Hello,
My Comp. is relatively new
In the past month I have noticed that it is going very slow (even with little active applications).
When I play music (via Win. media player or explorer) it jumps
Is it a virus of some sort?
Thanks in advance
We need to see some logs to see whats going on
aswMBR Log
Important! Please do not perform any fix options offered in aswMBR
Please download
aswMBR to your desktop.
Double click the aswMBR icon to run it.Click the Scan button to start scan. If you are asked to update the Avast Virus database please allow it to do so. When it finishes, press the Save Log button, save the logfile to your desktop and post its contents in your next reply.
[external image: Posted Image]
Download
DDS from one of the links below to your desktop
Link 1
Link 2
Double click the tool to run it.A black Screen will open, just read the contents and do nothing. When the tool finishes, it will open 2 reports, DDS.txt and attach.txt Copy/Paste the contents of 'DDS.txt' into your post. 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Hi Ken
Thank you for your help
Here are there logs you requested:
aswMBR:
swMBR version 0.9.9.1707 Copyrightยฉ 2011 AVAST Software
Run date: 2012-11-25 15:19:22
โโโโโโโโโโ
15:19:22.945 OS Version: Windows x64 6.1.7601 Service Pack 1
15:19:22.945 Number of processors: 4 586 0x2A07
15:19:22.946 ComputerName: HOME-PC UserName: Home
15:19:24.193 Initialize success
15:20:35.639 AVAST engine defs: 12112500
15:20:55.470 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
15:20:55.471 Disk 0 Vendor: SAMSUNG_HD103SI 1AG01118 Size: 953869MB BusType: 3
15:20:55.482 Disk 0 MBR read successfully
15:20:55.483 Disk 0 MBR scan
15:20:55.486 Disk 0 Windows 7 default MBR code
15:20:55.489 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
15:20:55.503 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848
15:20:55.519 Disk 0 scanning C:\Windows\system32\drivers
15:21:03.832 Service scanning
15:21:21.434 Modules scanning
15:21:21.438 Disk 0 trace - called modules:
15:21:21.450 ntoskrnl.exe CLASSPNP.SYS disk.sys PCTCore64.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
15:21:21.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80046f2790]
15:21:21.456 3 CLASSPNP.SYS[fffff88001b9243f] -> nt!IofCallDriver -> [0xfffffa80045c1a80]
15:21:21.459 5 PCTCore64.sys[fffff880010128a4] -> nt!IofCallDriver -> [0xfffffa800410e520]
15:21:21.463 7 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004110060]
15:21:22.543 AVAST engine scan C:\Windows
15:21:25.755 AVAST engine scan C:\Windows\system32
15:24:28.197 AVAST engine scan C:\Windows\system32\drivers
15:24:39.388 AVAST engine scan C:\Users\Home
15:31:23.536 AVAST engine scan C:\ProgramData
15:32:59.222 Scan finished successfully
15:33:32.268 Disk 0 MBR has been saved successfully to "C:\Users\Home\Desktop\Trojan\MBR.dat"
15:33:32.272 The log file has been saved successfully to "C:\Users\Home\Desktop\Trojan\aswMBR_251112.txt"
DDS.txt:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16455 BrowserJavaVersion: 10.9.2
Run by [removed] at 15:42:12 on 2012-11-25
Microsoft Windows 7 Ultimate 6.1.7601.1.1255.972.1033.18.3993.1332 [GMT 2:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe
C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe
C:\Program Files\Common Files\Nitro PDF\Professional\6.0\NitroPDFDriverServicex64.exe
C:\Windows\SysWOW64\NLSSRV32.EXE
C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\Microsoft Device Center\itype.exe
C:\Program Files\Microsoft Device Center\ipoint.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Users\Home\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Java\jre7\bin\javaw.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe
C:\Program Files (x86)\HSPA USB MODEM\ModemListener.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://econ.tau.ac.il/undergrad/bulletin.asp?theSubject=undergraduate
uURLSearchHooks: PC Tools Browser Guard: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: PC Tools Browser Guard BHO: {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
BHO: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Javaโข Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AcroIEToolbarHelper Class: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Javaโข Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: PC Tools Browser Guard: {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - C:\Program Files (x86)\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
uRun: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
uRun: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
uRun: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
uRun: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot
mRun: [PCTools FGuard] C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe
mRun: [ModemListener] C:\Program Files (x86)\HSPA USB MODEM\ModemListener.exe start
mRun: [Alcatel X220 HSPA USB Modem]
StartupFolder: C:\Users\Home\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Home\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\Home\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
StartupFolder: C:\Users\Home\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\TED-SH~1.LNK - C:\Program Files (x86)\Torrent Episode Downloader\ted.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ACROBA~1.LNK - C:\Program Files (x86)\Adobe\Acrobat 6.0\Distillr\acrotray.exe
uPolicies-Explorer: NoDrives = dword:0
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
LSP: C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{80F25CC4-7E95-48CF-9109-A5139C8F3B46} : DHCPNameServer = 192.168.0.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll
x64-BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe
x64-Run: [IntelliType Pro] "c:\Program Files\Microsoft Device Center\itype.exe"
x64-Run: [IntelliPoint] "c:\Program Files\Microsoft Device Center\ipoint.exe"
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
x64-Notify: igfxcui - igfxdev.dll
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\lblo695t.default\
FF - prefs.js: browser.startup.homepage - hxxp://express-google-search.blogspot.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/cse?cx=partner-pub-5528014799800033:cevktqnfrvl&ie=ISO-8859-1&q=
FF - prefs.js: browser.startup.homepage - hxxp://express-google-search.blogspot.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/cse?cx=partner-pub-5528014799800033:cevktqnfrvl&ie=ISO-8859-1&q=
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-4-19 28480]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-1-31 36944]
R0 PCTCore;PCTools KDS;C:\Windows\System32\drivers\PCTCore64.sys [2012-6-24 282440]
R0 pctDS;PC Tools Data Store;C:\Windows\System32\drivers\pctDS64.sys [2012-6-24 452872]
R0 pctEFA;PC Tools Extended File Attributes;C:\Windows\System32\drivers\pctEFA64.sys [2012-6-24 816016]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-7-26 291680]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2011-12-23 47696]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-8-24 384352]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-6-24 283200]
R1 pctgntdi;pctgntdi;C:\Windows\System32\drivers\pctgntdi64.sys [2012-6-24 337048]
R1 PCTSD;PC Tools Spyware Doctor Driver;C:\Windows\System32\drivers\PCTSD64.sys [2012-6-24 279344]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-8-13 5167736]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
R2 Browser Defender Update Service;Browser Defender Update Service;C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2012-6-24 337872]
R2 DeviceManager;DeviceManager;C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe -start โ> C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe -start [?]
R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;C:\Program Files\Common Files\Nitro PDF\Professional\6.0\NitroPDFDriverServicex64.exe [2011-1-12 341312]
R2 nlsX86cc;NLS Service;C:\Windows\SysWOW64\NLSSRV32.EXE [2011-1-12 68928]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2011-12-23 124496]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\avgidsfiltera.sys [2011-12-23 29776]
R3 pctNdisMP;PC Tools Driver;C:\Windows\System32\drivers\pctNdis64.sys [2012-6-24 77784]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-4-22 539240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 KMService;KMService;C:\Windows\System32\srvany.exe โ> C:\Windows\System32\srvany.exe [?]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 jrdusbser;Mobile Connector Device for Legacy Serial Communication;C:\Windows\System32\drivers\jrdusbser.sys [2012-7-13 119680]
S3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-6-30 24904]
S3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;C:\Windows\System32\drivers\pctNdis-PacketFilter64.sys [2012-6-24 119688]
S3 pctNdis;PC Tools Firewall Intermediate Filter Service;C:\Windows\System32\drivers\pctNdis64.sys [2012-6-24 77784]
S3 pctplfw;pctplfw;C:\Windows\System32\drivers\pctplfw64.sys [2012-6-24 180488]
S3 pctplsg;pctplsg;C:\Windows\System32\drivers\pctplsg64.sys [2012-6-24 92896]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 sdAuxService;PC Tools Auxiliary Service;C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe [2012-6-24 371472]
S3 sdCoreService;PC Tools Security Service;C:\Program Files (x86)\PC Tools Security\pctsSvc.exe [2012-6-24 1117144]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\System32\drivers\Synth3dVsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\System32\drivers\terminpt.sys [2010-11-21 34816]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;tsusbhub;C:\Windows\System32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-2-15 1255736]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
S4 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-9-7 655944]
.
=============== Created Last 30 ================
.
2012-11-25 12:55:11 โโโ dโโw- C:\Users\Home\AppData\Local\{F8657E4F-B242-4ABF-9369-FEAA24E28FE0}
2012-11-17 20:44:01 โโโ dโโw- C:\Users\Home\AppData\Local\Apple Computer
2012-11-17 20:43:20 33240 โ-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-11-17 20:42:21 โโโ dโโw- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-11-17 20:42:21 โโโ dโโw- C:\Program Files\iTunes
2012-11-17 20:42:21 โโโ dโโw- C:\Program Files\iPod
2012-11-17 20:42:21 โโโ dโโw- C:\Program Files (x86)\iTunes
2012-11-17 20:41:13 โโโ dโโw- C:\Users\Home\AppData\Local\Apple
2012-11-17 20:40:07 โโโ dโโw- C:\Program Files\Bonjour
2012-11-17 20:40:07 โโโ dโโw- C:\Program Files (x86)\Bonjour
2012-11-17 16:35:15 โโโ dโโw- C:\Users\Home\AppData\Local\{FD6DE30C-2585-4B9F-AD55-758900BB219E}
2012-11-16 16:34:38 โโโ dโโw- C:\Users\Home\AppData\Local\{581B3ECD-E789-4805-A7C1-405FCF74A099}
2012-11-16 04:34:13 โโโ dโโw- C:\Users\Home\AppData\Local\{744FE3A1-AB33-4A8D-8BEA-F3F192D1A238}
2012-11-16 01:06:59 2560 โ-a-w- C:\Windows\System32\drivers\he-IL\wdf01000.sys.mui
2012-11-16 01:06:59 2560 โ-a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2012-11-16 01:06:58 9728 โ-a-w- C:\Windows\System32\Wdfres.dll
2012-11-16 01:06:58 785512 โ-a-w- C:\Windows\System32\drivers\Wdf01000.sys
2012-11-16 01:06:58 54376 โ-a-w- C:\Windows\System32\drivers\WdfLdr.sys
2012-11-16 00:25:08 55296 โ-a-w- C:\Windows\System32\dhcpcsvc6.dll
2012-11-16 00:24:48 95744 โ-a-w- C:\Windows\System32\synceng.dll
2012-11-16 00:24:48 78336 โ-a-w- C:\Windows\SysWow64\synceng.dll
2012-11-15 04:33:35 โโโ dโโw- C:\Users\Home\AppData\Local\{D1C0A8D0-2D08-4175-A2E4-CEAA0A940AB2}
2012-11-09 07:22:26 โโโ dโโw- C:\Users\Home\AppData\Local\{31D780E0-572D-4B2B-84B7-ABCC9F6328D9}
2012-11-06 19:34:41 519824 โ-a-w- C:\Windows\ProShow Style Pack 3_12345.exe
2012-11-06 19:34:18 519824 โ-a-w- C:\Windows\ProShow Style Pack 2_12345.exe
2012-11-06 19:33:55 519824 โ-a-w- C:\Windows\ProShow Style Pack 1_12345.exe
2012-11-06 19:20:49 โโโ dโโw- C:\Users\Home\AppData\Local\{0B6D29A1-F85A-4C67-9552-6CABFA706CC8}
2012-11-06 19:16:45 โโโ dโโw- C:\Program Files (x86)\Photodex Presenter
2012-11-06 19:16:40 โโโ dโโw- C:\Program Files (x86)\Photodex
2012-11-06 19:13:42 โโโ dโโw- C:\Users\Home\AppData\Roaming\Photodex
2012-11-06 19:13:42 โโโ dโโw- C:\ProgramData\Photodex
2012-11-02 07:18:35 โโโ dโโw- C:\Users\Home\AppData\Local\{A9E9591C-5E0B-4FCB-B3FE-096D9F247F40}
2012-10-28 16:06:06 โโโ dโโr- C:\Users\Home\Dropbox
2012-10-26 18:38:25 โโโ dโโw- C:\Users\Home\AppData\Local\{35D14BFA-8D62-429E-8ADA-BB6D1C2417FB}
.
==================== Find3M ====================
.
2012-11-17 08:01:22 73656 โ-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-11-17 08:01:22 697272 โ-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-10-18 18:25:58 3149824 โ-a-w- C:\Windows\System32\win32k.sys
2012-10-14 16:38:08 10220472 โ-a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-10-09 18:17:13 226816 โ-a-w- C:\Windows\System32\dhcpcore6.dll
2012-10-09 17:40:31 44032 โ-a-w- C:\Windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40:31 193536 โ-a-w- C:\Windows\SysWow64\dhcpcore6.dll
2012-10-08 11:31:03 2312704 โ-a-w- C:\Windows\System32\jscript9.dll
2012-10-08 11:23:52 1392128 โ-a-w- C:\Windows\System32\wininet.dll
2012-10-08 11:22:55 1494528 โ-a-w- C:\Windows\System32\inetcpl.cpl
2012-10-08 11:18:22 173056 โ-a-w- C:\Windows\System32\ieUnatt.exe
2012-10-08 11:17:35 599040 โ-a-w- C:\Windows\System32\vbscript.dll
2012-10-08 11:13:33 2382848 โ-a-w- C:\Windows\System32\mshtml.tlb
2012-10-08 07:56:24 1800704 โ-a-w- C:\Windows\SysWow64\jscript9.dll
2012-10-08 07:48:03 1129472 โ-a-w- C:\Windows\SysWow64\wininet.dll
2012-10-08 07:47:44 1427968 โ-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-10-08 07:44:05 142848 โ-a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-10-08 07:43:21 420864 โ-a-w- C:\Windows\SysWow64\vbscript.dll
2012-10-08 07:40:56 2382848 โ-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-10-03 17:56:54 1914248 โ-a-w- C:\Windows\System32\drivers\tcpip.sys
2012-10-03 17:44:21 70656 โ-a-w- C:\Windows\System32\nlaapi.dll
2012-10-03 17:44:21 303104 โ-a-w- C:\Windows\System32\nlasvc.dll
2012-10-03 17:44:17 246272 โ-a-w- C:\Windows\System32\netcorehc.dll
2012-10-03 17:44:17 18944 โ-a-w- C:\Windows\System32\netevent.dll
2012-10-03 17:44:16 216576 โ-a-w- C:\Windows\System32\ncsi.dll
2012-10-03 17:42:16 569344 โ-a-w- C:\Windows\System32\iphlpsvc.dll
2012-10-03 16:42:24 18944 โ-a-w- C:\Windows\SysWow64\netevent.dll
2012-10-03 16:42:24 175104 โ-a-w- C:\Windows\SysWow64\netcorehc.dll
2012-10-03 16:42:23 156672 โ-a-w- C:\Windows\SysWow64\ncsi.dll
2012-10-03 16:07:26 45568 โ-a-w- C:\Windows\System32\drivers\tcpipreg.sys
2012-09-24 21:16:33 95208 โ-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-09-02 19:31:14 821736 โ-a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-09-02 19:31:14 746984 โ-a-w- C:\Windows\SysWow64\deployJava1.dll
.
============= FINISH: 15:42:25.99 ===============
Attach.txt is attached
Hi,
aswMBR checks for a rootkit and none was found and your DDS log looks fine
uTorrent.exe <โ A heads up on file sharing, this is one of the easiest ways of getting infected, your downloading that file from an unknown and untrusted source, not all but the greater percentage of those files are infected, its like playing Russian Roulette malwarewise, you would be doing yourself a big favor by staying away and not using any form of file sharing.
You have Malwarebytes installed, open it, go to the update tab and check for updates, then go to the scanner tab and run the quick scan, remove whatever it finds, if it does find something than post the log, if not then i dont need it.
ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan Click the [external image: Posted Image] button. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop. Double click on the [external image: Posted Image] icon on your desktop. Check [external image: Posted Image] Click the [external image: Posted Image] button. Accept any security warnings from your browser. Check [external image: Posted Image] Make sure that the option "Remove found threats" is Unchecked Push the Start button. ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time. When the scan completes, push [external image: Posted Image] Push [external image: Posted Image] , and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply. Push the [external image: Posted Image] button. Push [external image: Posted Image] Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
Hi,
The Malwarebytes didn't find anything.
The ESET however found some:
C:\old D\Role Playing Books\Advanced Dungeons&Dragons 2nd Edition\TSR 1105 First Quest.rar Win32/Boberog.A worm
C:\old D\Role Playing Books\Advanced Dungeons&Dragons 2nd Edition\TSR 1134 Introduction to Advanced Dungeons & Dragonsยฎaudio CD Game.rar Win32/Boberog.A worm
C:\old D\Role Playing Books\Advanced Dungeons&Dragons 2nd Edition\Mystara\TSR 2504 Red Steel Campaign Expansion.rar Win32/Boberog.A worm
C:\old D\Role Playing Books\Advanced Dungeons&Dragons 2nd Edition\Plane scape\TSR 2610 PS6 A Players Primer to the Outlands.rar Win32/Boberog.A worm
C:\old D\Role Playing Books\Advanced Dungeons&Dragons 2nd Edition\Plane scape\TSR 2610 PS6 A Player?s Primer to the Outlands 2.rar Win32/Boberog.A worm
C:\Users\Home\Downloads\DownloadSetup.exe Win32/Adware.1ClickDownload.G application
C:\Users\Home\Downloads\Reflexive Game - Ricochet Infinity Setup + CRACK\Reflexive_Patch.exe probably a variant of Win32/Adware.IeDefender.NHN application
C:\Users\Home\Downloads\Reflexive Game - Ricochet Infinity Setup + CRACK\RicochetInfinitySetup.exe probably a variant of Win32/Adware.IeDefender.NHN application
CKScanner 2.1 - Additional Security Risks - These are not necessarily bad
c:\old d\backup\ilan\favorites\torrents\crackzplanet.com - snowy lunch rush v1.0-delight.url
c:\old d\desktop\shay\trivia machine & keygen\code.txt
c:\old d\desktop\shay\trivia machine & keygen\trivia machine\keygen.exe
c:\old d\desktop\shay\trivia machine & keygen\trivia machine\triviamachinesetup.exe
c:\old d\emule-incoming\gem.shop.v1.1.keygen.zip
c:\old d\emule-incoming\realonearcade.gem shop.cracked.rar
c:\old d\games\dynomite\dynomite delux crack.exe
c:\old d\games\freshgames\cubis gold 2\games\tutorial\tutorial\crack and crumble.xml
c:\old d\games\freshgames\cubis gold 2\resources\sounds\cubecrack.ogg
c:\old d\games\gamehouse\collapse ii\perucracks.txt
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1031buyframe.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1031buymenu.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1031pregame.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1031racnotinstalled.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1031strings.js
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1036buyframe.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1036buymenu.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1036pregame.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1036racnotinstalled.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1036strings.js
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1040buyframe.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1040buymenu.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1040pregame.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1040racnotinstalled.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1040strings.js
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1041buyframe.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1041buymenu.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1041pregame.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1041racnotinstalled.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1041strings.js
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1043buyframe.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1043buymenu.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1043pregame.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1043racnotinstalled.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\1043strings.js
c:\old d\games\gamehouse\gem shop\cracked\gem shop\3082buyframe.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\3082buymenu.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\3082pregame.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\3082racnotinstalled.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\3082strings.js
c:\old d\games\gamehouse\gem shop\cracked\gem shop\buyframe.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\buymenu.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\gemshop.ini
c:\old d\games\gamehouse\gem shop\cracked\gem shop\gemshop_r1a.exe
c:\old d\games\gamehouse\gem shop\cracked\gem shop\launch.ini
c:\old d\games\gamehouse\gem shop\cracked\gem shop\license.txt
c:\old d\games\gamehouse\gem shop\cracked\gem shop\osd230.osd
c:\old d\games\gamehouse\gem shop\cracked\gem shop\pregame.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\racnotinstalled.htm
c:\old d\games\gamehouse\gem shop\cracked\gem shop\readme.txt
c:\old d\games\gamehouse\gem shop\cracked\gem shop\setup.ini
c:\old d\games\gamehouse\gem shop\cracked\gem shop\status.js
c:\old d\games\gamehouse\gem shop\cracked\gem shop\strings.js
c:\old d\games\gamehouse\gem shop\cracked\gem shop\theuninstallfile.txt
c:\old d\games\gamehouse\gem shop\cracked\gem shop\version.txt
c:\old d\games\gamehouse\gem shop\cracked\gem shop\wrapper.cab
c:\old d\games\gamehouse\gem shop\cracked\gem shop\wrapper.ini
c:\old d\games\gamehouse\gem shop\cracked\gem shop\wrapper.log
c:\old d\games\gamehouse\jewel quest\audio\st_win3_crackle.ogg
c:\old d\games\gamehouse\jewel quest\jewel[1].quest.v1.206.cracked.winall-f4cg\jewelres.dll
c:\old d\games\gamehouse\jewel quest\jewel[1].quest.v1.206.cracked.winall-f4cg\jewel.quest.v1.206.cracked.winall-f4cg\crack.zip
c:\old d\games\gamehouse\jewel quest\jewel[1].quest.v1.206.cracked.winall-f4cg\jewel.quest.v1.206.cracked.winall-f4cg\f4cg.nfo
c:\old d\games\gamehouse\ricochet lost worlds\crack.zip
c:\old d\games\gamehouse\ricochet lost worlds\crack\rlwres.dll
c:\old d\games\gamehouse\shapeshifter\shape.shifter.v1.0.0.9.cracked.winall-f4cg\f4cg.nfo
c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_01\.material
c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_01\.mesh
c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_01\crack_01.def
c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_01\crack_01.mdl
c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_02\.material
c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_02\.mesh
c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_02\crack_02.def
c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_02\crack_02.mdl
c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_03\.material
c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_03\.mesh
c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_03\crack_03.def
c:\old d\games\majesty.2-kaos\resource\entity\landscape\rock\crack_03\crack_03.mdl
c:\old d\games\majesty.2-kaos\resource\texture\common\landscape\rock\crack.dds
c:\old d\games\majesty.2-kaos\resource\texture\fx\flares\cracks.dds
c:\old d\games\majesty.2-kaos\resource\texture\fx\flares\lightningcrack_n.dds
c:\old d\games installations\alawar alien outbreak 2 invasion crack.rar
c:\old d\games installations\alawar snowy space trip v1.1 + crack.zip
c:\old d\games installations\cubis gold 2 and crack.rar
c:\old d\games installations\luxor - amun rising 1.5.5.8 gh-crack.rar
c:\old d\games installations\mosaic tomb of mystery + crack.zip
c:\old d\games installations\mystery case files huntsville & keygen (reflexive arcade).rar
c:\old d\games installations\mystery case files huntsville crack.rar
c:\old d\games installations\mystery case files prime suspects v 1.1 crack.rar
c:\old d\games installations\pirate poppers + crack.rar
c:\old d\games installations\ricochet lw recharged crack note.txt
c:\old d\games installations\ricochet.lost.worlds.recharged.v1.1.29.keygen.exe
c:\old d\games installations\ricochet.xtreme.+.crack.zip
c:\old d\games installations\snowy games - bears adventures - spacetrip - puzzle island + packs - treasure hunter - cracked !!! - powered by phoenix.rar
c:\old d\games installations\anno 1701\crack\anno1701.exe
c:\old d\games installations\cubis gold 2 and crack\cubis gold 2.exe
c:\old d\games installations\cubis gold 2 and crack\cubis2.rar
c:\old d\games installations\cubis gold 2 and crack\cubis2\cubis2.exe
c:\old d\games installations\fish tycoon + keygen\fishtycoonsetup.exe
c:\old d\games installations\fish tycoon + keygen\keygen\eclacr18.exe
c:\old d\games installations\fish tycoon + keygen\keygen\eclipse.nfo
c:\old d\games installations\fish tycoon + keygen\keygen\file_id.diz
c:\old d\games installations\mystery case files prime suspects v 1.1 crack\mysterycasefiles'primesuspects'v1.1\en_mysterycasefilespr_inst.exe
c:\old d\games installations\mystery case files prime suspects v 1.1 crack\mysterycasefiles'primesuspects'v1.1\crack\primesuspects.exe
c:\old d\games installations\sacred\sacred crack.rar
c:\old d\games installations\snowy treasure hunter (alawar) - registered version\crack\instructions.txt
c:\old d\games installations\snowy treasure hunter (alawar) - registered version\crack\reg-key.txt
c:\old d\games installations\snowy treasure hunter (alawar) - registered version\crack\treasurehunter.exe
c:\old d\games installations\spore\spore.crackfix-reloaded\reloaded.nfo
c:\old d\games installations\spore\spore.crackfix-reloaded\rld-spof.rar
c:\old d\games installations\spore\spore.crackfix-reloaded\rld-spof.sfv
c:\old d\games installations\spore\spore.crackfix-reloaded\serial.txt
c:\old d\ilan\desktop\spyware doctor - update - v5.0.0.177 - inc crack - by speculum.rar
c:\old d\program install\region crack ltnrpc.zip
c:\old d\program install\compress\winrar\winrar password cracker.rar
c:\old d\program install\compress\winzip\wincrack.zip
c:\old d\program install\microsoft office\microsoft.office.2007.oga.crack.stealth\oga-stealth.rar
c:\old d\program install\microsoft office\microsoft.office.2007.oga.crack.stealth\stealth.nfo
c:\old d\program install\ocr\ligarure\3ac6f22d226a46c9 (ligature 4 crack) [sn- t934730434875].zip
c:\old d\rpg\campaign cartographer 2 v6 cracked.zip
c:\old d\tumblebugs\tumble bugs\2\keygen.nfo
c:\old d\warhammer\army builder + crack\ab22crack.rar
c:\old d\warhammer\army builder + crack\army builder + crack.rar
c:\old d\warhammer\army builder + crack\army builder 2.2.exe
c:\old d\warhammer\army builder + crack\armybuilder.zip
c:\old d\warhammer\army builder + crack\ea_v1p33.ab
c:\old d\warhammer\army builder + crack\kit22b.exe
c:\old d\warhammer\army builder + crack\p2gv191.ab
c:\old d\warhammer\army builder + crack\v4p8bfg.ab
c:\old d\warhammer\army builder + crack\wfbv7v007.ab
c:\old d\warhammer\army builder + crack\ab22crack\ab22crack.exe
c:\old d\warhammer\army builder + crack\ab22crack\abkey.lic
c:\old d\warhammer\army builder + crack\ab22crack\info.txt
c:\old f\trivia machine & keygen.rar
c:\old f\bigfish games - home sweet home 2 kitchens and baths + adnan_boy 2008 + precracked\home sweet home 2 kitchens and baths.exe
c:\old f\clue classic board game\crack\clueclassic.dll
c:\old f\gamehouse games - clue classic + adnan_boy 2008 + precracked\clue classic.exe
c:\old f\games\elizabeth find md diagnosis mystery - season 2 - full precracked\elizabeth find md diagnosis mystery - season 2.exe
c:\old f\games\nostradamus.the.last.prophecy-reloaded\new folder\crack\nostradamus.exe
c:\old f\haunted domains - full precracked\haunted domains - full precracked.exe
c:\old f\hide and secret 4 the lost world - full precracked\hide and secret 4 the lost world - full precracked.exe
c:\old f\mortimer beckett - crimson thief pe\mortimer beckett - crimson thief pe\gfx\video\firecracker.bik
c:\old f\sky taxi 4 - top secret - full precracked - foxy games\sky taxi 4 - top secret - full precracked - foxy games.exe
c:\old f\spooky mall - full precracked - foxy games\spooky mall - full precracked - foxy games.exe
c:\old f\star defender 4 v1.20 {precracked} {requested} {blaze69}\readme.txt
c:\old f\star defender 4 v1.20 {precracked} {requested} {blaze69}\star defender 4.exe
c:\old f\trivia machine & keygen\code.txt
c:\old f\trivia machine & keygen\trivia machine\keygen.exe
c:\old f\trivia machine & keygen\trivia machine\triviamachinesetup.exe
c:\users\home\downloads\activators\use this\removewat.exe
c:\users\home\downloads\activators\windows 7 activator + remove wat\removewat.exe
c:\users\home\downloads\activators\windows 7 activator removewat v2.2.5.2 by hazar~dibya\$rvwskje.exe
c:\users\home\downloads\activators\windows 7 activator removewat v2.2.5.2 by hazar~dibya\dibya9999.nfo
c:\users\home\downloads\activators\windows 7 activator removewat v2.2.5.2 by hazar~dibya\read me.txt
c:\users\home\downloads\activators\windows 7 activator removewat v2.2.5.2 by hazar~dibya\readme.txt
c:\users\home\downloads\activators\windows 7 activator removewat v2.2.5.2 by hazar~dibya\removewat.exe
c:\users\home\downloads\activators\windows 7 activator removewat v2.2.5.2 by hazar~dibya\windows 7 activator removewat v2.2.5.2 by hazar~dibya.rar0
c:\users\home\downloads\activators\windows 7 activator [2010] [blaze69] [new]\new windows 7 activator [2010]\removewat.exe
c:\users\home\downloads\reflexive game - ricochet infinity setup + crack\reflexive_patch.exe
c:\users\home\downloads\reflexive game - ricochet infinity setup + crack\ricochetinfinitysetup.exe
c:\users\home\downloads\reflexive game - ricochet infinity setup + crack\thumbs.db
c:\windows\system32\slmgr.vbs.removewat
c:\windows\syswow64\slmgr.vbs.removewat
scanner sequence 3.ZZ.11.DVNASO
โโ EOF โโ
This is where we are at. You used the torrents to download and install illegal software, looks like your win 7 operating system maybe illegal also, this forum as well as all the other malware removal forums do not support the use of illegal software , except for there removal, if i was to continue helping you it could be construed in the eyes of the law as aiding and abetting a crime.
If you want to continue with cleaning your system, you need to look over the CKScanner log and remove all the illegal stuff, I dont have the time or desire to help you with this. Then run CKScanner again and post a new log.
Then were going to run a program to see if your operating system is illegal, if it is then you will have to contact Microsoft and purchase a licence.
If you dont agree to any of the above than this thread will be closed and no more help will be offered
I understand and apologize
Sorry to have bothered
Will try to find alternate solution
Hi,
I try to make people understand that almost 99.99999% of illegal software is infected but they still download it. If you where sitting in my seat and where aware of all the latest threats it would make your hair stand on end, malware thats steals personal info including Credit Card Numbers, log on passwords that you may use for online shopping and banking along with your banking account numbers, and this is just the tip of the iceburg. There are a couple of nasties going around that are uncleanable, the only recourse would be to format and reinstall windows.
Thanks for understanding, I think what I would do if i where you would be to go online to Amazon or eBay and purchase a legal copy of windows, format and reinstall it and stay way from any form of File Sharing
Since this issue appears to be resolved โฆ this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.