windows\system32\perfc009.dat
- 2006-06-29 13:05 . 2009-01-07 22:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-29 13:05 . 2009-01-07 23:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-28 22:59 . 2009-01-07 23:20 24576 c:\windows\system32\nlsdl.dll
- 2006-06-28 22:59 . 2009-01-07 22:20 24576 c:\windows\system32\nlsdl.dll
+ 2006-11-07 08:26 . 2009-03-08 09:32 36864 c:\windows\system32\ieudinit.exe
- 2006-11-07 08:26 . 2009-03-08 08:32 36864 c:\windows\system32\ieudinit.exe
- 2006-06-29 13:05 . 2009-01-07 22:20 26112 c:\windows\system32\idndl.dll
+ 2006-06-29 13:05 . 2009-01-07 23:20 26112 c:\windows\system32\idndl.dll
- 2006-11-22 02:39 . 2009-01-07 22:21 121856 c:\windows\system32\xmllite.dll
+ 2006-11-22 02:39 . 2009-01-07 23:21 121856 c:\windows\system32\xmllite.dll
- 2004-08-05 12:00 . 2009-11-03 04:25 441438 c:\windows\system32\perfh009.dat
+ 2004-08-05 12:00 . 2009-11-06 02:15 441438 c:\windows\system32\perfh009.dat
+ 2009-01-07 22:20 . 2009-01-07 23:20 265720 c:\windows\system32\msdbg2.dll
- 2009-01-07 22:20 . 2009-01-07 22:20 265720 c:\windows\system32\msdbg2.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-28 1217808]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VX6000"="c:\windows\vVX6000.exe" [2006-10-13 994096]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 277296]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 88584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-12 86016]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-01-26 53248]
"Malwarebytes Anti-Malware (reboot)"="c:\nexon\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2003-10-06 24576]
"Logitech Utility"="Logi_MwX.Exe" - c:\windows\LOGI_MWX.EXE [2003-12-17 19968]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-11-12 1630208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Ultra Hal Text-to-Speech Reader Startup.lnk - c:\windows\Installer\{96EF451E-A402-44D8-BAEE-D70D558A4122}\New_Shortcut_S1449_0EB7CDB78E0C4A918D2CA535D5B8160C.exe [2006-9-24 40960]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\xpand rally\\xpandrally.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\xpand rally\\ChromEd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\il 2 sturmovik 1946\\il2fb.exe"=
"c:\\Nexon\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58719:TCP"= 58719:TCP:Pando Media Booster
"58719:UDP"= 58719:UDP:Pando Media Booster

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-10-27 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-11-04 206256]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-03-20 55152]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Fichiers communs\Symantec Shared\CCSVCHST.EXE [2008-02-18 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-05-30 101936]
S3 BS_DEF;BS_DEF;c:\program files\ASUS\AsusUpdate\BS_DEF.sys [2006-04-07 12800]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-01-12 23888]
S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 LwAdiHid;Périphériques numériques WingMan Logitech (détection automatique);c:\windows\system32\drivers\LwAdiHid.sys [2008-12-11 20864]
S3 Razerlow;Razerlow USB Filter Driver;c:\windows\system32\drivers\Razerlow.sys [2006-05-06 13225]
S3 sdAuxService;PC Tools Auxiliary Service;c:\nexon\Spyware Doctor1\pctsAuxs.exe [2009-11-04 348752]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [2006-04-13 2383152]

--- Autres Services/Pilotes en mémoire ---

*NewlyCreated* - COMHOST
*Deregistered* - mbr
*Deregistered* - mchInjDrv
*Deregistered* - PROCEXP113
.
Contenu du dossier 'Tâches planifiées'

2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-11-06 c:\windows\Tasks\User_Feed_Synchronization-{FFAC0B8B-CE55-4AEE-BE8F-39D5A6F04342}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
DPF: {BFD90062-6B5E-4F8F-87B1-5F022C14E32F} - hxxp://www.meetstream.com/activex/28019/activereceiver.cab
DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} - hxxp://www.meetstream.com/activex/28081/activeid.cab
FF - ProfilePath - c:\documents and settings\joe\Application Data\Mozilla\Firefox\Profiles\i4sf4rhw.default\
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHELINS SUPPRIMES - - - -

AddRemove-RegDefense - c:\nexon\RegDefense\uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-05 21:31
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'explorer.exe'(2260)
c:\program files\Logitech\MouseWare\System\LgWndHk.dll
c:\program files\Fichiers communs\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\eappprxy.dll
.
Heure de fin: 2009-11-06 21:34
ComboFix-quarantined-files.txt 2009-11-06 02:34
ComboFix2.txt 2009-11-03 04:47

Avant-CF: 12 834 304 000 octets libres
Après-CF: 12 790 235 136 octets libres

- - End Of File - - E2E93EDFBB41941E6C27B70017DC399E

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Please use Internet Explorer and run a BitDefender Online scan

  • Please check I agree with the Terms and Conditions and click Start Here
  • You will need to allow an Active X install for the scan to run.
  • Leave the scanning options at default and click Start Scan
Please post the results in your next reply.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
I can't do that. I can't open Internet Explorer and I can't connect to the internet.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Do you have Firefox or a different browser? Optionally you can download this one:

ESET Online Scanner

  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Hi

No I cant use firefx either. I'm telling you its like the malaware, virus or whatever blocked all my internet ports or dns or access. Firefox tells me I got no connection, iexplorer doesnt even open I get an error message and when I install a program such as a anti virus, spyware removal or else the update doesnt work saying I can't connect.

But my windows live messenger does connect! And my connection sends packets and receives it its on.

Its like if I have been unauthorized to use it.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Please re-run ComboFix and make sure your computer reboots - then post a log in your next reply.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
ok..

By The Way; at the beggining ComboFix says something about my PC not having a console to recuperate or something, and that it will install one, but then fails to connect to the internet so it doesnt install it and then proceed to run.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Here it is:

ComboFix 09-11-05.01 - joe 2009-11-07 13:28.4.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.2.1036.18.1023.561 [GMT -5:00]
Lancé depuis: c:\documents and settings\joe\Bureau\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Outdated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
FW: Norton 360 *disabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}

AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.

((((((((((((((((((((((((((((( Fichiers créés du 2009-10-07 au 2009-11-07 ))))))))))))))))))))))))))))))))))))
.

2009-11-05 03:34 . 2008-12-11 13:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-11-05 03:34 . 2009-08-24 19:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-11-05 03:34 . 2009-08-19 16:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-11-05 03:34 . 2009-11-05 03:35 -------- d-----w- c:\program files\Fichiers communs\PC Tools
2009-11-05 03:34 . 2008-12-10 16:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-11-05 03:34 . 2009-11-05 03:34 -------- d-----w- c:\documents and settings\joe\Application Data\PC Tools
2009-11-05 03:34 . 2009-11-05 03:34 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-11-04 17:34 . 2009-11-05 03:02 -------- d-----w- c:\program files\PC Tools AntiVirus
2009-11-03 04:26 . 2005-01-17 05:43 88576 ----a-w- c:\windows\system32\drivers\nvatabus.sys
2009-11-03 04:26 . 2008-04-13 18:40 96512 -c--a-w- c:\windows\system32\dllcache\atapi.sys
2009-11-03 04:26 . 2008-04-13 18:40 96512 ------w- c:\windows\system32\drivers\atapi.sys
2009-11-03 04:20 . 2009-11-03 04:20 -------- d-----w- c:\program files\Trend Micro
2009-11-03 03:53 . 2009-11-05 03:02 -------- d-----w- c:\program files\RegDefense
2009-11-03 03:48 . 2009-11-03 03:48 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2009-11-03 03:17 . 2009-11-03 03:17 -------- d-----w- c:\documents and settings\joe\Local Settings\Application Data\Mozilla
2009-11-03 02:39 . 2009-11-03 04:13 22016 ----a-w- c:\windows\system32\tdlwsp.dll
2009-11-02 23:19 . 2009-11-02 23:19 -------- d-----w- c:\documents and settings\joe\Application Data\Malwarebytes
2009-11-02 23:13 . 2009-11-06 02:12 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-28 05:28 . 2009-10-28 05:30 -------- d-----w- c:\program files\Windows Live Safety Center
2009-10-28 04:51 . 2009-10-28 04:51 -------- d-----w- c:\documents and settings\joe\Application Data\AVG8
2009-10-28 04:31 . 2009-06-30 14:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-10-23 07:32 . 2009-10-23 07:32 -------- d-----w- c:\documents and settings\joe\Application Data\SUPERAntiSpyware.com
2009-10-23 07:19 . 2008-11-26 16:08 131 ----a-w- c:\windows\IDB.zip
2009-10-23 07:19 . 2009-10-02 18:19 1152470 ----a-w- c:\windows\UDB.zip
2009-10-23 07:07 . 2009-10-28 04:22 -------- d-----w- c:\documents and settings\Malwarebytes' Anti-Malware
2009-10-23 07:07 . 2009-10-23 07:10 20949 ----a-w- c:\documents and settings\Malwarebytes' Anti-Malware\unins000.dat
2009-10-23 07:07 . 2009-10-23 07:10 -------- d-----w- c:\documents and settings\Malwarebytes' Anti-Malware\Languages
2009-10-23 06:50 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-23 06:50 . 2009-10-28 04:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-23 06:50 . 2009-10-23 06:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-23 06:50 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-23 05:40 . 2009-10-28 04:31 -------- d-----w- c:\program files\Panda Security
2009-10-23 05:37 . 2009-11-03 02:38 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-07 18:07 . 2005-10-26 22:25 -------- d-----w- c:\program files\Steam
2009-11-06 02:44 . 2006-05-27 16:36 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000004-20021102}.dat
2009-11-06 02:44 . 2006-05-27 16:36 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000004-20021102}.dat
2009-11-06 02:19 . 2006-02-04 17:22 -------- d-----w- c:\program files\Java
2009-11-06 02:15 . 2004-08-05 12:00 84874 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-06 02:15 . 2004-08-05 12:00 510656 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-28 05:18 . 2005-10-26 21:34 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2009-10-28 05:18 . 2005-10-26 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-28 05:13 . 2008-08-05 01:27 -------- d-----w- c:\program files\Norton 360
2009-10-23 07:31 . 2005-11-07 02:45 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2009-10-23 07:25 . 2009-10-28 04:17 8530 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Personal_32_1036.dat
2009-10-23 07:05 . 2007-12-25 22:22 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-30 18:58 . 2008-02-18 19:38 9576 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\CCMSLLUM.DLL
2009-09-22 02:58 . 2009-09-22 02:58 -------- d-----w- c:\program files\Cool MOV To WMV Converter
2009-09-11 23:18 . 2008-06-23 02:09 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000004-10001102}.dat
2009-09-11 23:18 . 2008-06-23 02:09 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000004-10001102}.dat
2009-09-11 14:18 . 2004-08-05 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 21:39 . 2009-03-21 00:01 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-07 05:39 . 2009-08-18 13:58 5 ----a-w- c:\windows\system32\SySAVI2WMV.dat
2009-09-04 21:04 . 2004-08-05 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 2004-08-05 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-27 08:34 . 2005-10-27 01:44 81504 ----a-w- c:\documents and settings\joe\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 08:01 . 2004-08-05 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 13:48 . 2009-08-18 13:48 34 ---ha-w- c:\windows\system32\Converter_sysquict.dat
1999-04-06 13:27 . 1999-04-06 13:27 99840 ----a-w- c:\program files\Fichiers communs\IRAABOUT.DLL
1998-12-09 03:53 . 1998-12-09 03:53 70144 ----a-w- c:\program files\Fichiers communs\IRAMDMTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 48640 ----a-w- c:\program files\Fichiers communs\IRALPTTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 31744 ----a-w- c:\program files\Fichiers communs\IRAWEBTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 186368 ----a-w- c:\program files\Fichiers communs\IRAREG.DLL
1998-12-09 03:53 . 1998-12-09 03:53 17920 ----a-w- c:\program files\Fichiers communs\IRASRIAL.DLL
.

((((((((((((((((((((((((((((( SnapShot@2009-11-03_04.41.32 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-05 12:00 . 2009-11-03 04:25 71374 c:\windows\system32\perfc009.dat
+ 2004-08-05 12:00 . 2009-11-06 02:15 71374 c:\windows\system32\perfc009.dat
- 2006-06-29 13:05 . 2009-01-07 22:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-29 13:05 . 2009-01-07 23:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-28 22:59 . 2009-01-07 23:20 24576 c:\windows\system32\nlsdl.dll
- 2006-06-28 22:59 . 2009-01-07 22:20 24576 c:\windows\system32\nlsdl.dll
+ 2006-11-07 08:26 . 2009-03-08 09:32 36864 c:\windows\system32\ieudinit.exe
- 2006-11-07 08:26 . 2009-03-08 08:32 36864 c:\windows\system32\ieudinit.exe
- 2006-06-29 13:05 . 2009-01-07 22:20 26112 c:\windows\system32\idndl.dll
+ 2006-06-29 13:05 . 2009-01-07 23:20 26112 c:\windows\system32\idndl.dll
- 2006-11-22 02:39 . 2009-01-07 22:21 121856 c:\windows\system32\xmllite.dll
+ 2006-11-22 02:39 . 2009-01-07 23:21 121856 c:\windows\system32\xmllite.dll
- 2004-08-05 12:00 . 2009-11-03 04:25 441438 c:\windows\system32\perfh009.dat
+ 2004-08-05 12:00 . 2009-11-06 02:15 441438 c:\windows\system32\perfh009.dat
+ 2009-01-07 22:20 . 2009-01-07 23:20 265720 c:\windows\system32\msdbg2.dll
- 2009-01-07 22:20 . 2009-01-07 22:20 265720 c:\windows\system32\msdbg2.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-28 1217808]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VX6000"="c:\windows\vVX6000.exe" [2006-10-13 994096]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 277296]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 88584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-12 86016]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-01-26 53248]
"Malwarebytes Anti-Malware (reboot)"="c:\nexon\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2003-10-06 24576]
"Logitech Utility"="Logi_MwX.Exe" - c:\windows\LOGI_MWX.EXE [2003-12-17 19968]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-11-12 1630208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Ultra Hal Text-to-Speech Reader Startup.lnk - c:\windows\Installer\{96EF451E-A402-44D8-BAEE-D70D558A4122}\New_Shortcut_S1449_0EB7CDB78E0C4A918D2CA535D5B8160C.exe [2006-9-24 40960]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\xpand rally\\xpandrally.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\xpand rally\\ChromEd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\il 2 sturmovik 1946\\il2fb.exe"=
"c:\\Nexon\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58719:TCP"= 58719:TCP:Pando Media Booster
"58719:UDP"= 58719:UDP:Pando Media Booster

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-10-27 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-11-04 206256]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-03-20 55152]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Fichiers communs\Symantec Shared\CCSVCHST.EXE [2008-02-18 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-05-30 101936]
S3 BS_DEF;BS_DEF;c:\program files\ASUS\AsusUpdate\BS_DEF.sys [2006-04-07 12800]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-01-12 23888]
S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 LwAdiHid;Périphériques numériques WingMan Logitech (détection automatique);c:\windows\system32\drivers\LwAdiHid.sys [2008-12-11 20864]
S3 Razerlow;Razerlow USB Filter Driver;c:\windows\system32\drivers\Razerlow.sys [2006-05-06 13225]
S3 sdAuxService;PC Tools Auxiliary Service;c:\nexon\Spyware Doctor1\pctsAuxs.exe [2009-11-04 348752]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [2006-04-13 2383152]

--- Autres Services/Pilotes en mémoire ---

*NewlyCreated* - COMHOST
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
Contenu du dossier 'Tâches planifiées'

2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-11-07 c:\windows\Tasks\User_Feed_Synchronization-{FFAC0B8B-CE55-4AEE-BE8F-39D5A6F04342}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
DPF: {BFD90062-6B5E-4F8F-87B1-5F022C14E32F} - hxxp://www.meetstream.com/activex/28019/activereceiver.cab
DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} - hxxp://www.meetstream.com/activex/28081/activeid.cab
FF - ProfilePath - c:\documents and settings\joe\Application Data\Mozilla\Firefox\Profiles\i4sf4rhw.default\
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-07 13:35
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'explorer.exe'(2212)
c:\program files\Logitech\MouseWare\System\LgWndHk.dll
c:\program files\Fichiers communs\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\eappprxy.dll
.
Heure de fin: 2009-11-07 13:38
ComboFix-quarantined-files.txt 2009-11-07 18:38
ComboFix2.txt 2009-11-07 18:22
ComboFix3.txt 2009-11-06 02:34
ComboFix4.txt 2009-11-03 04:47

Avant-CF: 12 779 466 752 octets libres
Après-CF: 12 757 917 696 octets libres

- - End Of File - - DC307C18F5E768F7C5173386A4354694

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Please post a new HijackThis log.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:33:14, on 2009-11-07
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\vVX6000.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\program files\steam\steam.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Zabaware\HalReader\HalReader.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Nexon\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Nexon\Spyware Doctor\BDT\PCTBrowserDefender.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Nexon\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Ultra Hal Text-to-Speech Reader Startup.lnk = ?
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - https://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - https://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - https://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1139865876750
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://toinc009.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - https://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BFD90062-6B5E-4F8F-87B1-5F022C14E32F} (ActiveReceiver Control) - http://www.meetstream.com/activex/28019/activereceiver.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15021/CTPID.cab
O16 - DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} (ActiveID Control) - http://www.meetstream.com/activex/28081/activeid.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Nexon\Spyware Doctor1\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Nexon\Spyware Doctor1\pctsSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 10176 bytes

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Please use Internet Explorer and run a BitDefender Online scan

  • Please check I agree with the Terms and Conditions and click Start Here
  • You will need to allow an Active X install for the scan to run.
  • Leave the scanning options at default and click Start Scan
Please post the results in your next reply.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
can't still cannot use internet, says unauthorised right to use iexplorer.exe.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
I cant open iexplorer.exe at all and mozilla cannot connect. I cant use any programs automatic update such as the mbam one it says I'm not connected.

However my connection does show in my tool bar, I can also connect to wlmsn. I did a reset of dns, ip release ip renew in cmd DOS still didnt fȋxed anything.

I think ill just refrmt my hard drive, I havent moved since a 2 weeks now Sad tearing

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Are you saying you want to do a reformat and reinstall?

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
DragonMaster Jay wrote:
Are you saying you want to do a reformat and reinstall?


Well my problem is that my Windows copy is at my mom house a 3 hours drive :S . I would like to avoid to reformat and reinstall everything and lose a lot of data, reinstalling all those hardware drivers etc...

But so far i'm out of solutions. I read others forum where people also lost connection after a spyware, malaware virus removal, and they all ended up giving up and reformating because the solutions proposed didnt worked.

Plus here I'v been telling you guys 5 times I don't have internet acces with iexplorer or firefox and you keep giving me internet links to do online scans. I ... cannot.. connect! I can only connect with limewire and windows live messenger.

Can you help? Ill go get my windows copy next weekend, so I still have a week to try everything you tell me!

Cheers

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
There may not be a reason to do the reformat and reinstall.

My apologies on the Internet issue. Most of the time, we instruct users to transfer the download from another computer, on to the infected computer - using a flash drive, burnt CD/DVD, or external drive.

With that in mind, we are going to need a tool that will probably help restore the connection. Please transfer the download from another computer to the infected one.

Download Dial-A-Fix from here.

Save it to your Desktop.

Open Dial-a-fix.exe

Click the green checkmark at the bottom of the window; this should select all options.

Now, click GO.

Allow it to run (the status will be displayed at the bottom), and follow any prompts you receive.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Hi,

It doesnt work, I got a bunch of error 127 during the scan. saying a .dll file is either corrupted or not recognized. Should I write them down for you?

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Yes, knowing the DLLs will be good. Having the log will be better.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
how do I get the log? does it save it somewhere?

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Ok I got it.

Log of DIal-a-fix

00:25:36 | Dial-a-fix was unable to determine your version of Internet Explorer
Notes about this log:
1) "->" denotes an external command being executed, and "-> (number)" indicates
the return code from the previous command
2) Not all external command return codes are accurate, or useful
3) Sometimes commands return 0 (no error) even when they fail or crash
4) If an error occurs while registering an object, please send an email to:
dial-a-fix@DjLizard.net and include a copy of this log

DAF version: v0.60.0.24

--- System info ---
OS: Microsoft Windows XP Service Pack 3
IE version: 8.0.6001.18702
MPC: 76412-OEM
CPU: AMD Athlon(tm) 64 Processor 3500+ (~2220MHz)
CPU: CPU is 64-bit or has 64-bit extensions
BIOS: 2005-06-30
Memory (approx): 1023MB
Uptime: 0 hour(s)
Current directory: C:\Nexon\Dial-a-fix-v0.60.0.24
---

2009-11-10 00:25:36 -- Dial-a-fix : [v0.60.0.24] -- started
00:25:36 | Policy scan started
00:25:36 | Policy scan ended - no restrictive policies were found
--- Emptying temp folders ---
00:25:44 | Deleting C:\Documents and Settings\joe\Local Settings\temp...
00:25:44 | C:\Documents and Settings\joe\Local Settings\temp could not be completely emptied, please reboot and try again
00:25:44 | Deleting C:\WINDOWS\temp...
00:25:44 | C:\WINDOWS\temp has been re-created
00:25:44 | Deleting C:\DOCUME~1\joe\LOCALS~1\Temp...
00:25:44 | C:\DOCUME~1\joe\LOCALS~1\Temp could not be completely emptied, please reboot and try again
--- MSI ---
00:25:47 | Registered: C:\WINDOWS\system32\msi.dll
--- Windows Update ---
--- Registration: Windows Update/Automatic Update DLLs ---
00:25:55 | Unregistered: C:\WINDOWS\system32\msxml.dll
00:25:55 | Registered: C:\WINDOWS\system32\msxml.dll
00:25:55 | Unregistered: C:\WINDOWS\system32\msxml2.dll
00:25:55 | Registered: C:\WINDOWS\system32\msxml2.dll
00:25:58 | Unregistered: C:\WINDOWS\system32\msxml3.dll
00:25:58 | Registered: C:\WINDOWS\system32\msxml3.dll
00:25:58 | Unregistered: C:\WINDOWS\system32\qmgr.dll
00:25:58 | Registered: C:\WINDOWS\system32\qmgr.dll
00:25:58 | Unregistered: C:\WINDOWS\system32\qmgrprxy.dll
00:25:58 | Registered: C:\WINDOWS\system32\qmgrprxy.dll
00:25:58 | Unregistered: C:\WINDOWS\system32\muweb.dll
00:25:58 | Registered: C:\WINDOWS\system32\muweb.dll
00:25:58 | Unregistered: C:\WINDOWS\system32\winhttp.dll
00:25:59 | Registered: C:\WINDOWS\system32\winhttp.dll
00:25:59 | Registered: C:\WINDOWS\system32\wuapi.dll
00:25:59 | Unregistered: C:\WINDOWS\system32\wuaueng.dll
00:25:59 | Registered: C:\WINDOWS\system32\wuaueng.dll
00:25:59 | Unregistered: C:\WINDOWS\system32\wuaueng1.dll
00:25:59 | Registered: C:\WINDOWS\system32\wuaueng1.dll
00:25:59 | Unregistered: C:\WINDOWS\system32\wucltui.dll
00:25:59 | Registered: C:\WINDOWS\system32\wucltui.dll
00:25:59 | Unregistered: C:\WINDOWS\system32\wups.dll
00:25:59 | Registered: C:\WINDOWS\system32\wups.dll
00:25:59 | Unregistered: C:\WINDOWS\system32\wups2.dll
00:25:59 | Registered: C:\WINDOWS\system32\wups2.dll
00:25:59 | Unregistered: C:\WINDOWS\system32\wuweb.dll
00:25:59 | Registered: C:\WINDOWS\system32\wuweb.dll
00:25:59 | Registered: C:\WINDOWS\system32\ole32.dll
--- SSL/HTTPS/Cryptography ---
00:26:11 | Executed 'cmd.exe /c rmdir /q /s C:\WINDOWS\system32\Catroot2'
--- Registration: SSL/HTTPS/Cryptography ---
00:26:15 | Unregistered: C:\WINDOWS\system32\cryptdlg.dll
00:26:15 | Registered: C:\WINDOWS\system32\cryptdlg.dll
00:26:15 | Unregistered: C:\WINDOWS\system32\cryptui.dll
00:26:15 | Registered: C:\WINDOWS\system32\cryptui.dll
00:26:16 | Unregistered: C:\WINDOWS\system32\cryptext.dll
00:26:16 | Registered: C:\WINDOWS\system32\cryptext.dll
00:26:16 | Unregistered: C:\WINDOWS\system32\dssenh.dll
00:26:16 | Registered: C:\WINDOWS\system32\dssenh.dll
00:26:16 | Unregistered: C:\WINDOWS\system32\gpkcsp.dll
00:26:16 | Registered: C:\WINDOWS\system32\gpkcsp.dll
00:26:16 | Unregistered: C:\WINDOWS\system32\initpki.dll
00:26:36 | Registered: C:\WINDOWS\system32\initpki.dll
00:26:36 | Unregistered: C:\WINDOWS\system32\licdll.dll
00:26:36 | Registered: C:\WINDOWS\system32\licdll.dll
00:26:36 | Unregistered: C:\WINDOWS\system32\mssign32.dll
00:26:36 | Registered: C:\WINDOWS\system32\mssign32.dll
00:26:36 | Unregistered: C:\WINDOWS\system32\mssip32.dll
00:26:36 | Registered: C:\WINDOWS\system32\mssip32.dll
00:26:37 | Unregistered: C:\WINDOWS\system32\scardssp.dll
00:26:37 | Registered: C:\WINDOWS\system32\scardssp.dll
00:26:37 | Unregistered: C:\WINDOWS\system32\sccbase.dll
00:26:37 | Registered: C:\WINDOWS\system32\sccbase.dll
00:26:37 | Unregistered: C:\WINDOWS\system32\scecli.dll
00:26:37 | Registered: C:\WINDOWS\system32\scecli.dll
00:26:37 | Unregistered: C:\WINDOWS\system32\softpub.dll
00:26:37 | Registered: C:\WINDOWS\system32\softpub.dll
00:26:37 | Unregistered: C:\WINDOWS\system32\slbcsp.dll
00:26:37 | Registered: C:\WINDOWS\system32\slbcsp.dll
00:26:37 | Unregistered: C:\WINDOWS\system32\regwizc.dll
00:26:37 | Registered: C:\WINDOWS\system32\regwizc.dll
00:26:37 | Unregistered: C:\WINDOWS\system32\rsaenh.dll
00:26:37 | Registered: C:\WINDOWS\system32\rsaenh.dll
00:26:37 | Unregistered: C:\WINDOWS\system32\winhttp.dll
00:26:37 | Registered: C:\WINDOWS\system32\winhttp.dll
00:26:37 | Unregistered: C:\WINDOWS\system32\wintrust.dll
00:26:37 | Registered: C:\WINDOWS\system32\wintrust.dll
--- Registration: ActiveX controls/codecs ---
00:26:37 | Registered: C:\WINDOWS\system32\acelpdec.ax
00:26:37 | Registered: C:\WINDOWS\system32\actxprxy.dll
00:26:37 | Registered: C:\WINDOWS\system32\asctrls.ocx
00:26:37 | Registered: C:\WINDOWS\system32\daxctle.ocx
00:26:38 | Registered: C:\WINDOWS\system32\hhctrl.ocx
00:26:38 | Registered: C:\WINDOWS\system32\l3codecx.ax
00:26:38 | Registered: C:\WINDOWS\system32\licmgr10.dll
00:26:38 | Registered: C:\WINDOWS\system32\mpg4ds32.ax
00:26:39 | Registered: C:\WINDOWS\system32\msdxm.ocx
00:26:39 | Registered: C:\WINDOWS\system32\proctexe.ocx
00:26:39 | Registered: C:\WINDOWS\system32\tdc.ocx
00:26:39 | Registered: C:\WINDOWS\system32\wshom.ocx
--- Registration: Control Panel applets ---
00:26:39 | DllInstalled: C:\WINDOWS\system32\inetcpl.cpl
00:26:39 | DllInstalled: C:\WINDOWS\system32\appwiz.cpl
00:26:39 | Registered: C:\WINDOWS\system32\appwiz.cpl
00:26:39 | DllInstalled: C:\WINDOWS\system32\nusrmgr.cpl
00:26:39 | Registered: C:\WINDOWS\system32\nusrmgr.cpl
--- Registration: Direct[X|Draw|Show|Media] ---
00:26:40 | Registered: C:\WINDOWS\system32\quartz.dll
00:26:40 | Registered: C:\WINDOWS\system32\danim.dll
00:26:40 | Registered: C:\WINDOWS\system32\dmscript.dll
00:26:40 | Registered: C:\WINDOWS\system32\dmstyle.dll
00:26:40 | Registered: C:\WINDOWS\system32\dxmasf.dll
00:26:40 | Registered: C:\WINDOWS\system32\dxtmsft.dll
00:26:40 | Registered: C:\WINDOWS\system32\dxtrans.dll
00:26:40 | Registered: C:\WINDOWS\system32\sbe.dll
--- Registration: Programming cores/runtimes ---
00:26:40 | Registered: C:\WINDOWS\system32\atl.dll
00:26:40 | Registered: C:\WINDOWS\system32\corpol.dll
00:26:40 | Registered: C:\WINDOWS\system32\jscript.dll
00:26:40 | Registered: C:\WINDOWS\system32\dispex.dll
00:26:40 | Registered: C:\WINDOWS\system32\scrrun.dll
00:26:40 | Registered: C:\WINDOWS\system32\scrobj.dll
00:26:40 | Registered: C:\WINDOWS\system32\vbscript.dll
00:26:40 | Registered: C:\WINDOWS\system32\wshext.dll
--- Registration: Explorer/IE/OE/shell/WMP ---
00:26:40 | Registered: C:\WINDOWS\system32\activeds.dll
00:26:40 | Registered: C:\WINDOWS\system32\audiodev.dll
00:26:40 | DllInstalled: C:\WINDOWS\system32\browseui.dll
00:26:40 | Registered: C:\WINDOWS\system32\browseui.dll
00:26:41 | Registered: C:\WINDOWS\system32\browsewm.dll
00:26:41 | Registered: C:\WINDOWS\system32\cabview.dll
00:26:41 | Registered: C:\WINDOWS\system32\cdfview.dll
00:26:41 | Registered: C:\WINDOWS\system32\clbcatex.dll
00:26:41 | Registered: C:\WINDOWS\system32\clbcatq.dll
00:26:41 | Registered: C:\WINDOWS\system32\comcat.dll
00:26:41 | Registered: C:\WINDOWS\system32\cscui.dll
00:26:41 | Registered: C:\WINDOWS\system32\credui.dll
00:26:41 | Registered: C:\WINDOWS\system32\datime.dll
00:26:41 | Registered: C:\WINDOWS\system32\devmgr.dll
00:26:41 | Registered: C:\WINDOWS\system32\dfsshlex.dll
00:26:41 | Registered: C:\WINDOWS\system32\dmdlgs.dll
00:26:41 | Registered: C:\WINDOWS\system32\dmdskmgr.dll
00:26:41 | Registered: C:\WINDOWS\system32\dmloader.dll
00:26:41 | Registered: C:\WINDOWS\system32\dmocx.dll
00:26:41 | Registered: C:\WINDOWS\system32\dmview.ocx
00:26:41 | DllInstalled: C:\WINDOWS\system32\dsuiext.dll
00:26:41 | Registered: C:\WINDOWS\system32\dsuiext.dll
00:26:41 | DllInstalled: C:\WINDOWS\system32\dsquery.dll
00:26:41 | Registered: C:\WINDOWS\system32\dsquery.dll
00:26:41 | Registered: C:\WINDOWS\system32\dskquoui.dll
00:26:41 | Registered: C:\WINDOWS\system32\els.dll
00:26:41 | Registered: C:\WINDOWS\system32\es.dll
00:26:41 | Registered: C:\WINDOWS\system32\fontext.dll
00:26:41 | Registered: C:\WINDOWS\system32\hlink.dll
00:26:41 | Registered: C:\WINDOWS\system32\hnetcfg.dll
00:26:42 | Registered: C:\WINDOWS\system32\iedkcs32.dll
00:26:42 | Registered: C:\WINDOWS\system32\iepeers.dll
00:26:42 | Error 127: C:\WINDOWS\system32\iesetup.dll is not registerable or the file is corrupted. Version: 8.00.6001.18702
00:28:04 | Error 127: C:\WINDOWS\system32\iesetup.dll is not DLLInstall-able or the file is corrupted. Version: 8.00.6001.18702
00:28:20 | Registered: C:\WINDOWS\system32\ils.dll
00:28:20 | Error 127: C:\WINDOWS\system32\imgutil.dll is not registerable or the file is corrupted. Version: 8.00.6001.18702
00:30:12 | Registered: C:\WINDOWS\system32\inetcfg.dll
00:30:12 | Registered: C:\WINDOWS\system32\inetcomm.dll
00:30:12 | Error 127: C:\WINDOWS\system32\inseng.dll is not registerable or the file is corrupted. Version: 8.00.6001.18702
00:30:42 | Error 127: C:\WINDOWS\system32\inseng.dll is not DLLInstall-able or the file is corrupted. Version: 8.00.6001.18702
00:30:44 | Registered: C:\WINDOWS\system32\laprxy.dll
00:30:44 | Registered: C:\WINDOWS\system32\lmrt.dll
00:30:44 | Registered: C:\WINDOWS\system32\mlang.dll
00:30:45 | Registered: C:\WINDOWS\system32\mmcndmgr.dll
00:30:45 | Registered: C:\WINDOWS\system32\mmcshext.dll
00:30:45 | Registered: C:\WINDOWS\system32\mscoree.dll
00:30:45 | Error 127: C:\WINDOWS\system32\mshtml.dll is not registerable or the file is corrupted. Version: 8.00.6001.18828
00:31:30 | Error 127: C:\WINDOWS\system32\mshtml.dll is not DLLInstall-able or the file is corrupted. Version: 8.00.6001.18828
00:31:36 | Registered: C:\WINDOWS\system32\mshtmled.dll
00:31:36 | Registered: C:\WINDOWS\system32\msieftp.dll
00:31:36 | Registered: C:\WINDOWS\system32\msoeacct.dll
00:31:36 | Registered: C:\WINDOWS\system32\msr2c.dll
00:31:36 | Error 127: C:\WINDOWS\system32\msrating.dll is not registerable or the file is corrupted. Version: 8.00.6001.18702
00:32:14 | DllInstalled: C:\WINDOWS\system32\mydocs.dll
00:32:14 | Registered: C:\WINDOWS\system32\mydocs.dll
00:32:15 | Registered: C:\WINDOWS\system32\mstime.dll
00:32:15 | Registered: C:\WINDOWS\system32\netcfgx.dll
00:32:15 | DllInstalled: C:\WINDOWS\system32\netplwiz.dll
00:32:15 | Registered: C:\WINDOWS\system32\netplwiz.dll
00:32:15 | Registered: C:\WINDOWS\system32\netman.dll
00:32:15 | Registered: C:\WINDOWS\system32\netshell.dll
00:32:15 | Registered: C:\WINDOWS\system32\ntmsevt.dll
00:32:15 | Registered: C:\WINDOWS\system32\ntmsmgr.dll
00:32:15 | DllInstalled: C:\WINDOWS\system32\ntmssvc.dll
00:32:15 | Registered: C:\WINDOWS\system32\ntmssvc.dll
00:32:15 | Error 127: C:\WINDOWS\system32\occache.dll is not registerable or the file is corrupted. Version: 8.00.6001.18828
00:32:47 | Error 127: C:\WINDOWS\system32\occache.dll is not DLLInstall-able or the file is corrupted. Version: 8.00.6001.18828
00:32:50 | Registered: C:\WINDOWS\system32\ole32.dll
00:32:50 | Registered: C:\WINDOWS\system32\oleaut32.dll
00:32:50 | Registered: C:\WINDOWS\system32\oleacc.dll
00:32:50 | Registered: C:\WINDOWS\system32\olepro32.dll
00:32:50 | DllInstalled: C:\WINDOWS\system32\photowiz.dll
00:32:50 | Registered: C:\WINDOWS\system32\photowiz.dll
00:32:50 | Error 127: C:\WINDOWS\system32\pngfilt.dll is not registerable or the file is corrupted. Version: 8.00.6001.18702
00:33:15 | Registered: C:\WINDOWS\system32\remotepg.dll
00:33:15 | Registered: C:\WINDOWS\system32\rpcrt4.dll
00:33:15 | Registered: C:\WINDOWS\system32\rshx32.dll
00:33:15 | Registered: C:\WINDOWS\system32\sendmail.dll
00:33:15 | Registered: C:\WINDOWS\system32\slayerxp.dll
00:33:15 | DllInstalled: C:\WINDOWS\system32\shdocvw.dll
00:33:15 | Registered: C:\WINDOWS\system32\shdocvw.dll
00:33:15 | Registered: C:\WINDOWS\system32\shell32.dll
00:33:17 | DllInstalled: C:\WINDOWS\system32\shell32.dll
00:33:17 | Registered: C:\WINDOWS\system32\shmedia.dll
00:33:17 | DllInstalled: C:\WINDOWS\system32\shimgvw.dll
00:33:17 | Registered: C:\WINDOWS\system32\shimgvw.dll
00:33:17 | DllInstalled: C:\WINDOWS\system32\shsvcs.dll
00:33:17 | Registered: C:\WINDOWS\system32\shsvcs.dll
00:33:17 | Registered: C:\WINDOWS\system32\srclient.dll
00:33:17 | Unregistered: C:\WINDOWS\system32\stobject.dll
00:33:17 | Registered: C:\WINDOWS\system32\stobject.dll
00:33:17 | DllInstalled: C:\WINDOWS\system32\themeui.dll
00:33:17 | Registered: C:\WINDOWS\system32\themeui.dll
00:33:17 | Registered: C:\WINDOWS\system32\twext.dll
00:33:17 | DllInstalled: C:\WINDOWS\system32\urlmon.dll
00:33:17 | Registered: C:\WINDOWS\system32\urlmon.dll
00:33:17 | Registered: C:\WINDOWS\system32\userenv.dll
00:33:17 | Error 127: C:\WINDOWS\system32\webcheck.dll is not registerable or the file is corrupted. Version: 8.00.6001.18702
00:33:40 | Error 127: C:\WINDOWS\system32\webcheck.dll is not DLLInstall-able or the file is corrupted. Version: 8.00.6001.18702
00:33:42 | Registered: C:\WINDOWS\system32\webvw.dll
00:33:42 | Registered: C:\WINDOWS\system32\winhttp.dll
00:33:42 | DllInstalled: C:\WINDOWS\system32\wininet.dll
00:33:42 | Registered: C:\WINDOWS\system32\zipfldr.dll
00:33:42 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\msdadc.dll
00:33:42 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\msdaenum.dll
00:33:42 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\msdaer.dll
00:33:42 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\msdaipp.dll
00:33:42 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\msdaora.dll
00:33:42 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\msdaosp.dll
00:33:42 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\msdaps.dll
00:33:42 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\msdasc.dll
00:33:43 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\msdasql.dll
00:33:43 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\msdatt.dll
00:33:43 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\msdaurl.dll
00:33:43 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\msxactps.dll
00:33:43 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\oledb32.dll
00:33:43 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\oledb32r.dll
00:33:43 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\sqloledb.dll
00:33:43 | Registered: C:\Program Files\Fichiers communs\system\Ole DB\sqlxmlx.dll


_____________________________

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
It appears Internet Explorer (8?) is corrupted.

Please go to Control Panel > Add or Remove programs, and uninstall Internet Explorer.

Then, see if you can access the Internet.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
I think I deleted it... Not sure it was shown as IE8 upgrades. Also went in windows elements unclicked iexplorer icon and it delted it as well.

Now I rebooted. So how do I reinstall it?

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
ouch, windows automatic updater made me redownload ie8 which I did but it failed. I also still cannot connect to online updater and other programs using an internet connection such as steam. Even worst my windows live messnger is asking to re install the new update and it fails too.

I think I deleted something I shouldnt have

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Go Start and then to Run,
Type in: sfc /scannow
Click OK.
Have Windows CD/DVD handy.
If System File Checker (sfc) finds any errors, it may ask you for the CD/DVD.
If sfc does not find any errors in Windows XP, it will simply quit, without any message.

If you don't have Windows CD....

Go Start and then Run
type in regedit and click OK


Navigate to the following key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup

On the right hand side, find: SourcePath

It probably has an entry pointing to your CD-ROM drive, usually D and that is why it is asking for the XP CD.
All we need to do is change it to: C:
Now, double click the SourcePath setting and a new box will pop up.
Change the drive letter from your CD drive to your root drive, usually C:
Close Registry Editor.

Now restart your computer and try sfc /scannow again!

After the first run, reboot your computer. Do a second run. Now the scan and fix is finished.

==

Then, see if those errors persist, please.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
yeah I do have my windows XP copy is just the cd key is at my mom house.

So anyway I performed the first scan, it didnt said nothing the CD Drive was spinning but it just finished like that. Am I supposed to get a report or something? Anyway because it takes a while to do I will perform the 2nd one tomorrow and let you know the result tomorrow night. Its 2 am and I work tomorrow, well in 5 hours!

Thanks for the help so far DragonMaster Jay!

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Hi Dragonmaster Jay,

After second scan nothing happened. No errors reported to fix, still have all my issues.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Would you be able to transfer a download of Internet Explorer from another computer to yours, to install?

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Im not sure I understand what your asking. I have acces to a laptop with internt and a USB storage key. Would that do it?

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Yes, it should.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Ok cool, so what should I do?

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Download Internet Explorer from here: http://www.microsoft.com/windows/Internet-explorer/default.aspx
Save the download, not open it.
Then, transfer the saved download to your flash drive or other storage media, and then on to the infected computer.

Install it after it gets transferred on to the infected computer. Did this work?

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Hi DragonMaster Jay,

It doesnt install, it does the same when windows update try to make me install it. It fails at the second step (detecting spyware etc) and at the third (installing explorer 8) and then it stops telling me it cant install explorer 8.

THings you should know:

Any programs that requieres the internet doesnt work. Anything related to explorer or spybots removal most of them dont work. My connection is on and alive tho.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
oh and since the beggining, when I click on the ie icon, I get the error message that windows cannot access the file or doesnt have the approprate authorisation to do so.

Again, I think thatg my problem is more as if I have been stripped off my admin rights on my computer.

descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

more_horiz
Once again, transfer the download, and then open it.

  1. Download peek.bat from the download link below and save it to your Desktop.

  • Double-click peek.bat to run it.
      A black Command Prompt window will appear shortly: the program is running.

  • Once it is finished, copy and paste the entire contents of the Log.txt (transfer the text file back, etc) file it creates as a reply to this post.
  • descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    Le volume dans le lecteur C n'a pas de nom.
    Le num‚ro de s‚rie du volume est 7C63-623B

    R‚pertoire de C:\WINDOWS\$NtServicePackUninstall$

    2004-08-05 07:00 186ÿ368 scecli.dll

    R‚pertoire de C:\WINDOWS\$NtServicePackUninstall$

    2004-08-05 07:00 407ÿ040 netlogon.dll

    R‚pertoire de C:\WINDOWS\$NtServicePackUninstall$

    2004-08-05 07:00 55ÿ808 eventlog.dll
    3 fichier(s) 649ÿ216 octets

    R‚pertoire de C:\WINDOWS\ERDNT\cache

    2008-04-13 21:33 187ÿ392 scecli.dll

    R‚pertoire de C:\WINDOWS\ERDNT\cache

    2008-04-13 21:33 407ÿ040 netlogon.dll

    R‚pertoire de C:\WINDOWS\ERDNT\cache

    2008-04-13 21:33 56ÿ320 eventlog.dll
    3 fichier(s) 650ÿ752 octets

    R‚pertoire de C:\WINDOWS\ServicePackFiles\i386

    2008-04-13 21:33 187ÿ392 scecli.dll

    R‚pertoire de C:\WINDOWS\ServicePackFiles\i386

    2008-04-13 21:33 407ÿ040 netlogon.dll

    R‚pertoire de C:\WINDOWS\ServicePackFiles\i386

    2008-04-13 21:33 56ÿ320 eventlog.dll
    3 fichier(s) 650ÿ752 octets

    R‚pertoire de C:\WINDOWS\system32

    2008-04-13 21:33 187ÿ392 scecli.dll

    R‚pertoire de C:\WINDOWS\system32

    2008-04-13 21:33 407ÿ040 netlogon.dll

    R‚pertoire de C:\WINDOWS\system32

    2008-04-13 21:33 56ÿ320 eventlog.dll
    3 fichier(s) 650ÿ752 octets

    R‚pertoire de C:\WINDOWS\system32\dllcache

    2008-04-13 21:33 187ÿ392 scecli.dll

    R‚pertoire de C:\WINDOWS\system32\dllcache

    2008-04-13 21:33 407ÿ040 netlogon.dll

    R‚pertoire de C:\WINDOWS\system32\dllcache

    2008-04-13 21:33 56ÿ320 eventlog.dll
    3 fichier(s) 650ÿ752 octets

    Total des fichiers list‚sÿ:
    15 fichier(s) 3ÿ252ÿ224 octets
    0 R‚p(s) 11ÿ234ÿ775ÿ040 octets libres

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:

      Code:


      :filefind
      scecli.dll
      netlogon.dll
      eventlog.dll
      winlogon.exe
      comres.dll
      crypt32.dll
      gpedit.dll
      rundll32.exe
      sfc.dll
      svchost.exe
      cngaudit.dll
      beep.sys
      wscntfy.exe
      atapi.sys


    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    There you go sir

    SystemLook v1.0 by jpshortstuff (29.08.09)
    Log created at 22:43 on 12/11/2009 by joe (Administrator - Elevation successful)

    ========== filefind ==========

    Searching for "scecli.dll"
    C:\WINDOWS\$NtServicePackUninstall$\scecli.dll -----c 186368 bytes [22:30 22/08/2008] [12:00 05/08/2004] DEC0397F35D027874804EC72979D03CC
    C:\WINDOWS\ERDNT\cache\scecli.dll --a--- 187392 bytes [04:45 03/11/2009] [02:33 14/04/2008] 973B36634C544948C663E8269AA1B3A3
    C:\WINDOWS\ServicePackFiles\i386\scecli.dll ------ 187392 bytes [02:33 14/04/2008] [02:33 14/04/2008] 973B36634C544948C663E8269AA1B3A3
    C:\WINDOWS\system32\dllcache\scecli.dll --a--c 187392 bytes [12:00 05/08/2004] [02:33 14/04/2008] 973B36634C544948C663E8269AA1B3A3
    C:\WINDOWS\system32\scecli.dll ------ 187392 bytes [12:00 05/08/2004] [02:33 14/04/2008] 973B36634C544948C663E8269AA1B3A3

    Searching for "netlogon.dll"
    C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll -----c 407040 bytes [22:30 22/08/2008] [12:00 05/08/2004] FAF07FDCDE76000621A28D19F8E2E8EB
    C:\WINDOWS\ERDNT\cache\netlogon.dll --a--- 407040 bytes [04:45 03/11/2009] [02:33 14/04/2008] 04821179C3171554C1BD1F9888A113E2
    C:\WINDOWS\ServicePackFiles\i386\netlogon.dll ------ 407040 bytes [02:33 14/04/2008] [02:33 14/04/2008] 04821179C3171554C1BD1F9888A113E2
    C:\WINDOWS\system32\dllcache\netlogon.dll --a--c 407040 bytes [12:00 05/08/2004] [02:33 14/04/2008] 04821179C3171554C1BD1F9888A113E2
    C:\WINDOWS\system32\netlogon.dll ------ 407040 bytes [12:00 05/08/2004] [02:33 14/04/2008] 04821179C3171554C1BD1F9888A113E2

    Searching for "eventlog.dll"
    C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll -----c 55808 bytes [22:30 22/08/2008] [12:00 05/08/2004] 21E83876A6287F15538EF187D286FE11
    C:\WINDOWS\ERDNT\cache\eventlog.dll --a--- 56320 bytes [04:45 03/11/2009] [02:33 14/04/2008] 4EC800BDF80521B0207BD2301DFC7D14
    C:\WINDOWS\ServicePackFiles\i386\eventlog.dll ------ 56320 bytes [02:33 14/04/2008] [02:33 14/04/2008] 4EC800BDF80521B0207BD2301DFC7D14
    C:\WINDOWS\system32\dllcache\eventlog.dll --a--c 56320 bytes [12:00 05/08/2004] [02:33 14/04/2008] 4EC800BDF80521B0207BD2301DFC7D14
    C:\WINDOWS\system32\eventlog.dll ------ 56320 bytes [12:00 05/08/2004] [02:33 14/04/2008] 4EC800BDF80521B0207BD2301DFC7D14

    Searching for "winlogon.exe"
    C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe -----c 506368 bytes [22:30 22/08/2008] [12:00 05/08/2004] D2DE785AEAB0BB8CA4C14A8A199DBE4E
    C:\WINDOWS\ERDNT\cache\winlogon.exe --a--- 512000 bytes [04:45 03/11/2009] [02:34 14/04/2008] DD73D6B9F6B4CB630CF35B438B540174
    C:\WINDOWS\ServicePackFiles\i386\winlogon.exe ------ 512000 bytes [02:34 14/04/2008] [02:34 14/04/2008] DD73D6B9F6B4CB630CF35B438B540174
    C:\WINDOWS\system32\dllcache\winlogon.exe --a--c 512000 bytes [12:00 05/08/2004] [02:34 14/04/2008] DD73D6B9F6B4CB630CF35B438B540174
    C:\WINDOWS\system32\winlogon.exe ------ 512000 bytes [12:00 05/08/2004] [02:34 14/04/2008] DD73D6B9F6B4CB630CF35B438B540174

    Searching for "comres.dll"
    C:\WINDOWS\$NtServicePackUninstall$\comres.dll -----c 851968 bytes [22:30 22/08/2008] [12:00 05/08/2004] 19428638D8F4440F67519BD03A623BBB
    C:\WINDOWS\ServicePackFiles\i386\comres.dll ------ 851968 bytes [02:33 14/04/2008] [02:33 14/04/2008] F4B7146C7EED6C4E158DCD9B5266C25A
    C:\WINDOWS\system32\comres.dll --a--- 851968 bytes [12:00 05/08/2004] [02:33 14/04/2008] F4B7146C7EED6C4E158DCD9B5266C25A
    C:\WINDOWS\system32\dllcache\comres.dll --a--c 851968 bytes [12:00 05/08/2004] [02:33 14/04/2008] F4B7146C7EED6C4E158DCD9B5266C25A

    Searching for "crypt32.dll"
    C:\WINDOWS\$NtServicePackUninstall$\crypt32.dll -----c 604672 bytes [22:30 22/08/2008] [12:00 05/08/2004] FD8631128E14583F135EB4B3F37EF626
    C:\WINDOWS\ServicePackFiles\i386\crypt32.dll ------ 606208 bytes [02:33 14/04/2008] [02:33 14/04/2008] 39976DAD9564B336B153184268DB032F
    C:\WINDOWS\system32\crypt32.dll --a--- 606208 bytes [12:00 05/08/2004] [02:33 14/04/2008] 39976DAD9564B336B153184268DB032F
    C:\WINDOWS\system32\dllcache\crypt32.dll --a--c 606208 bytes [12:00 05/08/2004] [02:33 14/04/2008] 39976DAD9564B336B153184268DB032F

    Searching for "gpedit.dll"
    No files found.

    Searching for "rundll32.exe"
    C:\WINDOWS\$NtServicePackUninstall$\rundll32.exe -----c 33792 bytes [22:30 22/08/2008] [12:00 05/08/2004] F5402CD47B7389DDC21F92119A906EEE
    C:\WINDOWS\ServicePackFiles\i386\rundll32.exe ------ 33792 bytes [02:34 14/04/2008] [02:34 14/04/2008] 93AD0B78C7357A05F50E594EC7C22300
    C:\WINDOWS\system32\dllcache\rundll32.exe --a--c 33792 bytes [12:00 05/08/2004] [02:34 14/04/2008] 93AD0B78C7357A05F50E594EC7C22300
    C:\WINDOWS\system32\rundll32.exe --a--- 33792 bytes [12:00 05/08/2004] [02:34 14/04/2008] 93AD0B78C7357A05F50E594EC7C22300

    Searching for "sfc.dll"
    C:\WINDOWS\$NtServicePackUninstall$\sfc.dll -----c 5120 bytes [22:30 22/08/2008] [12:00 05/08/2004] 94559DE281DADCB58E6A3919C7EAC0B4
    C:\WINDOWS\ERDNT\cache\sfc.dll --a--- 5120 bytes [04:45 03/11/2009] [02:33 14/04/2008] 9A4E7ECBB5B7FB86F3B926AB039F4FEC
    C:\WINDOWS\ServicePackFiles\i386\sfc.dll ------ 5120 bytes [02:33 14/04/2008] [02:33 14/04/2008] 9A4E7ECBB5B7FB86F3B926AB039F4FEC
    C:\WINDOWS\system32\dllcache\sfc.dll --a--c 5120 bytes [12:00 05/08/2004] [02:33 14/04/2008] 9A4E7ECBB5B7FB86F3B926AB039F4FEC
    C:\WINDOWS\system32\sfc.dll ------ 5120 bytes [12:00 05/08/2004] [02:33 14/04/2008] 9A4E7ECBB5B7FB86F3B926AB039F4FEC

    Searching for "svchost.exe"
    C:\WINDOWS\$NtServicePackUninstall$\svchost.exe -----c 14336 bytes [22:30 22/08/2008] [12:00 05/08/2004] 1BD6C2F707A275CB7C16FD99FE0F31CA
    C:\WINDOWS\ERDNT\cache\svchost.exe --a--- 14336 bytes [04:45 03/11/2009] [02:34 14/04/2008] E4BDF223CD75478BF44567B4D5C2634D
    C:\WINDOWS\ServicePackFiles\i386\svchost.exe ------ 14336 bytes [02:34 14/04/2008] [02:34 14/04/2008] E4BDF223CD75478BF44567B4D5C2634D
    C:\WINDOWS\system32\dllcache\svchost.exe --a--c 14336 bytes [12:00 05/08/2004] [02:34 14/04/2008] E4BDF223CD75478BF44567B4D5C2634D
    C:\WINDOWS\system32\svchost.exe ------ 14336 bytes [12:00 05/08/2004] [02:34 14/04/2008] E4BDF223CD75478BF44567B4D5C2634D

    Searching for "cngaudit.dll"
    No files found.

    Searching for "beep.sys"
    C:\WINDOWS\ERDNT\cache\beep.sys --a--- 4224 bytes [04:45 03/11/2009] [12:00 05/08/2004] DA1F27D85E0D1525F6621372E7B685E9
    C:\WINDOWS\system32\dllcache\beep.sys --a--c 4224 bytes [12:00 05/08/2004] [12:00 05/08/2004] DA1F27D85E0D1525F6621372E7B685E9
    C:\WINDOWS\system32\drivers\beep.sys ------ 4224 bytes [12:00 05/08/2004] [12:00 05/08/2004] DA1F27D85E0D1525F6621372E7B685E9

    Searching for "wscntfy.exe"
    C:\WINDOWS\$NtServicePackUninstall$\wscntfy.exe -----c 13824 bytes [22:31 22/08/2008] [12:00 05/08/2004] 54CDDAD404557ED98433D6ECBFC92691
    C:\WINDOWS\ERDNT\cache\wscntfy.exe --a--- 13824 bytes [04:45 03/11/2009] [02:34 14/04/2008] 02DA31AB433A6C1110A736C85701DECA
    C:\WINDOWS\ServicePackFiles\i386\wscntfy.exe ------ 13824 bytes [02:34 14/04/2008] [02:34 14/04/2008] 02DA31AB433A6C1110A736C85701DECA
    C:\WINDOWS\system32\dllcache\wscntfy.exe --a--c 13824 bytes [12:00 05/08/2004] [02:34 14/04/2008] 02DA31AB433A6C1110A736C85701DECA
    C:\WINDOWS\system32\wscntfy.exe ------ 13824 bytes [12:00 05/08/2004] [02:34 14/04/2008] 02DA31AB433A6C1110A736C85701DECA

    Searching for "atapi.sys"
    C:\WINDOWS\$NtServicePackUninstall$\atapi.sys -----c 95360 bytes [22:30 22/08/2008] [12:00 05/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
    C:\WINDOWS\ERDNT\cache\atapi.sys --a--- 96512 bytes [02:33 06/11/2009] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
    C:\WINDOWS\ServicePackFiles\i386\atapi.sys ------ 96512 bytes [18:40 13/04/2008] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
    C:\WINDOWS\system32\dllcache\atapi.sys --a--c 96512 bytes [04:26 03/11/2009] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
    C:\WINDOWS\system32\drivers\atapi.sys ------ 96512 bytes [04:26 03/11/2009] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674

    -=End Of File=-

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    Sorry this has been difficult. I need to take a big picture of your system here:

    (if you have an old version, please use that.)

    Please download the latest version of Kaspersky GetSystemInfo (GSI) from Kaspersky.fr and save it to your Desktop.
    • Please close all other applications running on your system.
    • Please double click GetSystemInfo.exe to open it.
    • Click the Settings button.
    • Set it to Maximum
    • IMPORTANT! Then please click Customize - choose Driver / Ports tab and
    • Uncheck Scan Ports.
    • Click Create Report to run it.
    • It will create a zip folder called GetSystemInfo_XXXXXXXXXXXXXX.zip on your Desktop. Please upload the folder to Kaspersky GSI Parser and click the Submit button.

    THE ZIP FOLDER ABOVE CAN BE TRANSFERRED TO ANOTHER COMPUTER IF NECESSARY, THEN UPLOAD TO THE PARSER
    Please copy and paste the url of the GSI Parser report (not the log) in your next reply.

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    here it is Dragn Mastah Jay!

    http://www.getsysteminfo.com/read.php?file=304c3b3172d75faaca3fb6469da45537

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    Download SREng

    • Extract it to Desktop and double click SREngLdr.EXE to run it
    • Select System Repair from the left pane.
    • Click on File Association
    • Select all entries that has an Error status click [Repair]
    • Refer to this image for an example:

      Security Tool and maybe more malaware - Page 1 SystemRepair_FileAssocs
    • Close SREng now.


    ==

    Please download RBFA to your desktop

    • Double click the program to run it. It will only take a few seconds to run.
    • You will be prompted to press any key at the end to close it
    • Once it is finished, it will remove itself. If not, delete it yourself


    ==

    Please navigate to this webpage: http://support.microsoft.com/kb/313222 and see the section "Fix it for me" and click the Microsoft Fix-It button. This will download a fix utility to repair the security settings on your computer, due to damages of malware or other harmful system changes. Install the file after download.

    ==

    Please re-open Malwarebytes, select Perform Quick Scan, and press Scan. Remove selected, and post the log in your next reply.

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    Hi DragonMaster Jay,

    THe first program did not found any error status all files were considered normal is the status.

    The second program the RBFA seemes t have a virus detected by my office pc. Anyway I was still able to DL it on my usb key put it on my desktop, however when I used I had multiuple errors dialog box.

    Third seemed to work, funny enough it was asking if I wanted to seek help online I clicked by curiosity see if I would connect... and... I DID!

    Im performing the Malwarebytes scan right now, however I couldnt update it.

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    Malaware detected nothing

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    Malwarebytes' Anti-Malware 1.41
    Version de la base de données: 2775
    Windows 5.1.2600 Service Pack 3

    2009-11-13 22:52:43
    mbam-log-2009-11-13 (22-52-43).txt

    Type de recherche: Examen rapide
    Eléments examinés: 91181
    Temps écoulé: 2 minute(s), 36 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    So we fȋxed explorer. But I tried right away to update spyware removal, connect to msn, connect to steam, do online scans, nȯne of them worked.

    Sad tearing

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    You have been proper patient. Right On!

    I am ever so curious if your Internet connection is all the way blocked, or just partially. Let me think

    Let's do this, please:

    Please reboot to Safe Mode with Networking (tap the F8 key just before Windows starts to load and select the Safe Mode with Networking option from the menu).

    Then, please try to access the Internet. Is it possible?

    Also, are you running an antivirus software or antispyware? Please list any that your currently have installed.

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    Just so you know, when you asked me to remove internet explorer since then msn doesnt work.

    Ok so I did rebooted on safe mode with network. I dont know if its normal but I had the choice to log in either as joe my usual profile or... administrator...

    So it didnt connected to the internet Sad tearing

    For anti virus I have Norton 360 Internet Security, but its expired.

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    !!! When I turned the PC off it told me :"some users opened sessions on this cmputer, closing the computer might make them lose unsaved data or work" smething like that in french....

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    Please download SmitfraudFix (by S!Ri)
    Extract the content (a folder named SmitfraudFix) to your Desktop.

    Double-click smitfraudfix.exe
    Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
    Please copy/paste the content of that report into your next reply.

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    SmitFraudFix v2.424

    Rapport fait à 17:44:16,42, 2009-11-14
    Executé à partir de C:\Documents and Settings\joe\Bureau\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    Le type du système de fichiers est NTFS
    Fix executé en mode normal

    »»»»»»»»»»»»»»»»»»»»»»»» Process

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\WINDOWS\vVX6000.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Logitech\Gaming Software\LWEMon.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Zabaware\HalReader\HalReader.exe
    C:\Program Files\Microsoft LifeCam\MSCamS32.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\WINDOWS\system32\cmd.exe

    »»»»»»»»»»»»»»»»»»»»»»»» hosts


    »»»»»»»»»»»»»»»»»»»»»»»» C:\


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\joe


    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\joe\LOCALS~1\Temp


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\joe\Application Data


    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer


    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\joe\Favoris


    »»»»»»»»»»»»»»»»»»»»»»»» Bureau


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues


    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Ma page d'accueil"


    »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    o4Patch
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri



    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri



    »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    Agent.OMZ.Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    404Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

    »»»»»»»»»»»»»»»»»»»»»»»» RK

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""




    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    Description: NVIDIA nForce Networking Controller - Miniport d'ordonnancement de paquets
    DNS Server Search Order: 192.168.0.1

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{CC639DF9-27EF-469C-B576-FBF0361F3B58}: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{CC639DF9-27EF-469C-B576-FBF0361F3B58}: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{CC639DF9-27EF-469C-B576-FBF0361F3B58}: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1


    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll


    »»»»»»»»»»»»»»»»»»»»»»»» Fin

    THANKS FOR NOT GIVING UP ON ME MASTAH JAY

    descriptionSecurity Tool and maybe more malaware - Page 1 EmptyRe: Security Tool and maybe more malaware

    more_horiz
    privacy_tip Permissions in this forum:
    You cannot reply to topics in this forum