Virus that disables antivirus - Page 2

Solved
Previous
  • 1
  • 2
  1. lenormand49 Posted messages 115 Status Member 8
     
    It was pending

    Malwarebytes' Anti-Malware 1.43
    Database version: 3510
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    01/08/2010 17:57:23
    mbam-log-2010-01-08 (17-57-23).txt

    Scan type: Full scan (C:\|D:\|H:\|)
    Items scanned: 285903
    Time elapsed: 53 minute(s), 23 second(s)

    Infected memory process(es): 0
    Infected memory module(s): 0
    Infected Registry key(s): 0
    Infected Registry value(s): 2
    Infected Registry data item(s): 1
    Infected folder(s): 0
    Infected file(s): 1

    Infected memory process(es):
    (No malicious item detected)

    Infected memory module(s):
    (No malicious item detected)

    Infected Registry key(s):
    (No malicious item detected)

    Infected Registry value(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\upsms (Worm.P2P) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\rhcl90j0ejcr (Rogue.AntiVirusXP) -> Quarantined and deleted successfully.

    Infected Registry data item(s):
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Infected folder(s):
    (No malicious item detected)

    Infected file(s):
    C:\System Volume Information\_restore{3D64EAA2-C25B-4ABD-AA55-F123DEE84BD0}\RP1\A0000082.sys (Malware.Trace) -> Quarantined and deleted successfully.
    0
  2. lenormand49 Posted messages 115 Status Member 8
     
    The PC starts up fine in safe mode
    the antivirus still doesn’t work (in any mode)
    spybot seems to be working normally (updates + control + vaccination + re-control OK)

    that's it for now
    0
  3. Anonymous user
     
    Have you run Ccleaner?

    If so,
    restart your PC in normal mode
    run another scan and post the report

    Thank you.
    0
  4. lenormand49 Posted messages 115 Status Member 8
     
    When I did my tests, CCleaner had finished, I restarted the computer in normal mode and then without failures, in both cases I got error messages at the startup of the antivirus and the security settings are disabled, impossible to reactivate them.

    Here is the RSIT report

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by Admin at 2010-01-08 19:02:44
    Microsoft Windows XP Professional Service Pack 3
    System drive C: has 25 GB (25%) free of 100 GB
    Total RAM: 2046 MB (73% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:03:00, on 08/01/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Commander Pro\UPServ.exe
    C:\Program Files\Commander Pro\UPS.EXE
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\rmctrl.exe
    C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb03.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam\Quickcam.exe
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\NCLAUNCH.EXe
    C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Hercules\WiFi Station for Livebox\WifiStationLB.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\HAMA Joystick Outlandish\GM_DevUpdate.exe
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Documents and Settings\Admin.XPSP2-0ECD3B1B5\Desktop\RSIT.exe
    C:\Program Files\trend micro\Admin.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
    O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
    O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb03.exe
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
    O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
    O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    O4 - HKLM\..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
    O4 - Startup: GM_DevUpdate.lnk = C:\Program Files\HAMA Joystick Outlandish\GM_DevUpdate.exe
    O4 - Global Startup: WiFi Station pour Livebox.lnk = ?
    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O8 - Extra context menu item: E&xporter to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    O23 - Service: UPSmanager - Macrovision - C:\PROGRA~1\COMMAN~1\manager.exe
    O23 - Service: UPSmart - Unknown owner - C:\Program Files\Commander Pro\UPServ.exe
    O23 - Service: UPSmonitor - Macrovision - C:\PROGRA~1\COMMAN~1\monitor.exe
    O23 - Service: UPSRMI - Macrovision - C:\PROGRA~1\COMMAN~1\wpRMI.exe

    --
    End of file - 10213 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
    Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "UpdateManager"=C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe [2003-08-19 110592]
    "Synchronization Manager"=C:\WINDOWS\system32\mobsync.exe [2008-04-14 143872]
    "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-05-05 14396416]
    "RemoteControl"=C:\WINDOWS\system32\rmctrl.exe [2000-10-16 32768]
    "pccguide.exe"=C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe [2010-01-07 823361]
    "Omnipage"=C:\Program Files\ScanSoft\OmniPageSE\opware32.exe [2002-06-03 49152]
    "NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
    "HPDJ Taskbar Utility"=C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb03.exe [2001-06-19 200704]
    "High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
    "BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
    "LogitechCommunicationsManager"=C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2007-07-25 563984]
    "LogitechQuickCamRibbon"=C:\Program Files\Logitech\QuickCam\Quickcam.exe [2007-07-25 2027792]
    "EM_EXEC"=C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE [2001-10-04 35328]
    "Logitech Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2004-09-15 37888]
    "AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-08-13 177440]
    "ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2007-10-11 31232]
    "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-06-10 13758464]
    "nwiz"=nwiz.exe /install []
    "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-06-10 86016]
    "CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2008-03-10 689488]
    "CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2008-03-17 1848648]
    "IJNetworkScanUtility"=C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE [2007-11-19 128352]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
    "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
    "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
    "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
    "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "NCLaunch"=C:\WINDOWS\NCLAUNCH.EXe [2007-03-19 40960]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [2005-09-03 94208]
    "Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe [2004-04-14 45056]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link AirPlus G]
    C:\Program Files\D-Link\AirPlus G\AirGCFG.exe [2004-07-09 1249280]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]

    C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage
    WiFi Station pour Livebox.lnk - C:\Program Files\Hercules\WiFi Station pour Livebox\WifiStationLB.exe
    Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe

    C:\Documents and Settings\Admin.XPSP2-0ECD3B1B5\Menu Démarrer\Programmes\Démarrage
    GM_DevUpdate.lnk - C:\Program Files\HAMA Joystick Outlandish\GM_DevUpdate.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\WINDOWS\system32\WgaLogon.dll [2008-10-18 200064]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 240128]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=323
    "MemCheckBoxInRunDlg"=1
    "NoSMBalloonTip"=1
    "NoDesktopCleanupWizard"=1
    "NoWelcomeScreen"=1
    "NoAutoUpdate"=1
    "NoBandCustomize"=1
    "NoDriveAutoRun"=67108863
    "HonorAutoRunSetting"=0
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "HonorAutoRunSetting"=
    "NoDriveAutoRun"=
    "NoDriveTypeAutoRun"=
    "NoDrives"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\Westwood\SUN\GAME.ICD"="C:\Program Files\Westwood\SUN\GAME.ICD:*:Enabled:Main executable for Tiberian Sun"
    "C:\Program Files\Westwood\SUN\Game.exe"="C:\Program Files\Westwood\SUN\Game.exe:*:Enabled:Main executable for Tiberian Sun"
    "C:\Program Files\EA Games\Command and Conquer Generals\patchget.dat"="C:\Program Files\EA Games\Command and Conquer Generals\patchget.dat:*:Enabled:patchgrabber"
    "C:\Program Files\ScanSoft\OmniPageSE\EregFre\NAVBrowser.exe"="C:\Program Files\ScanSoft\OmniPageSE\EregFre\NAVBrowser.exe:*:Enabled:NAVBrowser"
    "C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
    "C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE:*:Enabled:OUTLOOK.EXE"
    "C:\Program Files\EA Games\Command and Conquer Generals\game.dat"="C:\Program Files\EA Games\Command and Conquer Generals\game.dat:*:Enabled:game"
    "C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Enabled:presentation"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

    ======List of files/folders created in the last 1 months======

    2010-01-08 18:49:31 ----A---- C:\WINDOWS\ntbtlog.txt
    2010-01-08 18:29:13 ----SHD---- C:\RECYCLER
    2010-01-07 22:04:42 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2010-01-07 21:51:56 ----A---- C:\ComboFix.txt
    2010-01-07 21:13:31 ----A---- C:\Boot.bak
    2010-01-07 21:13:24 ----RASHD---- C:\cmdcons
    2010-01-07 21:11:56 ----A----
    0
  5. Anonymous user
     
    Uninstall your antivirus, I think it has breathed its last! :
    Trend Micro® Internet Security Suite

    Install this one instead:
    • Download Antivir in French: http://www.commentcamarche.net/telecharger/telecharger-55-antivir

    Or here:
    https://www.01net.com/telecharger/windows/Securite/antivirus-antitrojan/fiches/13198.html

    Why change? : Avast Vs Antivir :
    A point on antivirus: http://forum.malekal.com/ftopic3123.php
    Antivir VS Avast! http://forum.malekal.com/ftopic3528.php
    Antivir tutorial: https://www.malekal.com/avira-free-security-antivirus-gratuit/
    • Manual update tutorial for Avira:

    http://www.libellules.ch/...

    • Antivir configuration:

    Right-click on its icon in the taskbar and select Configure Antivir.

    Check the box: Expert Mode (top left of the window)..

    => Click on Scanner in the left pane:

    > In "Files" select All files.

    > In search procedure, check Allow stop, and in "scanner priority" select Medium.

    > In "Other settings" check all boxes.

    /!\ DO NOT FORGET TO CHECK "SEARCH ROOTKIT ON START OF SEARCH" (the box to the right of this window)

    => Click on "Search" in the left pane and apply the same settings as before.

    => Expand "Search" by clicking on the +. Click on "Heuristic":

    > Check "Heuristic" with medium identification degree!

    => In the left pane, expand "Guard":
    Check: control during reading and writing, then next to it: all files.
    Image help:
    https://www.commentcamarche.net/faq/16831-tutoriel-configuration-optimale-d-antivir-personal#2-la-configuration

    Video configuration tutorial (thanks to Nico for the video):
    http://sd-1.archive-host.com/membres/up/829108531491024/video-Antivir.zip

    NOTE: For the cleaning to be effective, you need to run the Avira scan in safe mode.
    0
  6. lenormand49 Posted messages 115 Status Member 8
     
    I will also need to install a new firewall, so I imagine ZoneAlarm...
    0
  7. Anonymous user
     
    Yes, but first download Avira and the firewall, then disconnect, delete the ones in place, and then reconnect to the internet :-)
    0
  8. lenormand49 Posted messages 115 Status Member 8
     
    c'est fait
    0
  9. lenormand49 Posted messages 115 Status Member 8
     
    Fuck, I'm scanning and there's bagle everywhere.
    0
  10. Anonymous user
     
    Be careful, Avira may detect the disinfection tools, let it finish and put everything in quarantine,
    once the scan is finished, empty its quarantine, then restart it ;-)
    0
  11. lenormand49 Posted messages 115 Status Member 8
     
    Avira AntiVir Personal
    Report file creation date: Saturday, January 9, 2010 1:45 PM

    The scan covers 1,512,108 virus strains.

    License holder: Avira AntiVir Personal - FREE Antivirus
    Serial number: 0000149996-ADJIE-0000001
    Platform: Windows XP
    Windows version: (Service Pack 3) [5.1.2600]
    Boot Mode: Started normally
    Identifier: SYSTEM
    Computer name: CYBER2006

    Version information:
    BUILD.DAT: 9.0.0.74 21698 Bytes 12/04/2009 1:56:00 PM
    AVSCAN.EXE: 9.0.3.10 466689 Bytes 10/13/2009 10:25:46 AM
    AVSCAN.DLL: 9.0.3.0 49409 Bytes 03/03/2009 9:21:02 AM
    LUKE.DLL: 9.0.3.2 209665 Bytes 02/20/2009 10:35:11 AM
    LUKERES.DLL: 9.0.2.0 13569 Bytes 03/03/2009 9:21:31 AM
    VBASE000.VDF: 7.10.0.0 19875328 Bytes 11/06/2009 6:35:52 AM
    VBASE001.VDF: 7.10.1.0 1372672 Bytes 11/19/2009 7:46:17 PM
    VBASE002.VDF: 7.10.1.1 2048 Bytes 11/19/2009 7:46:18 PM
    VBASE003.VDF: 7.10.1.2 2048 Bytes 11/19/2009 7:46:18 PM
    VBASE004.VDF: 7.10.1.3 2048 Bytes 11/19/2009 7:46:18 PM
    VBASE005.VDF: 7.10.1.4 2048 Bytes 11/19/2009 7:46:18 PM
    VBASE006.VDF: 7.10.1.5 2048 Bytes 11/19/2009 7:46:18 PM
    VBASE007.VDF: 7.10.1.6 2048 Bytes 11/19/2009 7:46:18 PM
    VBASE008.VDF: 7.10.1.7 2048 Bytes 11/19/2009 7:46:18 PM
    VBASE009.VDF: 7.10.1.8 2048 Bytes 11/19/2009 7:46:18 PM
    VBASE010.VDF: 7.10.1.9 2048 Bytes 11/19/2009 7:46:19 PM
    VBASE011.VDF: 7.10.1.10 2048 Bytes 11/19/2009 7:46:19 PM
    VBASE012.VDF: 7.10.1.11 2048 Bytes 11/19/2009 7:46:19 PM
    VBASE013.VDF: 7.10.1.79 209920 Bytes 11/25/2009 7:46:25 PM
    VBASE014.VDF: 7.10.1.128 197632 Bytes 11/30/2009 7:46:28 PM
    VBASE015.VDF: 7.10.1.178 195584 Bytes 12/07/2009 7:46:31 PM
    VBASE016.VDF: 7.10.1.224 183296 Bytes 12/14/2009 7:46:36 PM
    VBASE017.VDF: 7.10.1.247 182272 Bytes 12/15/2009 7:46:38 PM
    VBASE018.VDF: 7.10.2.30 198144 Bytes 12/21/2009 7:46:41 PM
    VBASE019.VDF: 7.10.2.63 187392 Bytes 12/24/2009 7:46:44 PM
    VBASE020.VDF: 7.10.2.93 195072 Bytes 12/29/2009 7:46:47 PM
    VBASE021.VDF: 7.10.2.131 201216 Bytes 01/07/2010 7:46:51 PM
    VBASE022.VDF: 7.10.2.132 2048 Bytes 01/07/2010 7:46:51 PM
    VBASE023.VDF: 7.10.2.133 2048 Bytes 01/07/2010 7:46:51 PM
    VBASE024.VDF: 7.10.2.134 2048 Bytes 01/07/2010 7:46:51 PM
    VBASE025.VDF: 7.10.2.135 2048 Bytes 01/07/2010 7:46:51 PM
    VBASE026.VDF: 7.10.2.136 2048 Bytes 01/07/2010 7:46:52 PM
    VBASE027.VDF: 7.10.2.137 2048 Bytes 01/07/2010 7:46:52 PM
    VBASE028.VDF: 7.10.2.138 2048 Bytes 01/07/2010 7:46:52 PM
    VBASE029.VDF: 7.10.2.139 2048 Bytes 01/07/2010 7:46:52 PM
    VBASE030.VDF: 7.10.2.140 2048 Bytes 01/07/2010 7:46:52 PM
    VBASE031.VDF: 7.10.2.151 146944 Bytes 01/08/2010 7:46:55 PM
    Engine version: 8.2.1.134
    AEVDF.DLL: 8.1.1.2 106867 Bytes 11/08/2009 6:38:52 AM
    AESCRIPT.DLL: 8.1.3.7 594296 Bytes 01/08/2010 7:47:26 PM
    AESCN.DLL: 8.1.3.0 127348 Bytes 01/08/2010 7:47:23 PM
    AESBX.DLL: 8.1.1.1 246132 Bytes 11/08/2009 6:38:44 AM
    AERDL.DLL: 8.1.3.4 479605 Bytes 01/08/2010 7:47:23 PM
    AEPACK.DLL: 8.2.0.4 422263 Bytes 01/08/2010 7:47:20 PM
    AEOFFICE.DLL: 8.1.0.38 196987 Bytes 11/08/2009 6:38:38 AM
    AEHEUR.DLL: 8.1.0.194 2228599 Bytes 01/08/2010 7:47:16 PM
    AEHELP.DLL: 8.1.9.0 237943 Bytes 01/08/2010 7:47:02 PM
    AEGEN.DLL: 8.1.1.83 369014 Bytes 01/08/2010 7:47:01 PM
    AEEMU.DLL: 8.1.1.0 393587 Bytes 11/08/2009 6:38:26 AM
    AECORE.DLL: 8.1.9.1 180598 Bytes 01/08/2010 7:46:58 PM
    AEBB.DLL: 8.1.0.3 53618 Bytes 11/08/2009 6:38:20 AM
    AVWINLL.DLL: 9.0.0.3 18177 Bytes 12/12/2008 7:47:30 AM
    AVPREF.DLL: 9.0.3.0 44289 Bytes 08/26/2009 2:13:31 PM
    AVREP.DLL: 8.0.0.3 155905 Bytes 01/20/2009 1:34:28 PM
    AVREG.DLL: 9.0.0.0 36609 Bytes 11/07/2008 2:24:42 PM
    AVARKT.DLL: 9.0.0.3 292609 Bytes 03/24/2009 2:05:22 PM
    AVEVTLOG.DLL: 9.0.0.7 167169 Bytes 01/30/2009 9:36:37 AM
    SQLITE3.DLL: 3.6.1.0 326401 Bytes 01/28/2009 2:03:49 PM
    SMTPLIB.DLL: 9.2.0.25 28417 Bytes 02/02/2009 7:20:57 AM
    NETNT.DLL: 9.0.0.0 11521 Bytes 11/07/2008 2:40:59 PM
    RCIMAGE.DLL: 9.0.0.25 2438913 Bytes 06/17/2009 12:44:26 PM
    RCTEXT.DLL: 9.0.73.0 88321 Bytes 11/02/2009 3:58:32 PM

    Configuration for the current scan:
    Task name....................................: Full system check
    Configuration file............................: c:\program files\avira\antivir desktop\sysscan.avp
    Documentation................................: low
    Main action...................................: interactive
    Secondary action................................: ignore
    Scan master boot sectors.....................: on
    Scan boot sectors..............................: on
    Boot sectors...................................: C:, D:,
    Scan active programs.........................: on
    Scan the registry..............................: on
    Rootkit detection..............................: on
    System file integrity check...................: off
    Optimized scan................................: on
    Search mode file...............................: All files
    Scan archives..................................: on
    Limit recursion depth.........................: 20
    Smart archive extensions.....................: on
    Macrovirus heuristic............................: on
    File heuristic...................................: medium
    Divergent danger categories...................: +APPL,+GAME,+JOKE,+PCK,+PFS,+SPR,

    Scan start time: Saturday, January 9, 2010 1:45 PM

    The search for hidden objects begins.
    '53889' objects have been checked, '0' hidden objects have been found.

    The scan on started processes begins:
    Scanning process 'avcenter.exe' - '1' module(s) checked
    Scanning process 'firefox.exe' - '1' module(s) checked
    Scanning process 'COCIManager.exe' - '1' module(s) checked
    Scanning process 'iPodService.exe' - '1' module(s) checked
    Scanning process 'GM_DevUpdate.exe' - '1' module(s) checked
    Scanning process 'WindowsSearch.exe' - '1' module(s) checked
    Scanning process 'NMBgMonitor.exe' - '1' module(s) checked
    Scanning process 'NCLAUNCH.EXe' - '1' module(s) checked
    Scanning process 'avgnt.exe' - '1' module(s) checked
    Scanning process 'iTunesHelper.exe' - '1' module(s) checked
    Scanning process 'jusched.exe' - '1' module(s) checked
    Scanning process 'avscan.exe' - '1' module(s) checked
    Scanning process 'avscan.exe' - '1' module(s) checked
    Scanning process 'rundll32.exe' - '1' module(s) checked
    Scanning process 'ACDaemon.exe' - '1' module(s) checked
    Scanning process 'Communications_Helper.exe' - '1' module(s) checked
    Scanning process 'rundll32.exe' - '1' module(s) checked
    Scanning process 'opware32.exe' - '1' module(s) checked
    Scanning process 'rmctrl.exe' - '1' module(s) checked
    Scanning process 'RTHDCPL.EXE' - '1' module(s) checked
    Scanning process 'alg.exe' - '1' module(s) checked
    Scanning process 'explorer.exe' - '1' module(s) checked
    Scanning process 'UPS.exe' - '1' module(s) checked
    Scanning process 'searchindexer.exe' - '1' module(s) checked
    Scanning process 'LVComSer.exe' - '1' module(s) checked
    Scanning process 'UPServ.exe' - '1' module(s) checked
    Scanning process 'svchost.exe' - '1' module(s) checked
    Scanning process 'StarWindService.exe' - '1' module(s) checked
    Scanning process 'RichVideo.exe' - '1' module(s) checked
    Scanning process 'PnkBstrB.exe' - '1' module(s) checked
    Scanning process 'PnkBstrA.exe' - '1' module(s) checked
    Scanning process 'MDM.EXE' - '1' module(s) checked
    Scanning process 'LVComSer.exe' - '1' module(s) checked
    Scanning process 'jqs.exe' - '1' module(s) checked
    Scanning process 'svchost.exe' - '1' module(s) checked
    Scanning process 'svchost.exe' - '1' module(s) checked
    Scanning process 'mDNSResponder.exe' - '1' module(s) checked
    Scanning process 'BTNtService.exe' - '1' module(s) checked
    Scanning process 'AppleMobileDeviceService.exe' - '1' module(s) checked
    Scanning process 'avguard.exe' - '1' module(s) checked
    Scanning process 'ACService.exe' - '1' module(s) checked
    Scanning process 'sched.exe' - '1' module(s) checked
    Scanning process 'LVPrcSrv.exe' - '1' module(s) checked
    Scanning process 'spoolsv.exe' - '1' module(s) checked
    Scanning process 'svchost.exe' - '1' module(s) checked
    Scanning process 'svchost.exe' - '1' module(s) checked
    Scanning process 'svchost.exe' - '1' module(s) checked
    Scanning process 'svchost.exe' - '1' module(s) checked
    Scanning process 'nvsvc32.exe' - '1' module(s) checked
    Scanning process 'lsass.exe' - '1' module(s) checked
    Scanning process 'services.exe' - '1' module(s) checked
    Scanning process 'winlogon.exe' - '1' module(s) checked
    Scanning process 'csrss.exe' - '1' module(s) checked
    Scanning process 'smss.exe' - '1' module(s) checked
    '54' processes have been checked with '54' modules

    The scan on master boot sectors begins:
    Master boot sector HD0
    [INFO] No virus found!
    Master boot sector HD1
    [INFO] No virus found!
    Master boot sector HD2
    [INFO] No virus found!
    Master boot sector HD3
    [INFO] No virus found!
    Master boot sector HD4
    [INFO] No virus found!

    The scan on boot sectors begins:
    Boot sector 'C:\'
    [INFO] No virus found!
    Boot sector 'D:\'
    [INFO] No virus found!

    The scan on executable file references (registry) begins:
    The registry was checked ('73' files).

    The scan on selected files begins:

    Scan starting in 'C:\'
    C:\pagefile.sys
    [WARNING] Cannot open file!
    [NOTE] This file is a Windows system file.
    [NOTE] It is correct that this file cannot be opened for scanning.
    Scan starting in 'D:\' <Docs>

    End of scan: Saturday, January 9, 2010 3:31 PM
    Time taken: 1:46:08 Hour(s)

    The scan has been completed in full

    13869 Directories have been checked
    521764 Files have been checked
    0 Viruses or unwanted programs have been found
    0 Files have been classified as suspicious
    0 Files have been deleted
    0 Viruses or unwanted programs have been repaired
    0 Files have been moved to quarantine
    0 Files have been renamed
    1 Cannot check files
    521763 Files not infected
    3361 Archives have been checked
    1 Warnings
    1 Guidelines
    53889 Objects have been checked during the Rootkit scan
    0 Hidden objects have been found
    0
  12. lenormand49 Posted messages 115 Status Member 8
     
    With CC Cleaner, I have run "repair errors" several times and there is always one that remains, otherwise it's okay
    I will probably need to reinstall a firewall?
    0
  13. lenormand49 Posted messages 115 Status Member 8
     
    [ ToolsCleaner report version 2.3.11 (by A.Rothstein & dj QUIOU) ]

    --> Search:

    C:\Combofix.txt: found!
    C:\UsbFix.txt: found!
    C:\Qoobox: found!
    C:\UsbFix: found!
    C:\FindyKill: found!
    C:\Rsit: found!
    C:\Documents and Settings\Admin.XPSP2-0ECD3B1B5\Desktop\Rsit.exe: found!
    C:\HJ\HijackThis.exe: found!
    C:\HJT\HijackThis.exe: found!
    C:\Program Files\Trend Micro\HijackThis.exe: found!
    C:\Program Files\Trend Micro\hijackthis.log: found!
    C:\Qoobox\Quarantine\catchme.log: found!
    C:\WINDOWS\mbr.exe: found!

    ---------------------------------
    --> Deletion:

    C:\HJ\HijackThis.exe: deleted!
    C:\HJT\HijackThis.exe: deleted!
    C:\Program Files\Trend Micro\HijackThis.exe: deleted!
    C:\Combofix.txt: deleted!
    C:\UsbFix.txt: deleted!
    C:\Documents and Settings\Admin.XPSP2-0ECD3B1B5\Desktop\Rsit.exe: deleted!
    C:\Program Files\Trend Micro\hijackthis.log: deleted!
    C:\Qoobox\Quarantine\catchme.log: deleted!
    C:\WINDOWS\mbr.exe: deleted!
    C:\Qoobox: deleted!
    C:\UsbFix: deleted!
    C:\FindyKill: deleted!
    C:\Rsit: deleted!
    0
  14. Anonymous user
     
    You already have a firewall:
    AV: Trend Micro PC-cillin Internet Security 12 12.0.1364 [ Enabled | Updated ]
    # FW: Trend Micro PC-cillin Internet Security 12 [ Enabled ] 12


    At the end of the operation of post 31, update your antivirus and run a full scan of your PC, then post its report.
    We'll see if it's working correctly or if it needs to be reinstalled :-)
    0
  15. lenormand49 Posted messages 115 Status Member 8
     
    Avira AntiVir Personal
    Report file creation date: Sunday, January 10, 2010 01:26

    The scan covers 1,512,108 virus strains.

    License Holder: Avira AntiVir Personal - FREE Antivirus
    Serial Number: 0000149996-ADJIE-0000001
    Platform: Windows XP
    Windows Version: (Service Pack 3) [5.1.2600]
    Boot Mode: Started normally
    Identifier: SYSTEM
    Computer Name: CYBER2006

    Version Information:
    BUILD.DAT: 9.0.0.74 21698 Bytes 04/12/2009 13:56:00
    AVSCAN.EXE: 9.0.3.10 466689 Bytes 13/10/2009 10:25:46
    AVSCAN.DLL: 9.0.3.0 49409 Bytes 03/03/2009 09:21:02
    LUKE.DLL: 9.0.3.2 209665 Bytes 20/02/2009 10:35:11
    LUKERES.DLL: 9.0.2.0 13569 Bytes 03/03/2009 09:21:31
    VBASE000.VDF: 7.10.0.0 19875328 Bytes 06/11/2009 06:35:52
    VBASE001.VDF: 7.10.1.0 1372672 Bytes 19/11/2009 19:46:17
    VBASE002.VDF: 7.10.1.1 2048 Bytes 19/11/2009 19:46:18
    VBASE003.VDF: 7.10.1.2 2048 Bytes 19/11/2009 19:46:18
    VBASE004.VDF: 7.10.1.3 2048 Bytes 19/11/2009 19:46:18
    VBASE005.VDF: 7.10.1.4 2048 Bytes 19/11/2009 19:46:18
    VBASE006.VDF: 7.10.1.5 2048 Bytes 19/11/2009 19:46:18
    VBASE007.VDF: 7.10.1.6 2048 Bytes 19/11/2009 19:46:18
    VBASE008.VDF: 7.10.1.7 2048 Bytes 19/11/2009 19:46:18
    VBASE009.VDF: 7.10.1.8 2048 Bytes 19/11/2009 19:46:18
    VBASE010.VDF: 7.10.1.9 2048 Bytes 19/11/2009 19:46:19
    VBASE011.VDF: 7.10.1.10 2048 Bytes 19/11/2009 19:46:19
    VBASE012.VDF: 7.10.1.11 2048 Bytes 19/11/2009 19:46:19
    VBASE013.VDF: 7.10.1.79 209920 Bytes 25/11/2009 19:46:25
    VBASE014.VDF: 7.10.1.128 197632 Bytes 30/11/2009 19:46:28
    VBASE015.VDF: 7.10.1.178 195584 Bytes 07/12/2009 19:46:31
    VBASE016.VDF: 7.10.1.224 183296 Bytes 14/12/2009 19:46:36
    VBASE017.VDF: 7.10.1.247 182272 Bytes 15/12/2009 19:46:38
    VBASE018.VDF: 7.10.2.30 198144 Bytes 21/12/2009 19:46:41
    VBASE019.VDF: 7.10.2.63 187392 Bytes 24/12/2009 19:46:44
    VBASE020.VDF: 7.10.2.93 195072 Bytes 29/12/2009 19:46:47
    VBASE021.VDF: 7.10.2.131 201216 Bytes 07/01/2010 19:46:51
    VBASE022.VDF: 7.10.2.132 2048 Bytes 07/01/2010 19:46:51
    VBASE023.VDF: 7.10.2.133 2048 Bytes 07/01/2010 19:46:51
    VBASE024.VDF: 7.10.2.134 2048 Bytes 07/01/2010 19:46:51
    VBASE025.VDF: 7.10.2.135 2048 Bytes 07/01/2010 19:46:51
    VBASE026.VDF: 7.10.2.136 2048 Bytes 07/01/2010 19:46:52
    VBASE027.VDF: 7.10.2.137 2048 Bytes 07/01/2010 19:46:52
    VBASE028.VDF: 7.10.2.138 2048 Bytes 07/01/2010 19:46:52
    VBASE029.VDF: 7.10.2.139 2048 Bytes 07/01/2010 19:46:52
    VBASE030.VDF: 7.10.2.140 2048 Bytes 07/01/2010 19:46:52
    VBASE031.VDF: 7.10.2.151 146944 Bytes 08/01/2010 19:46:55
    Engine Version: 8.2.1.134
    AEVDF.DLL: 8.1.1.2 106867 Bytes 08/11/2009 06:38:52
    AESCRIPT.DLL: 8.1.3.7 594296 Bytes 08/01/2010 19:47:26
    AESCN.DLL: 8.1.3.0 127348 Bytes 08/01/2010 19:47:23
    AESBX.DLL: 8.1.1.1 246132 Bytes 08/11/2009 06:38:44
    AERDL.DLL: 8.1.3.4 479605 Bytes 08/01/2010 19:47:23
    AEPACK.DLL: 8.2.0.4 422263 Bytes 08/01/2010 19:47:20
    AEOFFICE.DLL: 8.1.0.38 196987 Bytes 08/11/2009 06:38:38
    AEHEUR.DLL: 8.1.0.194 2228599 Bytes 08/01/2010 19:47:16
    AEHELP.DLL: 8.1.9.0 237943 Bytes 08/01/2010 19:47:02
    AEGEN.DLL: 8.1.1.83 369014 Bytes 08/01/2010 19:47:01
    AEEMU.DLL: 8.1.1.0 393587 Bytes 08/11/2009 06:38:26
    AECORE.DLL: 8.1.9.1 180598 Bytes 08/01/2010 19:46:58
    AEBB.DLL: 8.1.0.3 53618 Bytes 08/11/2009 06:38:20
    AVWINLL.DLL: 9.0.0.3 18177 Bytes 12/12/2008 07:47:30
    AVPREF.DLL: 9.0.3.0 44289 Bytes 26/08/2009 14:13:31
    AVREP.DLL: 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
    AVREG.DLL: 9.0.0.0 36609 Bytes 07/11/2008 14:24:42
    AVARKT.DLL: 9.0.0.3 292609 Bytes 24/03/2009 14:05:22
    AVEVTLOG.DLL: 9.0.0.7 167169 Bytes 30/01/2009 09:36:37
    SQLITE3.DLL: 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
    SMTPLIB.DLL: 9.2.0.25 28417 Bytes 02/02/2009 07:20:57
    NETNT.DLL: 9.0.0.0 11521 Bytes 07/11/2008 14:40:59
    RCIMAGE.DLL: 9.0.0.25 2438913 Bytes 17/06/2009 12:44:26
    RCTEXT.DLL: 9.0.73.0 88321 Bytes 02/11/2009 15:58:32

    Configuration for the current scan:
    Task Name..................................: Full System Scan
    Configuration File...........................: c:\program files\avira\antivir desktop\sysscan.avp
    Documentation.................................: low
    Main Action.................................: interactive
    Secondary Action.............................: ignore
    Scan Master Boot Sectors....................: on
    Scan Boot Sectors............................: on
    Boot Sectors................................: C:, D:,
    Scan Active Programs.........................: on
    Scan Registry................................: on
    Scan for Rootkits............................: on
    File System Integrity Check..................: off
    Optimized Scan...............................: on
    File Search Mode.............................: All files
    Scan Archives................................: on
    Limit Recursion Depth.........................: 20
    Archive Smart Extensions......................: on
    Macrovirus Heuristic.........................: on
    File Heuristic...............................: medium
    Diverse Danger Categories.....................: +APPL,+GAME,+JOKE,+PCK,+PFS,+SPR,

    Scan Start: Sunday, January 10, 2010 01:26

    The scan for hidden objects begins.
    '53,514' objects were checked, '0' hidden objects were found.

    The scan on running processes begins:
    Process Scan 'avscan.exe' - '1' module(s) checked
    Process Scan 'avcenter.exe' - '1' module(s) checked
    Process Scan 'iPodService.exe' - '1' module(s) checked
    Process Scan 'COCIManager.exe' - '1' module(s) checked
    Process Scan 'GM_DevUpdate.exe' - '1' module(s) checked
    Process Scan 'WindowsSearch.exe' - '1' module(s) checked
    Process Scan 'Skype.exe' - '1' module(s) checked
    Process Scan 'NMBgMonitor.exe' - '1' module(s) checked
    Process Scan 'NCLAUNCH.EXe' - '1' module(s) checked
    Process Scan 'avgnt.exe' - '1' module(s) checked
    Process Scan 'iTunesHelper.exe' - '1' module(s) checked
    Process Scan 'jusched.exe' - '1' module(s) checked
    Process Scan 'CNMNSUT.EXE' - '1' module(s) checked
    Process Scan 'rundll32.exe' - '1' module(s) checked
    Process Scan 'ACDaemon.exe' - '1' module(s) checked
    Process Scan 'Communications_Helper.exe' - '1' module(s) checked
    Process Scan 'rundll32.exe' - '1' module(s) checked
    Process Scan 'hpztsb03.exe' - '1' module(s) checked
    Process Scan 'opware32.exe' - '1' module(s) checked
    Process Scan 'rmctrl.exe' - '1' module(s) checked
    Process Scan 'RTHDCPL.EXE' - '1' module(s) checked
    Process Scan 'alg.exe' - '1' module(s) checked
    Process Scan 'UPS.exe' - '1' module(s) checked
    Process Scan 'LVComSer.exe' - '1' module(s) checked
    Process Scan 'explorer.exe' - '1' module(s) checked
    Process Scan 'searchindexer.exe' - '1' module(s) checked
    Process Scan 'UPServ.exe' - '1' module(s) checked
    Process Scan 'svchost.exe' - '1' module(s) checked
    Process Scan 'StarWindService.exe' - '1' module(s) checked
    Process Scan 'RichVideo.exe' - '1' module(s) checked
    Process Scan 'PnkBstrB.exe' - '1' module(s) checked
    Process Scan 'PnkBstrA.exe' - '1' module(s) checked
    Process Scan 'MDM.EXE' - '1' module(s) checked
    Process Scan 'LVComSer.exe' - '1' module(s) checked
    Process Scan 'jqs.exe' - '1' module(s) checked
    Process Scan 'svchost.exe' - '1' module(s) checked
    Process Scan 'svchost.exe' - '1' module(s) checked
    Process Scan 'mDNSResponder.exe' - '1' module(s) checked
    Process Scan 'BTNtService.exe' - '1' module(s) checked
    Process Scan 'AppleMobileDeviceService.exe' - '1' module(s) checked
    Process Scan 'avguard.exe' - '1' module(s) checked
    Process Scan 'ACService.exe' - '1' module(s) checked
    Process Scan 'sched.exe' - '1' module(s) checked
    Process Scan 'LVPrcSrv.exe' - '1' module(s) checked
    Process Scan 'spoolsv.exe' - '1' module(s) checked
    Process Scan 'svchost.exe' - '1' module(s) checked
    Process Scan 'svchost.exe' - '1' module(s) checked
    Process Scan 'svchost.exe' - '1' module(s) checked
    Process Scan 'svchost.exe' - '1' module(s) checked
    Process Scan 'nvsvc32.exe' - '1' module(s) checked
    Process Scan 'lsass.exe' - '1' module(s) checked
    Process Scan 'services.exe' - '1' module(s) checked
    Process Scan 'winlogon.exe' - '1' module(s) checked
    Process Scan 'csrss.exe' - '1' module(s) checked
    Process Scan 'smss.exe' - '1' module(s) checked
    '55' processes were checked with '55' modules

    The master boot sector scan begins:
    Master Boot Sector HD0
    [INFO] No virus found!
    Master Boot Sector HD1
    [INFO] No virus found!
    Master Boot Sector HD2
    [INFO] No virus found!
    Master Boot Sector HD3
    [INFO] No virus found!
    Master Boot Sector HD4
    [INFO] No virus found!

    The boot sectors scan begins:
    Boot Sector 'C:\'
    [INFO] No virus found!
    Boot Sector 'D:\'
    [INFO] No virus found!

    The scan for references to executable files (registry) begins:
    The registry has been checked ('73' files).

    The scan for selected files begins:

    Scan starting in 'C:\'
    C:\pagefile.sys
    [WARNING] Unable to open file!
    [NOTE] This file is a Windows system file.
    [NOTE] It is correct that this file cannot be opened for scanning.
    Scan starting in 'D:\' <Docs>

    End of the scan: Sunday, January 10, 2010 02:41
    Time taken: 1:15:07 Hours

    The scan was completed thoroughly

    13,824 Directories were checked
    520,267 Files were checked
    0 Viruses or unwanted programs were found
    0 Files were classified as suspicious
    0 Files were deleted
    0 Viruses or unwanted programs were repaired
    0 Files were moved to quarantine
    0 Files were renamed
    1 Unable to check files
    520,266 Non-infected files
    3,391 Archives were checked
    1 Warnings
    1 Guidelines
    53,514 Objects were checked during the Rootkit scan
    0 Hidden objects were found
    0
  16. Anonymous user
     
    Hello,
    make sure to uninstall the other antivirus so that you have only one :-)

    If you don't have any more issues, please mark your post as resolved :-)

    Happy surfing and have a great day ;-)
    0
  17. lenormand49 Posted messages 115 Status Member 8
     
    Well, if there's a firewall problem
    it was integrated into PC-cillin that I uninstalled.
    0
  18. Anonymous user
     
    install in another one:
    you have the choice between kirio, comodo, Zonalarm ....
    0
Previous
  • 1
  • 2