This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus? [Solved]

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, My Comp. is relatively new In the past month I have noticed that it is going very slow (even with little active applications). When I play music (via Win. media player or explorer) it jumps Is it a virus of some sort? Thanks in advance
:welcome:

We need to see some logs to see whats going on

aswMBR Log

Important! Please do not perform any fix options offered in aswMBR

Please download aswMBR to your desktop.


  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the Save Log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]






Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Hi Ken Thank you for your help Here are there logs you requested: aswMBR: swMBR version 0.9.9.1707 Copyrightยฉ 2011 AVAST Software Run date: 2012-11-25 15:19:22 โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“ 15:19:22.945 OS Version: Windows x64 6.1.7601 Service Pack 1 15:19:22.945 Number of processors: 4 586 0x2A07 15:19:22.946 ComputerName: HOME-PC UserName: Home 15:19:24.193 Initialize success 15:20:35.639 AVAST engine defs: 12112500 15:20:55.470 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 15:20:55.471 Disk 0 Vendor: SAMSUNG_HD103SI 1AG01118 Size: 953869MB BusType: 3 15:20:55.482 Disk 0 MBR read successfully 15:20:55.483 Disk 0 MBR scan 15:20:55.486 Disk 0 Windows 7 default MBR code 15:20:55.489 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 15:20:55.503 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848 15:20:55.519 Disk 0 scanning C:\Windows\system32\drivers 15:21:03.832 Service scanning 15:21:21.434 Modules scanning 15:21:21.438 Disk 0 trace - called modules: 15:21:21.450 ntoskrnl.exe CLASSPNP.SYS disk.sys PCTCore64.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 15:21:21.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80046f2790] 15:21:21.456 3 CLASSPNP.SYS[fffff88001b9243f] -> nt!IofCallDriver -> [0xfffffa80045c1a80] 15:21:21.459 5 PCTCore64.sys[fffff880010128a4] -> nt!IofCallDriver -> [0xfffffa800410e520] 15:21:21.463 7 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004110060] 15:21:22.543 AVAST engine scan C:\Windows 15:21:25.755 AVAST engine scan C:\Windows\system32 15:24:28.197 AVAST engine scan C:\Windows\system32\drivers 15:24:39.388 AVAST engine scan C:\Users\Home 15:31:23.536 AVAST engine scan C:\ProgramData 15:32:59.222 Scan finished successfully 15:33:32.268 Disk 0 MBR has been saved successfully to "C:\Users\Home\Desktop\Trojan\MBR.dat" 15:33:32.272 The log file has been saved successfully to "C:\Users\Home\Desktop\Trojan\aswMBR_251112.txt" DDS.txt: DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 9.0.8112.16455 BrowserJavaVersion: 10.9.2 Run by [removed] at 15:42:12 on 2012-11-25 Microsoft Windows 7 Ultimate 6.1.7601.1.1255.972.1033.18.3993.1332 [GMT 2:00] . AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\PROGRA~2\AVG\AVG2012\avgrsa.exe C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskhost.exe C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe C:\Program Files\Common Files\Nitro PDF\Professional\6.0\NitroPDFDriverServicex64.exe C:\Windows\SysWOW64\NLSSRV32.EXE C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe C:\Program Files (x86)\AVG\AVG2012\avgemca.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe C:\Windows\WindowsMobile\wmdc.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files\Microsoft Device Center\itype.exe C:\Program Files\Microsoft Device Center\ipoint.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Samsung\Kies\Kies.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Program Files (x86)\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\Users\Home\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE C:\Program Files (x86)\Java\jre7\bin\javaw.exe C:\Program Files (x86)\AVG\AVG2012\avgtray.exe C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe C:\Program Files (x86)\HSPA USB MODEM\ModemListener.exe C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://econ.tau.ac.il/undergrad/bulletin.asp?theSubject=undergraduate uURLSearchHooks: PC Tools Browser Guard: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: PC Tools Browser Guard BHO: {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll BHO: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL BHO: Javaโ„ข Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: AcroIEToolbarHelper Class: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL BHO: Javaโ„ข Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll TB: PC Tools Browser Guard: {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - C:\Program Files (x86)\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED uRun: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun uRun: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload uRun: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup uRun: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background uRun: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices mRun: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot mRun: [PCTools FGuard] C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe mRun: [ModemListener] C:\Program Files (x86)\HSPA USB MODEM\ModemListener.exe start mRun: [Alcatel X220 HSPA USB Modem] StartupFolder: C:\Users\Home\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Home\AppData\Roaming\Dropbox\bin\Dropbox.exe StartupFolder: C:\Users\Home\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE StartupFolder: C:\Users\Home\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\TED-SH~1.LNK - C:\Program Files (x86)\Torrent Episode Downloader\ted.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ACROBA~1.LNK - C:\Program Files (x86)\Adobe\Acrobat 6.0\Distillr\acrotray.exe uPolicies-Explorer: NoDrives = dword:0 uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoDrives = dword:0 mPolicies-System: ConsentPromptBehaviorAdmin = dword:0 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableLUA = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll LSP: C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: NameServer = 192.168.0.1 TCP: Interfaces\{80F25CC4-7E95-48CF-9109-A5139C8F3B46} : DHCPNameServer = 192.168.0.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL x64-BHO: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll x64-BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe x64-Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe x64-Run: [IntelliType Pro] "c:\Program Files\Microsoft Device Center\itype.exe" x64-Run: [IntelliPoint] "c:\Program Files\Microsoft Device Center\ipoint.exe" x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll x64-IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - x64-Notify: igfxcui - igfxdev.dll x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\lblo695t.default\ FF - prefs.js: browser.startup.homepage - hxxp://express-google-search.blogspot.com FF - prefs.js: keyword.URL - hxxp://www.google.com/cse?cx=partner-pub-5528014799800033:cevktqnfrvl&ie=ISO-8859-1&q= FF - prefs.js: browser.startup.homepage - hxxp://express-google-search.blogspot.com FF - prefs.js: keyword.URL - hxxp://www.google.com/cse?cx=partner-pub-5528014799800033:cevktqnfrvl&ie=ISO-8859-1&q= . ============= SERVICES / DRIVERS =============== . R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-4-19 28480] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-1-31 36944] R0 PCTCore;PCTools KDS;C:\Windows\System32\drivers\PCTCore64.sys [2012-6-24 282440] R0 pctDS;PC Tools Data Store;C:\Windows\System32\drivers\pctDS64.sys [2012-6-24 452872] R0 pctEFA;PC Tools Extended File Attributes;C:\Windows\System32\drivers\pctEFA64.sys [2012-6-24 816016] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-7-26 291680] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2011-12-23 47696] R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-8-24 384352] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-6-24 283200] R1 pctgntdi;pctgntdi;C:\Windows\System32\drivers\pctgntdi64.sys [2012-6-24 337048] R1 PCTSD;PC Tools Spyware Doctor Driver;C:\Windows\System32\drivers\PCTSD64.sys [2012-6-24 279344] R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-8-13 5167736] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288] R2 Browser Defender Update Service;Browser Defender Update Service;C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2012-6-24 337872] R2 DeviceManager;DeviceManager;C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe -start โ€“> C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe -start [?] R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;C:\Program Files\Common Files\Nitro PDF\Professional\6.0\NitroPDFDriverServicex64.exe [2011-1-12 341312] R2 nlsX86cc;NLS Service;C:\Windows\SysWOW64\NLSSRV32.EXE [2011-1-12 68928] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2011-12-23 124496] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\avgidsfiltera.sys [2011-12-23 29776] R3 pctNdisMP;PC Tools Driver;C:\Windows\System32\drivers\pctNdis64.sys [2012-6-24 77784] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-4-22 539240] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 KMService;KMService;C:\Windows\System32\srvany.exe โ€“> C:\Windows\System32\srvany.exe [?] S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168] S3 jrdusbser;Mobile Connector Device for Legacy Serial Communication;C:\Windows\System32\drivers\jrdusbser.sys [2012-7-13 119680] S3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-6-30 24904] S3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;C:\Windows\System32\drivers\pctNdis-PacketFilter64.sys [2012-6-24 119688] S3 pctNdis;PC Tools Firewall Intermediate Filter Service;C:\Windows\System32\drivers\pctNdis64.sys [2012-6-24 77784] S3 pctplfw;pctplfw;C:\Windows\System32\drivers\pctplfw64.sys [2012-6-24 180488] S3 pctplsg;pctplsg;C:\Windows\System32\drivers\pctplsg64.sys [2012-6-24 92896] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992] S3 sdAuxService;PC Tools Auxiliary Service;C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe [2012-6-24 371472] S3 sdCoreService;PC Tools Security Service;C:\Program Files (x86)\PC Tools Security\pctsSvc.exe [2012-6-24 1117144] S3 Synth3dVsc;Synth3dVsc;C:\Windows\System32\drivers\Synth3dVsc.sys [2010-11-21 88960] S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\System32\drivers\terminpt.sys [2010-11-21 34816] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232] S3 tsusbhub;tsusbhub;C:\Windows\System32\drivers\tsusbhub.sys [2010-11-21 117248] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-2-15 1255736] S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464] S4 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-9-7 655944] . =============== Created Last 30 ================ . 2012-11-25 12:55:11 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Home\AppData\Local\{F8657E4F-B242-4ABF-9369-FEAA24E28FE0} 2012-11-17 20:44:01 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Home\AppData\Local\Apple Computer 2012-11-17 20:43:20 33240 โ€”-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2012-11-17 20:42:21 โ€”โ€”โ€“ dโ€”โ€“w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-11-17 20:42:21 โ€”โ€”โ€“ dโ€”โ€“w- C:\Program Files\iTunes 2012-11-17 20:42:21 โ€”โ€”โ€“ dโ€”โ€“w- C:\Program Files\iPod 2012-11-17 20:42:21 โ€”โ€”โ€“ dโ€”โ€“w- C:\Program Files (x86)\iTunes 2012-11-17 20:41:13 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Home\AppData\Local\Apple 2012-11-17 20:40:07 โ€”โ€”โ€“ dโ€”โ€“w- C:\Program Files\Bonjour 2012-11-17 20:40:07 โ€”โ€”โ€“ dโ€”โ€“w- C:\Program Files (x86)\Bonjour 2012-11-17 16:35:15 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Home\AppData\Local\{FD6DE30C-2585-4B9F-AD55-758900BB219E} 2012-11-16 16:34:38 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Home\AppData\Local\{581B3ECD-E789-4805-A7C1-405FCF74A099} 2012-11-16 04:34:13 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Home\AppData\Local\{744FE3A1-AB33-4A8D-8BEA-F3F192D1A238} 2012-11-16 01:06:59 2560 โ€”-a-w- C:\Windows\System32\drivers\he-IL\wdf01000.sys.mui 2012-11-16 01:06:59 2560 โ€”-a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui 2012-11-16 01:06:58 9728 โ€”-a-w- C:\Windows\System32\Wdfres.dll 2012-11-16 01:06:58 785512 โ€”-a-w- C:\Windows\System32\drivers\Wdf01000.sys 2012-11-16 01:06:58 54376 โ€”-a-w- C:\Windows\System32\drivers\WdfLdr.sys 2012-11-16 00:25:08 55296 โ€”-a-w- C:\Windows\System32\dhcpcsvc6.dll 2012-11-16 00:24:48 95744 โ€”-a-w- C:\Windows\System32\synceng.dll 2012-11-16 00:24:48 78336 โ€”-a-w- C:\Windows\SysWow64\synceng.dll 2012-11-15 04:33:35 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Home\AppData\Local\{D1C0A8D0-2D08-4175-A2E4-CEAA0A940AB2} 2012-11-09 07:22:26 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Home\AppData\Local\{31D780E0-572D-4B2B-84B7-ABCC9F6328D9} 2012-11-06 19:34:41 519824 โ€”-a-w- C:\Windows\ProShow Style Pack 3_12345.exe 2012-11-06 19:34:18 519824 โ€”-a-w- C:\Windows\ProShow Style Pack 2_12345.exe 2012-11-06 19:33:55 519824 โ€”-a-w- C:\Windows\ProShow Style Pack 1_12345.exe 2012-11-06 19:20:49 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Home\AppData\Local\{0B6D29A1-F85A-4C67-9552-6CABFA706CC8} 2012-11-06 19:16:45 โ€”โ€”โ€“ dโ€”โ€“w- C:\Program Files (x86)\Photodex Presenter 2012-11-06 19:16:40 โ€”โ€”โ€“ dโ€”โ€“w- C:\Program Files (x86)\Photodex 2012-11-06 19:13:42 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Home\AppData\Roaming\Photodex 2012-11-06 19:13:42 โ€”โ€”โ€“ dโ€”โ€“w- C:\ProgramData\Photodex 2012-11-02 07:18:35 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Home\AppData\Local\{A9E9591C-5E0B-4FCB-B3FE-096D9F247F40} 2012-10-28 16:06:06 โ€”โ€”โ€“ dโ€”โ€“r- C:\Users\Home\Dropbox 2012-10-26 18:38:25 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Home\AppData\Local\{35D14BFA-8D62-429E-8ADA-BB6D1C2417FB} . ==================== Find3M ==================== . 2012-11-17 08:01:22 73656 โ€”-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-11-17 08:01:22 697272 โ€”-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-10-18 18:25:58 3149824 โ€”-a-w- C:\Windows\System32\win32k.sys 2012-10-14 16:38:08 10220472 โ€”-a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe 2012-10-09 18:17:13 226816 โ€”-a-w- C:\Windows\System32\dhcpcore6.dll 2012-10-09 17:40:31 44032 โ€”-a-w- C:\Windows\SysWow64\dhcpcsvc6.dll 2012-10-09 17:40:31 193536 โ€”-a-w- C:\Windows\SysWow64\dhcpcore6.dll 2012-10-08 11:31:03 2312704 โ€”-a-w- C:\Windows\System32\jscript9.dll 2012-10-08 11:23:52 1392128 โ€”-a-w- C:\Windows\System32\wininet.dll 2012-10-08 11:22:55 1494528 โ€”-a-w- C:\Windows\System32\inetcpl.cpl 2012-10-08 11:18:22 173056 โ€”-a-w- C:\Windows\System32\ieUnatt.exe 2012-10-08 11:17:35 599040 โ€”-a-w- C:\Windows\System32\vbscript.dll 2012-10-08 11:13:33 2382848 โ€”-a-w- C:\Windows\System32\mshtml.tlb 2012-10-08 07:56:24 1800704 โ€”-a-w- C:\Windows\SysWow64\jscript9.dll 2012-10-08 07:48:03 1129472 โ€”-a-w- C:\Windows\SysWow64\wininet.dll 2012-10-08 07:47:44 1427968 โ€”-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-10-08 07:44:05 142848 โ€”-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-10-08 07:43:21 420864 โ€”-a-w- C:\Windows\SysWow64\vbscript.dll 2012-10-08 07:40:56 2382848 โ€”-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-10-03 17:56:54 1914248 โ€”-a-w- C:\Windows\System32\drivers\tcpip.sys 2012-10-03 17:44:21 70656 โ€”-a-w- C:\Windows\System32\nlaapi.dll 2012-10-03 17:44:21 303104 โ€”-a-w- C:\Windows\System32\nlasvc.dll 2012-10-03 17:44:17 246272 โ€”-a-w- C:\Windows\System32\netcorehc.dll 2012-10-03 17:44:17 18944 โ€”-a-w- C:\Windows\System32\netevent.dll 2012-10-03 17:44:16 216576 โ€”-a-w- C:\Windows\System32\ncsi.dll 2012-10-03 17:42:16 569344 โ€”-a-w- C:\Windows\System32\iphlpsvc.dll 2012-10-03 16:42:24 18944 โ€”-a-w- C:\Windows\SysWow64\netevent.dll 2012-10-03 16:42:24 175104 โ€”-a-w- C:\Windows\SysWow64\netcorehc.dll 2012-10-03 16:42:23 156672 โ€”-a-w- C:\Windows\SysWow64\ncsi.dll 2012-10-03 16:07:26 45568 โ€”-a-w- C:\Windows\System32\drivers\tcpipreg.sys 2012-09-24 21:16:33 95208 โ€”-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2012-09-02 19:31:14 821736 โ€”-a-w- C:\Windows\SysWow64\npDeployJava1.dll 2012-09-02 19:31:14 746984 โ€”-a-w- C:\Windows\SysWow64\deployJava1.dll . ============= FINISH: 15:42:25.99 =============== Attach.txt is attached
Hi,

aswMBR checks for a rootkit and none was found and your DDS log looks fine

uTorrent.exe <โ€“ A heads up on file sharing, this is one of the easiest ways of getting infected, your downloading that file from an unknown and untrusted source, not all but the greater percentage of those files are infected, its like playing Russian Roulette malwarewise, you would be doing yourself a big favor by staying away and not using any form of file sharing.


You have Malwarebytes installed, open it, go to the update tab and check for updates, then go to the scanner tab and run the quick scan, remove whatever it finds, if it does find something than post the log, if not then i dont need it.


ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
Hi, The Malwarebytes didn't find anything. The ESET however found some: C:\old D\Role Playing Books\Advanced Dungeons&Dragons 2nd Edition\TSR 1105 First Quest.rar Win32/Boberog.A worm C:\old D\Role Playing Books\Advanced Dungeons&Dragons 2nd Edition\TSR 1134 Introduction to Advanced Dungeons & Dragonsยฎaudio CD Game.rar Win32/Boberog.A worm C:\old D\Role Playing Books\Advanced Dungeons&Dragons 2nd Edition\Mystara\TSR 2504 Red Steel Campaign Expansion.rar Win32/Boberog.A worm C:\old D\Role Playing Books\Advanced Dungeons&Dragons 2nd Edition\Plane scape\TSR 2610 PS6 A Players Primer to the Outlands.rar Win32/Boberog.A worm C:\old D\Role Playing Books\Advanced Dungeons&Dragons 2nd Edition\Plane scape\TSR 2610 PS6 A Player?s Primer to the Outlands 2.rar Win32/Boberog.A worm C:\Users\Home\Downloads\DownloadSetup.exe Win32/Adware.1ClickDownload.G application C:\Users\Home\Downloads\Reflexive Game - Ricochet Infinity Setup + CRACK\Reflexive_Patch.exe probably a variant of Win32/Adware.IeDefender.NHN application C:\Users\Home\Downloads\Reflexive Game - Ricochet Infinity Setup + CRACK\RicochetInfinitySetup.exe probably a variant of Win32/Adware.IeDefender.NHN application
Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Please Run this program only once
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
CKScanner 2.1 - Additional Security Risks - These are not necessarily bad c:\old d\backup\ilan\favorites\torrents\crackzplanet.com - snowy lunch rush v1.0-delight.url c:\old d\desktop\shay\trivia machine & keygen\code.txt c:\old d\desktop\shay\trivia machine & keygen\trivia machine\keygen.exe c:\old d\desktop\shay\trivia machine & keygen\trivia machine\triviamachinesetup.exe c:\old d\emule-incoming\gem.shop.v1.1.keygen.zip c:\old d\emule-incoming\realonearcade.gem shop.cracked.rar c:\old d\games\dynomite\dynomite delux crack.exe c:\old d\games\freshgames\cubis gold 2\games\tutorial\tutorial\crack and crumble.xml c:\old d\games\freshgames\cubis gold 2\resources\sounds\cubecrack.ogg c:\old d\games\gamehouse\collapse ii\perucracks.txt c:\old d\games\gamehouse\gem shop\cracked\gem shop\1031buyframe.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1031buymenu.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1031pregame.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1031racnotinstalled.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1031strings.js c:\old d\games\gamehouse\gem shop\cracked\gem shop\1036buyframe.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1036buymenu.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1036pregame.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1036racnotinstalled.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1036strings.js c:\old d\games\gamehouse\gem shop\cracked\gem shop\1040buyframe.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1040buymenu.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1040pregame.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1040racnotinstalled.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1040strings.js c:\old d\games\gamehouse\gem shop\cracked\gem shop\1041buyframe.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1041buymenu.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1041pregame.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1041racnotinstalled.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1041strings.js c:\old d\games\gamehouse\gem shop\cracked\gem shop\1043buyframe.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1043buymenu.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1043pregame.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1043racnotinstalled.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\1043strings.js c:\old d\games\gamehouse\gem shop\cracked\gem shop\3082buyframe.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\3082buymenu.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\3082pregame.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\3082racnotinstalled.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\3082strings.js c:\old d\games\gamehouse\gem shop\cracked\gem shop\buyframe.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\buymenu.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\gemshop.ini c:\old d\games\gamehouse\gem shop\cracked\gem shop\gemshop_r1a.exe c:\old d\games\gamehouse\gem shop\cracked\gem shop\launch.ini c:\old d\games\gamehouse\gem shop\cracked\gem shop\license.txt c:\old d\games\gamehouse\gem shop\cracked\gem shop\osd230.osd c:\old d\games\gamehouse\gem shop\cracked\gem shop\pregame.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\racnotinstalled.htm c:\old d\games\gamehouse\gem shop\cracked\gem shop\readme.txt c:\old d\games\gamehouse\gem shop\cracked\gem shop\setup.ini c:\old d\games\gamehouse\gem shop\cracked\gem shop\status.js c:\old d\games\gamehouse\gem shop\cracked\gem shop\strings.js c:\old d\games\gamehouse\gem shop\cracked\gem shop\theuninstallfile.txt c:\old d\games\gamehouse\gem shop\cracked\gem shop\version.txt c:\old d\games\gamehouse\gem shop\cracked\gem shop\wrapper.cab c:\old d\games\gamehouse\gem shop\cracked\gem shop\wrapper.ini c:\old d\games\gamehouse\gem shop\cracked\gem shop\wrapper.log c:\old d\games\gamehouse\jewel quest\audio\st_win3_crackle.ogg c:\old d\games\gamehouse\jewel quest\jewel[1].quest.v1.206.cracked.winall-f4cg\jewelres.dll c:\old d\games\gamehouse\jewel quest\jewel[1].quest.v1.206.cracked.winall-f4cg\jewel.quest.v1.206.cracked.winall-f4cg\crack.zip c:\old d\games\gamehouse\jewel quest\jewel[1].quest.v1.206.cracked.winall-f4cg\jewel.quest.v1.206.cracked.winall-f4cg\f4cg.nfo c:\old d\games\gamehouse\ricochet lost worlds\crack.zip c:\old d\games\gamehouse\ricochet lost worlds\crack\rlwres.dll c:\old d\games\gamehouse\shapeshifter\shape.shifter.v1.0.0.9.cracked.winall-f4cg\f4cg.nfo c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_01\.material c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_01\.mesh c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_01\crack_01.def c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_01\crack_01.mdl c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_02\.material c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_02\.mesh c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_02\crack_02.def c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_02\crack_02.mdl c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_03\.material c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_03\.mesh c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_03\crack_03.def c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_03\crack_03.mdl c:\old d\games\majesty.2-kaos\resource\texture\common\landscape\rock\crack.dds c:\old d\games\majesty.2-kaos\resource\texture\fx\flares\cracks.dds c:\old d\games\majesty.2-kaos\resource\texture\fx\flares\lightningcrack_n.dds c:\old d\games installations\alawar alien outbreak 2 invasion crack.rar c:\old d\games installations\alawar snowy space trip v1.1 + crack.zip c:\old d\games installations\cubis gold 2 and crack.rar c:\old d\games installations\luxor - amun rising 1.5.5.8 gh-crack.rar c:\old d\games installations\mosaic tomb of mystery + crack.zip c:\old d\games installations\mystery case files huntsville & keygen (reflexive arcade).rar c:\old d\games installations\mystery case files huntsville crack.rar c:\old d\games installations\mystery case files prime suspects v 1.1 crack.rar c:\old d\games installations\pirate poppers + crack.rar c:\old d\games installations\ricochet lw recharged crack note.txt c:\old d\games installations\ricochet.lost.worlds.recharged.v1.1.29.keygen.exe c:\old d\games installations\ricochet.xtreme.+.crack.zip c:\old d\games installations\snowy games - bears adventures - spacetrip - puzzle island + packs - treasure hunter - cracked !!! - powered by phoenix.rar c:\old d\games installations\anno 1701\crack\anno1701.exe c:\old d\games installations\cubis gold 2 and crack\cubis gold 2.exe c:\old d\games installations\cubis gold 2 and crack\cubis2.rar c:\old d\games installations\cubis gold 2 and crack\cubis2\cubis2.exe c:\old d\games installations\fish tycoon + keygen\fishtycoonsetup.exe c:\old d\games installations\fish tycoon + keygen\keygen\eclacr18.exe c:\old d\games installations\fish tycoon + keygen\keygen\eclipse.nfo c:\old d\games installations\fish tycoon + keygen\keygen\file_id.diz c:\old d\games installations\mystery case files prime suspects v 1.1 crack\mysterycasefiles'primesuspects'v1.1\en_mysterycasefilespr_inst.exe c:\old d\games installations\mystery case files prime suspects v 1.1 crack\mysterycasefiles'primesuspects'v1.1\crack\primesuspects.exe c:\old d\games installations\sacred\sacred crack.rar c:\old d\games installations\snowy treasure hunter (alawar) - registered version\crack\instructions.txt c:\old d\games installations\snowy treasure hunter (alawar) - registered version\crack\reg-key.txt c:\old d\games installations\snowy treasure hunter (alawar) - registered version\crack\treasurehunter.exe c:\old d\games installations\spore\spore.crackfix-reloaded\reloaded.nfo c:\old d\games installations\spore\spore.crackfix-reloaded\rld-spof.rar c:\old d\games installations\spore\spore.crackfix-reloaded\rld-spof.sfv c:\old d\games installations\spore\spore.crackfix-reloaded\serial.txt c:\old d\ilan\desktop\spyware doctor - update - v5.0.0.177 - inc crack - by speculum.rar c:\old d\program install\region crack ltnrpc.zip c:\old d\program install\compress\winrar\winrar password cracker.rar c:\old d\program install\compress\winzip\wincrack.zip c:\old d\program install\microsoft office\microsoft.office.2007.oga.crack.stealth\oga-stealth.rar c:\old d\program install\microsoft office\microsoft.office.2007.oga.crack.stealth\stealth.nfo c:\old d\program install\ocr\ligarure\3ac6f22d226a46c9 (ligature 4 crack) [sn- t934730434875].zip c:\old d\rpg\campaign cartographer 2 v6 cracked.zip c:\old d\tumblebugs\tumble bugs\2\keygen.nfo c:\old d\warhammer\army builder + crack\ab22crack.rar c:\old d\warhammer\army builder + crack\army builder + crack.rar c:\old d\warhammer\army builder + crack\army builder 2.2.exe c:\old d\warhammer\army builder + crack\armybuilder.zip c:\old d\warhammer\army builder + crack\ea_v1p33.ab c:\old d\warhammer\army builder + crack\kit22b.exe c:\old d\warhammer\army builder + crack\p2gv191.ab c:\old d\warhammer\army builder + crack\v4p8bfg.ab c:\old d\warhammer\army builder + crack\wfbv7v007.ab c:\old d\warhammer\army builder + crack\ab22crack\ab22crack.exe c:\old d\warhammer\army builder + crack\ab22crack\abkey.lic c:\old d\warhammer\army builder + crack\ab22crack\info.txt c:\old f\trivia machine & keygen.rar c:\old f\bigfish games - home sweet home 2 kitchens and baths + adnan_boy 2008 + precracked\home sweet home 2 kitchens and baths.exe c:\old f\clue classic board game\crack\clueclassic.dll c:\old f\gamehouse games - clue classic + adnan_boy 2008 + precracked\clue classic.exe c:\old f\games\elizabeth find md diagnosis mystery - season 2 - full precracked\elizabeth find md diagnosis mystery - season 2.exe c:\old f\games\nostradamus.the.last.prophecy-reloaded\new folder\crack\nostradamus.exe c:\old f\haunted domains - full precracked\haunted domains - full precracked.exe c:\old f\hide and secret 4 the lost world - full precracked\hide and secret 4 the lost world - full precracked.exe c:\old f\mortimer beckett - crimson thief pe\mortimer beckett - crimson thief pe\gfx\video\firecracker.bik c:\old f\sky taxi 4 - top secret - full precracked - foxy games\sky taxi 4 - top secret - full precracked - foxy games.exe c:\old f\spooky mall - full precracked - foxy games\spooky mall - full precracked - foxy games.exe c:\old f\star defender 4 v1.20 {precracked} {requested} {blaze69}\readme.txt c:\old f\star defender 4 v1.20 {precracked} {requested} {blaze69}\star defender 4.exe c:\old f\trivia machine & keygen\code.txt c:\old f\trivia machine & keygen\trivia machine\keygen.exe c:\old f\trivia machine & keygen\trivia machine\triviamachinesetup.exe c:\users\home\downloads\activators\use this\removewat.exe c:\users\home\downloads\activators\windows 7 activator + remove wat\removewat.exe c:\users\home\downloads\activators\windows 7 activator removewat v2.2.5.2 by hazar~dibya\$rvwskje.exe c:\users\home\downloads\activators\windows 7 activator removewat v2.2.5.2 by hazar~dibya\dibya9999.nfo c:\users\home\downloads\activators\windows 7 activator removewat v2.2.5.2 by hazar~dibya\read me.txt c:\users\home\downloads\activators\windows 7 activator removewat v2.2.5.2 by hazar~dibya\readme.txt c:\users\home\downloads\activators\windows 7 activator removewat v2.2.5.2 by hazar~dibya\removewat.exe c:\users\home\downloads\activators\windows 7 activator removewat v2.2.5.2 by hazar~dibya\windows 7 activator removewat v2.2.5.2 by hazar~dibya.rar0 c:\users\home\downloads\activators\windows 7 activator [2010] [blaze69] [new]\new windows 7 activator [2010]\removewat.exe c:\users\home\downloads\reflexive game - ricochet infinity setup + crack\reflexive_patch.exe c:\users\home\downloads\reflexive game - ricochet infinity setup + crack\ricochetinfinitysetup.exe c:\users\home\downloads\reflexive game - ricochet infinity setup + crack\thumbs.db c:\windows\system32\slmgr.vbs.removewat c:\windows\syswow64\slmgr.vbs.removewat scanner sequence 3.ZZ.11.DVNASO โ€”โ€“ EOF โ€”โ€“
This is where we are at. You used the torrents to download and install illegal software, looks like your win 7 operating system maybe illegal also, this forum as well as all the other malware removal forums do not support the use of illegal software , except for there removal, if i was to continue helping you it could be construed in the eyes of the law as aiding and abetting a crime. If you want to continue with cleaning your system, you need to look over the CKScanner log and remove all the illegal stuff, I dont have the time or desire to help you with this. Then run CKScanner again and post a new log. Then were going to run a program to see if your operating system is illegal, if it is then you will have to contact Microsoft and purchase a licence. If you dont agree to any of the above than this thread will be closed and no more help will be offered
Hi, I try to make people understand that almost 99.99999% of illegal software is infected but they still download it. If you where sitting in my seat and where aware of all the latest threats it would make your hair stand on end, malware thats steals personal info including Credit Card Numbers, log on passwords that you may use for online shopping and banking along with your banking account numbers, and this is just the tip of the iceburg. There are a couple of nasties going around that are uncleanable, the only recourse would be to format and reinstall windows. Thanks for understanding, I think what I would do if i where you would be to go online to Amazon or eBay and purchase a legal copy of windows, format and reinstall it and stay way from any form of File Sharing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI