Daniel14
Topic Starter
Hello people,
my name is Daniel and this is my first post at whatthetech forums. First of all, I did not come here just to 'seek and go', no. I did not visit this website just for help, and then after my infection (hopefully) is cleared and removed I go away. That's not my purpose. In fact, I came here to learn, because I felt like using computer for 10 years taught me nothing about this subject, I am so ashamed. So long time ago I wanted to be part of a friendly community that teaches many stuff about computing and it came in coincidence that I am facing this problem, and like we say 'two birds with one stone..'. This whole speech may be useless for some people, but it's not for me and hopefully some people will understand me eventually.
Let's start about when it happened, how it happened. Well, quite frankly I have no idea how I got infected, I'm probably browsing 'without a head' or something like that. I trust what I download, I even scan before downloading with two different 'computer-protectors' such as Avast and Malwarebytes anti-malware. Yup, this last is powerful! I trust what I download.. Before I visit a website, I usually scan it with an online PC scanner that relies on multiple protectors. Would you believe me if I tell you that I had a virus in my computer for around 8 months of trying to remove it?! I was so lazy, dayam on me! I finally realized that I need serious help, not on that 8 month-infection thing, but on a different one that I recently got. I was so foolish when I got it! I don't know if it's the one I talk about in this topic, but I think I got it from a program that didn't open - YYYCracker.exe.. Yup, too foolish, I knew it was malware, but my friend insisted.. Oh too foolish! Back on subject, the infection is basically a malware that identifies installation .exe as INVALID WIN32 APPLICATION. Other symptoms:
- When trying to open 'My computer's properties, Anti Trojan Elite says it has found trojan(s) on my computer, and directly after, an error pops up with the white X in the red circle informing that XYZ/XYZ/XYZblabla/rundll32.exe is INVALID WIN32 APPLICATION
- When trying to open 'Configuration panel' (translated from French, the one inside you can uninstall/install programs) - It says Anti Trojan elite found trojan(s) in computer, but despite that it opens.
- [Possible symptom] My screen goes black and dark and then it returns to normal.
DDS.txt:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 16:17:18 on 2012-07-09
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1013.223 [GMT 1:00]
.
AV: Norton Internet Security *Enabled/Outdated* {E10A9785-9598-4754-B552-92431C1C35F8}
AV: avast! antivirus 4.8.1351 [VPS 091101-0] *Enabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Norton Internet Security *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\1.3.21.111\GoogleCrashHandler.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Fichiers communs\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Micro Application\Cloneur Expert\TrueImageMonitor.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Anti Trojan Elite\TJEnder.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Documents and Settings\too\Local Settings\Application Data\Akamai\netsession_win.exe
C:\Documents and Settings\too\Local Settings\Application Data\Akamai\netsession_win.exe
C:\Program Files\Menara\dslmon.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Update\1.3.21.111\GoogleCrashHandler.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Mozilla Firefox\firefox.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
uSearchAssistant = hxxp://dts.search-results.com/sr?src=ieb&appid=1022&systemid=1&sr=0&q={searchTerms}
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant =
uURLSearchHooks: ToolbarURLSearchHook Class: {ca3eb689-8f09-4026-aa10-b9534c691ce0} - c:\program files\mdickie db toolbar toolbar\tbhelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\fichiers communs\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Wincore Mediabar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} - c:\progra~1\imesha~1\mediabar\datamngr\toolbar\wincoreimdtx.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\fichiers communs\symantec shared\coshared\browser\2.5\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\fichie~1\symant~1\ids\IPSBHO.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\fichiers communs\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SMTTB2009 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\mdickie db toolbar toolbar\tbcore3.dll
TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\fichiers communs\symantec shared\coshared\browser\2.5\CoIEPlg.dll
TB: Wincore Mediabar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} - c:\progra~1\imesha~1\mediabar\datamngr\toolbar\wincoreimdtx.dll
TB: MDickie DB Toolbar Toolbar: {338b4dfe-2e2c-4338-9e41-e176d497299e} - c:\program files\mdickie db toolbar toolbar\tbcore3.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
EB: {ACEBB9C5-8B00-43A3-B821-A5DCEFECCF0F} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [svvhost2] c:\windows\system32\svvhost2.exe
uRun: [systemlog] c:\windows\system32\systemlog.exe
uRun: [swinlogin] c:\windows\system32\swinlogin.exe
uRun: [winlogin2] c:\windows\system32\winlogin2.exe
uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" /MINIMIZED
uRun: [Akamai NetSession Interface] "c:\documents and settings\too\local settings\application data\akamai\netsession_win.exe"
uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTAgent.exe" -autorun
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [Google Update] "c:\documents and settings\too\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [ccApp] "c:\program files\fichiers communs\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton internet security\osCheck.exe"
mRun: [Cloneur Expert Monitor] "c:\program files\micro application\cloneur expert\TrueImageMonitor.exe"
mRun: [Acronis Scheduler2 Service] "c:\program files\fichiers communs\acronis\schedule2\schedhlp.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [TkBellExe] "c:\program files\fichiers communs\real\update_ob\realsched.exe" -osboot
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [SunJavaUpdateSched] "c:\program files\fichiers communs\java\java update\jusched.exe"
mRun: [Google Updater] "c:\program files\google\google updater\GoogleUpdater.exe" -check_deprecation
mRun: [snpstd3] c:\windows\vsnpstd3.exe
mRun: [Freecorder FLV Service] "c:\program files\freecorder\FLVSrvc.exe" /run
mRun: [GameXL]
mRun: [Anti Trojan Elite] c:\program files\anti trojan elite\TJEnder.exe :NO
dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\too\menudm~1\progra~1\dmarra~1\fifa11~1.lnk - c:\program files\ea sports\fifa 11\support\EAregister.exe
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\dslmon.lnk - c:\program files\menara\dslmon.exe
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\metacafe.lnk - c:\program files\metacafe\MetacafeAgent.exe
uPolicies-explorer: MemCheckBoxInRunDlg = 0 (0x0)
uPolicies-explorer: NoStrCmpLogical = 0 (0x0)
mPolicies-explorer: NoChangeAnimation = 0 (0x0)
mPolicies-explorer: NoStrCmpLogical = 0 (0x0)
mPolicies-system: RunStartupScriptSync = 1 (0x1)
IE: &Download All using 4shared Desktop - c:\program files\4shared desktop\down_all.htm
IE: &Search
IE: E&xporter vers Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Télécharger avec Mipony - file://c:\program files\mipony\browser\IEContext.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/plugins/activex/YoYo.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: Interfaces\{FB9CD8EC-1988-48E9-953C-88B70A14CA0E} : NameServer = 62.251.229.223 62.251.229.237
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\fichie~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: CLKERN.DLL c:\progra~1\google\go333c~1\GOEC62~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\
FF - prefs.js: browser.search.selectedEngine - Search
FF - prefs.js: browser.startup.homepage - hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
FF - prefs.js: keyword.URL - hxxp://www.bigseekpro.com/search/toolbar/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}?q=
FF - component: c:\program files\google\google gears\firefox\lib\ff36\gears.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\extensions\{1bc9ba34-1eed-42ca-a505-6d2f1a935bbb}\plugins\npietab2.dll
FF - plugin: c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\extensions\[removed]\plugins\npBFHUpdater.dll
FF - plugin: c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\extensions\[removed]\plugins\npBP4FUpdater.dll
FF - plugin: c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\nppanda3d.dll
FF - plugin: c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\extensions\[removed]\plugins\NPYYGInstantPlay.dll
FF - plugin: c:\documents and settings\too\local settings\application data\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\documents and settings\too\local settings\application data\robloxversions\version-6ca07d14e2274822\NPRobloxProxy.dll
FF - plugin: c:\documents and settings\too\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_235.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-9-2 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-9-2 20560]
R2 ATE_PROCMON;ATE_PROCMON;c:\program files\anti trojan elite\ATEPMON.sys [2012-6-2 9984]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-9-2 138680]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\fichiers communs\symantec shared\CCSVCHST.EXE [2008-1-25 149352]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\fichiers communs\symantec shared\CCSVCHST.EXE [2008-1-25 149352]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\fichiers communs\symantec shared\CCSVCHST.EXE [2008-1-25 149352]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\fichiers communs\pc tools\smonitor\StartManSvc.exe [2012-5-31 793048]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-9-2 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-9-2 352920]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\fichiers communs\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-9-18 99376]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2008-9-18 41216]
R3 NAVENG;NAVENG;c:\progra~1\fichie~1\symant~1\virusd~1\20080917.039\NAVENG.SYS [2008-9-18 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\fichie~1\symant~1\virusd~1\20080917.039\NAVEX15.SYS [2008-9-18 873552]
S2 EjxBPXiHAs;EjxBPXiHAs;cmd /c "c:\docume~1\too\locals~1\temp\svhost.exe" –> cmd [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-8-2 133104]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-4-5 158856]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-1-12 23888]
S3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [2011-8-15 500704]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\garena messenger\room\safedrv.sys –> c:\program files\garena messenger\room\safedrv.sys [?]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2010-1-12 30192]
S3 gupdatem;Service Google Update (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-8-2 133104]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-12-1 34384]
S3 Symantec Core LC;Symantec Core LC;c:\progra~1\fichie~1\symant~1\ccpd-lc\symlcsvc.exe [2008-9-18 1245064]
S3 UsbEvdomAtc;LGE EVDOM USB Serial Port;c:\windows\system32\drivers\lgevdomatc.sys [2009-2-17 19840]
S3 usbevdombus;LGE EVDOM Composite USB Device;c:\windows\system32\drivers\lgevdombus.sys [2009-2-17 13696]
S3 UsbEvdomDiag;LGE EVDOM USB Serial DM Port;c:\windows\system32\drivers\lgevdomdiag.sys [2009-2-17 19840]
S3 USBEVDOmModem;LGE EVDOM USB Modem;c:\windows\system32\drivers\lgevdommodem.sys [2009-2-17 21632]
S3 vproiah;vproiah;c:\windows\system32\drivers\vproiah.sys –> c:\windows\system32\drivers\vproiah.sys [?]
S3 XDva389;XDva389;\??\c:\windows\system32\xdva389.sys –> c:\windows\system32\XDva389.sys [?]
S3 XDva397;XDva397;c:\windows\system32\XDva397.sys [2012-5-6 77136]
.
=============== Created Last 30 ================
.
2012-07-05 12:46:19 ——– d—–w- c:\program files\Strogino CS Portal
2012-06-28 15:53:51 ——– d—–w- c:\program files\ZeusPro
2012-06-28 10:25:30 ——– d—–w- c:\program files\ESET
2012-06-12 19:55:29 ——– d—–w- c:\documents and settings\too\local settings\application data\RobloxDownloads
2012-06-12 19:55:24 ——– d—–w- c:\documents and settings\too\local settings\application data\RobloxVersions
2012-06-12 19:55:10 ——– d—–w- c:\documents and settings\too\local settings\application data\Roblox
.
==================== Find3M ====================
.
2012-07-06 13:35:41 219128 —-a-w- c:\windows\system32\PnkBstrB.xtr
2012-07-06 13:35:41 219128 —-a-w- c:\windows\system32\PnkBstrB.exe
2012-07-06 13:32:54 138592 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-07-06 13:32:20 219128 —-a-w- c:\windows\system32\PnkBstrB.ex0
2012-05-20 12:21:30 138056 —-a-w- c:\documents and settings\too\application data\PnkBstrK.sys
2012-05-20 12:21:06 75136 —-a-w- c:\windows\system32\PnkBstrA.exe
2012-05-18 17:26:05 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-18 17:26:05 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-11 19:06:07 98304 —-a-w- c:\windows\system32\CmdLineExt.dll
2012-05-06 12:10:24 77136 —-a-w- c:\windows\system32\XDva397.sys
2012-04-16 20:31:20 19456 —-a-w- c:\windows\ed4.exe
2012-04-16 20:29:30 34795 —-a-w- c:\windows\libregex.dll
2012-04-16 20:29:12 327308 —-a-w- c:\windows\libssl32.dll
2012-04-16 20:29:07 186928 —-a-w- c:\windows\stoneh.exe
2012-04-16 20:28:41 775 —-a-w- c:\documents and settings\too\ds.bat
2012-04-15 19:02:16 68888 —-a-w- c:\windows\system\xinput1_3.dll
2012-04-15 19:02:16 444776 —-a-w- c:\windows\system\d3dx10_35.dll
2012-04-15 19:02:16 3727720 —-a-w- c:\windows\system\d3dx9_35.dll
2012-04-15 19:02:16 3497832 —-a-w- c:\windows\system\d3dx9_34.dll
.
============= FINISH: 16:19:28.01 ===============
P.S: I attached attach.txt in the bottom because in the preparation guide it says there is another dds.txt which I cannot found except attach.txt
my name is Daniel and this is my first post at whatthetech forums. First of all, I did not come here just to 'seek and go', no. I did not visit this website just for help, and then after my infection (hopefully) is cleared and removed I go away. That's not my purpose. In fact, I came here to learn, because I felt like using computer for 10 years taught me nothing about this subject, I am so ashamed. So long time ago I wanted to be part of a friendly community that teaches many stuff about computing and it came in coincidence that I am facing this problem, and like we say 'two birds with one stone..'. This whole speech may be useless for some people, but it's not for me and hopefully some people will understand me eventually.
Let's start about when it happened, how it happened. Well, quite frankly I have no idea how I got infected, I'm probably browsing 'without a head' or something like that. I trust what I download, I even scan before downloading with two different 'computer-protectors' such as Avast and Malwarebytes anti-malware. Yup, this last is powerful! I trust what I download.. Before I visit a website, I usually scan it with an online PC scanner that relies on multiple protectors. Would you believe me if I tell you that I had a virus in my computer for around 8 months of trying to remove it?! I was so lazy, dayam on me! I finally realized that I need serious help, not on that 8 month-infection thing, but on a different one that I recently got. I was so foolish when I got it! I don't know if it's the one I talk about in this topic, but I think I got it from a program that didn't open - YYYCracker.exe.. Yup, too foolish, I knew it was malware, but my friend insisted.. Oh too foolish! Back on subject, the infection is basically a malware that identifies installation .exe as INVALID WIN32 APPLICATION. Other symptoms:
- When trying to open 'My computer's properties, Anti Trojan Elite says it has found trojan(s) on my computer, and directly after, an error pops up with the white X in the red circle informing that XYZ/XYZ/XYZblabla/rundll32.exe is INVALID WIN32 APPLICATION
- When trying to open 'Configuration panel' (translated from French, the one inside you can uninstall/install programs) - It says Anti Trojan elite found trojan(s) in computer, but despite that it opens.
- [Possible symptom] My screen goes black and dark and then it returns to normal.
DDS.txt:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 16:17:18 on 2012-07-09
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1013.223 [GMT 1:00]
.
AV: Norton Internet Security *Enabled/Outdated* {E10A9785-9598-4754-B552-92431C1C35F8}
AV: avast! antivirus 4.8.1351 [VPS 091101-0] *Enabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Norton Internet Security *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\1.3.21.111\GoogleCrashHandler.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Fichiers communs\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Micro Application\Cloneur Expert\TrueImageMonitor.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Anti Trojan Elite\TJEnder.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Documents and Settings\too\Local Settings\Application Data\Akamai\netsession_win.exe
C:\Documents and Settings\too\Local Settings\Application Data\Akamai\netsession_win.exe
C:\Program Files\Menara\dslmon.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Update\1.3.21.111\GoogleCrashHandler.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Mozilla Firefox\firefox.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
uSearchAssistant = hxxp://dts.search-results.com/sr?src=ieb&appid=1022&systemid=1&sr=0&q={searchTerms}
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant =
uURLSearchHooks: ToolbarURLSearchHook Class: {ca3eb689-8f09-4026-aa10-b9534c691ce0} - c:\program files\mdickie db toolbar toolbar\tbhelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\fichiers communs\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Wincore Mediabar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} - c:\progra~1\imesha~1\mediabar\datamngr\toolbar\wincoreimdtx.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\fichiers communs\symantec shared\coshared\browser\2.5\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\fichie~1\symant~1\ids\IPSBHO.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\fichiers communs\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SMTTB2009 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\mdickie db toolbar toolbar\tbcore3.dll
TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\fichiers communs\symantec shared\coshared\browser\2.5\CoIEPlg.dll
TB: Wincore Mediabar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} - c:\progra~1\imesha~1\mediabar\datamngr\toolbar\wincoreimdtx.dll
TB: MDickie DB Toolbar Toolbar: {338b4dfe-2e2c-4338-9e41-e176d497299e} - c:\program files\mdickie db toolbar toolbar\tbcore3.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
EB: {ACEBB9C5-8B00-43A3-B821-A5DCEFECCF0F} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [svvhost2] c:\windows\system32\svvhost2.exe
uRun: [systemlog] c:\windows\system32\systemlog.exe
uRun: [swinlogin] c:\windows\system32\swinlogin.exe
uRun: [winlogin2] c:\windows\system32\winlogin2.exe
uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" /MINIMIZED
uRun: [Akamai NetSession Interface] "c:\documents and settings\too\local settings\application data\akamai\netsession_win.exe"
uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTAgent.exe" -autorun
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [Google Update] "c:\documents and settings\too\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [ccApp] "c:\program files\fichiers communs\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton internet security\osCheck.exe"
mRun: [Cloneur Expert Monitor] "c:\program files\micro application\cloneur expert\TrueImageMonitor.exe"
mRun: [Acronis Scheduler2 Service] "c:\program files\fichiers communs\acronis\schedule2\schedhlp.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [TkBellExe] "c:\program files\fichiers communs\real\update_ob\realsched.exe" -osboot
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [SunJavaUpdateSched] "c:\program files\fichiers communs\java\java update\jusched.exe"
mRun: [Google Updater] "c:\program files\google\google updater\GoogleUpdater.exe" -check_deprecation
mRun: [snpstd3] c:\windows\vsnpstd3.exe
mRun: [Freecorder FLV Service] "c:\program files\freecorder\FLVSrvc.exe" /run
mRun: [GameXL]
mRun: [Anti Trojan Elite] c:\program files\anti trojan elite\TJEnder.exe :NO
dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\too\menudm~1\progra~1\dmarra~1\fifa11~1.lnk - c:\program files\ea sports\fifa 11\support\EAregister.exe
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\dslmon.lnk - c:\program files\menara\dslmon.exe
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\metacafe.lnk - c:\program files\metacafe\MetacafeAgent.exe
uPolicies-explorer: MemCheckBoxInRunDlg = 0 (0x0)
uPolicies-explorer: NoStrCmpLogical = 0 (0x0)
mPolicies-explorer: NoChangeAnimation = 0 (0x0)
mPolicies-explorer: NoStrCmpLogical = 0 (0x0)
mPolicies-system: RunStartupScriptSync = 1 (0x1)
IE: &Download All using 4shared Desktop - c:\program files\4shared desktop\down_all.htm
IE: &Search
IE: E&xporter vers Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Télécharger avec Mipony - file://c:\program files\mipony\browser\IEContext.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/plugins/activex/YoYo.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: Interfaces\{FB9CD8EC-1988-48E9-953C-88B70A14CA0E} : NameServer = 62.251.229.223 62.251.229.237
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\fichie~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: CLKERN.DLL c:\progra~1\google\go333c~1\GOEC62~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\
FF - prefs.js: browser.search.selectedEngine - Search
FF - prefs.js: browser.startup.homepage - hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
FF - prefs.js: keyword.URL - hxxp://www.bigseekpro.com/search/toolbar/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}?q=
FF - component: c:\program files\google\google gears\firefox\lib\ff36\gears.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\extensions\{1bc9ba34-1eed-42ca-a505-6d2f1a935bbb}\plugins\npietab2.dll
FF - plugin: c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\extensions\[removed]\plugins\npBFHUpdater.dll
FF - plugin: c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\extensions\[removed]\plugins\npBP4FUpdater.dll
FF - plugin: c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\nppanda3d.dll
FF - plugin: c:\documents and settings\too\application data\mozilla\firefox\profiles\kjl3xhnd.default\extensions\[removed]\plugins\NPYYGInstantPlay.dll
FF - plugin: c:\documents and settings\too\local settings\application data\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\documents and settings\too\local settings\application data\robloxversions\version-6ca07d14e2274822\NPRobloxProxy.dll
FF - plugin: c:\documents and settings\too\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_235.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-9-2 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-9-2 20560]
R2 ATE_PROCMON;ATE_PROCMON;c:\program files\anti trojan elite\ATEPMON.sys [2012-6-2 9984]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-9-2 138680]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\fichiers communs\symantec shared\CCSVCHST.EXE [2008-1-25 149352]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\fichiers communs\symantec shared\CCSVCHST.EXE [2008-1-25 149352]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\fichiers communs\symantec shared\CCSVCHST.EXE [2008-1-25 149352]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\fichiers communs\pc tools\smonitor\StartManSvc.exe [2012-5-31 793048]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-9-2 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-9-2 352920]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\fichiers communs\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-9-18 99376]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2008-9-18 41216]
R3 NAVENG;NAVENG;c:\progra~1\fichie~1\symant~1\virusd~1\20080917.039\NAVENG.SYS [2008-9-18 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\fichie~1\symant~1\virusd~1\20080917.039\NAVEX15.SYS [2008-9-18 873552]
S2 EjxBPXiHAs;EjxBPXiHAs;cmd /c "c:\docume~1\too\locals~1\temp\svhost.exe" –> cmd [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-8-2 133104]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-4-5 158856]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-1-12 23888]
S3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [2011-8-15 500704]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\garena messenger\room\safedrv.sys –> c:\program files\garena messenger\room\safedrv.sys [?]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2010-1-12 30192]
S3 gupdatem;Service Google Update (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-8-2 133104]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-12-1 34384]
S3 Symantec Core LC;Symantec Core LC;c:\progra~1\fichie~1\symant~1\ccpd-lc\symlcsvc.exe [2008-9-18 1245064]
S3 UsbEvdomAtc;LGE EVDOM USB Serial Port;c:\windows\system32\drivers\lgevdomatc.sys [2009-2-17 19840]
S3 usbevdombus;LGE EVDOM Composite USB Device;c:\windows\system32\drivers\lgevdombus.sys [2009-2-17 13696]
S3 UsbEvdomDiag;LGE EVDOM USB Serial DM Port;c:\windows\system32\drivers\lgevdomdiag.sys [2009-2-17 19840]
S3 USBEVDOmModem;LGE EVDOM USB Modem;c:\windows\system32\drivers\lgevdommodem.sys [2009-2-17 21632]
S3 vproiah;vproiah;c:\windows\system32\drivers\vproiah.sys –> c:\windows\system32\drivers\vproiah.sys [?]
S3 XDva389;XDva389;\??\c:\windows\system32\xdva389.sys –> c:\windows\system32\XDva389.sys [?]
S3 XDva397;XDva397;c:\windows\system32\XDva397.sys [2012-5-6 77136]
.
=============== Created Last 30 ================
.
2012-07-05 12:46:19 ——– d—–w- c:\program files\Strogino CS Portal
2012-06-28 15:53:51 ——– d—–w- c:\program files\ZeusPro
2012-06-28 10:25:30 ——– d—–w- c:\program files\ESET
2012-06-12 19:55:29 ——– d—–w- c:\documents and settings\too\local settings\application data\RobloxDownloads
2012-06-12 19:55:24 ——– d—–w- c:\documents and settings\too\local settings\application data\RobloxVersions
2012-06-12 19:55:10 ——– d—–w- c:\documents and settings\too\local settings\application data\Roblox
.
==================== Find3M ====================
.
2012-07-06 13:35:41 219128 —-a-w- c:\windows\system32\PnkBstrB.xtr
2012-07-06 13:35:41 219128 —-a-w- c:\windows\system32\PnkBstrB.exe
2012-07-06 13:32:54 138592 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-07-06 13:32:20 219128 —-a-w- c:\windows\system32\PnkBstrB.ex0
2012-05-20 12:21:30 138056 —-a-w- c:\documents and settings\too\application data\PnkBstrK.sys
2012-05-20 12:21:06 75136 —-a-w- c:\windows\system32\PnkBstrA.exe
2012-05-18 17:26:05 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-18 17:26:05 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-11 19:06:07 98304 —-a-w- c:\windows\system32\CmdLineExt.dll
2012-05-06 12:10:24 77136 —-a-w- c:\windows\system32\XDva397.sys
2012-04-16 20:31:20 19456 —-a-w- c:\windows\ed4.exe
2012-04-16 20:29:30 34795 —-a-w- c:\windows\libregex.dll
2012-04-16 20:29:12 327308 —-a-w- c:\windows\libssl32.dll
2012-04-16 20:29:07 186928 —-a-w- c:\windows\stoneh.exe
2012-04-16 20:28:41 775 —-a-w- c:\documents and settings\too\ds.bat
2012-04-15 19:02:16 68888 —-a-w- c:\windows\system\xinput1_3.dll
2012-04-15 19:02:16 444776 —-a-w- c:\windows\system\d3dx10_35.dll
2012-04-15 19:02:16 3727720 —-a-w- c:\windows\system\d3dx9_35.dll
2012-04-15 19:02:16 3497832 —-a-w- c:\windows\system\d3dx9_34.dll
.
============= FINISH: 16:19:28.01 ===============
P.S: I attached attach.txt in the bottom because in the preparation guide it says there is another dds.txt which I cannot found except attach.txt