This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

System Clock resets to April 2016

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Just after I installed a precracked game, my computer's date and time changed to 12th April 2016, 7:00AM. I've tried to correct the date and time but it changes again every time I restart my computer. I've ever got this problem and it was solved after I used system restore. However, this time I can't do it. It says that system restore cannot successfully done because it cannot access one of the files. Therefore, is there any way to solve this problem other than using system restore?

I've deleted the installed games as well as the installer. I've also scan my computer using Spyware Terminator but it's all clean. Please help.
Thank You.

Here is the scan results as required. However, I can't run the DDS. It says that "this tool does not support your operating system". What shall I do?

Malwarebytes' Anti-Malware 1.44
Database version: 3574
Windows 6.1.7600
Internet Explorer 8.0.7600.16385

1/16/2010 1:34:50 PM
mbam-log-2010-01-16 (13-34-50).txt

Scan type: Quick Scan
Objects scanned: 100760
Time elapsed: 3 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{62f5ht7i-unf8-k63p-6etx-fh24e2k4abmm} (Generic.Bot.H) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nvcpl (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\program files\common files\svchost.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\Windows\system32\userinit.exe,C:\Program Files\Common Files\svchost.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\Common Files\svchost.exe (Trojan.Agent) -> Delete on reboot.


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-16 13:42:33
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\jimmy\AppData\Local\Temp\kwldipog.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwClose [0xAAA9088E]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0xAAA900EC]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0xAAA8FDCE]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwCreateSection [0xAAA91938]
SSDT 94E77AEC ZwCreateThread
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0xAAA8FED8]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0xAAA8FFC2]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwLoadDriver [0xAAA90BBC]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0xAAA903F4]
SSDT 94E77AD8 ZwOpenProcess
SSDT 94E77ADD ZwOpenThread
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwSetInformationFile [0xAAA90526]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0xAAA8FBFC]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess [0xAAA90B04]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0xAAA9070C]

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C3CAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C3C104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C3C3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C24634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C24898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C3C1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C3C958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C3C6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C3CF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C3D1A8

—- Devices - GMER 1.0.15 —-

Device \Driver\ACPI_HAL \Device\00000048 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Bind \Device\{6283098F-C3B8-4331-A859-CA81155B6459}?\Device\{94756063-7226-4DC7-98AF-F363AB494D86}?\Device\{53227B99-E157-4CB9-AFEC-7CDCAE930913}?\Device\{BB902439-276F-4230-AA64-85F54079A186}?\Device\{08CB6922-1A08-429C-9ADE-7DD15C8F66D9}?\Device\{A175DD1E-B74D-447C-9A6B-B2ACA183620A}?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Route "{6283098F-C3B8-4331-A859-CA81155B6459}"?"{94756063-7226-4DC7-98AF-F363AB494D86}"?"{53227B99-E157-4CB9-AFEC-7CDCAE930913}"?"{BB902439-276F-4230-AA64-85F54079A186}"?"{08CB6922-1A08-429C-9ADE-7DD15C8F66D9}"?"{A175DD1E-B74D-447C-9A6B-B2ACA183620A}"?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Export \Device\TCPIP6TUNNEL_{6283098F-C3B8-4331-A859-CA81155B6459}?\Device\TCPIP6TUNNEL_{94756063-7226-4DC7-98AF-F363AB494D86}?\Device\TCPIP6TUNNEL_{53227B99-E157-4CB9-AFEC-7CDCAE930913}?\Device\TCPIP6TUNNEL_{BB902439-276F-4230-AA64-85F54079A186}?\Device\TCPIP6TUNNEL_{08CB6922-1A08-429C-9ADE-7DD15C8F66D9}?\Device\TCPIP6TUNNEL_{A175DD1E-B74D-447C-9A6B-B2ACA183620A}?
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002556e0519d
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch@Epoch 608
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch2@Epoch 242
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002556e0519d (not active ControlSet)

—- EOF - GMER 1.0.15 —-

Just after I installed a precracked game

Are you saying you download and installed a "cracked" game?
We do not support the use of illegal Pirated/Warez/Cracked software.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI