Security Tool and maybe more malaware
Page 2 of 7 • Share •
Page 2 of 7 •
1, 2, 3, 4, 5, 6, 7 
Re: Security Tool and maybe more malaware
btw, at the beggining combofix says it has to download something and asking to have an internet connection working. That part fails. Because again my internet access is like blocked.
delpiero0
Rookie Surfer
- Posts: 61
Joined: 2009-11-03
Operating System: XP
Re: Security Tool and maybe more malaware
here it is
ComboFix 09-11-05.01 - joe 2009-11-05 21:23.2.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.2.1036.18.1023.654 [GMT -5:00]
Lancé depuis: c:\documents and settings\joe\Bureau\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Outdated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
FW: Norton 360 *disabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
ADS - system32: deleted 142 bytes in 1 streams.
((((((((((((((((((((((((((((( Fichiers créés du 2009-10-06 au 2009-11-06 ))))))))))))))))))))))))))))))))))))
.
2009-11-05 03:34 . 2008-12-11 13:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-11-05 03:34 . 2009-08-24 19:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-11-05 03:34 . 2009-08-19 16:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-11-05 03:34 . 2009-11-05 03:35 -------- d-----w- c:\program files\Fichiers communs\PC Tools
2009-11-05 03:34 . 2008-12-10 16:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-11-05 03:34 . 2009-11-05 03:34 -------- d-----w- c:\documents and settings\joe\Application Data\PC Tools
2009-11-05 03:34 . 2009-11-05 03:34 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-11-04 17:34 . 2009-11-05 03:02 -------- d-----w- c:\program files\PC Tools AntiVirus
2009-11-03 04:26 . 2005-01-17 05:43 88576 ----a-w- c:\windows\system32\drivers\nvatabus.sys
2009-11-03 04:26 . 2008-04-13 18:40 96512 -c--a-w- c:\windows\system32\dllcache\atapi.sys
2009-11-03 04:26 . 2008-04-13 18:40 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-11-03 04:20 . 2009-11-03 04:20 -------- d-----w- c:\program files\Trend Micro
2009-11-03 03:53 . 2009-11-05 03:02 -------- d-----w- c:\program files\RegDefense
2009-11-03 03:48 . 2009-11-03 03:48 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2009-11-03 03:17 . 2009-11-03 03:17 -------- d-----w- c:\documents and settings\joe\Local Settings\Application Data\Mozilla
2009-11-03 02:39 . 2009-11-03 04:13 22016 ----a-w- c:\windows\system32\tdlwsp.dll
2009-11-02 23:19 . 2009-11-02 23:19 -------- d-----w- c:\documents and settings\joe\Application Data\Malwarebytes
2009-11-02 23:13 . 2009-11-06 02:12 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-28 05:28 . 2009-10-28 05:30 -------- d-----w- c:\program files\Windows Live Safety Center
2009-10-28 04:51 . 2009-10-28 04:51 -------- d-----w- c:\documents and settings\joe\Application Data\AVG8
2009-10-28 04:31 . 2009-06-30 14:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-10-23 07:32 . 2009-10-23 07:32 -------- d-----w- c:\documents and settings\joe\Application Data\SUPERAntiSpyware.com
2009-10-23 07:19 . 2008-11-26 16:08 131 ----a-w- c:\windows\IDB.zip
2009-10-23 07:19 . 2009-10-02 18:19 1152470 ----a-w- c:\windows\UDB.zip
2009-10-23 07:07 . 2009-10-28 04:22 -------- d-----w- c:\documents and settings\Malwarebytes' Anti-Malware
2009-10-23 07:07 . 2009-10-23 07:10 20949 ----a-w- c:\documents and settings\Malwarebytes' Anti-Malware\unins000.dat
2009-10-23 07:07 . 2009-10-23 07:10 -------- d-----w- c:\documents and settings\Malwarebytes' Anti-Malware\Languages
2009-10-23 06:50 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-23 06:50 . 2009-10-28 04:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-23 06:50 . 2009-10-23 06:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-23 06:50 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-23 05:40 . 2009-10-28 04:31 -------- d-----w- c:\program files\Panda Security
2009-10-23 05:37 . 2009-11-03 02:38 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-06 02:19 . 2006-02-04 17:22 -------- d-----w- c:\program files\Java
2009-11-06 02:15 . 2004-08-05 12:00 84874 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-06 02:15 . 2004-08-05 12:00 510656 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-06 02:08 . 2005-10-26 22:25 -------- d-----w- c:\program files\Steam
2009-11-06 00:04 . 2006-05-27 16:36 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000004-20021102}.dat
2009-11-06 00:04 . 2006-05-27 16:36 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000004-20021102}.dat
2009-10-28 05:18 . 2005-10-26 21:34 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2009-10-28 05:18 . 2005-10-26 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-28 05:13 . 2008-08-05 01:27 -------- d-----w- c:\program files\Norton 360
2009-10-23 07:31 . 2005-11-07 02:45 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2009-10-23 07:25 . 2009-10-28 04:17 8530 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Personal_32_1036.dat
2009-10-23 07:05 . 2007-12-25 22:22 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-30 18:58 . 2008-02-18 19:38 9576 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\CCMSLLUM.DLL
2009-09-22 02:58 . 2009-09-22 02:58 -------- d-----w- c:\program files\Cool MOV To WMV Converter
2009-09-11 23:18 . 2008-06-23 02:09 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000004-10001102}.dat
2009-09-11 23:18 . 2008-06-23 02:09 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000004-10001102}.dat
2009-09-11 14:18 . 2004-08-05 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 21:39 . 2009-03-21 00:01 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-07 05:39 . 2009-08-18 13:58 5 ----a-w- c:\windows\system32\SySAVI2WMV.dat
2009-09-07 05:01 . 2009-09-07 05:01 -------- d-----w- c:\program files\Windows Media Components
2009-09-04 21:04 . 2004-08-05 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 2004-08-05 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-27 08:34 . 2005-10-27 01:44 81504 ----a-w- c:\documents and settings\joe\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 08:01 . 2004-08-05 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 13:48 . 2009-08-18 13:48 34 ---ha-w- c:\windows\system32\Converter_sysquict.dat
1999-04-06 13:27 . 1999-04-06 13:27 99840 ----a-w- c:\program files\Fichiers communs\IRAABOUT.DLL
1998-12-09 03:53 . 1998-12-09 03:53 70144 ----a-w- c:\program files\Fichiers communs\IRAMDMTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 48640 ----a-w- c:\program files\Fichiers communs\IRALPTTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 31744 ----a-w- c:\program files\Fichiers communs\IRAWEBTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 186368 ----a-w- c:\program files\Fichiers communs\IRAREG.DLL
1998-12-09 03:53 . 1998-12-09 03:53 17920 ----a-w- c:\program files\Fichiers communs\IRASRIAL.DLL
.
((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-05 12:00 . 2009-11-03 04:25 71374 c:\windows\system32\perfc009.dat
+ 2004-08-05 12:00 . 2009-11-06 02:15 71374 c:\windows\system32\perfc009.dat
- 2006-06-29 13:05 . 2009-01-07 22:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-29 13:05 . 2009-01-07 23:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-28 22:59 . 2009-01-07 23:20 24576 c:\windows\system32\nlsdl.dll
- 2006-06-28 22:59 . 2009-01-07 22:20 24576 c:\windows\system32\nlsdl.dll
+ 2006-11-07 08:26 . 2009-03-08 09:32 36864 c:\windows\system32\ieudinit.exe
- 2006-11-07 08:26 . 2009-03-08 08:32 36864 c:\windows\system32\ieudinit.exe
- 2006-06-29 13:05 . 2009-01-07 22:20 26112 c:\windows\system32\idndl.dll
+ 2006-06-29 13:05 . 2009-01-07 23:20 26112 c:\windows\system32\idndl.dll
- 2006-11-22 02:39 . 2009-01-07 22:21 121856 c:\windows\system32\xmllite.dll
+ 2006-11-22 02:39 . 2009-01-07 23:21 121856 c:\windows\system32\xmllite.dll
- 2004-08-05 12:00 . 2009-11-03 04:25 441438 c:\windows\system32\perfh009.dat
+ 2004-08-05 12:00 . 2009-11-06 02:15 441438 c:\windows\system32\perfh009.dat
+ 2009-01-07 22:20 . 2009-01-07 23:20 265720 c:\windows\system32\msdbg2.dll
- 2009-01-07 22:20 . 2009-01-07 22:20 265720 c:\windows\system32\msdbg2.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-28 1217808]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VX6000"="c:\windows\vVX6000.exe" [2006-10-13 994096]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 277296]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 88584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-12 86016]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-01-26 53248]
"Malwarebytes Anti-Malware (reboot)"="c:\nexon\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2003-10-06 24576]
"Logitech Utility"="Logi_MwX.Exe" - c:\windows\LOGI_MWX.EXE [2003-12-17 19968]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-11-12 1630208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Ultra Hal Text-to-Speech Reader Startup.lnk - c:\windows\Installer\{96EF451E-A402-44D8-BAEE-D70D558A4122}\New_Shortcut_S1449_0EB7CDB78E0C4A918D2CA535D5B8160C.exe [2006-9-24 40960]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\xpand rally\\xpandrally.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\xpand rally\\ChromEd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\il 2 sturmovik 1946\\il2fb.exe"=
"c:\\Nexon\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58719:TCP"= 58719:TCP:Pando Media Booster
"58719:UDP"= 58719:UDP:Pando Media Booster
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-10-27 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-11-04 206256]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-03-20 55152]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Fichiers communs\Symantec Shared\CCSVCHST.EXE [2008-02-18 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-05-30 101936]
S3 BS_DEF;BS_DEF;c:\program files\ASUS\AsusUpdate\BS_DEF.sys [2006-04-07 12800]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-01-12 23888]
S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 LwAdiHid;Périphériques numériques WingMan Logitech (détection automatique);c:\windows\system32\drivers\LwAdiHid.sys [2008-12-11 20864]
S3 Razerlow;Razerlow USB Filter Driver;c:\windows\system32\drivers\Razerlow.sys [2006-05-06 13225]
S3 sdAuxService;PC Tools Auxiliary Service;c:\nexon\Spyware Doctor1\pctsAuxs.exe [2009-11-04 348752]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [2006-04-13 2383152]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - COMHOST
*Deregistered* - mbr
*Deregistered* - mchInjDrv
*Deregistered* - PROCEXP113
.
Contenu du dossier 'Tâches planifiées'
2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-11-06 c:\windows\Tasks\User_Feed_Synchronization-{FFAC0B8B-CE55-4AEE-BE8F-39D5A6F04342}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
DPF: {BFD90062-6B5E-4F8F-87B1-5F022C14E32F} - [You must be registered and logged in to see this link.]
DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} - [You must be registered and logged in to see this link.]
FF - ProfilePath - c:\documents and settings\joe\Application Data\Mozilla\Firefox\Profiles\i4sf4rhw.default\
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHELINS SUPPRIMES - - - -
AddRemove-RegDefense - c:\nexon\RegDefense\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-11-05 21:31
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(2260)
c:\program files\Logitech\MouseWare\System\LgWndHk.dll
c:\program files\Fichiers communs\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\eappprxy.dll
.
Heure de fin: 2009-11-06 21:34
ComboFix-quarantined-files.txt 2009-11-06 02:34
ComboFix2.txt 2009-11-03 04:47
Avant-CF: 12 834 304 000 octets libres
Après-CF: 12 790 235 136 octets libres
- - End Of File - - E2E93EDFBB41941E6C27B70017DC399E
ComboFix 09-11-05.01 - joe 2009-11-05 21:23.2.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.2.1036.18.1023.654 [GMT -5:00]
Lancé depuis: c:\documents and settings\joe\Bureau\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Outdated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
FW: Norton 360 *disabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
ADS - system32: deleted 142 bytes in 1 streams.
((((((((((((((((((((((((((((( Fichiers créés du 2009-10-06 au 2009-11-06 ))))))))))))))))))))))))))))))))))))
.
2009-11-05 03:34 . 2008-12-11 13:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-11-05 03:34 . 2009-08-24 19:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-11-05 03:34 . 2009-08-19 16:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-11-05 03:34 . 2009-11-05 03:35 -------- d-----w- c:\program files\Fichiers communs\PC Tools
2009-11-05 03:34 . 2008-12-10 16:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-11-05 03:34 . 2009-11-05 03:34 -------- d-----w- c:\documents and settings\joe\Application Data\PC Tools
2009-11-05 03:34 . 2009-11-05 03:34 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-11-04 17:34 . 2009-11-05 03:02 -------- d-----w- c:\program files\PC Tools AntiVirus
2009-11-03 04:26 . 2005-01-17 05:43 88576 ----a-w- c:\windows\system32\drivers\nvatabus.sys
2009-11-03 04:26 . 2008-04-13 18:40 96512 -c--a-w- c:\windows\system32\dllcache\atapi.sys
2009-11-03 04:26 . 2008-04-13 18:40 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-11-03 04:20 . 2009-11-03 04:20 -------- d-----w- c:\program files\Trend Micro
2009-11-03 03:53 . 2009-11-05 03:02 -------- d-----w- c:\program files\RegDefense
2009-11-03 03:48 . 2009-11-03 03:48 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2009-11-03 03:17 . 2009-11-03 03:17 -------- d-----w- c:\documents and settings\joe\Local Settings\Application Data\Mozilla
2009-11-03 02:39 . 2009-11-03 04:13 22016 ----a-w- c:\windows\system32\tdlwsp.dll
2009-11-02 23:19 . 2009-11-02 23:19 -------- d-----w- c:\documents and settings\joe\Application Data\Malwarebytes
2009-11-02 23:13 . 2009-11-06 02:12 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-28 05:28 . 2009-10-28 05:30 -------- d-----w- c:\program files\Windows Live Safety Center
2009-10-28 04:51 . 2009-10-28 04:51 -------- d-----w- c:\documents and settings\joe\Application Data\AVG8
2009-10-28 04:31 . 2009-06-30 14:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-10-23 07:32 . 2009-10-23 07:32 -------- d-----w- c:\documents and settings\joe\Application Data\SUPERAntiSpyware.com
2009-10-23 07:19 . 2008-11-26 16:08 131 ----a-w- c:\windows\IDB.zip
2009-10-23 07:19 . 2009-10-02 18:19 1152470 ----a-w- c:\windows\UDB.zip
2009-10-23 07:07 . 2009-10-28 04:22 -------- d-----w- c:\documents and settings\Malwarebytes' Anti-Malware
2009-10-23 07:07 . 2009-10-23 07:10 20949 ----a-w- c:\documents and settings\Malwarebytes' Anti-Malware\unins000.dat
2009-10-23 07:07 . 2009-10-23 07:10 -------- d-----w- c:\documents and settings\Malwarebytes' Anti-Malware\Languages
2009-10-23 06:50 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-23 06:50 . 2009-10-28 04:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-23 06:50 . 2009-10-23 06:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-23 06:50 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-23 05:40 . 2009-10-28 04:31 -------- d-----w- c:\program files\Panda Security
2009-10-23 05:37 . 2009-11-03 02:38 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-06 02:19 . 2006-02-04 17:22 -------- d-----w- c:\program files\Java
2009-11-06 02:15 . 2004-08-05 12:00 84874 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-06 02:15 . 2004-08-05 12:00 510656 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-06 02:08 . 2005-10-26 22:25 -------- d-----w- c:\program files\Steam
2009-11-06 00:04 . 2006-05-27 16:36 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000004-20021102}.dat
2009-11-06 00:04 . 2006-05-27 16:36 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000004-20021102}.dat
2009-10-28 05:18 . 2005-10-26 21:34 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2009-10-28 05:18 . 2005-10-26 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-28 05:13 . 2008-08-05 01:27 -------- d-----w- c:\program files\Norton 360
2009-10-23 07:31 . 2005-11-07 02:45 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2009-10-23 07:25 . 2009-10-28 04:17 8530 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Personal_32_1036.dat
2009-10-23 07:05 . 2007-12-25 22:22 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-30 18:58 . 2008-02-18 19:38 9576 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\CCMSLLUM.DLL
2009-09-22 02:58 . 2009-09-22 02:58 -------- d-----w- c:\program files\Cool MOV To WMV Converter
2009-09-11 23:18 . 2008-06-23 02:09 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000004-10001102}.dat
2009-09-11 23:18 . 2008-06-23 02:09 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000004-10001102}.dat
2009-09-11 14:18 . 2004-08-05 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 21:39 . 2009-03-21 00:01 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-07 05:39 . 2009-08-18 13:58 5 ----a-w- c:\windows\system32\SySAVI2WMV.dat
2009-09-07 05:01 . 2009-09-07 05:01 -------- d-----w- c:\program files\Windows Media Components
2009-09-04 21:04 . 2004-08-05 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 2004-08-05 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-27 08:34 . 2005-10-27 01:44 81504 ----a-w- c:\documents and settings\joe\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 08:01 . 2004-08-05 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 13:48 . 2009-08-18 13:48 34 ---ha-w- c:\windows\system32\Converter_sysquict.dat
1999-04-06 13:27 . 1999-04-06 13:27 99840 ----a-w- c:\program files\Fichiers communs\IRAABOUT.DLL
1998-12-09 03:53 . 1998-12-09 03:53 70144 ----a-w- c:\program files\Fichiers communs\IRAMDMTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 48640 ----a-w- c:\program files\Fichiers communs\IRALPTTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 31744 ----a-w- c:\program files\Fichiers communs\IRAWEBTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 186368 ----a-w- c:\program files\Fichiers communs\IRAREG.DLL
1998-12-09 03:53 . 1998-12-09 03:53 17920 ----a-w- c:\program files\Fichiers communs\IRASRIAL.DLL
.
((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-05 12:00 . 2009-11-03 04:25 71374 c:\windows\system32\perfc009.dat
+ 2004-08-05 12:00 . 2009-11-06 02:15 71374 c:\windows\system32\perfc009.dat
- 2006-06-29 13:05 . 2009-01-07 22:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-29 13:05 . 2009-01-07 23:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-28 22:59 . 2009-01-07 23:20 24576 c:\windows\system32\nlsdl.dll
- 2006-06-28 22:59 . 2009-01-07 22:20 24576 c:\windows\system32\nlsdl.dll
+ 2006-11-07 08:26 . 2009-03-08 09:32 36864 c:\windows\system32\ieudinit.exe
- 2006-11-07 08:26 . 2009-03-08 08:32 36864 c:\windows\system32\ieudinit.exe
- 2006-06-29 13:05 . 2009-01-07 22:20 26112 c:\windows\system32\idndl.dll
+ 2006-06-29 13:05 . 2009-01-07 23:20 26112 c:\windows\system32\idndl.dll
- 2006-11-22 02:39 . 2009-01-07 22:21 121856 c:\windows\system32\xmllite.dll
+ 2006-11-22 02:39 . 2009-01-07 23:21 121856 c:\windows\system32\xmllite.dll
- 2004-08-05 12:00 . 2009-11-03 04:25 441438 c:\windows\system32\perfh009.dat
+ 2004-08-05 12:00 . 2009-11-06 02:15 441438 c:\windows\system32\perfh009.dat
+ 2009-01-07 22:20 . 2009-01-07 23:20 265720 c:\windows\system32\msdbg2.dll
- 2009-01-07 22:20 . 2009-01-07 22:20 265720 c:\windows\system32\msdbg2.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-28 1217808]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VX6000"="c:\windows\vVX6000.exe" [2006-10-13 994096]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 277296]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 88584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-12 86016]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-01-26 53248]
"Malwarebytes Anti-Malware (reboot)"="c:\nexon\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2003-10-06 24576]
"Logitech Utility"="Logi_MwX.Exe" - c:\windows\LOGI_MWX.EXE [2003-12-17 19968]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-11-12 1630208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Ultra Hal Text-to-Speech Reader Startup.lnk - c:\windows\Installer\{96EF451E-A402-44D8-BAEE-D70D558A4122}\New_Shortcut_S1449_0EB7CDB78E0C4A918D2CA535D5B8160C.exe [2006-9-24 40960]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\xpand rally\\xpandrally.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\xpand rally\\ChromEd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\il 2 sturmovik 1946\\il2fb.exe"=
"c:\\Nexon\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58719:TCP"= 58719:TCP:Pando Media Booster
"58719:UDP"= 58719:UDP:Pando Media Booster
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-10-27 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-11-04 206256]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-03-20 55152]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Fichiers communs\Symantec Shared\CCSVCHST.EXE [2008-02-18 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-05-30 101936]
S3 BS_DEF;BS_DEF;c:\program files\ASUS\AsusUpdate\BS_DEF.sys [2006-04-07 12800]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-01-12 23888]
S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 LwAdiHid;Périphériques numériques WingMan Logitech (détection automatique);c:\windows\system32\drivers\LwAdiHid.sys [2008-12-11 20864]
S3 Razerlow;Razerlow USB Filter Driver;c:\windows\system32\drivers\Razerlow.sys [2006-05-06 13225]
S3 sdAuxService;PC Tools Auxiliary Service;c:\nexon\Spyware Doctor1\pctsAuxs.exe [2009-11-04 348752]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [2006-04-13 2383152]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - COMHOST
*Deregistered* - mbr
*Deregistered* - mchInjDrv
*Deregistered* - PROCEXP113
.
Contenu du dossier 'Tâches planifiées'
2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-11-06 c:\windows\Tasks\User_Feed_Synchronization-{FFAC0B8B-CE55-4AEE-BE8F-39D5A6F04342}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
DPF: {BFD90062-6B5E-4F8F-87B1-5F022C14E32F} - [You must be registered and logged in to see this link.]
DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} - [You must be registered and logged in to see this link.]
FF - ProfilePath - c:\documents and settings\joe\Application Data\Mozilla\Firefox\Profiles\i4sf4rhw.default\
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHELINS SUPPRIMES - - - -
AddRemove-RegDefense - c:\nexon\RegDefense\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-11-05 21:31
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(2260)
c:\program files\Logitech\MouseWare\System\LgWndHk.dll
c:\program files\Fichiers communs\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\eappprxy.dll
.
Heure de fin: 2009-11-06 21:34
ComboFix-quarantined-files.txt 2009-11-06 02:34
ComboFix2.txt 2009-11-03 04:47
Avant-CF: 12 834 304 000 octets libres
Après-CF: 12 790 235 136 octets libres
- - End Of File - - E2E93EDFBB41941E6C27B70017DC399E
delpiero0
Rookie Surfer
- Posts: 61
Joined: 2009-11-03
Operating System: XP
Re: Security Tool and maybe more malaware
Please use Internet Explorer and run a [You must be registered and logged in to see this link.]
- Please check I agree with the Terms and Conditions and click Start Here
- You will need to allow an Active X install for the scan to run.
- Leave the scanning options at default and click Start Scan
______________________________

[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.]

DragonMaster Jay
Moderator | Tech Staff
- Posts: 2126
Joined: 2009-09-06
Operating System: Windows 7 Ultimate 32-Bit

Re: Security Tool and maybe more malaware
I can't do that. I can't open Internet Explorer and I can't connect to the internet.
delpiero0
Rookie Surfer
- Posts: 61
Joined: 2009-11-03
Operating System: XP
Re: Security Tool and maybe more malaware
Do you have Firefox or a different browser? Optionally you can download this one:
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
- Tick the box next to YES, I accept the Terms of Use
- Click Start
- When asked, allow the ActiveX control to install
- Click Start
- Make sure that the options Remove found threats and the option Scan unwanted applications is checked
- Click Scan (This scan can take several hours, so please be patient)
- Once the scan is completed, you may close the window
- Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
- Copy and paste that log as a reply to this topic
______________________________

[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.]

DragonMaster Jay
Moderator | Tech Staff
- Posts: 2126
Joined: 2009-09-06
Operating System: Windows 7 Ultimate 32-Bit

Re: Security Tool and maybe more malaware
Hi
No I cant use firefx either. I'm telling you its like the malaware, virus or whatever blocked all my internet ports or dns or access. Firefox tells me I got no connection, iexplorer doesnt even open I get an error message and when I install a program such as a anti virus, spyware removal or else the update doesnt work saying I can't connect.
But my windows live messenger does connect! And my connection sends packets and receives it its on.
Its like if I have been unauthorized to use it.
No I cant use firefx either. I'm telling you its like the malaware, virus or whatever blocked all my internet ports or dns or access. Firefox tells me I got no connection, iexplorer doesnt even open I get an error message and when I install a program such as a anti virus, spyware removal or else the update doesnt work saying I can't connect.
But my windows live messenger does connect! And my connection sends packets and receives it its on.
Its like if I have been unauthorized to use it.
delpiero0
Rookie Surfer
- Posts: 61
Joined: 2009-11-03
Operating System: XP
Re: Security Tool and maybe more malaware
Please re-run ComboFix and make sure your computer reboots - then post a log in your next reply.
______________________________

[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.]

DragonMaster Jay
Moderator | Tech Staff
- Posts: 2126
Joined: 2009-09-06
Operating System: Windows 7 Ultimate 32-Bit

Re: Security Tool and maybe more malaware
ok..
By The Way; at the beggining ComboFix says something about my PC not having a console to recuperate or something, and that it will install one, but then fails to connect to the internet so it doesnt install it and then proceed to run.
By The Way; at the beggining ComboFix says something about my PC not having a console to recuperate or something, and that it will install one, but then fails to connect to the internet so it doesnt install it and then proceed to run.
delpiero0
Rookie Surfer
- Posts: 61
Joined: 2009-11-03
Operating System: XP
Re: Security Tool and maybe more malaware
Here it is:
ComboFix 09-11-05.01 - joe 2009-11-07 13:28.4.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.2.1036.18.1023.561 [GMT -5:00]
Lancé depuis: c:\documents and settings\joe\Bureau\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Outdated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
FW: Norton 360 *disabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-10-07 au 2009-11-07 ))))))))))))))))))))))))))))))))))))
.
2009-11-05 03:34 . 2008-12-11 13:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-11-05 03:34 . 2009-08-24 19:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-11-05 03:34 . 2009-08-19 16:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-11-05 03:34 . 2009-11-05 03:35 -------- d-----w- c:\program files\Fichiers communs\PC Tools
2009-11-05 03:34 . 2008-12-10 16:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-11-05 03:34 . 2009-11-05 03:34 -------- d-----w- c:\documents and settings\joe\Application Data\PC Tools
2009-11-05 03:34 . 2009-11-05 03:34 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-11-04 17:34 . 2009-11-05 03:02 -------- d-----w- c:\program files\PC Tools AntiVirus
2009-11-03 04:26 . 2005-01-17 05:43 88576 ----a-w- c:\windows\system32\drivers\nvatabus.sys
2009-11-03 04:26 . 2008-04-13 18:40 96512 -c--a-w- c:\windows\system32\dllcache\atapi.sys
2009-11-03 04:26 . 2008-04-13 18:40 96512 ------w- c:\windows\system32\drivers\atapi.sys
2009-11-03 04:20 . 2009-11-03 04:20 -------- d-----w- c:\program files\Trend Micro
2009-11-03 03:53 . 2009-11-05 03:02 -------- d-----w- c:\program files\RegDefense
2009-11-03 03:48 . 2009-11-03 03:48 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2009-11-03 03:17 . 2009-11-03 03:17 -------- d-----w- c:\documents and settings\joe\Local Settings\Application Data\Mozilla
2009-11-03 02:39 . 2009-11-03 04:13 22016 ----a-w- c:\windows\system32\tdlwsp.dll
2009-11-02 23:19 . 2009-11-02 23:19 -------- d-----w- c:\documents and settings\joe\Application Data\Malwarebytes
2009-11-02 23:13 . 2009-11-06 02:12 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-28 05:28 . 2009-10-28 05:30 -------- d-----w- c:\program files\Windows Live Safety Center
2009-10-28 04:51 . 2009-10-28 04:51 -------- d-----w- c:\documents and settings\joe\Application Data\AVG8
2009-10-28 04:31 . 2009-06-30 14:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-10-23 07:32 . 2009-10-23 07:32 -------- d-----w- c:\documents and settings\joe\Application Data\SUPERAntiSpyware.com
2009-10-23 07:19 . 2008-11-26 16:08 131 ----a-w- c:\windows\IDB.zip
2009-10-23 07:19 . 2009-10-02 18:19 1152470 ----a-w- c:\windows\UDB.zip
2009-10-23 07:07 . 2009-10-28 04:22 -------- d-----w- c:\documents and settings\Malwarebytes' Anti-Malware
2009-10-23 07:07 . 2009-10-23 07:10 20949 ----a-w- c:\documents and settings\Malwarebytes' Anti-Malware\unins000.dat
2009-10-23 07:07 . 2009-10-23 07:10 -------- d-----w- c:\documents and settings\Malwarebytes' Anti-Malware\Languages
2009-10-23 06:50 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-23 06:50 . 2009-10-28 04:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-23 06:50 . 2009-10-23 06:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-23 06:50 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-23 05:40 . 2009-10-28 04:31 -------- d-----w- c:\program files\Panda Security
2009-10-23 05:37 . 2009-11-03 02:38 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-07 18:07 . 2005-10-26 22:25 -------- d-----w- c:\program files\Steam
2009-11-06 02:44 . 2006-05-27 16:36 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000004-20021102}.dat
2009-11-06 02:44 . 2006-05-27 16:36 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000004-20021102}.dat
2009-11-06 02:19 . 2006-02-04 17:22 -------- d-----w- c:\program files\Java
2009-11-06 02:15 . 2004-08-05 12:00 84874 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-06 02:15 . 2004-08-05 12:00 510656 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-28 05:18 . 2005-10-26 21:34 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2009-10-28 05:18 . 2005-10-26 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-28 05:13 . 2008-08-05 01:27 -------- d-----w- c:\program files\Norton 360
2009-10-23 07:31 . 2005-11-07 02:45 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2009-10-23 07:25 . 2009-10-28 04:17 8530 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Personal_32_1036.dat
2009-10-23 07:05 . 2007-12-25 22:22 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-30 18:58 . 2008-02-18 19:38 9576 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\CCMSLLUM.DLL
2009-09-22 02:58 . 2009-09-22 02:58 -------- d-----w- c:\program files\Cool MOV To WMV Converter
2009-09-11 23:18 . 2008-06-23 02:09 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000004-10001102}.dat
2009-09-11 23:18 . 2008-06-23 02:09 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000004-10001102}.dat
2009-09-11 14:18 . 2004-08-05 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 21:39 . 2009-03-21 00:01 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-07 05:39 . 2009-08-18 13:58 5 ----a-w- c:\windows\system32\SySAVI2WMV.dat
2009-09-04 21:04 . 2004-08-05 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 2004-08-05 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-27 08:34 . 2005-10-27 01:44 81504 ----a-w- c:\documents and settings\joe\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 08:01 . 2004-08-05 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 13:48 . 2009-08-18 13:48 34 ---ha-w- c:\windows\system32\Converter_sysquict.dat
1999-04-06 13:27 . 1999-04-06 13:27 99840 ----a-w- c:\program files\Fichiers communs\IRAABOUT.DLL
1998-12-09 03:53 . 1998-12-09 03:53 70144 ----a-w- c:\program files\Fichiers communs\IRAMDMTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 48640 ----a-w- c:\program files\Fichiers communs\IRALPTTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 31744 ----a-w- c:\program files\Fichiers communs\IRAWEBTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 186368 ----a-w- c:\program files\Fichiers communs\IRAREG.DLL
1998-12-09 03:53 . 1998-12-09 03:53 17920 ----a-w- c:\program files\Fichiers communs\IRASRIAL.DLL
.
((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-05 12:00 . 2009-11-03 04:25 71374 c:\windows\system32\perfc009.dat
+ 2004-08-05 12:00 . 2009-11-06 02:15 71374 c:\windows\system32\perfc009.dat
- 2006-06-29 13:05 . 2009-01-07 22:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-29 13:05 . 2009-01-07 23:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-28 22:59 . 2009-01-07 23:20 24576 c:\windows\system32\nlsdl.dll
- 2006-06-28 22:59 . 2009-01-07 22:20 24576 c:\windows\system32\nlsdl.dll
+ 2006-11-07 08:26 . 2009-03-08 09:32 36864 c:\windows\system32\ieudinit.exe
- 2006-11-07 08:26 . 2009-03-08 08:32 36864 c:\windows\system32\ieudinit.exe
- 2006-06-29 13:05 . 2009-01-07 22:20 26112 c:\windows\system32\idndl.dll
+ 2006-06-29 13:05 . 2009-01-07 23:20 26112 c:\windows\system32\idndl.dll
- 2006-11-22 02:39 . 2009-01-07 22:21 121856 c:\windows\system32\xmllite.dll
+ 2006-11-22 02:39 . 2009-01-07 23:21 121856 c:\windows\system32\xmllite.dll
- 2004-08-05 12:00 . 2009-11-03 04:25 441438 c:\windows\system32\perfh009.dat
+ 2004-08-05 12:00 . 2009-11-06 02:15 441438 c:\windows\system32\perfh009.dat
+ 2009-01-07 22:20 . 2009-01-07 23:20 265720 c:\windows\system32\msdbg2.dll
- 2009-01-07 22:20 . 2009-01-07 22:20 265720 c:\windows\system32\msdbg2.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-28 1217808]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VX6000"="c:\windows\vVX6000.exe" [2006-10-13 994096]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 277296]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 88584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-12 86016]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-01-26 53248]
"Malwarebytes Anti-Malware (reboot)"="c:\nexon\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2003-10-06 24576]
"Logitech Utility"="Logi_MwX.Exe" - c:\windows\LOGI_MWX.EXE [2003-12-17 19968]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-11-12 1630208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Ultra Hal Text-to-Speech Reader Startup.lnk - c:\windows\Installer\{96EF451E-A402-44D8-BAEE-D70D558A4122}\New_Shortcut_S1449_0EB7CDB78E0C4A918D2CA535D5B8160C.exe [2006-9-24 40960]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\xpand rally\\xpandrally.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\xpand rally\\ChromEd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\il 2 sturmovik 1946\\il2fb.exe"=
"c:\\Nexon\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58719:TCP"= 58719:TCP:Pando Media Booster
"58719:UDP"= 58719:UDP:Pando Media Booster
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-10-27 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-11-04 206256]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-03-20 55152]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Fichiers communs\Symantec Shared\CCSVCHST.EXE [2008-02-18 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-05-30 101936]
S3 BS_DEF;BS_DEF;c:\program files\ASUS\AsusUpdate\BS_DEF.sys [2006-04-07 12800]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-01-12 23888]
S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 LwAdiHid;Périphériques numériques WingMan Logitech (détection automatique);c:\windows\system32\drivers\LwAdiHid.sys [2008-12-11 20864]
S3 Razerlow;Razerlow USB Filter Driver;c:\windows\system32\drivers\Razerlow.sys [2006-05-06 13225]
S3 sdAuxService;PC Tools Auxiliary Service;c:\nexon\Spyware Doctor1\pctsAuxs.exe [2009-11-04 348752]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [2006-04-13 2383152]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - COMHOST
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
Contenu du dossier 'Tâches planifiées'
2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-11-07 c:\windows\Tasks\User_Feed_Synchronization-{FFAC0B8B-CE55-4AEE-BE8F-39D5A6F04342}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
DPF: {BFD90062-6B5E-4F8F-87B1-5F022C14E32F} - [You must be registered and logged in to see this link.]
DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} - [You must be registered and logged in to see this link.]
FF - ProfilePath - c:\documents and settings\joe\Application Data\Mozilla\Firefox\Profiles\i4sf4rhw.default\
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-11-07 13:35
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(2212)
c:\program files\Logitech\MouseWare\System\LgWndHk.dll
c:\program files\Fichiers communs\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\eappprxy.dll
.
Heure de fin: 2009-11-07 13:38
ComboFix-quarantined-files.txt 2009-11-07 18:38
ComboFix2.txt 2009-11-07 18:22
ComboFix3.txt 2009-11-06 02:34
ComboFix4.txt 2009-11-03 04:47
Avant-CF: 12 779 466 752 octets libres
Après-CF: 12 757 917 696 octets libres
- - End Of File - - DC307C18F5E768F7C5173386A4354694
ComboFix 09-11-05.01 - joe 2009-11-07 13:28.4.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.2.1036.18.1023.561 [GMT -5:00]
Lancé depuis: c:\documents and settings\joe\Bureau\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Outdated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
FW: Norton 360 *disabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-10-07 au 2009-11-07 ))))))))))))))))))))))))))))))))))))
.
2009-11-05 03:34 . 2008-12-11 13:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-11-05 03:34 . 2009-08-24 19:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-11-05 03:34 . 2009-08-19 16:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-11-05 03:34 . 2009-11-05 03:35 -------- d-----w- c:\program files\Fichiers communs\PC Tools
2009-11-05 03:34 . 2008-12-10 16:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-11-05 03:34 . 2009-11-05 03:34 -------- d-----w- c:\documents and settings\joe\Application Data\PC Tools
2009-11-05 03:34 . 2009-11-05 03:34 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-11-04 17:34 . 2009-11-05 03:02 -------- d-----w- c:\program files\PC Tools AntiVirus
2009-11-03 04:26 . 2005-01-17 05:43 88576 ----a-w- c:\windows\system32\drivers\nvatabus.sys
2009-11-03 04:26 . 2008-04-13 18:40 96512 -c--a-w- c:\windows\system32\dllcache\atapi.sys
2009-11-03 04:26 . 2008-04-13 18:40 96512 ------w- c:\windows\system32\drivers\atapi.sys
2009-11-03 04:20 . 2009-11-03 04:20 -------- d-----w- c:\program files\Trend Micro
2009-11-03 03:53 . 2009-11-05 03:02 -------- d-----w- c:\program files\RegDefense
2009-11-03 03:48 . 2009-11-03 03:48 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2009-11-03 03:17 . 2009-11-03 03:17 -------- d-----w- c:\documents and settings\joe\Local Settings\Application Data\Mozilla
2009-11-03 02:39 . 2009-11-03 04:13 22016 ----a-w- c:\windows\system32\tdlwsp.dll
2009-11-02 23:19 . 2009-11-02 23:19 -------- d-----w- c:\documents and settings\joe\Application Data\Malwarebytes
2009-11-02 23:13 . 2009-11-06 02:12 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-28 05:28 . 2009-10-28 05:30 -------- d-----w- c:\program files\Windows Live Safety Center
2009-10-28 04:51 . 2009-10-28 04:51 -------- d-----w- c:\documents and settings\joe\Application Data\AVG8
2009-10-28 04:31 . 2009-06-30 14:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-10-23 07:32 . 2009-10-23 07:32 -------- d-----w- c:\documents and settings\joe\Application Data\SUPERAntiSpyware.com
2009-10-23 07:19 . 2008-11-26 16:08 131 ----a-w- c:\windows\IDB.zip
2009-10-23 07:19 . 2009-10-02 18:19 1152470 ----a-w- c:\windows\UDB.zip
2009-10-23 07:07 . 2009-10-28 04:22 -------- d-----w- c:\documents and settings\Malwarebytes' Anti-Malware
2009-10-23 07:07 . 2009-10-23 07:10 20949 ----a-w- c:\documents and settings\Malwarebytes' Anti-Malware\unins000.dat
2009-10-23 07:07 . 2009-10-23 07:10 -------- d-----w- c:\documents and settings\Malwarebytes' Anti-Malware\Languages
2009-10-23 06:50 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-23 06:50 . 2009-10-28 04:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-23 06:50 . 2009-10-23 06:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-23 06:50 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-23 05:40 . 2009-10-28 04:31 -------- d-----w- c:\program files\Panda Security
2009-10-23 05:37 . 2009-11-03 02:38 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-07 18:07 . 2005-10-26 22:25 -------- d-----w- c:\program files\Steam
2009-11-06 02:44 . 2006-05-27 16:36 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000004-20021102}.dat
2009-11-06 02:44 . 2006-05-27 16:36 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000004-20021102}.dat
2009-11-06 02:19 . 2006-02-04 17:22 -------- d-----w- c:\program files\Java
2009-11-06 02:15 . 2004-08-05 12:00 84874 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-06 02:15 . 2004-08-05 12:00 510656 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-28 05:18 . 2005-10-26 21:34 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2009-10-28 05:18 . 2005-10-26 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-28 05:13 . 2008-08-05 01:27 -------- d-----w- c:\program files\Norton 360
2009-10-23 07:31 . 2005-11-07 02:45 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2009-10-23 07:25 . 2009-10-28 04:17 8530 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Personal_32_1036.dat
2009-10-23 07:05 . 2007-12-25 22:22 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-30 18:58 . 2008-02-18 19:38 9576 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\CCMSLLUM.DLL
2009-09-22 02:58 . 2009-09-22 02:58 -------- d-----w- c:\program files\Cool MOV To WMV Converter
2009-09-11 23:18 . 2008-06-23 02:09 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000004-10001102}.dat
2009-09-11 23:18 . 2008-06-23 02:09 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000004-10001102}.dat
2009-09-11 14:18 . 2004-08-05 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 21:39 . 2009-03-21 00:01 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-07 05:39 . 2009-08-18 13:58 5 ----a-w- c:\windows\system32\SySAVI2WMV.dat
2009-09-04 21:04 . 2004-08-05 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 2004-08-05 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-27 08:34 . 2005-10-27 01:44 81504 ----a-w- c:\documents and settings\joe\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 08:01 . 2004-08-05 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 13:48 . 2009-08-18 13:48 34 ---ha-w- c:\windows\system32\Converter_sysquict.dat
1999-04-06 13:27 . 1999-04-06 13:27 99840 ----a-w- c:\program files\Fichiers communs\IRAABOUT.DLL
1998-12-09 03:53 . 1998-12-09 03:53 70144 ----a-w- c:\program files\Fichiers communs\IRAMDMTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 48640 ----a-w- c:\program files\Fichiers communs\IRALPTTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 31744 ----a-w- c:\program files\Fichiers communs\IRAWEBTR.DLL
1998-12-09 03:53 . 1998-12-09 03:53 186368 ----a-w- c:\program files\Fichiers communs\IRAREG.DLL
1998-12-09 03:53 . 1998-12-09 03:53 17920 ----a-w- c:\program files\Fichiers communs\IRASRIAL.DLL
.
((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-05 12:00 . 2009-11-03 04:25 71374 c:\windows\system32\perfc009.dat
+ 2004-08-05 12:00 . 2009-11-06 02:15 71374 c:\windows\system32\perfc009.dat
- 2006-06-29 13:05 . 2009-01-07 22:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-29 13:05 . 2009-01-07 23:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-28 22:59 . 2009-01-07 23:20 24576 c:\windows\system32\nlsdl.dll
- 2006-06-28 22:59 . 2009-01-07 22:20 24576 c:\windows\system32\nlsdl.dll
+ 2006-11-07 08:26 . 2009-03-08 09:32 36864 c:\windows\system32\ieudinit.exe
- 2006-11-07 08:26 . 2009-03-08 08:32 36864 c:\windows\system32\ieudinit.exe
- 2006-06-29 13:05 . 2009-01-07 22:20 26112 c:\windows\system32\idndl.dll
+ 2006-06-29 13:05 . 2009-01-07 23:20 26112 c:\windows\system32\idndl.dll
- 2006-11-22 02:39 . 2009-01-07 22:21 121856 c:\windows\system32\xmllite.dll
+ 2006-11-22 02:39 . 2009-01-07 23:21 121856 c:\windows\system32\xmllite.dll
- 2004-08-05 12:00 . 2009-11-03 04:25 441438 c:\windows\system32\perfh009.dat
+ 2004-08-05 12:00 . 2009-11-06 02:15 441438 c:\windows\system32\perfh009.dat
+ 2009-01-07 22:20 . 2009-01-07 23:20 265720 c:\windows\system32\msdbg2.dll
- 2009-01-07 22:20 . 2009-01-07 22:20 265720 c:\windows\system32\msdbg2.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-28 1217808]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VX6000"="c:\windows\vVX6000.exe" [2006-10-13 994096]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 277296]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 88584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-12 86016]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-01-26 53248]
"Malwarebytes Anti-Malware (reboot)"="c:\nexon\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2003-10-06 24576]
"Logitech Utility"="Logi_MwX.Exe" - c:\windows\LOGI_MWX.EXE [2003-12-17 19968]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-11-12 1630208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Ultra Hal Text-to-Speech Reader Startup.lnk - c:\windows\Installer\{96EF451E-A402-44D8-BAEE-D70D558A4122}\New_Shortcut_S1449_0EB7CDB78E0C4A918D2CA535D5B8160C.exe [2006-9-24 40960]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\xpand rally\\xpandrally.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\xpand rally\\ChromEd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\il 2 sturmovik 1946\\il2fb.exe"=
"c:\\Nexon\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58719:TCP"= 58719:TCP:Pando Media Booster
"58719:UDP"= 58719:UDP:Pando Media Booster
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-10-27 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-11-04 206256]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-03-20 55152]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Fichiers communs\Symantec Shared\CCSVCHST.EXE [2008-02-18 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-05-30 101936]
S3 BS_DEF;BS_DEF;c:\program files\ASUS\AsusUpdate\BS_DEF.sys [2006-04-07 12800]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-01-12 23888]
S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 LwAdiHid;Périphériques numériques WingMan Logitech (détection automatique);c:\windows\system32\drivers\LwAdiHid.sys [2008-12-11 20864]
S3 Razerlow;Razerlow USB Filter Driver;c:\windows\system32\drivers\Razerlow.sys [2006-05-06 13225]
S3 sdAuxService;PC Tools Auxiliary Service;c:\nexon\Spyware Doctor1\pctsAuxs.exe [2009-11-04 348752]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [2006-04-13 2383152]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - COMHOST
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
Contenu du dossier 'Tâches planifiées'
2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-11-07 c:\windows\Tasks\User_Feed_Synchronization-{FFAC0B8B-CE55-4AEE-BE8F-39D5A6F04342}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
DPF: {BFD90062-6B5E-4F8F-87B1-5F022C14E32F} - [You must be registered and logged in to see this link.]
DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} - [You must be registered and logged in to see this link.]
FF - ProfilePath - c:\documents and settings\joe\Application Data\Mozilla\Firefox\Profiles\i4sf4rhw.default\
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-11-07 13:35
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(2212)
c:\program files\Logitech\MouseWare\System\LgWndHk.dll
c:\program files\Fichiers communs\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\eappprxy.dll
.
Heure de fin: 2009-11-07 13:38
ComboFix-quarantined-files.txt 2009-11-07 18:38
ComboFix2.txt 2009-11-07 18:22
ComboFix3.txt 2009-11-06 02:34
ComboFix4.txt 2009-11-03 04:47
Avant-CF: 12 779 466 752 octets libres
Après-CF: 12 757 917 696 octets libres
- - End Of File - - DC307C18F5E768F7C5173386A4354694
delpiero0
Rookie Surfer
- Posts: 61
Joined: 2009-11-03
Operating System: XP
Re: Security Tool and maybe more malaware
Please post a new HijackThis log.
______________________________

[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.]

DragonMaster Jay
Moderator | Tech Staff
- Posts: 2126
Joined: 2009-09-06
Operating System: Windows 7 Ultimate 32-Bit

Re: Security Tool and maybe more malaware
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:33:14, on 2009-11-07
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\vVX6000.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\program files\steam\steam.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Zabaware\HalReader\HalReader.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Nexon\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Nexon\Spyware Doctor\BDT\PCTBrowserDefender.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Nexon\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Ultra Hal Text-to-Speech Reader Startup.lnk = ?
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - [You must be registered and logged in to see this link.]
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - [You must be registered and logged in to see this link.]
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - [You must be registered and logged in to see this link.]
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - [You must be registered and logged in to see this link.]
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - [You must be registered and logged in to see this link.]
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - [You must be registered and logged in to see this link.]
O16 - DPF: {BFD90062-6B5E-4F8F-87B1-5F022C14E32F} (ActiveReceiver Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - [You must be registered and logged in to see this link.]
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - [You must be registered and logged in to see this link.]
O16 - DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} (ActiveID Control) - [You must be registered and logged in to see this link.]
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Nexon\Spyware Doctor1\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Nexon\Spyware Doctor1\pctsSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
--
End of file - 10176 bytes
Scan saved at 22:33:14, on 2009-11-07
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\vVX6000.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\program files\steam\steam.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Zabaware\HalReader\HalReader.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Nexon\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Nexon\Spyware Doctor\BDT\PCTBrowserDefender.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Nexon\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Ultra Hal Text-to-Speech Reader Startup.lnk = ?
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - [You must be registered and logged in to see this link.]
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - [You must be registered and logged in to see this link.]
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - [You must be registered and logged in to see this link.]
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - [You must be registered and logged in to see this link.]
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - [You must be registered and logged in to see this link.]
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - [You must be registered and logged in to see this link.]
O16 - DPF: {BFD90062-6B5E-4F8F-87B1-5F022C14E32F} (ActiveReceiver Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - [You must be registered and logged in to see this link.]
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - [You must be registered and logged in to see this link.]
O16 - DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} (ActiveID Control) - [You must be registered and logged in to see this link.]
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Nexon\Spyware Doctor1\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Nexon\Spyware Doctor1\pctsSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
--
End of file - 10176 bytes
delpiero0
Rookie Surfer
- Posts: 61
Joined: 2009-11-03
Operating System: XP
Re: Security Tool and maybe more malaware
Please use Internet Explorer and run a [You must be registered and logged in to see this link.]
- Please check I agree with the Terms and Conditions and click Start Here
- You will need to allow an Active X install for the scan to run.
- Leave the scanning options at default and click Start Scan
______________________________

[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.]

DragonMaster Jay
Moderator | Tech Staff
- Posts: 2126
Joined: 2009-09-06
Operating System: Windows 7 Ultimate 32-Bit

Re: Security Tool and maybe more malaware
can't still cannot use internet, says unauthorised right to use iexplorer.exe.
delpiero0
Rookie Surfer
- Posts: 61
Joined: 2009-11-03
Operating System: XP
Re: Security Tool and maybe more malaware
I cant open iexplorer.exe at all and mozilla cannot connect. I cant use any programs automatic update such as the mbam one it says I'm not connected.
However my connection does show in my tool bar, I can also connect to wlmsn. I did a reset of dns, ip release ip renew in cmd DOS still didnt fȋxed anything.
I think ill just refrmt my hard drive, I havent moved since a 2 weeks now
However my connection does show in my tool bar, I can also connect to wlmsn. I did a reset of dns, ip release ip renew in cmd DOS still didnt fȋxed anything.
I think ill just refrmt my hard drive, I havent moved since a 2 weeks now

delpiero0
Rookie Surfer
- Posts: 61
Joined: 2009-11-03
Operating System: XP
Re: Security Tool and maybe more malaware
Are you saying you want to do a reformat and reinstall?
______________________________

[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.]

DragonMaster Jay
Moderator | Tech Staff
- Posts: 2126
Joined: 2009-09-06
Operating System: Windows 7 Ultimate 32-Bit

Page 2 of 7 •
1, 2, 3, 4, 5, 6, 7 
Permissions of this forum:
You cannot reply to topics in this forum










by 