This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Machine infected, viruses/maleware

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi i been working on this computer for a very long time, trying to resolve a critical issue with my pc being rather slow. I think i finally found the root of the problem. Before i talk about my virus issue, i want to share with you a bit what i think it is.

First of all i have ran Memtest for memory for all my ram cards over night and none of them received any sector errors at all. That being said, i can certainly say its not my ram thats causing the slow downs.

I found out that windows 7 32bit OS only allows like 2.75 gb of ram. Well there lies my problem indefinitely. I actually have 4 gb of ram in my computer right now and its only able to read 2.42 it says. I know there is no other known hard ware issues because i basically did a complete over haul of my pc just recently. It is impossible for me to have any other hardware related issues at this time. I just recently bought a new graphics card. A GTX 450. I had a 8800 GTS in my computer prior. The moment i installed that graphics card, my computer just turned into the "titanic" It is so ridiculously slow i can't hardly do anything. I believe this cause is because i don't have enough physical memory. The card that i had prior, only required bout 300 mb of memory. This new card requires 1gb of memory. I do have 4 gb of RAM in my computer but since my 32 bit OS is limiting my memory usage, im only able to use so much. When i installed that card, it just made matters even worse.

Anyways i know your know qualified to technically help me with these problems as you only deal with work in maleware but i wanted to give you kind of an analysis of what my computer is doing. Anyways what i want to do, is get rid of windows OS 32 bit and install windows OS 64 bit. I think that will reduce alot of my issues with my computer being slow. Because i can install my full 8 gb of ram into my computer.

Now bout the viruses. My internet is redirecting URLS. I tried to make a payment online for a bank account and it wont take my user id or password information, because its trying to redirect the URL to a different website. After bout 3 failed attempts at entering my user id and pass for my bank. They locked me out. so now i have to call them in order to make a payment. I was able to do it just fine on another pc, so i know for a fact this computer has the problems. Also i can't stream literally anything. Youtube is slow, megavideo is slow. Web pages are really slow and some times my browser will just freeze. This is kind of strange for me to have infections this early because i just recently reformatted my drive and started copying information over. Evidently something that i copied over from one of my external hard drives. Infected my machine again.

Anyways there is quite alot of data on my C drive, do i have to reformat again before installing windows OS 64 bit. Because if possible i would like to just do a direct re installed of the OS 64 bit and then start cleaning up my machine. I want to make absolutely sure that i do not infect my self again. I seem to have this problem ALL the time and its really agitating me. I am almost thinking bout just deleting all my old software and re downloading all new software. Starting completely fresh with new programs.

So yeah two things i want to do, fix my memory problem, by installing windows OS 64 bit and also cleaning up my machine so i dont get any more future infections.

Anyways here is my DDS log

.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_25
Run by [removed] at 12:21:01 on 2011-05-27
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2551.800 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\taskhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Users\Jeff\Desktop\dds(1).scr
C:\Windows\system32\WSCRIPT.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Mal Updater 2] c:\program files\mal updater 2\MalUpdater.exe
uRun: [PlayNC Launcher]
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10p_Plugin.exe -update plugin
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: []
StartupFolder: c:\users\jeff\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jeff\appdata\roaming\mozilla\firefox\profiles\ch5zmo76.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsl5254a14a;MpKsl5254a14a;c:\programdata\microsoft\microsoft antimalware\definition updates\{a9895eee-8585-477d-97d4-67f43bb01c71}\MpKsl5254a14a.sys [2011-5-26 28752]
R2 NAUpdate;Nero Update;c:\program files\nero\update\NASvc.exe [2011-3-29 598312]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-7-13 311296]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-4-29 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2011-05-26 10:26:55 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{a9895eee-8585-477d-97d4-67f43bb01c71}\MpKsl5254a14a.sys
2011-05-26 10:26:18 6962000 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{a9895eee-8585-477d-97d4-67f43bb01c71}\mpengine.dll
2011-05-26 00:12:10 ——– d—–w- c:\users\jeff\appdata\local\assembly
2011-05-25 22:50:50 ——– d—–w- c:\program files\NCsoft
2011-05-25 22:49:10 ——– d-sh–w- c:\users\jeff\appdata\roaming\.#
2011-05-25 09:13:12 ——– d—–w- c:\users\jeff\appdata\roaming\AnvSoft
2011-05-25 09:13:02 ——– d—–w- c:\program files\AnvSoft
2011-05-25 06:14:47 26496 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-05-25 03:54:07 ——– d—–w- c:\users\jeff\appdata\local\{254ABDCA-A421-4182-9720-2EDF10C5C4EF}
2011-05-25 03:46:18 ——– d—–w- c:\windows\en
2011-05-25 03:38:39 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2011-05-25 03:37:24 ——– d—–w- c:\windows\PCHEALTH
2011-05-24 05:33:20 ——– d—–w- c:\users\jeff\appdata\local\{126A424F-D7FC-4BFB-8E84-AF71782DB5B0}
2011-05-24 04:13:13 ——– d—–w- c:\program files\SquareEnix
2011-05-23 10:25:51 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll
2011-05-23 10:25:46 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\{243c3b92-6a5b-43ac-9c62-95ab1e06e6b0}\gapaengine.dll
2011-05-18 23:17:46 123904 —-a-w- c:\windows\system32\poqexec.exe
2011-05-17 15:07:48 ——– d—–w- c:\users\jeff\appdata\roaming\avidemux
2011-05-17 15:07:38 ——– d—–w- c:\program files\Avidemux 2.5
2011-05-12 14:29:18 ——– d—–w- c:\users\jeff\appdata\local\{967727EA-AEA5-4758-8E97-695EE7B66DFC}
2011-05-12 06:29:39 3957632 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-05-12 06:29:39 3901824 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-05-12 06:29:34 43008 —-a-w- c:\windows\system32\drivers\usbehci.sys
2011-05-12 06:29:34 284160 —-a-w- c:\windows\system32\drivers\usbport.sys
2011-05-12 06:29:33 75776 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2011-05-12 06:29:33 5888 —-a-w- c:\windows\system32\drivers\usbd.sys
2011-05-12 06:29:33 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys
2011-05-12 06:29:33 24064 —-a-w- c:\windows\system32\drivers\usbuhci.sys
2011-05-12 06:29:33 20480 —-a-w- c:\windows\system32\drivers\usbohci.sys
2011-05-07 22:28:19 ——– d—–w- c:\users\jeff\appdata\local\{EA48DFFF-28F9-4913-A6B9-751546ECB93C}
2011-05-07 14:42:53 ——– d—–w- c:\windows\system32\appmgmt
2011-05-06 22:27:43 ——– d—–w- c:\users\jeff\appdata\local\{643CF913-DC6A-440E-A66C-18D9F33A533F}
2011-05-06 20:56:00 175616 —-a-w- c:\windows\system32\unrar.dll
2011-05-06 20:55:56 ——– d—–w- c:\program files\K-Lite Codec Pack
2011-05-03 01:14:34 ——– d—–w- c:\users\jeff\appdata\local\{F67A9513-F66C-43F5-92CE-9E1DB0259ADB}
2011-05-02 08:24:36 ——– d—–w- C:\Anime
2011-05-02 08:21:49 ——– d—–w- c:\users\jeff\appdata\roaming\Mal Updater
2011-05-02 08:21:35 ——– d—–w- c:\program files\Mal Updater 2
2011-05-02 08:15:02 ——– d—–w- c:\users\jeff\appdata\local\{55B87F8F-35F1-4075-A63F-ABFCE4404A44}
2011-05-02 08:11:19 ——– d—–w- c:\program files\DVDFab 8
2011-05-02 08:01:21 ——– d—–w- c:\users\jeff\appdata\roaming\OpenOffice.org
2011-05-02 07:59:40 ——– d—–w- c:\program files\JRE
2011-05-02 07:59:13 ——– d—–w- c:\program files\OpenOffice.org 3
2011-04-30 23:22:47 ——– d—–w- c:\programdata\WEBREG
2011-04-30 23:16:01 ——– d—–w- c:\users\jeff\appdata\local\HP
2011-04-30 23:15:19 321536 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\hpzpp696.dll
2011-04-30 22:56:17 ——– d—–w- c:\users\jeff\appdata\roaming\HpUpdate
2011-04-30 22:56:14 ——– d—–w- c:\program files\Coupons
2011-04-30 22:52:55 ——– d—–w- c:\program files\common files\HP
2011-04-30 22:52:35 ——– d—–w- c:\program files\common files\Hewlett-Packard
2011-04-30 22:51:35 118272 —-a-w- c:\windows\system32\hpz3l696.dll
2011-04-30 22:51:14 ——– d—–w- c:\program files\HP
2011-04-30 22:50:26 261432 —-a-w- c:\windows\system32\hpzids01.dll
2011-04-30 22:50:24 966656 —-a-w- c:\windows\system32\hpost_p02a.dll
2011-04-30 22:50:24 737280 —-a-w- c:\windows\system32\hposwia_p02a.dll
2011-04-30 22:50:23 307200 —-a-w- c:\windows\system32\hposc_p02a.dll
2011-04-30 22:15:36 ——– d—–w- c:\users\jeff\appdata\roaming\Windows Live Writer
2011-04-30 22:15:36 ——– d—–w- c:\users\jeff\appdata\local\Windows Live Writer
2011-04-30 16:39:43 ——– d—–w- c:\users\jeff\appdata\local\{B4E96D64-0788-4367-BE75-5E04249DE109}
2011-04-29 18:31:21 ——– d—–w- c:\windows\system32\Wat
2011-04-29 15:56:52 6962000 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-04-29 10:13:11 257024 —-a-w- c:\windows\system32\msv1_0.dll
2011-04-29 10:11:03 99176 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2011-04-29 10:11:03 49472 —-a-w- c:\windows\system32\netfxperf.dll
2011-04-29 10:11:03 297808 —-a-w- c:\windows\system32\mscoree.dll
2011-04-29 10:11:03 295264 —-a-w- c:\windows\system32\PresentationHost.exe
2011-04-29 10:11:03 1130824 —-a-w- c:\windows\system32\dfshim.dll
2011-04-29 10:02:06 190976 —-a-w- c:\windows\system32\drivers\ks.sys
2011-04-29 10:01:22 ——– d—–w- c:\program files\MSXML 4.0
2011-04-29 10:00:52 276992 —-a-w- c:\windows\system32\wcncsvc.dll
2011-04-28 17:16:24 ——– d—–w- c:\users\jeff\appdata\local\{96992E14-4E64-41A9-AA7F-019279337BF7}
2011-04-28 17:16:07 ——– d—–w- c:\users\jeff\Tracing
2011-04-28 16:56:07 ——– d—–w- c:\users\jeff\appdata\local\MPlayer
2011-04-28 15:22:56 ——– d—–w- c:\program files\Microsoft
2011-04-28 15:19:11 ——– d—–w- c:\program files\uTorrent
2011-04-28 15:18:24 ——– d—–w- c:\users\jeff\appdata\roaming\uTorrent
2011-04-28 15:17:25 69464 —-a-w- c:\windows\system32\XAPOFX1_3.dll
2011-04-28 15:17:25 515416 —-a-w- c:\windows\system32\XAudio2_5.dll
2011-04-28 15:17:25 453456 —-a-w- c:\windows\system32\d3dx10_42.dll
2011-04-28 15:17:17 15712 —-a-w- c:\program files\common files\windows live\.cache\5c8db1871cc05b706\MeshBetaRemover.exe
2011-04-28 15:17:13 94040 —-a-w- c:\program files\common files\windows live\.cache\59beb6621cc05b705\DSETUP.dll
2011-04-28 15:17:13 525656 —-a-w- c:\program files\common files\windows live\.cache\59beb6621cc05b705\DXSETUP.exe
2011-04-28 15:17:13 1691480 —-a-w- c:\program files\common files\windows live\.cache\59beb6621cc05b705\dsetup32.dll
2011-04-28 15:16:40 3426072 —-a-w- c:\windows\system32\d3dx9_32.dll
2011-04-28 15:16:29 94040 —-a-w- c:\program files\common files\windows live\.cache\3f1b322e1cc05b704\DSETUP.dll
2011-04-28 15:16:29 525656 —-a-w- c:\program files\common files\windows live\.cache\3f1b322e1cc05b704\DXSETUP.exe
2011-04-28 15:16:29 1691480 —-a-w- c:\program files\common files\windows live\.cache\3f1b322e1cc05b704\dsetup32.dll
2011-04-28 15:08:45 2983424 —-a-w- c:\windows\system32\UIRibbon.dll
2011-04-28 15:08:45 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2011-04-28 15:07:32 3181568 —-a-w- c:\windows\system32\mf.dll
2011-04-28 15:07:32 196608 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-04-28 15:07:31 1619456 —-a-w- c:\windows\system32\WMVDECOD.DLL
2011-04-28 15:07:09 ——– d—–w- c:\users\jeff\appdata\roaming\PMS
2011-04-28 15:06:50 ——– d—–w- c:\program files\PS3 Media Server
2011-04-28 15:06:15 ——– d—–w- c:\users\jeff\appdata\local\Windows Live
2011-04-28 15:06:13 ——– d—–w- c:\program files\common files\Windows Live
2011-04-28 14:54:46 ——– d—–w- c:\program files\DVD Shrink
2011-04-28 14:49:51 ——– d—–w- c:\program files\common files\xing shared
2011-04-28 14:47:58 ——– dcsh–w- c:\program files\common files\WindowsLiveInstaller
2011-04-28 14:46:16 ——– d—–w- c:\users\jeff\appdata\roaming\CometPlayer
2011-04-28 14:44:34 ——– d—–w- c:\program files\DVD Decrypter
2011-04-28 14:43:59 ——– d—–w- c:\program files\VideoLAN
2011-04-28 14:43:10 ——– d—–w- c:\programdata\boost_interprocess
2011-04-28 14:43:05 ——– d—–w- c:\users\jeff\appdata\roaming\TigerPlayer
2011-04-28 14:42:32 ——– d—–w- c:\program files\MpcStar
2011-04-28 14:33:14 ——– d—–w- c:\users\jeff\appdata\roaming\Malwarebytes
2011-04-28 14:33:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-28 14:33:08 ——– d—–w- c:\programdata\Malwarebytes
2011-04-28 14:33:05 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-04-28 14:33:02 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-04-28 14:32:23 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-04-28 14:11:16 ——– d—–w- c:\programdata\Nero
2011-04-28 14:10:16 ——– d—–w- c:\program files\Nero
2011-04-28 14:05:54 1974616 —-a-w- c:\windows\system32\D3DCompiler_42.dll
2011-04-28 14:05:26 1892184 —-a-w- c:\windows\system32\D3DX9_42.dll
2011-04-28 14:04:54 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll
2011-04-28 14:04:27 3727720 —-a-w- c:\windows\system32\d3dx9_35.dll
2011-04-28 14:04:04 3497832 —-a-w- c:\windows\system32\d3dx9_34.dll
2011-04-28 13:56:52 ——– d—–w- c:\users\jeff\appdata\local\Adobe
2011-04-28 13:50:08 417792 —-a-w- c:\windows\system32\msdri.dll
2011-04-28 13:50:08 204288 —-a-w- c:\windows\system32\MSNP.ax
2011-04-28 13:50:07 465408 —-a-w- c:\windows\system32\psisdecd.dll
2011-04-28 13:48:47 28672 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-04-28 13:48:47 132608 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-04-28 13:48:39 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-04-28 13:48:39 294912 —-a-w- c:\windows\system32\atmfd.dll
2011-04-28 13:48:19 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\{42b072bb-4a7f-4d7b-9027-357faf4a87d4}\gapaengine.dll
2011-04-28 13:46:00 516096 —-a-w- c:\program files\windows mail\wab.exe
2011-04-28 13:44:50 37376 —-a-w- c:\windows\system32\rtutils.dll
2011-04-28 13:44:49 1619968 —-a-w- c:\program files\windows mail\msoe.dll
2011-04-28 13:44:45 541184 —-a-w- c:\windows\system32\kerberos.dll
2011-04-28 13:44:38 507568 —-a-w- c:\windows\system32\winload.exe
2011-04-28 13:44:38 442920 —-a-w- c:\windows\system32\winresume.exe
2011-04-28 13:44:38 1320960 —-a-w- c:\windows\system32\CertEnroll.dll
2011-04-28 13:43:47 67584 —-a-w- c:\windows\system32\asycfilt.dll
2011-04-28 13:43:46 530432 —-a-w- c:\windows\system32\comctl32.dll
2011-04-28 13:43:00 954752 —-a-w- c:\windows\system32\mfc40.dll
2011-04-28 13:42:59 954288 —-a-w- c:\windows\system32\mfc40u.dll
2011-04-28 13:42:02 164864 —-a-w- c:\program files\windows media player\wmplayer.exe
2011-04-28 13:42:01 12625408 —-a-w- c:\windows\system32\wmploc.DLL
2011-04-28 13:41:55 2331136 —-a-w- c:\windows\system32\win32k.sys
2011-04-28 13:41:51 191488 —-a-w- c:\windows\system32\FXSCOVER.exe
2011-04-28 13:41:50 70656 —-a-w- c:\windows\system32\fontsub.dll
2011-04-28 13:41:48 442880 —-a-w- c:\windows\system32\XpsPrint.dll
2011-04-28 13:41:41 292864 —-a-w- c:\windows\system32\apphelp.dll
2011-04-28 13:41:37 288256 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-04-28 13:38:55 1164288 —-a-w- c:\windows\system32\mfc42u.dll
2011-04-28 13:38:55 1137664 —-a-w- c:\windows\system32\mfc42.dll
2011-04-28 13:38:54 91648 —-a-w- c:\windows\system32\avifil32.dll
2011-04-28 13:38:54 84480 —-a-w- c:\windows\system32\mciavi32.dll
2011-04-28 13:38:54 50176 —-a-w- c:\windows\system32\iyuv_32.dll
2011-04-28 13:38:54 31744 —-a-w- c:\windows\system32\msvidc32.dll
2011-04-28 13:38:54 22016 —-a-w- c:\windows\system32\msyuv.dll
2011-04-28 13:38:54 13312 —-a-w- c:\windows\system32\msrle32.dll
2011-04-28 13:38:54 1328640 —-a-w- c:\windows\system32\quartz.dll
2011-04-28 13:38:54 12288 —-a-w- c:\windows\system32\tsbyuv.dll
2011-04-28 13:32:29 642048 —-a-w- c:\windows\system32\CPFilters.dll
2011-04-28 13:32:28 850432 —-a-w- c:\windows\system32\sbe.dll
2011-04-28 13:32:28 534528 —-a-w- c:\windows\system32\EncDec.dll
2011-04-28 13:32:28 199680 —-a-w- c:\windows\system32\mpg2splt.ax
2011-04-28 13:32:20 2614784 —-a-w- c:\windows\explorer.exe
2011-04-28 13:32:17 314368 —-a-w- c:\windows\system32\webio.dll
2011-04-28 13:32:12 2690560 —-a-w- c:\windows\system32\mstscax.dll
2011-04-28 13:32:11 1034240 —-a-w- c:\windows\system32\mstsc.exe
2011-04-28 13:31:49 740864 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-28 13:30:57 168448 —-a-w- c:\windows\system32\srvsvc.dll
2011-04-28 13:30:47 1289536 —-a-w- c:\windows\system32\ntdll.dll
2011-04-28 13:29:44 204288 —-a-w- c:\windows\system32\upnp.dll
2011-04-28 13:29:43 80384 —-a-w- c:\windows\system32\davclnt.dll
2011-04-28 13:29:43 73728 —-a-w- c:\windows\system32\wscsvc.dll
2011-04-28 13:29:43 51200 —-a-w- c:\windows\system32\wscapi.dll
2011-04-28 13:29:43 350720 —-a-w- c:\windows\system32\winhttp.dll
2011-04-28 13:29:43 204800 —-a-w- c:\windows\system32\WebClnt.dll
2011-04-28 13:29:43 14336 —-a-w- c:\windows\system32\slwga.dll
2011-04-28 13:29:43 1389568 —-a-w- c:\windows\system32\msxml6.dll
2011-04-28 13:29:43 1236992 —-a-w- c:\windows\system32\msxml3.dll
2011-04-28 13:29:06 738816 —-a-w- c:\windows\system32\wmpmde.dll
2011-04-28 13:29:06 101760 —-a-w- c:\windows\system32\consent.exe
2011-04-28 13:29:01 571904 —-a-w- c:\windows\system32\oleaut32.dll
2011-04-28 13:25:37 ——– d-sh–w- c:\windows\Installer
2011-04-28 13:25:36 ——– d—–w- c:\program files\Microsoft Security Client
2011-04-28 13:25:17 240008 —-a-w- c:\windows\system32\drivers\netio.sys
.
==================== Find3M ====================
.
2011-03-11 05:44:09 146304 —-a-w- c:\windows\system32\drivers\storport.sys
2011-03-11 05:44:01 143744 —-a-w- c:\windows\system32\drivers\nvstor.sys
2011-03-11 05:44:01 1210240 —-a-w- c:\windows\system32\drivers\ntfs.sys
2011-03-11 05:44:01 117120 —-a-w- c:\windows\system32\drivers\nvraid.sys
2011-03-11 05:43:55 332160 —-a-w- c:\windows\system32\drivers\iaStorV.sys
2011-03-11 05:43:46 80256 —-a-w- c:\windows\system32\drivers\amdsata.sys
2011-03-11 05:43:46 22400 —-a-w- c:\windows\system32\drivers\amdxata.sys
2011-03-11 05:39:35 1686016 —-a-w- c:\windows\system32\esent.dll
2011-03-11 05:37:34 74240 —-a-w- c:\windows\system32\fsutil.exe
.
============= FINISH: 12:21:36.62 ===============

Attachments:

Reformatting my drive again completely is going to take some time so I rather not do that since i just recently did it like a few days ago. There shouldn't be any reason to reformat. I just want to install windows OS 64 bit, with out repartitioning my drive and then CLEAN up my computer, on all drives, erase all remnants of any virus or infections on my C drive and my externals. So i don't ever get infected like this again. I have came back to this forum numerous times trying to get the infections off of my machine, you guys have excellent work in this and have helped me lot. But i keep re infecting my self in some way and i believe its because of my old files that i had for like years I am almost tempted to use something like Comodo firewall or Zone alarm well transferring my files to and from my hard drives. Those are the only firewalls that i know of that blocks ALL incoming and outgoing connections. So if anything is transferred over, i will know cause a red box will pop up, stating its malicious data.
Wow this is bad. Went i went to pay a house payment online on my computer. I noticed after 3 attempts my password didn't work correctly, so i think some how my personal information might of transferred to an unauthorized party. And my pass changed. I have done it 100 times before and NEVER had this issue playing bills online. This is the first time in which i had to call them and opt for a pass word reset completely. I hope to god my personal identity information hasn't been exploited.
This is ridiculous, i dont think any one in the world has as much issues i have with recurring viruses. I have them like constantly and i honestly think its nothing new, its old files that im transferring over to my C drive that just happens to re infect my machine again. So this time im going to take a diff approach, after my pc is clean. I think im going to use a stronger firewall, MSE just does not cover it. I know people say its the best for protection and the windows 7 fire wall should be enough. But when you have deep infections already on some of your external HDD's how do you know those software are going to pick them up. Well i am almost certain something like comodo security or Zone alarm, will pick up those infections as i try and do my transferring. I NEED to find exactly what the heck it is that is in my externals that is causing theses recurring infections. I only noticed this happening, the MOMENT i started transferring files from my external back to my c drive. I am almost certain if i did a system restore, it would probably fix the majority of the problems. But im not going to do that, ill wait for your instructions on how to thoroughly completely clean this computer, not just my C drive but all my other hard drives as well. I really need some help here not just with removing the infections but also possibly getting some programs that kill programs, such as kill box. That seems to work great cause it completely destroys the application and all registry values. I need to probably do that for each and every third party software i have on my machine. Then i need to go to the sites and re download the ones i want to use again. Before i wasn't able to run those fire wall software cause they use a ton of CPU resources but now i have a pretty strong machine and i should be able to run something stronger, better protection. At least with the upgrade to windows 64 bit, i should notice a VAST improvement in memory usage.
I also wanted to make a note that after installing the new drivers for my nvideo GTX 450 graphics card. When i play a game, it just crashes on me. It also goes slow as well. I would figure since i upgraded my card, that i shouldn't have any problems but i do. Again this could be because of memory. At least thats what i think. What do you think i should do, install windows 64 bit first. Then clean up my computer, or clean up my pc first and then install windows 64 bit?
Well i decided to actually install windows 64 bit anyways. I haven't really touched anything accept i downloaded MSE and zone alarm and im using those right now. But i did not format my drive, all my old files are in a system called "system old" I also noticed that a few things that weren't working before such as being able to link to my router page are now working so im assuming that clean install did something. I can also view my complete RAM which is 4gb. Instead of the previous 2.43 with windows 32 bit OS. So that is definitely cool. In any case, the viruses, infections still exist so i want to still make absolutely sure all of the infections are gone from my drive, in my "windows old" folder and also my other hard drives. There probably isn't any infections in my program files or my system since i did a clean install, but i can still transfer them back over very easily if i don't take precaution in trying to remove all infections on all my drives.
Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

Download MGADiag to your desktop.
  • Double-click on MGADiag.exe to launch the program.
  • Click Continue.
  • Ensure that the Windows tab is selected (it should be by default).
  • Click the Copy button to copy the MGA Diagnostic Report to the Windows clipboard.
  • Paste the MGA Diagnostic Report back here in your next reply.

Then, download CKScanner from here
Important - Save it to your desktop.
Right-Click CKScanner.exe, choose Run as administrator and click Search For Files.
After a couple minutes or less, when the cursor hourglass disappears, click Save List To File.
A message box will verify the file saved.
Double-click the CKFiles.txt icon on your desktop, give permission if asked, and copy/paste the contents in your next reply.
Thanks for replying.

Here is the information I just wanted to note before i copy this information, that the windows version that i have, a friend sent me. He told me there is no problems with it though. It seems to load up and install just fine. He said in most cases if you have a corrupted windows, that the disk won't even load all the drivers correctly. I actually used to have a old version of windows xp that had similar issues and wouldn't install all the way and some one on here concluded that, that was most likely a corrupted disk. In any case, the maleware issues im experiencing are recurring.

I also wanted to ask once were done with removing the infections on all my hard drives, if you can tell me what application i can use to give me a status report of my entire computer, including all serials and that kind of stuff. Cause i need them in order to activate some of my programs again. I forgot what the application is called but i got it from here.

Diagnostic Report (1.9.0027.0):
—————————————–
Windows Validation Data–>

Validation Code: 0
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-GJY49-VJBQ7-HYRR2
Windows Product Key Hash: W5/6nm6F2UPXrCkY5xUhXb/+21g=
Windows Product ID: 00426-OEM-8992662-00006
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.1.7600.2.00010100.0.0.001
ID: {4F6C7B47-A539-4697-B993-D851E1F5BF24}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Ultimate
Architecture: 0x00000009
Build lab: 7600.win7_gdr.110408-1633
TTS Error:
Validation Diagnostic:
Resolution Status: N/A

Vista WgaER Data–>
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002

Windows XP Notifications Data–>
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data–>
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data–>

Other data–>
Office Details: {4F6C7B47-A539-4697-B993-D851E1F5BF24}1.9.0027.06.1.7600.2.00010100.0.0.001x64*****-*****-*****-*****-HYRR200426-OEM-8992662-000062S-1-5-21-1437292590-29084685-17691827521E6551E655A27American Megatrends Inc.080016 20090909000000.000000+0002BBB3607018400FE04090409Pacific Standard Time(GMT-08:00)03ACRSYSACRPRDCT109

Spsys.log Content: 0x80070002

Licensing Data–>
Software licensing service version: 6.1.7600.16385

Name: Windows® 7, Ultimate edition
Description: Windows Operating System - Windows® 7, OEM_SLP channel
Activation ID: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00426-00178-926-600006-02-1033-7600.0000-1472011
Installation ID: 020293010622746081392280561912222231547470009921109576
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
Partial Product Key: HYRR2
License Status: Licensed
Remaining Windows rearm count: 3
Trusted time: 5/30/2011 4:27:47 AM

Windows Activation Technologies–>
HrOffline: 0x00000000
HrOnline: 0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 5:28:2011 05:46
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:


HWID Data–>
HWID Hash Current: OAAAAAIABgABAAEAAAABAAAAAgABAAEA6GFS2a8MAmNCxoCWgMAGnt5tCAx+ZloP5AekALIldlY=

OEM Activation 1.0 Data–>
N/A

OEM Activation 2.0 Data–>
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC 090909 APIC1554
FACP 090909 FACP1554
MCFG 090909 OEMMCFG
OEMB 090909 OEMB1554
SLIC ACRSYS ACRPRDCT








CKScanner - Additional Security Risks - These are not necessarily bad
c:\users\jeff\documents\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\degun.url
c:\users\jeff\documents\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100.exe
c:\users\jeff\documents\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\sctv83 - tpb.url
c:\users\jeff\documents\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\crack\nero recode digital plug-in nms 10.reg
c:\users\jeff\documents\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\crack\serial.txt
c:\windows.old\users\jeff\documents\desktop\dvdfab platinum v8.0.6.8 + crack [chattchitto rg]\chattchitto rg.nfo
c:\windows.old\users\jeff\documents\desktop\dvdfab platinum v8.0.6.8 + crack [chattchitto rg]\chattchitto rg.url
c:\windows.old\users\jeff\documents\desktop\dvdfab platinum v8.0.6.8 + crack [chattchitto rg]\dvdfab platinum v8.0.6.8 + crack [chattchitto rg].exe
c:\windows.old\users\jeff\documents\desktop\nero multimedia suite 10.0.13100 + key crack tested\nero\nero backitup 10.lnk
c:\windows.old\users\jeff\documents\desktop\nero multimedia suite 10.0.13100 + key crack tested\nero\nero burning rom 10.lnk
c:\windows.old\users\jeff\documents\desktop\nero multimedia suite 10.0.13100 + key crack tested\nero\nero mediahub 10.lnk
c:\windows.old\users\jeff\documents\desktop\nero multimedia suite 10.0.13100 + key crack tested\nero\nero vision 10.lnk
c:\windows.old\users\jeff\documents\desktop\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\degun.url
c:\windows.old\users\jeff\documents\desktop\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100.exe
c:\windows.old\users\jeff\documents\desktop\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\sctv83 - tpb.url
c:\windows.old\users\jeff\documents\desktop\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\crack\nero recode digital plug-in nms 10.reg
c:\windows.old\users\jeff\documents\desktop\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\crack\serial.txt
c:\windows.old\users\jeff\documents\dvdfab platinum v8.0.6.8 + crack [chattchitto rg]\chattchitto rg.nfo
c:\windows.old\users\jeff\documents\dvdfab platinum v8.0.6.8 + crack [chattchitto rg]\chattchitto rg.url
c:\windows.old\users\jeff\documents\dvdfab platinum v8.0.6.8 + crack [chattchitto rg]\dvdfab platinum v8.0.6.8 + crack [chattchitto rg].exe
c:\windows.old\users\jeff\documents\my documents\burnersoft_easy_dvd_shrink_v3_0_24_winall_cracked_palace.torrent
c:\windows.old\users\jeff\documents\my documents\dvd_next_copy_next_tech_4_2_5_2____keygen___rar.torrent
c:\windows.old\users\jeff\documents\my documents\dvd_next_copy_next_tech_v4_0_2_8_crack_latest__rh.torrent
c:\windows.old\users\jeff\documents\my documents\easy_dvd_shrink_3_0_19___crack.torrent
c:\windows.old\users\jeff\documents\my documents\bioware\dragon age\addins\elrondstent\module\override\toolsetexport\plt_cheese_and_crackers.nss
c:\windows.old\users\jeff\documents\my documents\bioware\dragon age\addins\elrondstent\module\override\toolsetexport\plt_cheese_and_crackers.plo
c:\windows.old\users\jeff\documents\my documents\game directory\emulators\nintendo_nes_roms\nintendo nes\crack out.zip
c:\windows.old\users\jeff\documents\my documents\game directory\emulators\nintendo_nes_roms\nintendo nes\nesroms\crackout (e).nes
c:\windows.old\users\jeff\documents\my documents\game directory\emulators\sega genesis collection 723 roms plus emulator h33t 1981camaroz28\genesis 723 roms\crack down (u) [!].zip
c:\windows.old\users\jeff\documents\my documents\game directory\encoding\dr. divx 1.0.6 crack\drdivx_v106_kg.exe
c:\windows.old\users\jeff\documents\my documents\game directory\encoding\dr. divx 1.0.6 crack\read me !!.txt
c:\windows.old\users\jeff\documents\my documents\programs\adobe after effects cs3. by toppel. new\adobe after effects cs3. by toppel. new one\crack\afterfx.dll
c:\windows.old\users\jeff\documents\my documents\programs\adobe after effects cs3. by toppel. new\adobe after effects cs3. by toppel. new one\crack\mkdev team serial.nfo
c:\windows.old\users\jeff\documents\my documents\programs\adobe after effects cs3. by toppel. new\adobe after effects cs3. by toppel. new one\crack\mkdev team.exe
c:\windows.old\users\jeff\documents\my documents\programs\adobe after effects cs3. by toppel. new\adobe after effects cs3. by toppel. new one\crack\crack mkdev team ilefx\mkdev team serial.nfo
c:\windows.old\users\jeff\documents\my documents\programs\adobe flash cs3 professional v9.0 all(working 100%)\adobe flash cs3 pro v9.0 incl keygen.daa
c:\windows.old\users\jeff\documents\my documents\programs\adobe premiere pro cs3 multi-language incl crack\adobe premiere pro cs3 multi.daa
c:\windows.old\users\jeff\documents\my documents\programs\adobe premiere pro cs3 multi-language incl crack\ahmbed.gz
c:\windows.old\users\jeff\documents\my documents\programs\adobe premiere pro cs3 multi-language incl crack\readme.txt
c:\windows.old\users\jeff\documents\my documents\programs\macromedia dreamweaver cs3 + plugins and crack\macromedia dreamweaver cs3 + crack.daa
c:\windows.old\users\jeff\documents\my documents\programs\macromedia dreamweaver cs3 + plugins and crack\macromedia dreamweaver plugins all in one 2007.daa
c:\windows.old\users\jeff\documents\my documents\programs\macromedia dreamweaver cs3 + plugins and crack\readme.txt
c:\windows.old\users\jeff\documents\my documents\programs\macromedia dreamweaver cs3 + plugins and crack\thumbs.db
c:\windows.old\users\jeff\documents\my documents\programs\nero multimedia suite 10.0.13100 + key crack tested\nero\nero backitup 10.lnk
c:\windows.old\users\jeff\documents\my documents\programs\nero multimedia suite 10.0.13100 + key crack tested\nero\nero burning rom 10.lnk
c:\windows.old\users\jeff\documents\my documents\programs\nero multimedia suite 10.0.13100 + key crack tested\nero\nero mediahub 10.lnk
c:\windows.old\users\jeff\documents\my documents\programs\nero multimedia suite 10.0.13100 + key crack tested\nero\nero vision 10.lnk
c:\windows.old\users\jeff\documents\my documents\programs\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\degun.url
c:\windows.old\users\jeff\documents\my documents\programs\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100.exe
c:\windows.old\users\jeff\documents\my documents\programs\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\sctv83 - tpb.url
c:\windows.old\users\jeff\documents\my documents\programs\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\crack\nero recode digital plug-in nms 10.reg
c:\windows.old\users\jeff\documents\my documents\programs\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\crack\serial.txt
c:\windows.old\users\jeff\documents\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\degun.url
c:\windows.old\users\jeff\documents\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100.exe
c:\windows.old\users\jeff\documents\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\sctv83 - tpb.url
c:\windows.old\users\jeff\documents\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\crack\nero recode digital plug-in nms 10.reg
c:\windows.old\users\jeff\documents\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\crack\serial.txt
c:\windows.old\users\jeff\documents\program files\yahoo!\messenger\profiles\ashdiaz_19\archive\messages\lilmz.cracker\20080701-ashdiaz_19.dat
c:\windows.old\users\jeff\documents\[laptop backup]\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\degun.url
c:\windows.old\users\jeff\documents\[laptop backup]\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100.exe
c:\windows.old\users\jeff\documents\[laptop backup]\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\sctv83 - tpb.url
c:\windows.old\users\jeff\documents\[laptop backup]\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\crack\nero recode digital plug-in nms 10.reg
c:\windows.old\users\jeff\documents\[laptop backup]\nero multimedia suite 10.0.13100 + key crack tested\nero multimedia suite 10.0.13100 + key crack tested\crack\serial.txt
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\windows 7 serials (x86-x64).txt
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\thank you.txt
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\7loader by hazar 1.5 (old one, but still works)\7loader v1.5.exe
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\7loader by hazar 1.5 (old one, but still works)\windows 7 activator read me.txt
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\7loader by hazar 1.6\loader.exe
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\keys.ini
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\windows 7 loader.exe
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\certificates\acer.xrm-ms
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\certificates\alienware.xrm-ms
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\certificates\asus.xrm-ms
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\certificates\dell.xrm-ms
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\certificates\founder.xrm-ms
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\certificates\fujitsu.xrm-ms
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\certificates\hp.xrm-ms
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\certificates\lenovo.xrm-ms
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\certificates\msi.xrm-ms
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\certificates\note.txt
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\certificates\toshiba.xrm-ms
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\notes\arguments.txt
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\notes\beta loader changelog.txt
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\notes\checksums.txt
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\notes\how to recover windows.txt
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\notes\how to restore tokens.txt
c:\windows.old\users\jeff\documents\[microsoft] windows 7 ultimate retail(final) x86 (32 bit) and x64 (64 bit)\cracks for x64 + x86\all working activators\windows 7 loader 1.6.9 by daz\notes\version history.txt
scanner sequence 3.ZZ.11
—– EOF —–
You are running an illegal pirated copy of Windows, and illegal pirated copies of pretty much everything else on your PC. No wonder you are infected.

Our terms of use state that "We will NOT help anyone we suspect of having obtained their software illegally."

Your best course of action would be to format the hard drive, reinstall a legal copy of Windows, and then pay for the programs you want to use. Using the pirated programs from your external hard drive are just going to keep reinfecting you.
Yeah a friend gave me a working windows disk with activators on them. So i been using that, i have actually never bought windows 7 yet. The rest of the programs, are from along time ago. I don't use any other pirated software on my computer any more. DVD fab was probably the most recent one, but i bought that one just recently. How ever i forgot the serial code and its asking me to re enter the serial code of the software. So can you send me that application that gives you a complete status report of your pc and gives you all serials that I used in the past. I need that, its very important cause it has all my serials that i used when i bought alot of these programs. Your saying you can't help me further? Until i install a new windows 7 right? I hope i am still able to receive support on this forum. I have been a member since july 09 and this forum is really my only means of getting excellent support. I even planned on joining the classroom or applying for it. Because the kind of work you do, im very interesting in. I even go to college for this type of computer tech work. I would be more then happy to help others in need of infections, and work on there computers. I actually run a side business where i build computer's for people just out of my own spare time. What you say makes sense though, so im going to take your advice definitely on this and actually buy windows 7. Basically this disk i have, has some kind of an activator that it loads and maybe that activator is installing a trojan on my computer or something. I don't know. Is there any possible way you can direct me to what software is infected on my other hard drives and my "system old" files. I need to be able to scan these other hard drives with all my back up data and make absolutely sure all of this is deleted it from my drives, if there is any existing cracks, key gens or software that i used in the past. I want to completely remove all that cause some of the infections might be caused from that. I just got done reformatting my hard drive. It won't do me any good even if i format again, because i have so many back up folders and files of all my programs. That i could potentional infect my self again by transferring old programs back onto my C drive. So i want to get rid of all the infections in all of my old files. So then when i format, install a bought version of windows 7, that i won't have to worry bout further infections when i start transferring my files over. Also do i really need to reformat. Can't i just install the new windows 7 when i get it, and just make another copy of windows old file. But don't actually partition the drive. I am sure you can help me with the rest, once i get the windows 7 install on there. But i don't think a format is necessary. I just reformatted like a few days. In other words the system is clean. What isn't clean is the "system old" back up files on my drive and also all my folders of back ups on my externals, I have not transferring anything like that over to my new C drive yet though. I think that is one of my major issues, is alot of these applications, programs, illegal software, cracks and that junk that i had from years ago is reinfecting my machine because i transfer the entire directory back onto my HD. It would be nice to know where these infections are originating from so i can get rid of this problem completely.
In the past you have been advised by our helpers to remove your pirated software, yet you have come back time and time again with it.

There are no more chances - we cannot help you recover your pirated license keys, and we will not help you remove malware from your machine that you have infected yourself with by engaging in these practices.

Topic Closed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI