This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infection that turns installation .exe into invalid win32 application

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry for the absence, I had RL things that needed to be sorted out. I have btw one question, do I have only to remove it from desktop or execute 'combofix /uninstall'?
No worries. Only remove it from the desktop because there is no way to uninstall it when you rename the extension to .scr.
ComboFix 12-07-18.04 - too 07/18/2012 19:02:35.2.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1013.471 [GMT 1:00]
Lancé depuis: c:\documents and settings\too\Bureau\ComboFix.com
AV: avast! antivirus 4.8.1351 [VPS 091101-0] *Enabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Norton Internet Security *Enabled/Outdated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
* Un nouveau point de restauration a été créé
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2012-06-18 au 2012-07-18 ))))))))))))))))))))))))))))))))))))
.
.
2012-07-18 17:55 . 2012-07-18 17:55 12568 —-a-w- c:\windows\system32\drivers\PROCEXP113.SYS
2012-07-05 12:46 . 2012-07-05 12:46 ——– d—–w- c:\program files\Strogino CS Portal
2012-06-28 15:53 . 2012-06-28 15:54 ——– d—–w- c:\program files\ZeusPro
2012-06-28 10:25 . 2012-06-28 10:25 ——– d—–w- c:\program files\ESET
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-06 13:35 . 2012-03-10 18:25 219128 —-a-w- c:\windows\system32\PnkBstrB.exe
2012-07-06 13:35 . 2011-03-10 18:21 219128 —-a-w- c:\windows\system32\PnkBstrB.xtr
2012-07-06 13:32 . 2011-03-10 13:59 138592 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-07-06 13:32 . 2011-03-10 13:58 219128 —-a-w- c:\windows\system32\PnkBstrB.ex0
2012-07-03 12:46 . 2012-02-07 19:21 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-05-20 12:21 . 2011-03-10 13:59 138056 —-a-w- c:\documents and settings\too\Application Data\PnkBstrK.sys
2012-05-20 12:21 . 2011-03-10 13:58 75136 —-a-w- c:\windows\system32\PnkBstrA.exe
2012-05-18 17:26 . 2012-05-18 12:30 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-18 17:26 . 2011-12-08 14:24 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-11 19:06 . 2009-09-18 18:53 98304 —-a-w- c:\windows\system32\CmdLineExt.dll
2012-05-06 12:10 . 2012-05-06 12:10 77136 —-a-w- c:\windows\system32\XDva397.sys
2010-06-25 20:29 . 2010-06-25 20:29 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 0B788EE2A876D7B31DF840C13F08CD2B . 360320 . . [5.1.2600.3394] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\tcpip.sys
[7] 2004-08-05 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
.
[-] 2008-09-17 . 9410E8164E2D95DAF81A21FB4994C107 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
[-] 2008-04-14 . E17C85D5B5CF477638433B851A98499E . 1571840 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2012-07-15_17.11.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-18 15:15 . 2012-07-18 15:15 16384 c:\windows\Temp\Perflib_Perfdata_754.dat
+ 2012-07-18 15:15 . 2012-07-18 15:15 16384 c:\windows\Temp\Perflib_Perfdata_3e0.dat
+ 2012-07-18 16:17 . 2012-07-18 16:17 22016 c:\windows\Installer\3914fd.msi
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-05 39408]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2011-09-17 3077528]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-06-03 880528]
"Akamai NetSession Interface"="c:\documents and settings\too\Local Settings\Application Data\Akamai\netsession_win.exe" [2012-05-26 4327744]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2012-02-02 3035968]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-04-05 17356424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-21 137752]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 16377344]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2008-02-06 718704]
"Cloneur Expert Monitor"="c:\program files\Micro Application\Cloneur Expert\TrueImageMonitor.exe" [2008-09-18 437675]
"Acronis Scheduler2 Service"="c:\program files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2008-09-18 61440]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-08-26 122368]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-10-25 198160]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-25 30192]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Google Updater"="c:\program files\Google\Google Updater\GoogleUpdater.exe" [2011-09-06 161336]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"Anti Trojan Elite"="c:\program files\Anti Trojan Elite\TJEnder.exe" [2009-06-14 4076544]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2004-08-05 101888]
.
c:\documents and settings\too\Menu Démarrer\Programmes\Démarrage\
FIFA 11 Registration.lnk - c:\program files\EA Sports\FIFA 11\Support\EAregister.exe [N/A]
.
c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\
DSLMON.lnk - c:\program files\Menara\dslmon.exe [2009-7-21 962661]
Metacafe.lnk - c:\program files\Metacafe\MetacafeAgent.exe [2009-3-3 145736]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeAnimation"= 0 (0x0)
"NoStrCmpLogical"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoStrCmpLogical"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LMabcoms.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Nouveau dossier\\Pro Evolution Soccer 2008\\PES2008.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\too\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\EA Games\\Battlefield Heroes\\BFHeroes.exe"=
"c:\\Documents and Settings\\too\\Local Settings\\Application Data\\TeamSpeak 3 Client\\ts3client_win32.exe"=
"c:\\Documents and Settings\\too\\Mes documents\\Downloads\\Left 4 Dead full game MP - SP -=AviaRa=-\\Left4Dead\\left4dead.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Counter-Strike\\hl.exe"=
"c:\\Program Files\\Z8Games\\CrossFire\\CF_G4box.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56779:TCP"= 56779:TCP:Pando Media Booster
"56779:UDP"= 56779:UDP:Pando Media Booster
"57786:TCP"= 57786:TCP:Pando Media Booster
"57786:UDP"= 57786:UDP:Pando Media Booster
"1459:TCP"= 1459:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys –> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [9/2/2009 7:03 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9/2/2009 7:03 PM 20560]
R2 ATE_PROCMON;ATE_PROCMON;c:\program files\Anti Trojan Elite\ATEPMON.sys [6/2/2012 3:25 PM 9984]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Fichiers communs\Symantec Shared\CCSVCHST.EXE [1/25/2008 5:47 PM 149352]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Fichiers communs\PC Tools\sMonitor\StartManSvc.exe [5/31/2012 4:10 PM 793048]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [9/18/2008 12:30 PM 99376]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [9/18/2008 1:11 PM 41216]
S2 EjxBPXiHAs;EjxBPXiHAs;cmd /c "c:\docume~1\too\LOCALS~1\Temp\svhost.exe" –> cmd [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/2/2009 9:28 PM 133104]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [4/5/2012 12:37 PM 158856]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [1/12/2008 6:32 PM 23888]
S3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [8/15/2011 11:00 PM 500704]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena Messenger\Room\safedrv.sys –> c:\program files\Garena Messenger\Room\safedrv.sys [?]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [1/12/2010 11:27 PM 30192]
S3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8/2/2009 9:28 PM 133104]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [12/1/2009 4:49 PM 34384]
S3 UsbEvdomAtc;LGE EVDOM USB Serial Port;c:\windows\system32\drivers\lgevdomatc.sys [2/17/2009 6:15 PM 19840]
S3 usbevdombus;LGE EVDOM Composite USB Device;c:\windows\system32\drivers\lgevdombus.sys [2/17/2009 6:15 PM 13696]
S3 UsbEvdomDiag;LGE EVDOM USB Serial DM Port;c:\windows\system32\drivers\lgevdomdiag.sys [2/17/2009 6:15 PM 19840]
S3 USBEVDOmModem;LGE EVDOM USB Modem;c:\windows\system32\drivers\lgevdommodem.sys [2/17/2009 6:15 PM 21632]
S3 vproiah;vproiah;c:\windows\system32\DRIVERS\vproiah.sys –> c:\windows\system32\DRIVERS\vproiah.sys [?]
S3 XDva389;XDva389;\??\c:\windows\system32\XDva389.sys –> c:\windows\system32\XDva389.sys [?]
S3 XDva397;XDva397;c:\windows\system32\XDva397.sys [5/6/2012 1:10 PM 77136]
.
— Autres Services/Pilotes en mémoire —
.
*NewlyCreated* - COMHOST
.
Contenu du dossier 'Tâches planifiées'
.
2012-07-18 c:\windows\Tasks\Game_Booster_Startup.job
- c:\program files\IObit\Game Booster 3\gbtray.exe [2012-02-24 14:05]
.
2012-07-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-05 13:19]
.
2012-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-02 20:28]
.
2012-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-02 20:28]
.
2012-07-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1592454029-839522115-1005Core.job
- c:\documents and settings\too\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-20 18:42]
.
2012-07-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1592454029-839522115-1005UA.job
- c:\documents and settings\too\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-20 18:42]
.
2012-07-16 c:\windows\Tasks\Norton Internet Security - Effectuer une analyse complète du système - poste.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2008-02-07 05:05]
.
2012-07-13 c:\windows\Tasks\Norton Security Scan for too.job
- c:\progra~1\NORTON~2\Engine\351~1.8\Nss.exe [2011-10-26 01:45]
.
2012-07-18 c:\windows\Tasks\RMAutoUpdate.job
- c:\program files\PC Tools Registry Mechanic\SULauncher.exe [2012-05-31 11:23]
.
2012-07-18 c:\windows\Tasks\RMSchedule.job
- c:\program files\PC Tools Registry Mechanic\RegMech.exe [2012-05-31 11:22]
.
2012-06-04 c:\windows\Tasks\WavePadReminder.job
- c:\program files\NCH Software\WavePad\wavepad.exe [2012-06-01 19:11]
.
2012-07-18 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-09-09 22:18]
.
.
——- Examen supplémentaire ——-
.
uStart Page = hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download All using 4shared Desktop - c:\program files\4shared Desktop\down_all.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Télécharger avec Mipony - file://c:\program files\MiPony\Browser\IEContext.htm
TCP: Interfaces\{FB9CD8EC-1988-48E9-953C-88B70A14CA0E}: NameServer = 62.251.229.223 62.251.229.237
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/plugins/activex/YoYo.cab
FF - ProfilePath - c:\documents and settings\too\Application Data\Mozilla\Firefox\Profiles\kjl3xhnd.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
FF - prefs.js: keyword.URL - hxxp://www.bigseekpro.com/search/toolbar/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}?q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-18 19:20
Windows 5.1.2600 Service Pack 2 NTFS
.
Recherche de processus cachés …
.
Recherche d'éléments en démarrage automatique cachés …
.
Recherche de fichiers cachés …
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EjxBPXiHAs]
"ImagePath"="cmd /c \"c:\docume~1\too\LOCALS~1\Temp\svhost.exe\""
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— CLES DE REGISTRE BLOQUEES ———————
.
[HKEY_USERS\S-1-5-21-1417001333-1592454029-839522115-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{38DEAE1B-BFA0-433A-8AC1-BE6559737B89}*tings]
"AppName"="Roblox.exe"
"Policy"=dword:00000003
"AppPath"="c:\\Documents and Settings\\too\\Local Settings\\Application Data\\RobloxVersions\\version-6ca07d14e2274822\\"
.
[HKEY_USERS\S-1-5-21-1417001333-1592454029-839522115-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4DF8E6F1-956F-469C-8337-EA02D67E820D}*tings]
"AppName"="Roblox.exe"
"Policy"=dword:00000003
"AppPath"="c:\\Documents and Settings\\too\\Local Settings\\Application Data\\RobloxVersions\\version-eecd9135a67340ab\\"
.
[HKEY_USERS\S-1-5-21-1417001333-1592454029-839522115-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF9D57E5-0B68-4F07-9983-F47976F1A3F7}*tings]
"AppName"="Roblox.exe"
"Policy"=dword:00000003
"AppPath"="c:\\Documents and Settings\\too\\Local Settings\\Application Data\\RobloxVersions\\version-e029025a3614426d\\"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Ñw*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Heure de fin: 2012-07-18 19:25:19
ComboFix-quarantined-files.txt 2012-07-18 18:25
ComboFix2.txt 2012-07-15 17:21
.
Avant-CF: 13,860,184,064 octets libres
Après-CF: 13,849,313,280 octets libres
.
- - End Of File - - ADF37E0E16034FE0B8599BEBCB86657B
Hi Daniel,

Do you have a Windows XP CD? We will need it to replace an infected driver.

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\docume~1\too\LOCALS~1\Temp\svhost.exe

Driver::
EjxBPXiHAs

FCopy::
c:\windows\system32\dllcache\tcpip.sys | c:\windows\system32\drivers\tcpip.sys
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste
Unfortunately, no. I never knew something about the XP CD. Let's hope we find a solution for this instead of giving up and trying the CD. I will try your solution :-)
Also, yesterday after running ComboFix, I was able to check time/date which showed error before ComboFix. I clicked on it yesterday and it worked. Now today I can't, it seems like the infection is back. I will do solution btw.
Okay, please run the script. The other solution would be to find another computer with Windows XP. Do you have another computer with Windows XP?
Greetings NoodleTech,

This is a good day, don't you think so?

After updating ComboFix, I immediately ran the script you provided, and here is the log:


ComboFix 12-07-19.02 - too 07/19/2012 17:12:24.3.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1013.406 [GMT 1:00]
Lancé depuis: c:\documents and settings\too\Bureau\ComboFix.com
Commutateurs utilisés :: c:\docume~1\too\Bureau\CFScript.txt
AV: avast! antivirus 4.8.1351 [VPS 091101-0] *Enabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Norton Internet Security *Enabled/Outdated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
FILE ::
"c:\docume~1\too\LOCALS~1\Temp\svhost.exe"
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
.
.
————— FCopy —————
.
c:\windows\system32\dllcache\tcpip.sys –> c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_EJXBPXIHAS
——-\Service_EjxBPXiHAs
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2012-06-19 au 2012-07-19 ))))))))))))))))))))))))))))))))))))
.
.
2012-07-19 16:37 . 2012-07-19 16:37 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2012-07-18 17:55 . 2012-07-19 16:08 12568 —-a-w- c:\windows\system32\drivers\PROCEXP113.SYS
2012-07-05 12:46 . 2012-07-05 12:46 ——– d—–w- c:\program files\Strogino CS Portal
2012-06-28 15:53 . 2012-06-28 15:54 ——– d—–w- c:\program files\ZeusPro
2012-06-28 10:25 . 2012-06-28 10:25 ——– d—–w- c:\program files\ESET
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-06 13:35 . 2012-03-10 18:25 219128 —-a-w- c:\windows\system32\PnkBstrB.exe
2012-07-06 13:35 . 2011-03-10 18:21 219128 —-a-w- c:\windows\system32\PnkBstrB.xtr
2012-07-06 13:32 . 2011-03-10 13:59 138592 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-07-06 13:32 . 2011-03-10 13:58 219128 —-a-w- c:\windows\system32\PnkBstrB.ex0
2012-07-03 12:46 . 2012-02-07 19:21 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-05-20 12:21 . 2011-03-10 13:59 138056 —-a-w- c:\documents and settings\too\Application Data\PnkBstrK.sys
2012-05-20 12:21 . 2011-03-10 13:58 75136 —-a-w- c:\windows\system32\PnkBstrA.exe
2012-05-18 17:26 . 2012-05-18 12:30 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-18 17:26 . 2011-12-08 14:24 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-11 19:06 . 2009-09-18 18:53 98304 —-a-w- c:\windows\system32\CmdLineExt.dll
2012-05-06 12:10 . 2012-05-06 12:10 77136 —-a-w- c:\windows\system32\XDva397.sys
2010-06-25 20:29 . 2010-06-25 20:29 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-09-17 . 9410E8164E2D95DAF81A21FB4994C107 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
[-] 2008-04-14 . E17C85D5B5CF477638433B851A98499E . 1571840 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2012-07-15_17.11.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-19 12:02 . 2012-07-19 12:02 16384 c:\windows\Temp\Perflib_Perfdata_768.dat
+ 2012-07-19 16:34 . 2012-07-19 16:34 16384 c:\windows\Temp\Perflib_Perfdata_714.dat
+ 2012-07-19 16:34 . 2012-07-19 16:34 16384 c:\windows\Temp\Perflib_Perfdata_30c.dat
+ 2012-07-18 16:17 . 2012-07-18 16:17 22016 c:\windows\Installer\3914fd.msi
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-05 39408]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2011-09-17 3077528]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-06-03 880528]
"Akamai NetSession Interface"="c:\documents and settings\too\Local Settings\Application Data\Akamai\netsession_win.exe" [2012-05-26 4327744]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2012-02-02 3035968]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-04-05 17356424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-21 137752]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 16377344]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2008-02-06 718704]
"Cloneur Expert Monitor"="c:\program files\Micro Application\Cloneur Expert\TrueImageMonitor.exe" [2008-09-18 437675]
"Acronis Scheduler2 Service"="c:\program files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2008-09-18 61440]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-08-26 122368]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-10-25 198160]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-25 30192]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Google Updater"="c:\program files\Google\Google Updater\GoogleUpdater.exe" [2011-09-06 161336]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"Anti Trojan Elite"="c:\program files\Anti Trojan Elite\TJEnder.exe" [2009-06-14 4076544]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2004-08-05 101888]
.
c:\documents and settings\too\Menu Démarrer\Programmes\Démarrage\
FIFA 11 Registration.lnk - c:\program files\EA Sports\FIFA 11\Support\EAregister.exe [N/A]
.
c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\
DSLMON.lnk - c:\program files\Menara\dslmon.exe [2009-7-21 962661]
Metacafe.lnk - c:\program files\Metacafe\MetacafeAgent.exe [2009-3-3 145736]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeAnimation"= 0 (0x0)
"NoStrCmpLogical"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoStrCmpLogical"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LMabcoms.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Nouveau dossier\\Pro Evolution Soccer 2008\\PES2008.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\too\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\EA Games\\Battlefield Heroes\\BFHeroes.exe"=
"c:\\Documents and Settings\\too\\Local Settings\\Application Data\\TeamSpeak 3 Client\\ts3client_win32.exe"=
"c:\\Documents and Settings\\too\\Mes documents\\Downloads\\Left 4 Dead full game MP - SP -=AviaRa=-\\Left4Dead\\left4dead.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Counter-Strike\\hl.exe"=
"c:\\Program Files\\Z8Games\\CrossFire\\CF_G4box.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56779:TCP"= 56779:TCP:Pando Media Booster
"56779:UDP"= 56779:UDP:Pando Media Booster
"57786:TCP"= 57786:TCP:Pando Media Booster
"57786:UDP"= 57786:UDP:Pando Media Booster
.
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys –> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [9/2/2009 7:03 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9/2/2009 7:03 PM 20560]
R2 ATE_PROCMON;ATE_PROCMON;c:\program files\Anti Trojan Elite\ATEPMON.sys [6/2/2012 3:25 PM 9984]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Fichiers communs\Symantec Shared\CCSVCHST.EXE [1/25/2008 5:47 PM 149352]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Fichiers communs\PC Tools\sMonitor\StartManSvc.exe [5/31/2012 4:10 PM 793048]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [9/18/2008 12:30 PM 99376]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [9/18/2008 1:11 PM 41216]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/2/2009 9:28 PM 133104]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [4/5/2012 12:37 PM 158856]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [1/12/2008 6:32 PM 23888]
S3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [8/15/2011 11:00 PM 500704]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena Messenger\Room\safedrv.sys –> c:\program files\Garena Messenger\Room\safedrv.sys [?]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [1/12/2010 11:27 PM 30192]
S3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8/2/2009 9:28 PM 133104]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [12/1/2009 4:49 PM 34384]
S3 UsbEvdomAtc;LGE EVDOM USB Serial Port;c:\windows\system32\drivers\lgevdomatc.sys [2/17/2009 6:15 PM 19840]
S3 usbevdombus;LGE EVDOM Composite USB Device;c:\windows\system32\drivers\lgevdombus.sys [2/17/2009 6:15 PM 13696]
S3 UsbEvdomDiag;LGE EVDOM USB Serial DM Port;c:\windows\system32\drivers\lgevdomdiag.sys [2/17/2009 6:15 PM 19840]
S3 USBEVDOmModem;LGE EVDOM USB Modem;c:\windows\system32\drivers\lgevdommodem.sys [2/17/2009 6:15 PM 21632]
S3 vproiah;vproiah;c:\windows\system32\DRIVERS\vproiah.sys –> c:\windows\system32\DRIVERS\vproiah.sys [?]
S3 XDva389;XDva389;\??\c:\windows\system32\XDva389.sys –> c:\windows\system32\XDva389.sys [?]
S3 XDva397;XDva397;c:\windows\system32\XDva397.sys [5/6/2012 1:10 PM 77136]
.
— Autres Services/Pilotes en mémoire —
.
*NewlyCreated* - COMHOST
.
Contenu du dossier 'Tâches planifiées'
.
2012-07-19 c:\windows\Tasks\Game_Booster_Startup.job
- c:\program files\IObit\Game Booster 3\gbtray.exe [2012-02-24 14:05]
.
2012-07-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-05 13:19]
.
2012-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-02 20:28]
.
2012-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-02 20:28]
.
2012-07-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1592454029-839522115-1005Core.job
- c:\documents and settings\too\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-20 18:42]
.
2012-07-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1592454029-839522115-1005UA.job
- c:\documents and settings\too\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-20 18:42]
.
2012-07-16 c:\windows\Tasks\Norton Internet Security - Effectuer une analyse complète du système - poste.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2008-02-07 05:05]
.
2012-07-19 c:\windows\Tasks\Norton Security Scan for too.job
- c:\progra~1\NORTON~2\Engine\351~1.8\Nss.exe [2011-10-26 01:45]
.
2012-07-19 c:\windows\Tasks\RMAutoUpdate.job
- c:\program files\PC Tools Registry Mechanic\SULauncher.exe [2012-05-31 11:23]
.
2012-07-18 c:\windows\Tasks\RMSchedule.job
- c:\program files\PC Tools Registry Mechanic\RegMech.exe [2012-05-31 11:22]
.
2012-06-04 c:\windows\Tasks\WavePadReminder.job
- c:\program files\NCH Software\WavePad\wavepad.exe [2012-06-01 19:11]
.
2012-07-19 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-09-09 22:18]
.
.
——- Examen supplémentaire ——-
.
uStart Page = hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: &Download All using 4shared Desktop - c:\program files\4shared Desktop\down_all.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Télécharger avec Mipony - file://c:\program files\MiPony\Browser\IEContext.htm
TCP: Interfaces\{FB9CD8EC-1988-48E9-953C-88B70A14CA0E}: NameServer = 62.251.229.223 62.251.229.237
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/plugins/activex/YoYo.cab
FF - ProfilePath - c:\documents and settings\too\Application Data\Mozilla\Firefox\Profiles\kjl3xhnd.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bigseekpro.com/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}
FF - prefs.js: keyword.URL - hxxp://www.bigseekpro.com/search/toolbar/mdickie/{7F528376-C4C0-4CA2-8667-E6A5B848625B}?q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-19 17:37
Windows 5.1.2600 Service Pack 2 NTFS
.
Recherche de processus cachés …
.
Recherche d'éléments en démarrage automatique cachés …
.
Recherche de fichiers cachés …
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— CLES DE REGISTRE BLOQUEES ———————
.
[HKEY_USERS\S-1-5-21-1417001333-1592454029-839522115-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{38DEAE1B-BFA0-433A-8AC1-BE6559737B89}*tings]
"AppName"="Roblox.exe"
"Policy"=dword:00000003
"AppPath"="c:\\Documents and Settings\\too\\Local Settings\\Application Data\\RobloxVersions\\version-6ca07d14e2274822\\"
.
[HKEY_USERS\S-1-5-21-1417001333-1592454029-839522115-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4DF8E6F1-956F-469C-8337-EA02D67E820D}*tings]
"AppName"="Roblox.exe"
"Policy"=dword:00000003
"AppPath"="c:\\Documents and Settings\\too\\Local Settings\\Application Data\\RobloxVersions\\version-eecd9135a67340ab\\"
.
[HKEY_USERS\S-1-5-21-1417001333-1592454029-839522115-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF9D57E5-0B68-4F07-9983-F47976F1A3F7}*tings]
"AppName"="Roblox.exe"
"Policy"=dword:00000003
"AppPath"="c:\\Documents and Settings\\too\\Local Settings\\Application Data\\RobloxVersions\\version-e029025a3614426d\\"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Ñw*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
———————— Autres processus actifs ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Fichiers communs\Acronis\Schedule2\schedul2.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Google\Update\1.3.21.115\GoogleCrashHandler.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTHDCPL.EXE
.
**************************************************************************
.
Heure de fin: 2012-07-19 17:44:30 - La machine a redémarré
ComboFix-quarantined-files.txt 2012-07-19 16:44
ComboFix2.txt 2012-07-18 18:25
ComboFix3.txt 2012-07-15 17:21
.
Avant-CF: 11,429,122,048 octets libres
Après-CF: 11,412,234,240 octets libres
.
- - End Of File - - E4F1FD6D8DB5787BE602CD610352A468

———————————————————————————————-

I understand. Unfortunately my father updated to Windows 7 few months ago on his laptop.
Hi Daniel,

Yes, today was a good day :). How is your computer behaving now? Are you still having issues opening .exe files?

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
So far, installation .exe files are open-able. What is weird, is that yesterday after running ComboFix, the issue was still there. I will do your proposal.
18:36:02.0062 4000 TDSS rootkit removing tool [removed] Jul 16 2012 22:10:11 18:36:04.0062 4000 ============================================================ 18:36:04.0062 4000 Current date / time: 2012/07/20 18:36:04.0062 18:36:04.0062 4000 SystemInfo: 18:36:04.0062 4000 18:36:04.0062 4000 OS Version: 5.1.2600 ServicePack: 2.0 18:36:04.0062 4000 Product type: Workstation 18:36:04.0062 4000 ComputerName: FSC 18:36:04.0062 4000 UserName: too 18:36:04.0062 4000 Windows directory: C:\WINDOWS 18:36:04.0062 4000 System windows directory: C:\WINDOWS 18:36:04.0062 4000 Processor architecture: Intel x86 18:36:04.0062 4000 Number of processors: 2 18:36:04.0062 4000 Page size: 0x1000 18:36:04.0062 4000 Boot type: Normal boot 18:36:04.0062 4000 ============================================================ 18:36:08.0109 4000 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 18:36:08.0125 4000 ============================================================ 18:36:08.0125 4000 \Device\Harddisk0\DR0: 18:36:08.0125 4000 MBR partitions: 18:36:08.0125 4000 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A18A82 18:36:08.0125 4000 ============================================================ 18:36:08.0406 4000 C: <-> \Device\Harddisk0\DR0\Partition0 18:36:08.0437 4000 ============================================================ 18:36:08.0437 4000 Initialize success 18:36:08.0437 4000 ============================================================ 18:36:19.0875 2892 ============================================================ 18:36:19.0875 2892 Scan started 18:36:19.0875 2892 Mode: Manual; 18:36:19.0875 2892 ============================================================ 18:36:23.0031 2892 Aavmker4 (1ebbd84e856f54eb16d46df9648e872a) C:\WINDOWS\system32\drivers\Aavmker4.sys 18:36:23.0046 2892 Aavmker4 - ok 18:36:23.0046 2892 Abiosdsk - ok 18:36:23.0062 2892 abp480n5 - ok 18:36:23.0218 2892 ACPI (0bd94fbfc14ea3606cd6ca4c0255baa3) C:\WINDOWS\system32\DRIVERS\ACPI.sys 18:36:23.0218 2892 ACPI - ok 18:36:23.0296 2892 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\drivers\ACPIEC.sys 18:36:23.0375 2892 ACPIEC - ok 18:36:23.0875 2892 AcrSch2Svc (3e085118bdde603452dc165107dc8fa4) C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe 18:36:23.0906 2892 AcrSch2Svc - ok 18:36:24.0078 2892 ADILOADER (2b3b8c0a2c979dd77ba6dc9376074854) C:\WINDOWS\system32\Drivers\adildr.sys 18:36:24.0078 2892 ADILOADER - ok 18:36:24.0296 2892 adiusbaw (6f20677e1c73a265c37c8794ce499d36) C:\WINDOWS\system32\DRIVERS\adiusbaw.sys 18:36:24.0343 2892 adiusbaw - ok 18:36:24.0343 2892 adpu160m - ok 18:36:24.0421 2892 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys 18:36:24.0421 2892 aec - ok 18:36:24.0515 2892 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys 18:36:24.0531 2892 AFD - ok 18:36:24.0531 2892 Aha154x - ok 18:36:24.0546 2892 aic78u2 - ok 18:36:24.0546 2892 aic78xx - ok 18:36:24.0703 2892 Alerter (d1b6794bc9c2fca07378cc2d7afee189) C:\WINDOWS\system32\alrsvc.dll 18:36:24.0718 2892 Alerter - ok 18:36:24.0781 2892 ALG (2fe681d10c5fc343dbbc0610b8dd4d24) C:\WINDOWS\System32\alg.exe 18:36:24.0781 2892 ALG - ok 18:36:24.0796 2892 AliIde - ok 18:36:24.0796 2892 amsint - ok 18:36:24.0875 2892 AppMgmt (ce66077813d83c2d6908cdc64ae7e55a) C:\WINDOWS\System32\appmgmts.dll 18:36:24.0875 2892 AppMgmt - ok 18:36:24.0890 2892 asc - ok 18:36:24.0890 2892 asc3350p - ok 18:36:24.0890 2892 asc3550 - ok 18:36:25.0390 2892 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 18:36:25.0875 2892 aspnet_state - ok 18:36:25.0937 2892 aswFsBlk (062287cee536e8af6680d33259de6bd6) C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys 18:36:26.0593 2892 aswFsBlk - ok 18:36:26.0765 2892 aswMon2 (05960396794e51ebbb9507c86b8b009e) C:\WINDOWS\system32\drivers\aswMon2.sys 18:36:26.0812 2892 aswMon2 - ok 18:36:27.0093 2892 aswRdr (06b360d8179959798d2bf054437df923) C:\WINDOWS\system32\drivers\aswRdr.sys 18:36:27.0125 2892 aswRdr - ok 18:36:27.0593 2892 aswSP (045ed8ef540e69a41e9c0e255fbaf0c0) C:\WINDOWS\system32\drivers\aswSP.sys 18:36:27.0593 2892 aswSP - ok 18:36:27.0750 2892 aswTdi (2410f10faa00f222b3a29308741598d6) C:\WINDOWS\system32\drivers\aswTdi.sys 18:36:27.0781 2892 aswTdi - ok 18:36:27.0953 2892 aswUpdSv (5e692b54ec3d9c586417f9c5822cbec9) C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 18:36:27.0984 2892 aswUpdSv - ok 18:36:28.0125 2892 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 18:36:28.0281 2892 AsyncMac - ok 18:36:28.0593 2892 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 18:36:28.0593 2892 atapi - ok 18:36:28.0593 2892 Atdisk - ok 18:36:29.0671 2892 ATE_PROCMON (8492eaadb882c0f0b38a40dee1206445) C:\Program Files\Anti Trojan Elite\ATEPMon.sys 18:36:29.0671 2892 ATE_PROCMON - ok 18:36:29.0968 2892 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 18:36:30.0156 2892 Atmarpc - ok 18:36:30.0250 2892 AudioSrv (32957b7b46cbe2066c47febc7e56050e) C:\WINDOWS\System32\audiosrv.dll 18:36:30.0250 2892 AudioSrv - ok 18:36:30.0359 2892 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 18:36:30.0390 2892 audstub - ok 18:36:30.0593 2892 Automatic LiveUpdate Scheduler (2843669c89a00950195f51dbb5db0b8e) C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe 18:36:30.0734 2892 Automatic LiveUpdate Scheduler - ok 18:36:30.0921 2892 avast! Antivirus (72c4bb55413d2d621bcc1dbf4074eb5d) C:\Program Files\Alwil Software\Avast4\ashServ.exe 18:36:30.0921 2892 avast! Antivirus - ok 18:36:30.0937 2892 avast! Mail Scanner (aef50b1cea979739ede53c68556b95e5) C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 18:36:30.0953 2892 avast! Mail Scanner - ok 18:36:31.0078 2892 avast! Web Scanner (a62a0418be5a5b8b0ecf3d8f73325113) C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 18:36:31.0078 2892 avast! Web Scanner - ok 18:36:31.0656 2892 b57w2k (66dd574749c38153c6067ebba929befc) C:\WINDOWS\system32\DRIVERS\b57xp32.sys 18:36:31.0703 2892 b57w2k - ok 18:36:31.0843 2892 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 18:36:31.0843 2892 Beep - ok 18:36:31.0906 2892 BITS (87424817f82cf6a7f55dac01a20111a3) C:\WINDOWS\system32\qmgr.dll 18:36:32.0000 2892 BITS - ok 18:36:32.0078 2892 Browser (ce9dc7cc6d75515ee62ca341473ec5f3) C:\WINDOWS\System32\browser.dll 18:36:32.0078 2892 Browser - ok 18:36:32.0078 2892 catchme - ok 18:36:32.0140 2892 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 18:36:32.0140 2892 cbidf2k - ok 18:36:32.0171 2892 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 18:36:32.0171 2892 CCDECODE - ok 18:36:32.0328 2892 ccEvtMgr (2f237aab91497aaa03af48eae68758fc) C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe 18:36:32.0328 2892 ccEvtMgr - ok 18:36:32.0328 2892 ccSetMgr (2f237aab91497aaa03af48eae68758fc) C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe 18:36:32.0328 2892 ccSetMgr - ok 18:36:32.0328 2892 cd20xrnt - ok 18:36:32.0328 2892 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 18:36:32.0343 2892 Cdaudio - ok 18:36:32.0406 2892 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 18:36:32.0406 2892 Cdfs - ok 18:36:32.0406 2892 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 18:36:32.0421 2892 Cdrom - ok 18:36:32.0421 2892 Changer - ok 18:36:32.0437 2892 CiSvc (d24f6382f5171b07705364812e9459e2) C:\WINDOWS\system32\cisvc.exe 18:36:32.0437 2892 CiSvc - ok 18:36:32.0453 2892 ClipSrv (711db3a49efde3e2640cdb782d478628) C:\WINDOWS\system32\clipsrv.exe 18:36:32.0453 2892 ClipSrv - ok 18:36:32.0593 2892 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 18:36:32.0718 2892 clr_optimization_v2.0.50727_32 - ok 18:36:32.0718 2892 CLTNetCnService (2f237aab91497aaa03af48eae68758fc) C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe 18:36:32.0718 2892 CLTNetCnService - ok 18:36:32.0734 2892 CmdIde - ok 18:36:32.0781 2892 COH_Mon (6186b6b953bdc884f0f379b84b3e3a98) C:\WINDOWS\system32\Drivers\COH_Mon.sys 18:36:32.0921 2892 COH_Mon - ok 18:36:33.0406 2892 comHost (75a69ca9998577f8b2be8695040e5df4) C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe 18:36:33.0765 2892 comHost - ok 18:36:33.0781 2892 COMSysApp - ok 18:36:33.0953 2892 CO_Mon (73f5d6835bfa66019c03e316d99649da) C:\WINDOWS\system32\drivers\CO_Mon.sys 18:36:33.0984 2892 CO_Mon - ok 18:36:33.0984 2892 Cpqarray - ok 18:36:34.0125 2892 CryptSvc (bddf3723d95dc28d78b1e93119e0e6ab) C:\WINDOWS\System32\cryptsvc.dll 18:36:34.0125 2892 CryptSvc - ok 18:36:34.0140 2892 dac2w2k - ok 18:36:34.0140 2892 dac960nt - ok 18:36:34.0203 2892 DcomLaunch (5620353b93dd08016674e4fee280190b) C:\WINDOWS\system32\rpcss.dll 18:36:34.0218 2892 DcomLaunch - ok 18:36:34.0312 2892 Dhcp (b9d04e1839d82a2f512c180177773eec) C:\WINDOWS\System32\dhcpcsvc.dll 18:36:34.0312 2892 Dhcp - ok 18:36:34.0328 2892 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 18:36:34.0328 2892 Disk - ok 18:36:34.0328 2892 dmadmin - ok 18:36:34.0484 2892 dmboot (e2d3b7620310fe56685f9b15a6b404b3) C:\WINDOWS\system32\drivers\dmboot.sys 18:36:34.0656 2892 dmboot - ok 18:36:34.0656 2892 dmio (c77f5c20aa70197a69aa84baa9de43c8) C:\WINDOWS\system32\drivers\dmio.sys 18:36:34.0656 2892 dmio - ok 18:36:34.0703 2892 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 18:36:34.0718 2892 dmload - ok 18:36:34.0796 2892 dmserver (316c1bab74ca10613ab2da46a2ef3e47) C:\WINDOWS\System32\dmserver.dll 18:36:34.0796 2892 dmserver - ok 18:36:34.0906 2892 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 18:36:34.0906 2892 DMusic - ok 18:36:34.0921 2892 Dnscache (8d4d8d797cde07a7ec53c8992bf3e95f) C:\WINDOWS\System32\dnsrslvr.dll 18:36:34.0921 2892 Dnscache - ok 18:36:34.0921 2892 dpti2o - ok 18:36:34.0937 2892 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 18:36:34.0937 2892 drmkaud - ok 18:36:35.0000 2892 EagleXNt (a8c4b2ae80afe54ec01d4591dbc1c396) C:\WINDOWS\system32\drivers\EagleXNt.sys 18:36:35.0265 2892 EagleXNt - ok 18:36:35.0609 2892 eeCtrl (47ce4e650d91dc095a2fddb15631a78a) C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\eeCtrl.sys 18:36:35.0625 2892 eeCtrl - ok 18:36:35.0687 2892 EraserUtilRebootDrv (ce3ef5c79cb0bfa036e844f74c52d759) C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 18:36:35.0687 2892 EraserUtilRebootDrv - ok 18:36:35.0750 2892 ERSvc (be3ce05230890e1baf8f0dd09d7a00fe) C:\WINDOWS\System32\ersvc.dll 18:36:35.0750 2892 ERSvc - ok 18:36:35.0812 2892 Eventlog (9d6bf82fe50d55f20f8e10e0f6653886) C:\WINDOWS\system32\services.exe 18:36:35.0828 2892 Eventlog - ok 18:36:35.0937 2892 EventSystem (a5b1b7c76134329aa7547f6e6da35410) C:\WINDOWS\system32\es.dll 18:36:35.0953 2892 EventSystem - ok 18:36:35.0968 2892 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 18:36:35.0984 2892 Fastfat - ok 18:36:36.0062 2892 FastUserSwitchingCompatibility (b590e69a45ae8fcbf7ddade89cce3588) C:\WINDOWS\System32\shsvcs.dll 18:36:36.0062 2892 FastUserSwitchingCompatibility - ok 18:36:36.0078 2892 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys 18:36:36.0078 2892 Fdc - ok 18:36:36.0140 2892 Fips (8b121ff880683607ab2aef0340721718) C:\WINDOWS\system32\drivers\Fips.sys 18:36:36.0140 2892 Fips - ok 18:36:36.0156 2892 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys 18:36:36.0156 2892 Flpydisk - ok 18:36:36.0218 2892 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 18:36:36.0218 2892 FltMgr - ok 18:36:36.0406 2892 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 18:36:36.0515 2892 FontCache3.0.0.0 - ok 18:36:36.0578 2892 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 18:36:36.0593 2892 Fs_Rec - ok 18:36:36.0625 2892 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 18:36:36.0625 2892 Ftdisk - ok 18:36:36.0625 2892 GGSAFERDriver - ok 18:36:36.0781 2892 GoogleDesktopManager-051210-111108 (9f5f2f0fb0a7f5aa9f16b9a7b6dad89f) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 18:36:36.0781 2892 GoogleDesktopManager-051210-111108 - ok 18:36:36.0843 2892 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 18:36:36.0843 2892 Gpc - ok 18:36:36.0906 2892 gupdate (626a24ed1228580b9518c01930936df9) C:\Program Files\Google\Update\GoogleUpdate.exe 18:36:36.0921 2892 gupdate - ok 18:36:36.0921 2892 gupdatem (626a24ed1228580b9518c01930936df9) C:\Program Files\Google\Update\GoogleUpdate.exe 18:36:36.0921 2892 gupdatem - ok 18:36:37.0000 2892 gusvc (408ddd80eede47175f6844817b90213e) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 18:36:37.0015 2892 gusvc - ok 18:36:37.0109 2892 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 18:36:37.0125 2892 HDAudBus - ok 18:36:37.0234 2892 helpsvc (f8881957e5fd648f35998f518af0b0af) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 18:36:37.0234 2892 helpsvc - ok 18:36:37.0296 2892 HidServ (007b1da566d0ae7b8169fde4dc618b70) C:\WINDOWS\System32\hidserv.dll 18:36:37.0296 2892 HidServ - ok 18:36:37.0359 2892 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 18:36:37.0359 2892 hidusb - ok 18:36:37.0359 2892 hpn - ok 18:36:37.0437 2892 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys 18:36:37.0453 2892 HTTP - ok 18:36:37.0484 2892 HTTPFilter (6effd66fdbaa3fd3908b9388755bf435) C:\WINDOWS\System32\w3ssl.dll 18:36:37.0531 2892 HTTPFilter - ok 18:36:37.0531 2892 i2omgmt - ok 18:36:37.0531 2892 i2omp - ok 18:36:37.0609 2892 i8042prt (d1efcbd693b5ba21314d06368c471070) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 18:36:37.0609 2892 i8042prt - ok 18:36:37.0937 2892 ialm (cd32607f1cc8ac67224334ae123f7b98) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 18:36:38.0187 2892 ialm - ok 18:36:38.0640 2892 idsvc (c01ac32dc5c03076cfb852cb5da5229c) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 18:36:38.0875 2892 idsvc - ok 18:36:39.0078 2892 IFXTPM (667cfdb801df771f47b7c39373c2d850) C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS 18:36:39.0078 2892 IFXTPM - ok 18:36:39.0156 2892 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 18:36:39.0156 2892 Imapi - ok 18:36:39.0171 2892 ImapiService (40432437bba5cd10b76a2d3b3cd5ad2d) C:\WINDOWS\system32\imapi.exe 18:36:39.0187 2892 ImapiService - ok 18:36:39.0187 2892 ini910u - ok 18:36:39.0375 2892 IntcAzAudAddService (915ce2a58c6917e3c53be1e91fa66ba8) C:\WINDOWS\system32\drivers\RtkHDAud.sys 18:36:39.0500 2892 IntcAzAudAddService - ok 18:36:39.0656 2892 IntelIde - ok 18:36:39.0687 2892 intelppm (dd5ad1e79ac26d3f8d8828ad4627f160) C:\WINDOWS\system32\DRIVERS\intelppm.sys 18:36:39.0687 2892 intelppm - ok 18:36:39.0718 2892 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 18:36:39.0750 2892 Ip6Fw - ok 18:36:40.0062 2892 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 18:36:40.0078 2892 IpFilterDriver - ok 18:36:40.0093 2892 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 18:36:40.0140 2892 IpInIp - ok 18:36:40.0171 2892 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys 18:36:40.0171 2892 IpNat - ok 18:36:40.0187 2892 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 18:36:40.0187 2892 IPSec - ok 18:36:40.0265 2892 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 18:36:40.0281 2892 IRENUM - ok 18:36:40.0359 2892 isapnp (54632f1a7de61dc3615d756f2a90fa72) C:\WINDOWS\system32\DRIVERS\isapnp.sys 18:36:40.0359 2892 isapnp - ok 18:36:40.0593 2892 JavaQuickStarterService (5e06a9d23727daf96faa796f1135fdcd) C:\Program Files\Java\jre6\bin\jqs.exe 18:36:40.0593 2892 JavaQuickStarterService - ok 18:36:40.0656 2892 Kbdclass (e798705e8dc7fab596ef6bfdf167e007) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 18:36:40.0656 2892 Kbdclass - ok 18:36:40.0671 2892 kbdhid (62dd5eefcec4ef4163f1168d4262a9e4) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 18:36:40.0671 2892 kbdhid - ok 18:36:40.0734 2892 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys 18:36:40.0750 2892 kmixer - ok 18:36:40.0812 2892 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys 18:36:40.0812 2892 KSecDD - ok 18:36:40.0875 2892 lanmanserver (3d95fb97cd22b7dd44f660b0ebfba4b9) C:\WINDOWS\System32\srvsvc.dll 18:36:40.0890 2892 lanmanserver - ok 18:36:40.0953 2892 lanmanworkstation (1a1a7ace3190224c82f70561fc7a4774) C:\WINDOWS\System32\wkssvc.dll 18:36:40.0953 2892 lanmanworkstation - ok 18:36:40.0953 2892 lbrtfdc - ok 18:36:41.0203 2892 LiveUpdate (36375738dc0b3cd1f764268008e74fdf) C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE 18:36:41.0312 2892 LiveUpdate - ok 18:36:41.0546 2892 LiveUpdate Notice (2f237aab91497aaa03af48eae68758fc) C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe 18:36:41.0546 2892 LiveUpdate Notice - ok 18:36:41.0750 2892 lmab_device - ok 18:36:41.0968 2892 LmHosts (fe6c55d366d48f04df9318605d6ed5a7) C:\WINDOWS\System32\lmhsvc.dll 18:36:41.0968 2892 LmHosts - ok 18:36:42.0046 2892 MDM (11f714f85530a2bd134074dc30e99fca) C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE 18:36:42.0062 2892 MDM - ok 18:36:42.0140 2892 Messenger (97939358ed4487cbb4a0d743ce958266) C:\WINDOWS\System32\msgsvc.dll 18:36:42.0156 2892 Messenger - ok 18:36:42.0234 2892 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 18:36:42.0234 2892 mnmdd - ok 18:36:42.0312 2892 mnmsrvc (75b66eb2a2fb8db29c838f1800cede90) C:\WINDOWS\system32\mnmsrvc.exe 18:36:42.0312 2892 mnmsrvc - ok 18:36:42.0328 2892 Modem (5ac7e16f5b40a6da14b5f2b3ada4693e) C:\WINDOWS\system32\drivers\Modem.sys 18:36:42.0375 2892 Modem - ok 18:36:42.0421 2892 Mouclass (7d4f19411bd941e1d432a99e24230386) C:\WINDOWS\system32\DRIVERS\mouclass.sys 18:36:42.0421 2892 Mouclass - ok 18:36:42.0453 2892 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys 18:36:42.0453 2892 mouhid - ok 18:36:42.0500 2892 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 18:36:42.0500 2892 MountMgr - ok 18:36:42.0500 2892 mraid35x - ok 18:36:42.0515 2892 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 18:36:42.0515 2892 MRxDAV - ok 18:36:42.0593 2892 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 18:36:42.0593 2892 MRxSmb - ok 18:36:42.0671 2892 MSDTC (680639b08040cec24b8bd873b1f02f51) C:\WINDOWS\system32\msdtc.exe 18:36:42.0671 2892 MSDTC - ok 18:36:42.0734 2892 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 18:36:42.0750 2892 Msfs - ok 18:36:42.0750 2892 MSIServer - ok 18:36:42.0828 2892 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 18:36:42.0875 2892 MSKSSRV - ok 18:36:42.0921 2892 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 18:36:42.0921 2892 MSPCLOCK - ok 18:36:42.0921 2892 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 18:36:42.0937 2892 MSPQM - ok 18:36:42.0953 2892 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 18:36:42.0953 2892 mssmbios - ok 18:36:42.0984 2892 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys 18:36:43.0000 2892 MSTEE - ok 18:36:43.0015 2892 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 18:36:43.0031 2892 Mup - ok 18:36:43.0093 2892 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 18:36:43.0109 2892 NABTSFEC - ok 18:36:43.0500 2892 NAVENG (d8f9e712479f2f8dc8c3524a62365f95) C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20080917.039\NAVENG.SYS 18:36:43.0500 2892 NAVENG - ok 18:36:43.0546 2892 NAVEX15 (0b127bbe41300dede016e86e47329cdd) C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20080917.039\NAVEX15.SYS 18:36:43.0562 2892 NAVEX15 - ok 18:36:43.0640 2892 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 18:36:43.0640 2892 NDIS - ok 18:36:43.0703 2892 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 18:36:43.0750 2892 NdisIP - ok 18:36:43.0812 2892 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 18:36:43.0812 2892 NdisTapi - ok 18:36:43.0812 2892 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 18:36:43.0812 2892 Ndisuio - ok 18:36:43.0812 2892 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 18:36:43.0812 2892 NdisWan - ok 18:36:43.0828 2892 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 18:36:43.0828 2892 NDProxy - ok 18:36:43.0828 2892 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 18:36:43.0843 2892 NetBIOS - ok 18:36:43.0843 2892 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 18:36:43.0859 2892 NetBT - ok 18:36:43.0875 2892 NetDDE (9ce77f7a22c27366da628ed4ba7d4ff9) C:\WINDOWS\system32\netdde.exe 18:36:43.0875 2892 NetDDE - ok 18:36:43.0890 2892 NetDDEdsdm (9ce77f7a22c27366da628ed4ba7d4ff9) C:\WINDOWS\system32\netdde.exe 18:36:43.0890 2892 NetDDEdsdm - ok 18:36:43.0906 2892 Netlogon (9f3744a5c6f49291a7a685040a013399) C:\WINDOWS\system32\lsass.exe 18:36:43.0906 2892 Netlogon - ok 18:36:43.0921 2892 Netman (624cf700bbfd8be4097aaa146e6bd363) C:\WINDOWS\System32\netman.dll 18:36:43.0937 2892 Netman - ok 18:36:44.0109 2892 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 18:36:44.0156 2892 NetTcpPortSharing - ok 18:36:44.0234 2892 Nla (8a52de10680a40ecd04fa2c0fbc34190) C:\WINDOWS\System32\mswsock.dll 18:36:44.0250 2892 Nla - ok 18:36:44.0296 2892 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 18:36:44.0296 2892 Npfs - ok 18:36:44.0312 2892 npggsvc - ok 18:36:44.0437 2892 NPPTNT2 (9131fe60adfab595c8da53ad6a06aa31) C:\WINDOWS\system32\npptNT2.sys 18:36:44.0437 2892 NPPTNT2 - ok 18:36:44.0484 2892 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys 18:36:44.0578 2892 Ntfs - ok 18:36:44.0578 2892 NtLmSsp (9f3744a5c6f49291a7a685040a013399) C:\WINDOWS\system32\lsass.exe 18:36:44.0578 2892 NtLmSsp - ok 18:36:44.0625 2892 NtmsSvc (3f82a4226289510df300813b9b87f0e5) C:\WINDOWS\system32\ntmssvc.dll 18:36:44.0640 2892 NtmsSvc - ok 18:36:44.0703 2892 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 18:36:44.0703 2892 Null - ok 18:36:44.0718 2892 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 18:36:44.0718 2892 NwlnkFlt - ok 18:36:44.0734 2892 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 18:36:44.0765 2892 NwlnkFwd - ok 18:36:45.0031 2892 ose (7a56cf3e3f12e8af599963b16f50fb6a) C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE 18:36:45.0078 2892 ose - ok 18:36:45.0125 2892 Parport (318696359ac7df48d1e51974ec527dd2) C:\WINDOWS\system32\DRIVERS\parport.sys 18:36:45.0125 2892 Parport - ok 18:36:45.0187 2892 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 18:36:45.0187 2892 PartMgr - ok 18:36:45.0203 2892 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys 18:36:45.0203 2892 ParVdm - ok 18:36:45.0328 2892 PCI (7c5da5c1ed801ad8b0309d5514f0b75e) C:\WINDOWS\system32\DRIVERS\pci.sys 18:36:45.0343 2892 PCI - ok 18:36:45.0343 2892 PCIDump - ok 18:36:45.0343 2892 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\DRIVERS\pciide.sys 18:36:45.0343 2892 PCIIde - ok 18:36:45.0359 2892 Pcmcia (641da274e163617ea7a33506bc6da8e3) C:\WINDOWS\system32\drivers\Pcmcia.sys 18:36:45.0390 2892 Pcmcia - ok 18:36:45.0531 2892 PCToolsSSDMonitorSvc (0aea7303e97c02dad9245ebdfbd4d253) C:\Program Files\Fichiers communs\PC Tools\sMonitor\StartManSvc.exe 18:36:45.0562 2892 PCToolsSSDMonitorSvc - ok 18:36:45.0562 2892 PDCOMP - ok 18:36:45.0562 2892 PDFRAME - ok 18:36:45.0562 2892 PDRELI - ok 18:36:45.0562 2892 PDRFRAME - ok 18:36:45.0578 2892 perc2 - ok 18:36:45.0578 2892 perc2hib - ok 18:36:45.0640 2892 PlugPlay (9d6bf82fe50d55f20f8e10e0f6653886) C:\WINDOWS\system32\services.exe 18:36:45.0640 2892 PlugPlay - ok 18:36:45.0687 2892 PnkBstrA (3a2bdd76e7d2a5f40a7174793d1ba794) C:\WINDOWS\system32\PnkBstrA.exe 18:36:45.0687 2892 PnkBstrA - ok 18:36:45.0750 2892 PnkBstrB (6973753aed84d72d0b32450458bc575f) C:\WINDOWS\system32\PnkBstrB.exe 18:36:45.0765 2892 PnkBstrB - ok 18:36:45.0875 2892 PnkBstrK (8a2a9fc051e3fd499050da41b95bc0a5) C:\WINDOWS\system32\drivers\PnkBstrK.sys 18:36:45.0906 2892 PnkBstrK - ok 18:36:46.0015 2892 PolicyAgent (9f3744a5c6f49291a7a685040a013399) C:\WINDOWS\system32\lsass.exe 18:36:46.0015 2892 PolicyAgent - ok 18:36:46.0078 2892 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 18:36:46.0078 2892 PptpMiniport - ok 18:36:46.0078 2892 ProtectedStorage (9f3744a5c6f49291a7a685040a013399) C:\WINDOWS\system32\lsass.exe 18:36:46.0078 2892 ProtectedStorage - ok 18:36:46.0093 2892 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 18:36:46.0093 2892 PSched - ok 18:36:46.0156 2892 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 18:36:46.0156 2892 Ptilink - ok 18:36:46.0218 2892 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys 18:36:46.0218 2892 PxHelp20 - ok 18:36:46.0234 2892 ql1080 - ok 18:36:46.0234 2892 Ql10wnt - ok 18:36:46.0234 2892 ql12160 - ok 18:36:46.0234 2892 ql1240 - ok 18:36:46.0234 2892 ql1280 - ok 18:36:46.0296 2892 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 18:36:46.0296 2892 RasAcd - ok 18:36:46.0312 2892 RasAuto (24ea2ad2f7c2ba4721e35010b97fb4e3) C:\WINDOWS\System32\rasauto.dll 18:36:46.0328 2892 RasAuto - ok 18:36:46.0343 2892 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 18:36:46.0343 2892 Rasl2tp - ok 18:36:46.0390 2892 RasMan (6cbcbbd8d6dadd5f6fb0994cd67a8679) C:\WINDOWS\System32\rasmans.dll 18:36:46.0406 2892 RasMan - ok 18:36:46.0406 2892 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 18:36:46.0406 2892 RasPppoe - ok 18:36:46.0421 2892 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 18:36:46.0421 2892 Raspti - ok 18:36:46.0437 2892 Rdbss (29d66245adba878fff574cd66abd2884) C:\WINDOWS\system32\DRIVERS\rdbss.sys 18:36:46.0453 2892 Rdbss - ok 18:36:46.0453 2892 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 18:36:46.0453 2892 RDPCDD - ok 18:36:46.0531 2892 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 18:36:46.0531 2892 rdpdr - ok 18:36:46.0625 2892 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys 18:36:46.0671 2892 RDPWD - ok 18:36:46.0750 2892 RDSessMgr (3126d9d63cdef5e3244ee2d97fbad59d) C:\WINDOWS\system32\sessmgr.exe 18:36:46.0765 2892 RDSessMgr - ok 18:36:46.0796 2892 redbook (2cc30b68dd62b73d444a41322cd7fc4c) C:\WINDOWS\system32\DRIVERS\redbook.sys 18:36:46.0796 2892 redbook - ok 18:36:46.0859 2892 RemoteAccess (6e2cbbd6956a605ef98ffd4843928fed) C:\WINDOWS\System32\mprdim.dll 18:36:46.0859 2892 RemoteAccess - ok 18:36:46.0921 2892 RemoteRegistry (345d02087f5696749c6120359b1e2988) C:\WINDOWS\system32\regsvc.dll 18:36:46.0921 2892 RemoteRegistry - ok 18:36:46.0984 2892 RpcLocator (57cf313eb5cb2c9a0b3ff67437becdfa) C:\WINDOWS\system32\locator.exe 18:36:47.0000 2892 RpcLocator - ok 18:36:47.0062 2892 RpcSs (5620353b93dd08016674e4fee280190b) C:\WINDOWS\System32\rpcss.dll 18:36:47.0078 2892 RpcSs - ok 18:36:47.0140 2892 RSVP (414964844f4793acb868d057e8ed997e) C:\WINDOWS\system32\rsvp.exe 18:36:47.0156 2892 RSVP - ok 18:36:47.0171 2892 SamSs (9f3744a5c6f49291a7a685040a013399) C:\WINDOWS\system32\lsass.exe 18:36:47.0171 2892 SamSs - ok 18:36:47.0203 2892 SCardSvr (781f04fbbe9e1abc0f4769809ccaefc3) C:\WINDOWS\System32\SCardSvr.exe 18:36:47.0203 2892 SCardSvr - ok 18:36:47.0281 2892 Schedule (4612ec6daf695b87a2529fcbb95b75de) C:\WINDOWS\system32\schedsvc.dll 18:36:47.0296 2892 Schedule - ok 18:36:47.0312 2892 SCREAMINGBDRIVER (a643d6df1b7546256b11fb5d6b5d1375) C:\WINDOWS\system32\drivers\ScreamingBAudio.sys 18:36:47.0328 2892 SCREAMINGBDRIVER - ok 18:36:47.0515 2892 SeaPort (271077b91d7ad1b616f8afdfe8e3f981) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 18:36:47.0531 2892 SeaPort - ok 18:36:47.0562 2892 Secdrv (07f7f501ad50de2ba2d5842d9b6d6155) C:\WINDOWS\system32\DRIVERS\secdrv.sys 18:36:47.0578 2892 Secdrv - ok 18:36:47.0609 2892 seclogon (775a33a1df28b4a98eeee5da2cdb12d9) C:\WINDOWS\System32\seclogon.dll 18:36:47.0609 2892 seclogon - ok 18:36:47.0609 2892 SENS (50f6f8e01ad2af261af86a3077b6fb6c) C:\WINDOWS\system32\sens.dll 18:36:47.0625 2892 SENS - ok 18:36:47.0625 2892 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys 18:36:47.0625 2892 serenum - ok 18:36:47.0640 2892 Serial (653201755ca96ab4aaa4131daf6da356) C:\WINDOWS\system32\DRIVERS\serial.sys 18:36:47.0640 2892 Serial - ok 18:36:47.0687 2892 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\DRIVERS\sfloppy.sys 18:36:47.0703 2892 Sfloppy - ok 18:36:47.0750 2892 SharedAccess (24a66112b3428c237b23efe70d2cf54d) C:\WINDOWS\System32\ipnathlp.dll 18:36:47.0765 2892 SharedAccess - ok 18:36:47.0781 2892 ShellHWDetection (b590e69a45ae8fcbf7ddade89cce3588) C:\WINDOWS\System32\shsvcs.dll 18:36:47.0781 2892 ShellHWDetection - ok 18:36:47.0796 2892 Simbad - ok 18:36:47.0859 2892 SkypeUpdate (68ea68d03bf58389fe6ad2b38fad798c) C:\Program Files\Skype\Updater\Updater.exe 18:36:47.0859 2892 SkypeUpdate - ok 18:36:47.0906 2892 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys 18:36:47.0937 2892 SLIP - ok 18:36:48.0140 2892 snapman (9bae383d3116a545758d45d0b994ba32) C:\WINDOWS\system32\DRIVERS\snapman.sys 18:36:48.0140 2892 snapman - ok 18:36:48.0578 2892 SNPSTD3 (11bb0e11d42cc3a43d741d9b30839be1) C:\WINDOWS\system32\DRIVERS\snpstd3.sys 18:36:48.0937 2892 SNPSTD3 - ok 18:36:49.0140 2892 Sparrow - ok 18:36:49.0453 2892 SPBBCDrv (dc4dc886d3779c446f9b0e9d6b006e72) C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCDrv.sys 18:36:49.0468 2892 SPBBCDrv - ok 18:36:49.0531 2892 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys 18:36:49.0531 2892 splitter - ok 18:36:49.0578 2892 Spooler (b4ef928e4fad79364a80acba6d999934) C:\WINDOWS\system32\spoolsv.exe 18:36:49.0578 2892 Spooler - ok 18:36:49.0656 2892 sptd (ab5c8f6e63674dbad9c1e449e8fd77ce) C:\WINDOWS\System32\Drivers\sptd.sys 18:36:49.0671 2892 sptd - ok 18:36:49.0734 2892 sr (b52181023b827acda36c1b76751ebffd) C:\WINDOWS\system32\DRIVERS\sr.sys 18:36:49.0734 2892 sr - ok 18:36:49.0781 2892 srservice (6469c53f4d16fa6055cca265bc03db66) C:\WINDOWS\system32\srsvc.dll 18:36:49.0781 2892 srservice - ok 18:36:49.0828 2892 SRTSP (e0e54a571d4323567e95e11fe76a5ff3) C:\WINDOWS\system32\Drivers\SRTSP.SYS 18:36:49.0828 2892 SRTSP - ok 18:36:49.0875 2892 SRTSPL (4e44f0e22df824d318988caa6f321c30) C:\WINDOWS\system32\Drivers\SRTSPL.SYS 18:36:49.0921 2892 SRTSPL - ok 18:36:49.0968 2892 SRTSPX (d3bb40427cf3d02e56bba97feda0a3aa) C:\WINDOWS\system32\Drivers\SRTSPX.SYS 18:36:49.0968 2892 SRTSPX - ok 18:36:50.0031 2892 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys 18:36:50.0046 2892 Srv - ok 18:36:50.0125 2892 SSDPSRV (b636478a2569ae69caf003254022a742) C:\WINDOWS\System32\ssdpsrv.dll 18:36:50.0125 2892 SSDPSRV - ok 18:36:50.0156 2892 stisvc (52b7ec594152429daba1261b2b68ca01) C:\WINDOWS\system32\wiaservc.dll 18:36:50.0156 2892 stisvc - ok 18:36:50.0218 2892 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 18:36:50.0296 2892 streamip - ok 18:36:50.0312 2892 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 18:36:50.0312 2892 swenum - ok 18:36:50.0375 2892 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 18:36:50.0375 2892 swmidi - ok 18:36:50.0390 2892 SwPrv - ok 18:36:51.0250 2892 Symantec Core LC (438fafe708c93b2236fc26b6f2bd5fd0) C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe 18:36:51.0406 2892 Symantec Core LC - ok 18:36:51.0421 2892 symc810 - ok 18:36:51.0421 2892 symc8xx - ok 18:36:51.0515 2892 SYMDNS (fe9f8b3a8bc22d85332b42e92308ddf9) C:\WINDOWS\System32\Drivers\SYMDNS.SYS 18:36:51.0515 2892 SYMDNS - ok 18:36:51.0609 2892 SymEvent (06b95820df51502099a8a15c93e87986) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 18:36:51.0609 2892 SymEvent - ok 18:36:51.0625 2892 SYMFW (a0ea9d273889e53cfaabf2444692ccbf) C:\WINDOWS\System32\Drivers\SYMFW.SYS 18:36:51.0625 2892 SYMFW - ok 18:36:51.0640 2892 SYMIDS (23527b9cd4f7b9e31160e98d340e7e85) C:\WINDOWS\System32\Drivers\SYMIDS.SYS 18:36:51.0640 2892 SYMIDS - ok 18:36:52.0218 2892 SYMIDSCO (c87748b4a7541b81c9564ed5b3cf8697) C:\PROGRA~1\FICHIE~1\SYMANT~1\SymcData\ipsdefs\20080916.005\SymIDSCo.sys 18:36:52.0234 2892 SYMIDSCO - ok 18:36:52.0296 2892 SymIM (b54f7959afb4aaf1a8c589b0aa7fde02) C:\WINDOWS\system32\DRIVERS\SymIM.sys 18:36:52.0296 2892 SymIM - ok 18:36:52.0296 2892 SymIMMP (b54f7959afb4aaf1a8c589b0aa7fde02) C:\WINDOWS\system32\DRIVERS\SymIM.sys 18:36:52.0296 2892 SymIMMP - ok 18:36:52.0296 2892 SYMNDIS (d605af3a380a83f4a562f1ad3ee19ecd) C:\WINDOWS\System32\Drivers\SYMNDIS.SYS 18:36:52.0312 2892 SYMNDIS - ok 18:36:52.0312 2892 SYMREDRV (7c6505ea598e58099d3b7e1f70426864) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS 18:36:52.0312 2892 SYMREDRV - ok 18:36:52.0328 2892 SYMTDI (e6ff7ace71d07ca90119f2c6ab592ba4) C:\WINDOWS\System32\Drivers\SYMTDI.SYS 18:36:52.0328 2892 SYMTDI - ok 18:36:52.0343 2892 sym_hi - ok 18:36:52.0343 2892 sym_u3 - ok 18:36:52.0406 2892 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 18:36:52.0406 2892 sysaudio - ok 18:36:52.0484 2892 SysmonLog (0151e81b0e42f55bccbb0136982e360f) C:\WINDOWS\system32\smlogsvc.exe 18:36:52.0484 2892 SysmonLog - ok 18:36:52.0562 2892 TapiSrv (2490cae37db8b6ec55e7a9415473d0ab) C:\WINDOWS\System32\tapisrv.dll 18:36:52.0578 2892 TapiSrv - ok 18:36:52.0640 2892 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys 18:36:52.0656 2892 Tcpip - ok 18:36:52.0703 2892 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 18:36:52.0718 2892 TDPIPE - ok 18:36:52.0734 2892 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 18:36:52.0765 2892 TDTCP - ok 18:36:52.0796 2892 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 18:36:52.0796 2892 TermDD - ok 18:36:52.0875 2892 TermService (7d521b8cf926459e270d18c559323815) C:\WINDOWS\System32\termsrv.dll 18:36:52.0968 2892 TermService - ok 18:36:53.0187 2892 TestHandler (0309c520ab9f1dbb4bf0f0a4d4df01bd) C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe 18:36:53.0203 2892 TestHandler - ok 18:36:53.0265 2892 Themes (b590e69a45ae8fcbf7ddade89cce3588) C:\WINDOWS\System32\shsvcs.dll 18:36:53.0265 2892 Themes - ok 18:36:53.0343 2892 tifsfilter (38e6ee805f15f829982dceec07a70b2d) C:\WINDOWS\system32\DRIVERS\tifsfilt.sys 18:36:53.0343 2892 tifsfilter - ok 18:36:53.0359 2892 timounter (727e235ab6dcc4dd4fe023366b7da2d3) C:\WINDOWS\system32\DRIVERS\timntr.sys 18:36:53.0375 2892 timounter - ok 18:36:53.0437 2892 TlntSvr (3fa7832ec7174f6fd4eff0f567d2ea08) C:\WINDOWS\system32\tlntsvr.exe 18:36:53.0437 2892 TlntSvr - ok 18:36:53.0453 2892 TosIde - ok 18:36:53.0484 2892 TrkWks (ad69cbd0be5073f52e92737579b79a67) C:\WINDOWS\system32\trkwks.dll 18:36:53.0484 2892 TrkWks - ok 18:36:53.0515 2892 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 18:36:53.0546 2892 Udfs - ok 18:36:53.0546 2892 ultra - ok 18:36:53.0609 2892 UMWdf (c81b8635dee0d3ef5f64b3dd643023a5) C:\WINDOWS\system32\wdfmgr.exe 18:36:53.0609 2892 UMWdf - ok 18:36:53.0687 2892 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys 18:36:53.0703 2892 Update - ok 18:36:53.0734 2892 upnphost (168ae9938f6be31d198af92496ccfa33) C:\WINDOWS\System32\upnphost.dll 18:36:53.0750 2892 upnphost - ok 18:36:53.0765 2892 UPS (55a7273aea6f3160fcfc4aa7394f5047) C:\WINDOWS\System32\ups.exe 18:36:53.0765 2892 UPS - ok 18:36:53.0812 2892 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 18:36:53.0812 2892 usbccgp - ok 18:36:53.0859 2892 usbehci (a45ea1550ea4b368c4fba7ca9d056bc9) C:\WINDOWS\system32\DRIVERS\usbehci.sys 18:36:53.0859 2892 usbehci - ok 18:36:53.0921 2892 UsbEvdomAtc (5f3828d574a8b9b2c57b6e671e13413a) C:\WINDOWS\system32\DRIVERS\lgevdomatc.sys 18:36:53.0921 2892 UsbEvdomAtc - ok 18:36:53.0984 2892 usbevdombus (c9137565302785f7889ad4b0a5004c3f) C:\WINDOWS\system32\DRIVERS\lgevdombus.sys 18:36:54.0000 2892 usbevdombus - ok 18:36:54.0031 2892 UsbEvdomDiag (f89d5655dc7650b9e0ce0de37462e71b) C:\WINDOWS\system32\DRIVERS\lgevdomdiag.sys 18:36:54.0031 2892 UsbEvdomDiag - ok 18:36:54.0062 2892 USBEVDOmModem (087c1a5a1f096c6bdaf1fc40da065c97) C:\WINDOWS\system32\DRIVERS\lgevdommodem.sys 18:36:54.0093 2892 USBEVDOmModem - ok 18:36:54.0125 2892 usbhub (6d46b1f89134892a862ac56b00ac11fe) C:\WINDOWS\system32\DRIVERS\usbhub.sys 18:36:54.0125 2892 usbhub - ok 18:36:54.0156 2892 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys 18:36:54.0171 2892 usbprint - ok 18:36:54.0265 2892 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 18:36:54.0265 2892 USBSTOR - ok 18:36:54.0296 2892 usbuhci (0ee1925590ba1abec14254d54d9870f4) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 18:36:54.0296 2892 usbuhci - ok 18:36:54.0375 2892 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 18:36:54.0375 2892 VgaSave - ok 18:36:54.0421 2892 vhidmini (7f62c4adfbc6e653d740a5e93b0dc446) C:\WINDOWS\system32\DRIVERS\vjoy.sys 18:36:54.0437 2892 vhidmini - ok 18:36:54.0437 2892 ViaIde - ok 18:36:54.0453 2892 VolSnap (313b1a0d5db26dfe1c34a6c13b2ce0a7) C:\WINDOWS\system32\drivers\VolSnap.sys 18:36:54.0453 2892 VolSnap - ok 18:36:54.0468 2892 vproiah - ok 18:36:54.0500 2892 VSS (0f5b203240184d34852936696df3e91d) C:\WINDOWS\System32\vssvc.exe 18:36:54.0515 2892 VSS - ok 18:36:54.0546 2892 W32Time (fb89c8b1d6a3c260a39669320c5d5827) C:\WINDOWS\system32\w32time.dll 18:36:54.0562 2892 W32Time - ok 18:36:54.0578 2892 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 18:36:54.0578 2892 Wanarp - ok 18:36:54.0578 2892 WDICA - ok 18:36:54.0640 2892 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys 18:36:54.0656 2892 wdmaud - ok 18:36:54.0656 2892 WebClient (553186171b5b1b8e11bb4733a012546c) C:\WINDOWS\System32\webclnt.dll 18:36:54.0671 2892 WebClient - ok 18:36:54.0796 2892 winmgmt (06156f20b90c6866d724d9ee6792044d) C:\WINDOWS\system32\wbem\WMIsvc.dll 18:36:54.0812 2892 winmgmt - ok 18:36:54.0843 2892 WmdmPmSN (a477391b7a8b0a0daabadb17cf533a4b) C:\WINDOWS\system32\MsPMSNSv.dll 18:36:54.0859 2892 WmdmPmSN - ok 18:36:54.0921 2892 Wmi (ffc53381078f5d442cbb7f4633b47c2e) C:\WINDOWS\System32\advapi32.dll 18:36:54.0953 2892 Wmi - ok 18:36:54.0968 2892 WmiApSrv (77945ea0bfdd662203f07fe5513a409d) C:\WINDOWS\system32\wbem\wmiapsrv.exe 18:36:54.0968 2892 WmiApSrv - ok 18:36:55.0187 2892 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 18:36:55.0187 2892 WS2IFSL - ok 18:36:55.0250 2892 wscsvc (f4827282722d8edbe542e2a1ce1678ee) C:\WINDOWS\system32\wscsvc.dll 18:36:55.0250 2892 wscsvc - ok 18:36:55.0281 2892 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 18:36:55.0296 2892 WSTCODEC - ok 18:36:55.0328 2892 wuauserv (57fe69b6648e73559552779820fa0827) C:\WINDOWS\system32\wuauserv.dll 18:36:55.0328 2892 wuauserv - ok 18:36:55.0359 2892 WZCSVC (17647874e46121728a043bbd8e0e4081) C:\WINDOWS\System32\wzcsvc.dll 18:36:55.0359 2892 WZCSVC - ok 18:36:55.0359 2892 XDva389 - ok 18:36:55.0500 2892 XDva397 (9abe812c097f8be2db006805492f2f07) C:\WINDOWS\system32\XDva397.sys 18:36:55.0500 2892 XDva397 - ok 18:36:55.0546 2892 xmlprov (21056aef44322c3e2dd5391b6aefa75a) C:\WINDOWS\System32\xmlprov.dll 18:36:55.0546 2892 xmlprov - ok 18:36:55.0593 2892 MBR (0x1B8) (c99c3199cfaa4cbdcd91493f6d113a50) \Device\Harddisk0\DR0 18:36:55.0953 2892 \Device\Harddisk0\DR0 - ok 18:36:55.0968 2892 Boot (0x1200) (8f9de20a42b349b4841c63cf62949495) \Device\Harddisk0\DR0\Partition0 18:36:55.0968 2892 \Device\Harddisk0\DR0\Partition0 - ok 18:36:55.0968 2892 ============================================================ 18:36:55.0968 2892 Scan finished 18:36:55.0968 2892 ============================================================ 18:36:55.0968 3352 Detected object count: 0 18:36:55.0968 3352 Actual detected object count: 0
Hi Daniel,

We can fix that infected driver of yours by installing Windows XP Service Pack 3. The download link is here. It will bring your computer up to date and patch many vulnerabilities. Go ahead and download/install it. Let me know if you have any questions.
Hmm.. Something has happened, and I did a test.. With Anti trojan elite running, the error pops up. When I close it, the error is not there. Just out of curiousity, what does mean that driver is infected?
Hi Daniel,

Hmm.. Something has happened, and I did a test.. With Anti trojan elite running, the error pops up. When I close it, the error is not there.

I have no idea why that's happening as I have never used Anti Trojan Elite. I would suggest you uninstall it if it's giving you problems.

Just out of curiousity, what does mean that driver is infected?

This means a file that is important to the normal operation of your computer has been infected by malware and does not work properly. Installing the latest service pack should fix it.

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start.  The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button.  The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI