This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infection that turns installation .exe into invalid win32 application

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Daniel, exeHelper may have helped your current issue as it resets exe file associations, however ComboFix should also deal with your issue. ComboFix gives you no options after scanning. Just post the log when it has finished.
Hi Daniel, I looked through your logs again. I mistook Anti Trojan Elite to be a rogue anti-spyware program, which is why I had you run rkill. Did you intentionally install Anti Trojan Elite? If ComboFix refuses to run, please run exeHelper, then try running ComboFix again.
Anti Trojan Elite has been intentionally installed. Personally, if you check on Google about ATE you will find it on famous download websites. So it's not rogue. Because ComboFix has a setup based on .exe extension, I will change it to .scr
NoodleTech, another symptom: When executing something at 'Run' it says 'Rundll32 isn't valid win32 app' and something like that. I will run ComboFix today.. Glad yo'ure still with me :-)
My computer re-booted automatically without notice and an error has shown once re-booted.. Details of report: signature of error: BCCOde: 10000050 BCP1: E5C2901C BCPD2:00000000 BCP3: BF8326C3 BCP4: 00000001 OSVer: 5_1_2600 SP: 2_0 Product: 256_1 Details of report: C:\DOCUME~1\too\LOCALS~1\Temp\WER74d1.dir00\sysdata.xml C:\DOCUME~1\too\LOCALS~1\Temp\WER74d1.dir00\Mini071512-01.dmp What does this mean, please help
Daniel,

Thank you for all the information. Changing ComboFix's extension to .scr can have unintended consequences. Please do not do anything without asking in the future.

Download TDSSKiller.zip
  • Save it to a location OTHER THAN your desktop (eg. the C:\ drive)
  • Extract it
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Actually, the scan worked normally..


ComboFix 12-07-14.01 - too 07/15/2012 17:50:21.1.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1013.468 [GMT 1:00]
Lancé depuis: c:\documents and settings\too\Bureau\ComboFix.scr
Commutateurs utilisés :: /S
AV: avast! antivirus 4.8.1351 [VPS 091101-0] *Disabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Norton Internet Security *Enabled/Outdated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\CFLog
c:\documents and settings\All Users\Application Data\a52ae224743f6add27a87560cec7f7a9_c
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\too\Application Data\app
c:\documents and settings\too\Application Data\app\Jerakine_lang.dat
c:\documents and settings\too\Application Data\app\Jerakine_lang_vesrion.dat
c:\documents and settings\too\Application Data\PriceGong
c:\documents and settings\too\Application Data\PriceGong\Data\1.xml
c:\documents and settings\too\Application Data\PriceGong\Data\a.xml
c:\documents and settings\too\Application Data\PriceGong\Data\b.xml
c:\documents and settings\too\Application Data\PriceGong\Data\c.xml
c:\documents and settings\too\Application Data\PriceGong\Data\d.xml
c:\documents and settings\too\Application Data\PriceGong\Data\e.xml
c:\documents and settings\too\Application Data\PriceGong\Data\f.xml
c:\documents and settings\too\Application Data\PriceGong\Data\g.xml
c:\documents and settings\too\Application Data\PriceGong\Data\h.xml
c:\documents and settings\too\Application Data\PriceGong\Data\i.xml
c:\documents and settings\too\Application Data\PriceGong\Data\J.xml
c:\documents and settings\too\Application Data\PriceGong\Data\k.xml
c:\documents and settings\too\Application Data\PriceGong\Data\l.xml
c:\documents and settings\too\Application Data\PriceGong\Data\m.xml
c:\documents and settings\too\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\too\Application Data\PriceGong\Data\n.xml
c:\documents and settings\too\Application Data\PriceGong\Data\o.xml
c:\documents and settings\too\Application Data\PriceGong\Data\p.xml
c:\documents and settings\too\Application Data\PriceGong\Data\q.xml
c:\documents and settings\too\Application Data\PriceGong\Data\r.xml
c:\documents and settings\too\Application Data\PriceGong\Data\s.xml
c:\documents and settings\too\Application Data\PriceGong\Data\t.xml
c:\documents and settings\too\Application Data\PriceGong\Data\u.xml
c:\documents and settings\too\Application Data\PriceGong\Data\v.xml
c:\documents and settings\too\Application Data\PriceGong\Data\w.xml
c:\documents and settings\too\Application Data\PriceGong\Data\x.xml
c:\documents and settings\too\Application Data\PriceGong\Data\y.xml
c:\documents and settings\too\Application Data\PriceGong\Data\z.xml
c:\documents and settings\too\Application Data\too3SQLite3.dll
c:\documents and settings\too\Application Data\Toolbar4
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\affid.dat
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\basis.xml
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\icons.bmp
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\info.txt
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\install.ico
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\mbback.bmp
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\mbbigopen.bmp
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\mbclose.bmp
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\mbfwd.bmp
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\mbsep.bmp
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\nav1c.bmp
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\tbcore3.inf
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\TbHelper2.exe
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\uninstall.exe
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\UninstallToolbar.exe
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\update.exe
c:\documents and settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\version.txt
c:\documents and settings\too\Application Data\toolog.dat
c:\documents and settings\too\dat1.000
c:\documents and settings\too\GL4JavbJauGljJNI14.dll
c:\documents and settings\too\Local Settings\Application Data\atube-catcher-2-9-es-en-win.exe
c:\documents and settings\too\Setup_BlackShot_GarenaMessenger_Install_2_116.exe
c:\documents and settings\too\WINDOWS
c:\program files\MDickie DB Toolbar Toolbar\tbHElper.dll
c:\windows\InstallDir
c:\windows\system\16_1280.DRV
c:\windows\system\256_1024.DRV
c:\windows\system\CGA40850.FON
c:\windows\system\CGA80850.FON
c:\windows\system\d3dx9_35.dll
c:\windows\system\EGA40850.FON
c:\windows\system\EGA80850.FON
c:\windows\system32\install
c:\windows\system32\wshom.ocx.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_MYWEBSEARCHSERVICE
——-\Legacy_XPROTECTOR
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2012-06-15 au 2012-07-15 ))))))))))))))))))))))))))))))))))))
.
.
2012-07-15 16:15 . 2012-07-15 16:15 12568 —-a-w- c:\windows\system32\drivers\PROCEXP113.SYS
2012-07-05 12:46 . 2012-07-05 12:46 ——– d—–w- c:\program files\Strogino CS Portal
2012-06-28 15:53 . 2012-06-28 15:54 ——– d—–w- c:\program files\ZeusPro
2012-06-28 10:25 . 2012-06-28 10:25 ——– d—–w- c:\program files\ESET
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-06 13:35 . 2012-03-10 18:25 219128 —-a-w- c:\windows\system32\PnkBstrB.exe
2012-07-06 13:35 . 2011-03-10 18:21 219128 —-a-w- c:\windows\system32\PnkBstrB.xtr
2012-07-06 13:32 . 2011-03-10 13:59 138592 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-07-06 13:32 . 2011-03-10 13:58 219128 —-a-w- c:\windows\system32\PnkBstrB.ex0
2012-07-03 12:46 . 2012-02-07 19:21 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-05-20 12:21 . 2011-03-10 13:59 138056 —-a-w- c:\documents and settings\too\Application Data\PnkBstrK.sys
2012-05-20 12:21 . 2011-03-10 13:58 75136 —-a-w- c:\windows\system32\PnkBstrA.exe
2012-05-18 17:26 . 2012-05-18 12:30 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-18 17:26 . 2011-12-08 14:24 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-11 19:06 . 2009-09-18 18:53 98304 —-a-w- c:\windows\system32\CmdLineExt.dll
2012-05-06 12:10 . 2012-05-06 12:10 77136 —-a-w- c:\windows\system32\XDva397.sys
2012-04-16 20:31 . 2012-04-16 20:31 19456 —-a-w- c:\windows\ed4.exe
2012-04-16 20:29 . 2012-04-16 20:29 34795 —-a-w- c:\windows\libregex.dll
2012-04-16 20:29 . 2012-04-16 20:29 327308 —-a-w- c:\windows\libssl32.dll
2012-04-16 20:29 . 2012-04-16 20:29 186928 —-a-w- c:\windows\stoneh.exe
2012-04-16 20:28 . 2012-04-16 20:28 775 —-a-w- c:\documents and settings\too\ds.bat
2010-06-25 20:29 . 2010-06-25 20:29 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 0B788EE2A876D7B31DF840C13F08CD2B . 360320 . . [5.1.2600.3394] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\tcpip.sys
[7] 2004-08-05 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
.
[-] 2008-09-17 . 9410E8164E2D95DAF81A21FB4994C107 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
[-] 2008-04-14 . E17C85D5B5CF477638433B851A98499E . 1571840 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\sfcfiles.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-05 39408]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2011-09-17 3077528]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-06-03 880528]
"Akamai NetSession Interface"="c:\documents and settings\too\Local Settings\Application Data\Akamai\netsession_win.exe" [2012-05-26 4327744]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2012-02-02 3035968]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-04-05 17356424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-21 137752]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 16377344]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2008-02-06 718704]
"Cloneur Expert Monitor"="c:\program files\Micro Application\Cloneur Expert\TrueImageMonitor.exe" [2008-09-18 437675]
"Acronis Scheduler2 Service"="c:\program files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2008-09-18 61440]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-08-26 122368]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-10-25 198160]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-25 30192]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Google Updater"="c:\program files\Google\Google Updater\GoogleUpdater.exe" [2011-09-06 161336]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"Anti Trojan Elite"="c:\program files\Anti Trojan Elite\TJEnder.exe" [2009-06-14 4076544]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2004-08-05 101888]
.
c:\documents and settings\too\Menu Démarrer\Programmes\Démarrage\
FIFA 11 Registration.lnk - c:\program files\EA Sports\FIFA 11\Support\EAregister.exe [N/A]
.
c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\
DSLMON.lnk - c:\program files\Menara\dslmon.exe [2009-7-21 962661]
Metacafe.lnk - c:\program files\Metacafe\MetacafeAgent.exe [2009-3-3 145736]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeAnimation"= 0 (0x0)
"NoStrCmpLogical"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoStrCmpLogical"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LMabcoms.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Nouveau dossier\\Pro Evolution Soccer 2008\\PES2008.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\too\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\EA Games\\Battlefield Heroes\\BFHeroes.exe"=
"c:\\Documents and Settings\\too\\Local Settings\\Application Data\\TeamSpeak 3 Client\\ts3client_win32.exe"=
"c:\\Documents and Settings\\too\\Mes documents\\Downloads\\Left 4 Dead full game MP - SP -=AviaRa=-\\Left4Dead\\left4dead.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Counter-Strike\\hl.exe"=
"c:\\Program Files\\Z8Games\\CrossFire\\CF_G4box.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56779:TCP"= 56779:TCP:Pando Media Booster
"56779:UDP"= 56779:UDP:Pando Media Booster
"57786:TCP"= 57786:TCP:Pando Media Booster
"57786:UDP"= 57786:UDP:Pando Media Booster
"1820:TCP"= 1820:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys –> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [9/2/2009 7:03 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9/2/2009 7:03 PM 20560]
R2 ATE_PROCMON;ATE_PROCMON;c:\program files\Anti Trojan Elite\ATEPMON.sys [6/2/2012 3:25 PM 9984]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Fichiers communs\Symantec Shared\CCSVCHST.EXE [1/25/2008 5:47 PM 149352]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Fichiers communs\PC Tools\sMonitor\StartManSvc.exe [5/31/2012 4:10 PM 793048]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [9/18/2008 12:30 PM 99376]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [9/18/2008 1:11 PM 41216]
S2 EjxBPXiHAs;EjxBPXiHAs;cmd /c "c:\docume~1\too\LOCALS~1\Temp\svhost.exe" –> cmd [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/2/2009 9:28 PM 133104]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [4/5/2012 12:37 PM 158856]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [1/12/2008 6:32 PM 23888]
S3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [8/15/2011 11:00 PM 500704]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena Messenger\Room\safedrv.sys –> c:\program files\Garena Messenger\Room\safedrv.sys [?]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [1/12/2010 11:27 PM 30192]
S3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8/2/2009 9:28 PM 133104]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [12/1/2009 4:49 PM 34384]
S3 UsbEvdomAtc;LGE EVDOM USB Serial Port;c:\windows\system32\drivers\lgevdomatc.sys [2/17/2009 6:15 PM 19840]
S3 usbevdombus;LGE EVDOM Composite USB Device;c:\windows\system32\drivers\lgevdombus.sys [2/17/2009 6:15 PM 13696]
S3 UsbEvdomDiag;LGE EVDOM USB Serial DM Port;c:\windows\system32\drivers\lgevdomdiag.sys [2/17/2009 6:15 PM 19840]
S3 USBEVDOmModem;LGE EVDOM USB Modem;c:\windows\system32\drivers\lgevdommodem.sys [2/17/2009 6:15 PM 21632]
S3 vproiah;vproiah;c:\windows\system32\DRIVERS\vproiah.sys –> c:\windows\system32\DRIVERS\vproiah.sys [?]
S3 XDva389;XDva389;\??\c:\windows\system32\XDva389.sys –> c:\windows\system32\XDva389.sys [?]
S3 XDva397;XDva397;c:\windows\system32\XDva397.sys [5/6/2012 1:10 PM 77136]
.
— Autres Services/Pilotes en mémoire —
.
*NewlyCreated* - COMHOST
*NewlyCreated* - WS2IFSL
.
Contenu du dossier 'Tâches planifiées'
.
2012-02-24 c:\windows\Tasks\Game_Booster_Startup.job
- c:\program files\IObit\Game Booster 3\gbtray.exe [2012-02-24 14:05]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-02 20:28]
.
2012-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-02 20:28]
.
2012-07-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1592454029-839522115-1005Core.job
- c:\documents and settings\too\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-20 18:42]
.
2012-07-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1592454029-839522115-1005UA.job
- c:\documents and settings\too\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-20 18:42]
.
2012-07-02 c:\windows\Tasks\Norton Internet Security - Effectuer une analyse complète du système - poste.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2008-02-07 05:05]
.
2012-07-13 c:\windows\Tasks\Norton Security Scan for too.job
- c:\progra~1\NORTON~2\Engine\351~1.8\Nss.exe [2011-10-26 01:45]
.
2012-05-31 c:\windows\Tasks\RMAutoUpdate.job
- c:\program files\PC Tools Registry Mechanic\SULauncher.exe [2012-05-31 11:23]
.
2012-07-14 c:\windows\Tasks\RMSchedule.job
- c:\program files\PC Tools Registry Mechanic\RegMech.exe [2012-05-31 11:22]
.
2012-06-04 c:\windows\Tasks\WavePadReminder.job
- c:\program files\NCH Software\WavePad\wavepad.exe [2012-06-01 19:11]
.
2009-12-20 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-09-09 22:18]
.
.
——- Examen supplémentaire ——-
.
uStart Page = hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: &Download All using 4shared Desktop - c:\program files\4shared Desktop\down_all.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Télécharger avec Mipony - file://c:\program files\MiPony\Browser\IEContext.htm
TCP: Interfaces\{FB9CD8EC-1988-48E9-953C-88B70A14CA0E}: NameServer = 62.251.229.223 62.251.229.237
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/plugins/activex/YoYo.cab
FF - ProfilePath - c:\documents and settings\too\Application Data\Mozilla\Firefox\Profiles\kjl3xhnd.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
FF - prefs.js: keyword.URL - hxxp://www.bigseekpro.com/search/toolbar/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}?q=
.
- - - - ORPHELINS SUPPRIMES - - - -
.
BHO-{28387537-e3f9-4ed7-860c-11e69af4a8a0} - c:\progra~1\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll
Toolbar-{28387537-e3f9-4ed7-860c-11e69af4a8a0} - c:\progra~1\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll
Toolbar-10 - (no file)
HKCU-Run-svvhost2 - c:\windows\system32\svvhost2.exe
HKCU-Run-systemlog - c:\windows\system32\systemlog.exe
HKCU-Run-swinlogin - c:\windows\system32\swinlogin.exe
HKCU-Run-winlogin2 - c:\windows\system32\winlogin2.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
HKLM-Run-Freecorder FLV Service - c:\program files\Freecorder\FLVSrvc.exe
HKLM-Run-GameXL - (no file)
AddRemove-BattlEye A2 Free - c:\program files\Bohemia Interactive\ArmA 2 FreeBattlEye\UnInstallBE.exe
AddRemove-Liberty Unleashed - c:\documents and settings\too\Mes documents\Downloads\GTA III (PC)\GTA III\UninstallLU.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-15 18:11
Windows 5.1.2600 Service Pack 2 NTFS
.
Recherche de processus cachés …
.
Recherche d'éléments en démarrage automatique cachés …
.
Recherche de fichiers cachés …
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EjxBPXiHAs]
"ImagePath"="cmd /c \"c:\docume~1\too\LOCALS~1\Temp\svhost.exe\""
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— CLES DE REGISTRE BLOQUEES ———————
.
[HKEY_USERS\S-1-5-21-1417001333-1592454029-839522115-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{38DEAE1B-BFA0-433A-8AC1-BE6559737B89}*tings]
"AppName"="Roblox.exe"
"Policy"=dword:00000003
"AppPath"="c:\\Documents and Settings\\too\\Local Settings\\Application Data\\RobloxVersions\\version-6ca07d14e2274822\\"
.
[HKEY_USERS\S-1-5-21-1417001333-1592454029-839522115-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4DF8E6F1-956F-469C-8337-EA02D67E820D}*tings]
"AppName"="Roblox.exe"
"Policy"=dword:00000003
"AppPath"="c:\\Documents and Settings\\too\\Local Settings\\Application Data\\RobloxVersions\\version-eecd9135a67340ab\\"
.
[HKEY_USERS\S-1-5-21-1417001333-1592454029-839522115-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF9D57E5-0B68-4F07-9983-F47976F1A3F7}*tings]
"AppName"="Roblox.exe"
"Policy"=dword:00000003
"AppPath"="c:\\Documents and Settings\\too\\Local Settings\\Application Data\\RobloxVersions\\version-e029025a3614426d\\"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Ñw*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
———————— Autres processus actifs ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Fichiers communs\Acronis\Schedule2\schedul2.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Google\Update\1.3.21.111\GoogleCrashHandler.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTHDCPL.EXE
.
**************************************************************************
.
Heure de fin: 2012-07-15 18:21:24 - La machine a redémarré
ComboFix-quarantined-files.txt 2012-07-15 17:21
.
Avant-CF: 14,021,513,216 octets libres
Après-CF: 13,948,915,712 octets libres
.
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
.
- - End Of File - - 5CB10CEAD4ED0F806CB21BF2F5B59BC6
Sorry for not disabling Norton Internet S. - It drove me nuts that I was scared to disable everything related to security..
I have consulted BleepingComputer.com malware team and had no objection on changing extension to .scr.. Where do you think I got this idea from ?
Daniel, Following advice from more than one helper makes it extremely difficult to clean a machine. It not only ties up valuable helper time, but it also makes it very confusing as the helpers do not know what the other helper is doing. Sometimes the fixes can be in conflict with each other and cause problems. If you want my help, please follow my instructions exactly. Otherwise, I will close this thread and you may seek help elsewhere. Let me know how you would like to proceed.
I would like to proceed by following your advice, sorry for misunderstanding. In fact, Combofix was scanning while you already posted that advice. Also, I don't think it's a problem to change extensions. Sorry. Since I have posted ComboFix log, you are free to analyze it, I will be waiting for your next step.
Daniel14,

No problem. I'm glad we are on the same page now.

Changing ComboFix's extension to .scr is a huge problem because ComboFix skips many procedures when run this way. It is OK to run ComboFix with a .com extension, but not .scr.

I need you to delete ComboFix from your desktop, then download it from one of the two links below and run it again. This time, try running it without changing the extension. I figure that ComboFix may have already fixed the .exe file association problem. If it does not work, change the extension to .com.

Download Links:
Link 1
Link 2

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI