Welcome to What the Tech! ( Log In | Register ) What tech support ought to be... Fast, friendly and free! Once registered - you'll have the ability to post your question in the appropriate forum below. Additionally, if you can assist another member by sharing your tech knowledge, please post a reply! Best of all - Registration and all assistance is FREE! Once you've completed registration, simply choose the appropriate forum below, click on the "new topic" button, and post your question! What are you waiting for? Register today! *Registered users see NO ADVERTISING.
![]() ![]() |
May 23 2009, 08:50 PM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 13 Joined: 29-November 08 Member No.: 82,626 Operating System: Windows Vista |
There aren't really any other symptoms other than the computer being extremely slow and taking forever to start up and shutdown. Sometimes it freezes up when I'm trying to launch a program, it just depends on what it wants to that day. Mostly though, it's really just being extremely slow as of late.
Here's the HijackThis log for review. Thanks for the help in advance. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:49:36 PM, on 5/23/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Verizon\Verizon Internet Security Suite\rps.exe C:\Program Files\Verizon\VSP\VerizonServicepoint.exe C:\Program Files\Synaptics\SynTP\SynTPStart.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Lexmark X1100 Series\LXBKbmgr.exe C:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe C:\Users\SAM&CA~1\AppData\Local\Temp\RtkBtMnt.exe C:\Program Files\Raxco\PerfectDisk2008\PD91AgentS1.exe C:\Program Files\Launch Manager\QtZgAcer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Windows\System32\hkcmd.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Users\Sam & Carol\AppData\Local\Google\Update\GoogleUpdate.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Acer\Acer VCM\AcerVCM.exe C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaMonitor.exe C:\Windows\ehome\ehmsas.exe C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE C:\Windows\system32\igfxext.exe C:\Windows\system32\igfxsrvc.exe C:\Acer\Empowering Technology\eAudio\eAudio.exe C:\Program Files\Acer\Acer VCM\acp2HID.exe C:\Windows\System32\mobsync.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Users\Sam & Carol\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Sam & Carol\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Sam & Carol\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Sam & Carol\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Sam & Carol\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Sam & Carol\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Verizon\Verizon Internet Security Suite\pkR.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [Skytel] Skytel.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\Windows\PLFSet.dll,PLFDefSetting O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe" O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [lxbkbmgr.exe] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [Lto Manager] "C:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe" O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [Google Update] "C:\Users\Sam & Carol\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe O4 - Global Startup: Acer VCM.lnk = ? O4 - Global Startup: Empowering Technology Launcher.lnk = ? O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 O8 - Extra context menu item: Append to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O13 - Gopher Prefix: O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co...ex/qtplugin.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\aawservice.exe O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing) O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe O23 - Service: MrHealthy (MrHealthyService) - Symantec Corporation - C:\Program Files\Norton PC Checkup\executables\mrHealthy\MrHealthy.exe O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe O23 - Service: Verizon Internet Security Suite (Radialpoint Security Services) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe O23 - Service: Verizon Internet Security Suite SafeConnectAgent (RadialpointSafeConnectAgent) - Sana Security - C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe O23 - Service: Raw Socket Service (RS_Service) - Acer Inc. - C:\Program Files\Acer\Acer VCM\RS_Service.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 12629 bytes |
|
|
|
May 27 2009, 03:16 PM
Post
#2
|
|
![]() Advanced Member Group: Malware Team Posts: 546 Joined: 10-October 08 Member No.: 81,919 Operating System: Windows Xp Pro Windows Vista Premium |
Hello.
My name is Extremeboy or EB for short, and I will help you with any malware related problems you may have. If you do not make a reply in 5 days, we will need to close your topic. Please take note of some guidelines for this fix:
Download and Run DDS We need to see some information about what is happening in your machine. Please perform the following scan:
-- Note: The screen instructions indicate the attach.txt must be zipped before attaching (not posted) to your forum post. Instead, we want you to include attach.txt as an attachment to upload using the "Browse" button in the text editor when making your reply. ~Extremeboy |
|
|
|
May 27 2009, 04:20 PM
Post
#3
|
|
|
New Member ![]() Group: Authentic Member Posts: 13 Joined: 29-November 08 Member No.: 82,626 Operating System: Windows Vista |
Alright, I downloaded the DDS.src ran it, zipped the two text documents and attached it to this post via the browse button. Also, so I don't end up wasting your time, it's been a few days since I had originally posted this thread and I believe a few scans have been ran. Just in case, here's a new HijackThis log file for your reference.
Thanks for the help, it's much appreciated. of Trend Micro HijackThis v2.0.2 Scan saved at 6:18:05 PM, on 5/27/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Windows\ehome\ehtray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\wuauclt.exe C:\Users\Sam & Carol\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Verizon\Verizon Internet Security Suite\pkR.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [Skytel] Skytel.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\Windows\PLFSet.dll,PLFDefSetting O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe" O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [lxbkbmgr.exe] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [Lto Manager] "C:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe" O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [Google Update] "C:\Users\Sam & Carol\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe O4 - Global Startup: Acer VCM.lnk = ? O4 - Global Startup: Empowering Technology Launcher.lnk = ? O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 O8 - Extra context menu item: Append to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O13 - Gopher Prefix: O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co...ex/qtplugin.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\aawservice.exe O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing) O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe O23 - Service: MrHealthy (MrHealthyService) - Symantec Corporation - C:\Program Files\Norton PC Checkup\executables\mrHealthy\MrHealthy.exe O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe O23 - Service: Verizon Internet Security Suite (Radialpoint Security Services) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe O23 - Service: Verizon Internet Security Suite SafeConnectAgent (RadialpointSafeConnectAgent) - Sana Security - C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe O23 - Service: Raw Socket Service (RS_Service) - Acer Inc. - C:\Program Files\Acer\Acer VCM\RS_Service.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 10715 bytes
Attached File(s)
|
|
|
|
May 28 2009, 04:29 PM
Post
#4
|
|
![]() Advanced Member Group: Malware Team Posts: 546 Joined: 10-October 08 Member No.: 81,919 Operating System: Windows Xp Pro Windows Vista Premium |
Hello.
Slowness is not always caused by malware. Let's make sure you are free from malware first. 1. Peer-to-Peer Programs Warning Your log shows that you are using so called peer-to-peer or file-sharing programs (in your case UTorrent). These programs allow to share files between users as the name(s) suggest. In today's world cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it. It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. Some further readings on this subject, along the included links, are as follows: File-Sharing, otherwise known as Peer To Peer and Risks of File-Sharing Technology. It is also important to note that sharing entertainment files and proprietary software infringes the copyright laws in many countries over the world and you are putting yourself at risk of being indicted through organizations watching over the rights of the authors of such files (i.e. the RIAA for music files, or the MPAA for movie files in the USA) or the authors of the files themselves. Naturally there are also legal ways to use these services, such as downloading Linux distributions or office suites such as "Open Office." It is your decision whether or not you wish to keep your program(s) but I suggest you remove it via add/remove. However, please refrain from using them until your computer has been declared clean. 2. Update Java to Version 6 Update 13 Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
** If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it. *** The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually. 3. Run Scan with Kaspersky Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.) If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
You can refer to this animation by sundavis. Take a new DDS&Attach log afterwards. Hijackthis log is NOT needed since DDS shows the same information. ~Extremeboy |
|
|
|
May 30 2009, 11:37 AM
Post
#5
|
|
![]() Advanced Member Group: Malware Team Posts: 546 Joined: 10-October 08 Member No.: 81,919 Operating System: Windows Xp Pro Windows Vista Premium |
Hello.
Are you still there? If you are please follow the instructions in my previous post. If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic. Please reply back telling us so. If you don't reply within 5-7 from the day I replied, the topic will need to be closed. Thanks for understanding. With Regards, Extremeboy |
|
|
|
May 31 2009, 11:36 AM
Post
#6
|
|
|
New Member ![]() Group: Authentic Member Posts: 13 Joined: 29-November 08 Member No.: 82,626 Operating System: Windows Vista |
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT Sunday, May 31, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Saturday, May 30, 2009 22:59:15 Records in database: 2280723 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Files scanned: 210559 Threat name: 2 Infected objects: 2 Suspicious objects: 0 Duration of the scan: 06:58:40 File name / Threat name / Threats count C:\Users\Sam & Carol\Downloads\Daemon_Tool_Pro41.rar Infected: Trojan-Downloader.Win32.Agent.acqq 1 C:\Users\Sam & Carol\Downloads\Windows XP Ultimate Edition (by Johnny) [December2008-R3.9.4.1]\Windows XP Ultimate Edition (by Johnny) [December2008-R3.9.4.1].iso Infected: Worm.Win32.AutoIt.r 1 The selected area was scanned.
Attached File(s)
|
|
|
|
May 31 2009, 02:42 PM
Post
#7
|
|
![]() Advanced Member Group: Malware Team Posts: 546 Joined: 10-October 08 Member No.: 81,919 Operating System: Windows Xp Pro Windows Vista Premium |
Hello.
First, you installed a P2P program (UTorrent) as explained above which I'm sure is not for legitimate or legal purposes. Then you use that program to download infected and files/softwares that are bypassing copy-write laws. Daemon Tools Pro is not meant for free but to get the full version you will need to pay. I do not know what contains in those archive files but you need to delete both of of those files now. Furthermore, those are infected. Delete this folder: C:\Users\Sam & Carol\Downloads\Windows XP Ultimate Edition (by Johnny) [December2008-R3.9.4.1] Delete this file: C:\Users\Sam & Carol\Downloads\Daemon_Tool_Pro41.rar We need to update Java again and run rooter. Then you will run another tool that may help increase some system performance. Download and Install Latest Version of Java Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
-- If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it. -- The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually. Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click Ok and reboot your computer. Download and Run Rooter SD Please download Rooter.exe and save it to your desktop
System A bit Slow? Try StartupLight You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance. If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware. WIth Regards, Extremeboy |
|
|
|
May 31 2009, 04:21 PM
Post
#8
|
|
|
New Member ![]() Group: Authentic Member Posts: 13 Joined: 29-November 08 Member No.: 82,626 Operating System: Windows Vista |
Microsoft Windows Vista Home Edition (6.0.6001) Service Pack 1
C:\ [Fixed] - NTFS - (Total:71447 Mo/Free:1608 Mo) D:\ [Fixed] - NTFS - (Total:67864 Mo/Free:22 Mo) E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) F:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) Sun 05/31/2009|18:18 ----------------------\\ Processes.. --Locked-- [System Process] --Locked-- System ---------- \SystemRoot\System32\smss.exe ---------- C:\Windows\system32\csrss.exe ---------- C:\Windows\system32\wininit.exe ---------- C:\Windows\system32\services.exe ---------- C:\Windows\system32\lsass.exe ---------- C:\Windows\system32\lsm.exe ---------- C:\Windows\system32\svchost.exe ---------- C:\Windows\system32\svchost.exe ---------- C:\Windows\System32\svchost.exe ---------- C:\Windows\System32\svchost.exe ---------- C:\Windows\System32\svchost.exe ---------- C:\Windows\system32\svchost.exe --Locked-- audiodg.exe ---------- C:\Windows\system32\SLsvc.exe ---------- C:\Windows\system32\svchost.exe ---------- C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe ---------- C:\Windows\system32\svchost.exe ---------- D:\Program Files\aawservice.exe ---------- C:\Windows\System32\spoolsv.exe ---------- C:\Windows\system32\svchost.exe ---------- C:\Acer\ALaunch\ALaunchSvc.exe ---------- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe ---------- C:\Windows\system32\svchost.exe ---------- C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe ---------- C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe ---------- C:\Acer\Empowering Technology\eNet\eNet Service.exe ---------- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe ---------- C:\Program Files\Common Files\LightScribe\LSSrvc.exe ---------- C:\Windows\system32\lxbkcoms.exe ---------- C:\Program Files\Common Files\Motive\McciCMService.exe ---------- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe ---------- C:\Acer\Mobility Center\MobilityService.exe ---------- C:\Program Files\Norton PC Checkup\executables\mrHealthy\MrHealthy.exe ---------- C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe ---------- C:\Windows\system32\svchost.exe ---------- C:\Program Files\CyberLink\Shared Files\RichVideo.exe ---------- C:\Program Files\Acer\Acer VCM\RS_Service.exe ---------- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe ---------- C:\Windows\system32\svchost.exe ---------- C:\Program Files\Viewpoint\Common\ViewpointService.exe ---------- C:\Windows\System32\svchost.exe ---------- C:\Windows\system32\SearchIndexer.exe ---------- C:\Windows\system32\DRIVERS\xaudio.exe ---------- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe ---------- C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe ---------- C:\Acer\Empowering Technology\ePower\ePowerSvc.exe ---------- C:\Windows\system32\wbem\wmiprvse.exe ---------- C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe ---------- C:\Windows\system32\wbem\unsecapp.exe ---------- C:\Windows\system32\wbem\wmiprvse.exe ---------- C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe ---------- C:\Windows\system32\svchost.exe ---------- C:\Windows\system32\wbem\unsecapp.exe ---------- C:\Program Files\Windows Media Player\wmpnetwk.exe ---------- C:\Windows\system32\taskeng.exe ---------- C:\Windows\system32\vssvc.exe ---------- C:\Windows\System32\svchost.exe ---------- C:\Windows\system32\csrss.exe ---------- C:\Windows\system32\winlogon.exe ---------- C:\Windows\system32\taskeng.exe ---------- C:\Windows\system32\Dwm.exe ---------- C:\Windows\Explorer.EXE ---------- C:\Program Files\Verizon\Verizon Internet Security Suite\rps.exe ---------- C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe ---------- C:\Program Files\Verizon\VSP\VerizonServicepoint.exe ---------- C:\Program Files\Synaptics\SynTP\SynTPStart.exe ---------- C:\Windows\RtHDVCpl.exe ---------- C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe ---------- C:\Windows\System32\igfxpers.exe ---------- C:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe ---------- C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaMonitor.exe ---------- C:\Windows\system32\igfxsrvc.exe ---------- C:\Program Files\Verizon\Verizon Internet Security Suite\Kav\Bin\ScanningProcess.exe ---------- C:\Program Files\Launch Manager\QtZgAcer.EXE ---------- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe ---------- C:\Windows\System32\hkcmd.exe ---------- C:\Program Files\Windows Media Player\wmpnscfg.exe ---------- C:\Users\Sam & Carol\AppData\Local\Google\Update\GoogleUpdate.exe ---------- C:\Windows\ehome\ehtray.exe ---------- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ---------- C:\Program Files\Acer\Acer VCM\AcerVCM.exe ---------- C:\Windows\system32\igfxext.exe ---------- C:\Windows\system32\igfxsrvc.exe ---------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ---------- C:\Windows\ehome\ehmsas.exe ---------- C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE ---------- C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE ---------- C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE ---------- C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE ---------- C:\Users\SAM&CA~1\AppData\Local\Temp\RtkBtMnt.exe ---------- C:\Program Files\Acer\Acer VCM\acp2HID.exe ---------- C:\Acer\Empowering Technology\eAudio\eAudio.exe ---------- C:\Windows\system32\wuauclt.exe ---------- C:\Program Files\Raxco\PerfectDisk2008\PD91AgentS1.exe ---------- D:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe ---------- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe ---------- C:\Program Files\Mozilla Firefox\firefox.exe ---------- C:\Windows\system32\msiexec.exe ---------- C:\Windows\system32\DllHost.exe ---------- C:\Windows\system32\DllHost.exe ---------- C:\Windows\system32\cmd.exe ---------- C:\Rooter$\RK.exe ----------------------\\ Search.. ----------------------\\ ROOTKIT !! ----------------------\\ Cracks & Keygens.. C:\Users\SAM&CA~1\AppData\Roaming\uTorrent\Adobe Premier Pro 7+ Serial + Crack.zip.torrent C:\Users\SAM&CA~1\Documents\Downloads\Adobe Premier Pro 7+ Serial + Crack.zip [mininova].torrent C:\Users\SAM&CA~1\Downloads\Adobe Premier Pro 7+ Serial + Crack.zip C:\Users\SAM&CA~1\Downloads\Daemon Tools Pro Advanced v4.10.0218 + Crack\README.txt C:\Users\SAM&CA~1\Downloads\Daemon Tools Pro Advanced v4.10.0218 + Crack\Torrent downloaded from Demonoid.com.txt C:\Users\SAM&CA~1\Downloads\Daemon Tools Pro Advanced v4.10.0218 + Crack\Crack - Read Instructions\You must read this.txt C:\Users\SAM&CA~1\Downloads\Daemon Tools Pro Advanced v4.10.0218 + Crack\Setup\DTPro4100218Advanced.exe C:\Users\SAM&CA~1\Downloads\IsoBuster Pro 2.2.0.1 Final + WORKING Keygen [DXO]\isobuster_all_lang.exe C:\Users\SAM&CA~1\Downloads\IsoBuster Pro 2.2.0.1 Final + WORKING Keygen [DXO]\Torrent downloaded from Demonoid.com.txt C:\Users\SAM&CA~1\Downloads\Maxon Cinema 4D R11 Studio Bundle\C4D R11 KeyGen.exe 1 - "C:\Rooter$\Rooter_1.txt" - Sun 05/31/2009|18:19 ----------------------\\ Scan completed at 18:19 |
|
|
|
Jun 2 2009, 07:04 PM
Post
#9
|
|
![]() Advanced Member Group: Malware Team Posts: 546 Joined: 10-October 08 Member No.: 81,919 Operating System: Windows Xp Pro Windows Vista Premium |
Hello.
I see evidence of "cracks and keygens", this means You have used cracks or key generators. You should know that use of these is considered illegal activity, as it bypasses copyright laws. Some of the worst types of malware infections can be contracted and spread by visiting crack, keygen, warez and other pirated software sites. In many cases, these sites are infested with a sm?rg?sbord of malware. Those who attempt to get software for free can end up with a computer system so badly damaged that recovery is not possible and it cannot be repaired. When that happens there is nothing you can do besides reformatting and reinstalling Windows. Merely visiting such sites without downloading ANYTHING is one of the worst things a user can do online. They are illegal. Cracked software is notorious for carrying malware/infections. How do you think these people make their money... they aren't really giving you this software out of the goodness of their hearts. Antivirus programs cannot protect you against what you are deliberately running. The HJT Teams will have 0 tolerance of members that continue to reinfect their system from use of such programs. Please delete and remove everything that is related to this. This includes everything that Rooter found under the ----------------------\\ Cracks & Keygens.. heading. Tell me how your computer is now and what symptoms or issues you still have. Post a new set of DDS logs afterwards as well... Regards, Extremeboy |
|
|
|
Jun 4 2009, 06:35 AM
Post
#10
|
|
|
New Member ![]() Group: Authentic Member Posts: 13 Joined: 29-November 08 Member No.: 82,626 Operating System: Windows Vista |
Wow. You must assume I'm some fool. It's such a shame when you talk down to your members. I don't get keygens from these "sites" you talk about. And anything I torrent I scan. You must also understand I'm not the only person using this computer. The whole family uses it. You shouldn't assume I'm the source of these problems, I'm merely trying to fix them for someone else. You should always ask questions before you assume things, that's real life advice right there by the way.
Zero tolerance, lol. Trust me, I hardly care that it's illegal. Just because it's illegal doesn't make it wrong. It doesn't stop me from smoking weed. It might not even stop you from smoking weed, but hell, what do I know I don't make assumptions. Sure, I got Photoshop for free but have you seen the price tag? Anyway, once I start selling stuff out of Photoshop then I'll purchase the program. Until then, it's my free full featured demo. Anyway, I've posted twice on this site I believe. And the last time I posted it had nothing to do with these keygens you speak of. Believe it or not, those files were probably on this computer last time I posted here and whoever helped me didn't even notice them. How strange. I don't trust anyone on the internet, whether I'm downloading keygens OR asking for help. Now, we should probably get back to trying to just fixing things and not try to persuade each other to understand the significance of one anothers actions. Oh, and another thing. There's no such as the "goodness of their hearts." We're all ####### robots anyway, hearts are overrated. |
|
|
|
Jun 7 2009, 09:35 AM
Post
#11
|
|
![]() Advanced Member Group: Malware Team Posts: 546 Joined: 10-October 08 Member No.: 81,919 Operating System: Windows Xp Pro Windows Vista Premium |
Hello.
As already mentioned already P2P sharing programs above, I will not talk further on this topic. It doesn't matter if it's you or your whole family, they should know and since you are requested for help and I see these items in the log I will direct it at you. If it's someone else, fine but you should be responsible as it's your computer as well. As far as I'm concerned, if it's illegal I consider it wrong. Yes, we cannot stop you from doing anything but if we see members continue to use such programs and get re-infected and requesting for help then we have the right to not help you. It would be a waste of our time. If you do not trust us for help then why start a topic here? One's action, we can not control. Here at WhatTheTech and probably many other forums we help you get rid of anything you may have including cracks/keygenes or malware and give you some prevention tips however, we expect you to keep yourself clean and refrain from using such programs or visiting such sites again. That was the main message we were trying to let you know. Post a new DDS log for me to review. With Regards, Extremeboy |
|
|
|
Jun 12 2009, 03:14 PM
Post
#12
|
|
![]() Advanced Member Group: Malware Team Posts: 546 Joined: 10-October 08 Member No.: 81,919 Operating System: Windows Xp Pro Windows Vista Premium |
Due to inactivity this topic will be closed.
If you need help please start a new thread and post a new HJT log |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
2 | Ceil | 38 | Today, 05:02 AM Last post by: CatByte |
|||
![]() |
2 | deaiden08 | 49 | Today, 05:02 AM Last post by: CatByte |
|||
![]() |
2 | Barbzzz | 59 | Today, 05:01 AM Last post by: CatByte |
|||
![]() |
58 | Mirrodin | 983 | Today, 05:00 AM Last post by: CatByte |
|||
|
Time is now: 7th November 2009 - 03:41 PM |