This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

i try 3 differrents AV and 3 differents anti-spyware

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

For beginiing i use my pc a lot (gaming, torrent, testing apps, music, almost 24/7 24/24 sit here)
Everyday i clean my Pc with CCleaner for the registry and net browser cache etc…. ( i have 86 backup of my registry… ROFL)

I was using ESET NOD32 with malwarebytes and spybot - search and destroy
but recently there is something try to fu** up my computer.

I try a lot of scan then found some things (repair/delete)

I uninstall ESTE NOD32 and change it for Panda AV then found some things too with it….

BUT THE VIRUS/SPYWARE/MALWARE SH** is still here somewhere moving around.

Effect on pc:
sometimes im trying to delete a folder in c://program files for example…. i receive the error message: You need admin right to delete this file… bla bla bla . IM THE ONLY ADMIN OF THIS PC FOR 4 YEARS AND MORE.
incredibly slow (like RAM is not performing ok..)
freezing windows (windows 7 ultimate orion cesium x64)
double mouse click (opening an application for example) is incredibly long !!
pc is lagging/loading so much :(
*i notice a sysWow64 folder always reapearing during scanning i dont remember see this folder in the past im not sure….
*probably problem with Hosts files too im not sure too…..

Please help would be appreciate. :pullhair: :pullhair: :pullhair: :pullhair: :pullhair:

PC specs:

Operating System
MS Windows 7 Ultimate 64-bit
CPU
Intel Core 2 Duo E8500 @ 3.16GHz 42 °C
Wolfdale 45nm Technology
RAM
4.0GB Dual-Channel DDR2 @ 401MHz (6-6-6-18)
Motherboard
MICRO-STAR INTERNATIONAL CO.,LTD G31M3-L V2(MS-7529) (CPU 1)
Graphics
StudioDsply21 @ 1600x1200
Moniteur non Plug-and-Play générique @ 1024x768
512MB GeForce 9800 GT (EVGA)

I recently install an old Creative SB Audigy 1 sound card but cant make it work properly (have some issue, probably the driver )

Thx
KEYHOLE

HijackThis Log:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 03:17:10, on 17/12/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal

Running processes:
C:\PROGRAM FILES (X86)\PANDA SECURITY\PANDA ANTIVIRUS PRO 2011\WebProxy.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.8.13\ccSvcHst.exe
C:\Program Files (x86)\EVGA Precision\EVGAPrecision.exe
C:\Users\K-HOLE\Documents\LCDSirReal\LCDSirReal.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
C:\Windows\SysWOW64\CtHelper.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2011\ApVxdWin.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\EVGA Precision\Bundle\OSDServer\RTSS.exe
C:\Program Files (x86)\Razer\DeathAdder\razertra.exe
C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe
C:\Users\K-HOLE\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\K-HOLE\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\K-HOLE\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\K-HOLE\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\K-HOLE\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\K-HOLE\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\K-HOLE\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\K-HOLE\Desktop\HijackThis-v2.0.4\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
O1 - Hosts: ::1 localhost
O1 - Hosts: ———————————
O1 - Hosts: | Hosts Optimisé par Hajdar pour |
O1 - Hosts: | le bonheur des internautes |
O1 - Hosts: | hTTp://AdZHosts.BlogSpot.Com |
O1 - Hosts: | |
O1 - Hosts: |Merci à tous pour votre soutiens |
O1 - Hosts: | |
O1 - Hosts: | [removed] |
O1 - Hosts: ———————————
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Razer Mamba Driver] C:\Program Files (x86)\Razer\Mamba\RazerTray.exe
O4 - HKLM\..\Run: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
O4 - HKLM\..\Run: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2011\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2011\Inicio.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKUS\S-1-5-18\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'Système')
O4 - HKUS\.DEFAULT\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'Default user')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: @appmgmts.dll,-3250 (AppMgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Service d'état ASP.NET (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (AudioSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000 (c2wts) - Unknown owner - C:\Program Files (x86)\Windows Identity Foundation\v3.5\c2wtshost.exe (file missing)
O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\ehome\ehrecvr.exe,-101 (ehRecvr) - Unknown owner - C:\Windows\ehome\ehRecvr.exe
O23 - Service: @%SystemRoot%\ehome\ehsched.exe,-101 (ehSched) - Unknown owner - C:\Windows\ehome\ehsched.exe
O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (eventlog) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: HyperDesk's Custom Theme Enabler (HyperDeskCustomThemeEnabler) - Unknown owner - C:\Windows\Installer\MSI9A8B.tmp (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-500 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\netprofm.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: NIHardwareService - Native Instruments GmbH - C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.8.13\SymcPCCULaunchSvc.exe
O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Panda Software Controller - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2011\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Unknown owner - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2011\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe
O23 - Service: Panda On-Access Anti-Malware Service (PAVSRV) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2011\pavsrvx86.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.8.13\ccSvcHst.exe
O23 - Service: @%SystemRoot%\system32\peerdistsvc.dll,-9000 (PeerDistSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - Unknown owner - C:\Windows\SysWow64\perfhost.exe
O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Panda Host Service (PSHost) - Unknown owner - c:\program files (x86)\panda security\panda antivirus pro 2011\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Security S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2011\PsImSvc.exe
O23 - Service: Panda PSK service (PskSvcRetail) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2011\PskSvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%windir%\WindowsMobile\rapimgr.dll,-104 (RapiMgr) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP2\RpcAgentSrv.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ipnathlp.dll,-106 (SharedAccess) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Spouleur d’impression (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppuinotify.dll,-103 (sppuinotify) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2011\TPSrvWow.exe
O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\umrdp.dll,-1000 (UmRdpService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%windir%\WindowsMobile\wcescomm.dll,-40079 (WcesComm) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe
O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.exe

–
End of file - 23325 bytes


📎OTL.Txt
📎hijackthis.txt

Hi Julien,

I removed your non-family-friendly avatar.
Here's one you could use if you wish…
[attachment removed: Keyhole_blank2.GIF]
:welcome:

If your downloading files with Torrents your going to get infected. If your using a registry cleaner with out supervision your going to damage your system

Download the HostsXpert 4.3 - Hosts File Manager.
  • Unzip HostsXpert 4.2.0.0 - Hosts File Manager to a convenient folder such as C:\HostsXpert
  • Click HostsXpert.exe to Run HostsXpert - Hosts File Manager from its new home
  • Click "Make Hosts Writable?" in the upper left corner.
  • Click Restore Microsoft's Hosts file and then click OK.
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.




Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
First: thanks for the reply
Second: while waiting for your reply i keep searching what can be those problems and finish to found a process named: smss.exe - here: http://www.neuber.com/taskmanager/process/smss.exe.html
i think this spyware/virus can be the cause of 1 of my problem. Sometimes i try to delete a file/folder and windows open me a error message similar to this: you need right from ThrustedInstaller to make change to this folder…. something like this. BUT IM THE ONLY ADMIN OF THIS PC.

3 other process and 1 other file i found suspicious:
-SYS78.exe
-swreg.exe
-AQ1LRTJ4.SYS

and 1 file called:
-SteelWerx

If your downloading files with Torrents your going to get infected.

true but im trying to scan them ASAP when download finish… :S ( im thinking running utorrent in a VM to prevent virus access… what you think ? )


Malwarebyte's Quick Scan Log:

The scan found nothing


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5371

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

21/12/2010 21:21:48
mbam-log-2010-12-21 (21-21-48).txt

Scan type: Quick scan
Objects scanned: 171814
Time elapsed: 2 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hi

Did you run HostsXpert ?

If you download with torrents your going to get infected .


Hijackthis is not used much any more, we are using other scanners that show us much more, run this quick scan and post the log please


Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
yes i run Hostsexpert before Malwarebytre like you said. 📎Attach.txt 📎DDS.txt DDS (Ver_10-12-12.02) - NTFS_AMD64 Run by [removed] at 11:04:32.35 on 21/12/2010 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22 Microsoft Windows 7 Édition Intégrale 6.1.7600.0.1252.2.1036.18.4095.2408 [GMT -5:00] AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5} SP: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\AUDIODG.EXE C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\SysWOW64\PnkBstrA.exe C:\Windows\SysWOW64\PnkBstrB.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\EVGA Precision\EVGAPrecision.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\EVGA Precision\Bundle\OSDServer\RTSS.exe C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe C:\Users\K-HOLE\Documents\LCDSirReal\LCDSirReal.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe C:\Program Files (x86)\Razer\DeathAdder\razertra.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files (x86)\uTorrent\uTorrent.exe C:\Users\K-HOLE\AppData\Roaming\uTorrent\apps\VirusGuard\VirusGuard.exe C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 7\firefox.exe C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 7\plugin-container.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\K-HOLE\Desktop\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = about:blank uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO: Programme d'aide de l'Assistant de connexion Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File TB: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File uRun: [UnHackMe Monitor] C:\Program Files (x86)\UnHackMe\hackmon.exe mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\Update ESET's license.lnk - C:\Program Files (x86)\ESET\MiNODLogin\MiNODLogin.exe mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: SoftwareSASGeneration = 1 (0x1) dPolicies-explorer: NoResolveTrack = 1 (0x1) IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll {9030D464-4C02-4ABF-8ECC-5164760863C6} TB-X64: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File TB-X64: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File mRun-x64: [RivaTunerStartupDaemon] "C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe" /S mRun-x64: [RivaTuner] "C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe" /T mRun-x64: [Launch LgDeviceAgent] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe" mRun-x64: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" mRun-x64: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE mRun-x64: [AsioReg] REGSVR32.EXE /S CTASIO.DLL mRun-x64: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice ================= FIREFOX =================== FF - ProfilePath - C:\Users\K-HOLE\AppData\Roaming\Mozilla\Firefox\Profiles\lptr2pic.default\ FF - prefs.js: browser.startup.homepage - hxxp://forums.whatthetech.com/index.php?showtopic=116080 FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q= FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\K-HOLE\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: C:\Users\K-HOLE\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll FF - plugin: C:\Users\K-HOLE\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ============= SERVICES / DRIVERS =============== R2 eamonm;eamonm;C:\Windows\System32\drivers\eamonm.sys [2010-3-24 163888] R2 ekrn;ESET Service;C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-3-24 810120] R2 epfwwfpr;epfwwfpr;C:\Windows\System32\drivers\epfwwfpr.sys [2010-3-24 124760] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2010-12-21 363344] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-4-9 1153368] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256] R3 DAdderFltr;DeathAdder Mouse;C:\Windows\System32\drivers\dadder.sys [2010-11-25 12032] R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;C:\Windows\System32\drivers\LGBusEnum.sys [2009-11-23 22408] R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;C:\Windows\System32\drivers\LGVirHid.sys [2009-11-23 16008] R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2010-4-9 24152] R3 RivaTuner64;RivaTuner64;C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2009-8-22 19952] R3 RTCore64;RTCore64;C:\Program Files (x86)\EVGA Precision\RTCore64.sys [2010-11-3 14440] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-9-20 344680] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc –> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [?] S2 MBAMDrvService;MBAMDrvService;C:\Windows\System32\drivers\mbam.sys [2010-4-9 24152] S3 c2wts;Claims to Windows Token Service;C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [2010-1-21 13080] S3 COMMONFX;COMMONFX;C:\Windows\System32\drivers\COMMONFX.sys [2010-12-13 158808] S3 CTAUDFX;CTAUDFX;C:\Windows\System32\drivers\CTAUDFX.sys [2010-12-13 706648] S3 CTERFXFX;CTERFXFX;C:\Windows\System32\drivers\CTERFXFX.sys [2010-12-13 141912] S3 CTSBLFX;CTSBLFX;C:\Windows\System32\drivers\CTSBLFX.sys [2010-12-13 681048] S3 CYUSB;Cypress Generic USB Driver;C:\Windows\System32\drivers\CYUSB.sys [2010-4-9 47104] S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2010-8-29 48480] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-22 1493352] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-9-28 51712] S3 WatAdminSvc;WatAdminSvc;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-4-9 1255736] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] =============== Created Last 30 ================ 2010-12-22 02:18:45 38224 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2010-12-22 02:18:42 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2010-12-22 02:14:35 ——– d—–w- C:\HostsXpert 2010-12-21 08:46:22 37600 —-a-w- C:\Windows\SysWow64\Partizan.exe 2010-12-21 08:08:07 ——– d—–w- C:\122go - BACKUP E 2010-12-21 07:28:33 24416 —-a-w- C:\Windows\SysWow64\drivers\regguard.sys 2010-12-21 07:26:38 438 —-a-w- C:\Windows\SYSTEM32LOGRTIZAN.EXE 2010-12-21 07:24:10 37600 —-a-w- C:\Windows\System32\Partizan.exe 2010-12-21 07:22:31 35816 —-a-w- C:\Windows\SysWow64\drivers\Partizan.sys 2010-12-21 07:22:30 2 –shatr- C:\Windows\winstart.bat 2010-12-21 07:22:26 12808 —-a-w- C:\Windows\SysWow64\drivers\UnHackMeDrv.sys 2010-12-21 07:22:24 ——– d—–w- C:\Program Files (x86)\UnHackMe 2010-12-18 08:24:31 ——– d-sh–w- C:\$RECYCLE.BIN 2010-12-18 08:15:22 ——– d—–w- C:\Users\K-HOLE\AppData\Local\temp 2010-12-18 08:06:20 98816 —-a-w- C:\Windows\sed.exe 2010-12-18 08:06:20 89088 —-a-w- C:\Windows\MBR.exe 2010-12-18 08:06:20 256512 —-a-w- C:\Windows\PEV.exe 2010-12-18 08:06:20 161792 —-a-w- C:\Windows\SWREG.exe 2010-12-18 08:06:17 ——– d—–w- C:\ComboFix 2010-12-18 01:07:01 189520 —-a-w- C:\Windows\SysWow64\drivers\tmcomm.sys 2010-12-18 00:54:18 ——– d—–w- C:\Users\K-HOLE\AppData\Roaming\BSD 2010-12-18 00:54:18 ——– d—–w- C:\PROGRA~3\BSD 2010-12-18 00:54:10 2226176 —-a-w- C:\Windows\bsdsetup.dll 2010-12-18 00:54:10 ——– d—–w- C:\Program Files (x86)\DriverHive 2010-12-18 00:52:41 12872 —-a-w- C:\Windows\System32\bootdelete.exe 2010-12-18 00:47:06 19528 —-a-w- C:\Windows\System32\drivers\hitmanpro35.sys 2010-12-18 00:47:05 ——– d—–w- C:\Program Files\Hitman Pro 3.5 2010-12-18 00:46:02 ——– d—–w- C:\PROGRA~3\Hitman Pro 2010-12-17 15:19:18 ——– d—–w- C:\Program Files\ESET 2010-12-17 11:32:51 ——– d—–w- C:\PROGRA~3\Kaspersky Lab Setup Files 2010-12-17 11:05:54 ——– d—–w- C:\Users\K-HOLE\AppData\Roaming\SUPERAntiSpyware.com 2010-12-16 15:05:58 ——– d—–w- C:\Program Files\iPod 2010-12-16 15:05:54 ——– d—–w- C:\Program Files\iTunes 2010-12-16 15:03:03 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2010-12-16 15:03:03 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2010-12-16 15:03:03 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2010-12-16 15:03:03 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2010-12-16 15:03:03 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2010-12-16 15:03:03 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2010-12-16 15:03:03 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2010-12-16 10:05:53 ——– d—–w- C:\Windows\FltMgr 2010-12-16 09:58:48 ——– d—–w- C:\PROGRA~3\Panda Security 2010-12-16 09:34:41 ——– d—–w- C:\Program Files (x86)\Panda Security 2010-12-16 09:27:14 5632 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe 2010-12-16 09:21:11 ——– d—–w- C:\Program Files (x86)\Common Files\Symantec Shared 2010-12-16 09:18:55 ——– d—–w- C:\PROGRA~3\Symantec 2010-12-16 09:15:29 ——– d—–w- C:\Users\K-HOLE\AppData\Roaming\Tific 2010-12-16 09:15:29 ——– d—–w- C:\Users\K-HOLE\AppData\Local\Tific 2010-12-16 09:15:13 ——– d—–w- C:\PROGRA~3\Norton 2010-12-16 09:15:08 ——– d—–w- C:\PROGRA~3\NortonInstaller 2010-12-16 05:13:29 ——– d—–w- C:\Users\K-HOLE\AppData\Roaming\GetRightToGo 2010-12-16 01:13:38 ——– d—–w- C:\Program Files\Internet TV 2010-12-16 01:09:05 ——– d—–w- C:\Users\K-HOLE\AppData\Roaming\FDRLab 2010-12-16 01:05:23 679936 —-a-w- C:\Windows\SysWow64\D3DX81ab.dll 2010-12-16 01:05:23 1970176 —-a-w- C:\Windows\SysWow64\d3dx9.dll 2010-12-15 22:41:40 ——– d—–w- C:\Program Files (x86)\Geeks3D 2010-12-15 19:15:41 ——– d—–w- C:\Program Files (x86)\Emsisoft Anti-Malware 2010-12-14 21:57:07 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2010-12-14 21:57:07 2048 —-a-w- C:\Windows\System32\tzres.dll 2010-12-14 07:24:19 ——– d—–w- C:\Program Files (x86)\Common Files\Futuremark Shared 2010-12-14 06:56:49 ——– d—–w- C:\Program Files (x86)\OpenAL 1.1 SDK 2010-12-14 06:54:50 109080 —-a-w- C:\Windows\SysWow64\OpenAL32.dll 2010-12-14 06:10:01 5632 —-a-w- C:\Windows\SysWow64\drivers\Entech64.sys 2010-12-14 06:10:01 3972 —-a-w- C:\Windows\SysWow64\drivers\PciBus.sys 2010-12-14 06:10:01 21664 —-a-w- C:\Windows\SysWow64\drivers\Entech.sys 2010-12-14 06:10:01 ——– d—–w- C:\Windows\SysWow64\Futuremark 2010-12-14 06:09:13 ——– d—–w- C:\Program Files (x86)\Futuremark 2010-12-14 05:46:06 ——– d—–w- C:\Program Files (x86)\ATITool 2010-12-14 05:08:09 69715 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll 2010-12-14 05:08:09 5632 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe 2010-12-14 05:08:09 266240 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll 2010-12-14 05:08:09 192512 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll 2010-12-14 05:08:08 729088 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll 2010-12-14 05:07:57 188548 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll 2010-12-14 05:07:56 311428 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll 2010-12-13 23:46:07 86016 —-a-w- C:\Windows\SysWow64\cttele.dll 2010-12-13 05:51:03 ——– d—–w- C:\Windows\WindowsMobile 2010-12-13 02:19:30 ——– d—–w- C:\Program Files (x86)\Wepgen 2010-12-12 22:01:35 ——– d—–w- C:\PROGRA~3\Laconic Software 2010-12-11 07:57:39 ——– d—–w- C:\Users\K-HOLE\AppData\Roaming\UrbanTerror 2010-12-07 03:09:20 ——– d—–w- C:\Program Files (x86)\Counter Strike Source 2010 2010-12-03 06:29:54 314016 —-a-w- C:\Windows\System32\drivers\atksgt.sys 2010-12-03 06:29:53 43680 —-a-w- C:\Windows\System32\drivers\lirsgt.sys 2010-12-03 06:25:14 ——– d—–w- C:\PROGRA~3\Solidshield 2010-11-30 09:15:32 ——– d—–w- C:\Program Files (x86)\Counter-Strike 2D 2010-11-29 22:39:03 72200 —-a-w- C:\Windows\System32\XAPOFX1_1.dll 2010-11-29 22:39:03 68616 —-a-w- C:\Windows\SysWow64\XAPOFX1_1.dll 2010-11-29 22:39:03 513544 —-a-w- C:\Windows\System32\XAudio2_2.dll 2010-11-29 22:39:03 509448 —-a-w- C:\Windows\SysWow64\XAudio2_2.dll 2010-11-29 22:39:02 540688 —-a-w- C:\Windows\System32\d3dx10_39.dll 2010-11-29 22:39:02 467984 —-a-w- C:\Windows\SysWow64\d3dx10_39.dll 2010-11-29 22:39:02 1942552 —-a-w- C:\Windows\System32\D3DCompiler_39.dll 2010-11-29 22:39:02 1493528 —-a-w- C:\Windows\SysWow64\D3DCompiler_39.dll 2010-11-29 22:39:00 4992520 —-a-w- C:\Windows\System32\D3DX9_39.dll 2010-11-29 22:39:00 3851784 —-a-w- C:\Windows\SysWow64\D3DX9_39.dll 2010-11-29 22:38:30 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx 2010-11-29 22:38:30 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts 2010-11-25 05:00:07 12032 —-a-w- C:\Windows\System32\drivers\dadder.sys 2010-11-25 01:23:53 ——– d—–w- C:\Users\K-HOLE\AppVerifierLogs 2010-11-24 11:43:14 7680 —-a-w- C:\Program Files\Internet Explorer\iecompat.dll 2010-11-24 11:43:14 7680 —-a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll 2010-11-23 08:47:23 ——– d—–w- C:\Users\K-HOLE\AppData\Local\Cranium 2010-11-23 08:42:38 ——– d—–w- C:\PROGRA~3\VOWSoft 2010-11-23 08:42:37 ——– d—–w- C:\Program Files (x86)\plist Editor for Windows 2010-11-23 02:41:44 ——– d—–w- C:\Users\K-HOLE\AppData\Roaming\DiskAid 2010-11-23 02:07:23 ——– d—–w- C:\Program Files (x86)\TightVNC 2010-11-21 23:54:49 ——– d—–w- C:\Program Files (x86)\DigiDNA 2010-11-21 23:43:18 ——– d—–w- C:\Users\K-HOLE\AppData\Local\Cranium_Consulting_and_Cu 2010-11-21 23:39:24 ——– d—–w- C:\Program Files (x86)\iPhoneBrowser ==================== Find3M ==================== 2010-12-20 23:08:40 24152 —-a-w- C:\Windows\System32\drivers\mbam.sys 2010-12-14 06:57:25 122904 —-a-w- C:\Windows\System32\OpenAL32.dll 2010-12-14 06:57:21 466520 —-a-w- C:\Windows\System32\wrap_oal.dll 2010-12-14 06:57:21 445016 —-a-w- C:\Windows\SysWow64\wrap_oal.dll 2010-11-07 06:59:39 189480 —-a-w- C:\Windows\SysWow64\PnkBstrB.xtr 2010-11-07 06:59:39 189480 —-a-w- C:\Windows\SysWow64\PnkBstrB.exe 2010-11-07 06:25:14 277 —-a-w- C:\WorkerOutput.bin 2010-11-06 05:30:59 82816 —-a-w- C:\Users\K-HOLE\AppData\Roaming\pcouffin.sys 2010-11-04 06:38:12 57856 —-a-w- C:\Windows\System32\licmgr10.dll 2010-11-04 06:35:53 1194496 —-a-w- C:\Windows\System32\wininet.dll 2010-11-04 05:52:17 978944 —-a-w- C:\Windows\SysWow64\wininet.dll 2010-11-04 05:52:12 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll 2010-11-04 05:16:14 482816 —-a-w- C:\Windows\System32\html.iec 2010-11-04 04:43:48 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2010-11-04 04:41:26 386048 —-a-w- C:\Windows\SysWow64\html.iec 2010-11-04 04:10:00 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2010-11-02 05:23:15 1198592 —-a-w- C:\Windows\System32\taskschd.dll 2010-11-02 05:18:17 524288 —-a-w- C:\Windows\System32\wmicmiplugin.dll 2010-11-02 05:17:38 473600 —-a-w- C:\Windows\System32\taskcomp.dll 2010-11-02 05:16:53 1114624 —-a-w- C:\Windows\System32\schedsvc.dll 2010-11-02 05:10:47 464384 —-a-w- C:\Windows\System32\taskeng.exe 2010-11-02 05:10:32 285696 —-a-w- C:\Windows\System32\schtasks.exe 2010-11-02 04:40:36 305152 —-a-w- C:\Windows\SysWow64\taskcomp.dll 2010-11-02 04:34:44 192000 —-a-w- C:\Windows\SysWow64\taskeng.exe 2010-11-02 04:34:33 179712 —-a-w- C:\Windows\SysWow64\schtasks.exe 2010-11-02 04:28:47 505856 —-a-w- C:\Windows\SysWow64\taskschd.dll 2010-10-25 23:56:12 794408 —-a-w- C:\Windows\SysWow64\pbsvc.exe 2010-10-25 23:56:12 75064 —-a-w- C:\Windows\SysWow64\PnkBstrA.exe 2010-10-20 05:20:01 46080 —-a-w- C:\Windows\System32\atmlib.dll 2010-10-20 04:54:18 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2010-10-20 03:09:15 3124224 —-a-w- C:\Windows\System32\win32k.sys 2010-10-20 03:05:46 367104 —-a-w- C:\Windows\System32\atmfd.dll 2010-10-20 02:58:41 294400 —-a-w- C:\Windows\SysWow64\atmfd.dll 2010-10-16 18:13:54 5901416 —-a-w- C:\Windows\System32\nvcpl.dll 2010-10-16 18:13:34 989800 —-a-w- C:\Windows\System32\nvvsvc.exe 2010-10-16 18:13:34 2590824 —-a-w- C:\Windows\System32\nvsvc64.dll 2010-10-16 18:13:34 116328 —-a-w- C:\Windows\System32\nvmctray.dll 2010-10-16 05:23:13 112000 —-a-w- C:\Windows\System32\consent.exe 2010-10-16 05:19:41 395776 —-a-w- C:\Windows\System32\webio.dll 2010-10-16 04:36:10 314368 —-a-w- C:\Windows\SysWow64\webio.dll 2010-10-07 17:36:16 96544 —-a-w- C:\Windows\System32\dnssd.dll 2010-10-07 17:36:16 69408 —-a-w- C:\Windows\System32\jdns_sd.dll 2010-10-07 17:36:16 237856 —-a-w- C:\Windows\System32\dnssdX.dll 2010-10-07 17:36:16 119584 —-a-w- C:\Windows\System32\dns-sd.exe 2010-10-07 17:23:02 91424 —-a-w- C:\Windows\SysWow64\dnssd.dll 2010-10-07 17:23:02 107808 —-a-w- C:\Windows\SysWow64\dns-sd.exe 2010-09-28 20:44:52 51712 —-a-w- C:\Windows\System32\drivers\usbaapl64.sys 2010-09-28 20:44:52 4184352 —-a-w- C:\Windows\System32\usbaaplrc.dll 2010-09-25 03:11:48 2267 —-a-w- C:\PROGRA~3\xml2E6B.tmp 2010-09-25 03:11:47 5831 —-a-w- C:\PROGRA~3\xml27E1.tmp 2010-09-25 03:11:47 13289 —-a-w- C:\PROGRA~3\xml2D50.tmp 2010-09-23 04:47:28 49016 —-a-w- C:\Windows\SysWow64\sirenacm.dll 2010-09-23 04:32:56 301936 —-a-w- C:\Windows\WLXPGSS.SCR ============= FINISH: 11:05:23.58 ===============
Not seeing anything bad.

Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.



ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
i run the scan twice first time found a trojan scond time found another trojan now pc seems ok thanks a lot guys for all your help i wish you all a merry christmas :) KEY
Merry Christmas to you to Key.

I am glad things are working better but I would love to see the report on what ESET removed , it might give a clue on if we need to look further, can you remember what was removed, you may be able to find it in the ESET folder

C:\Program Files\EsetOnlineScanner\log.txt
i know i had remove 2 trojan the 2 infecteds files we see here (Se7en Eternity.iso and Windows_7_Loader_eXtreme-Edition v3.503) have been deleted too ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=5f75203fba83b74b9c6e078a5c944d2a # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-12-21 11:58:37 # local_time=2010-12-21 06:58:37 (-0500, Est) # country="Canada" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1536 16777215 100 0 0 0 0 0 # compatibility_mode=5893 16776574 100 94 7506058 44517499 0 0 # compatibility_mode=8199 39157181 100 72 0 22572205 0 0 # scanned=36011 # found=1 # cleaned=0 # scan_time=1868 # nod_component=V3 Build:0x30000000 C:\122go - BACKUP E\uTorrent Finish\Se7en Eternity.iso probably a variant of Win32/Agent.MAGOIAQ trojan (unable to clean) 00000000000000000000000000000000 I esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=5f75203fba83b74b9c6e078a5c944d2a # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-12-22 01:59:27 # local_time=2010-12-22 08:59:27 (-0500, Est) # country="Canada" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1536 16777215 100 0 0 0 0 0 # compatibility_mode=5893 16776574 100 94 7548103 44559544 0 0 # compatibility_mode=8199 39157181 100 72 0 22614250 0 0 # scanned=365038 # found=1 # cleaned=0 # scan_time=10272 # nod_component=V3 Build:0x30000000 C:\122go - BACKUP E\uTorrent Finish\Windows_7_Loader_eXtreme-Edition v3.503\w7lxe.exe multiple threats (unable to clean) 00000000000000000000000000000000 I
If you download with torrents your going to get infected .



Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
This thread is being closed on account of downloading pirated software via the torrents. Besides being illegal its also a good way of infecting your computer. If you post back and File Sharing Programs or illegal software is found on your system then no help will be offered.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI