Jump to content

I am infected?


Recommended Posts

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2012-11-20.01)

.

Microsoft Windows 7 Ultimate

Boot Device: \Device\HarddiskVolume1

Install Date: 26/04/2013 19:10:46

System Uptime: 03/06/2013 17:38:55 (0 hours ago)

.

Motherboard: Gigabyte Technology Co., Ltd. | | GA-870A-USB3

Processor: AMD Phenom II X4 B60 Processor | Socket M2 | 3400/200mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 119 GiB total, 94,466 GiB free.

D: is FIXED (NTFS) - 149 GiB total, 132,363 GiB free.

E: is CDROM ()

F: is Removable

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

No restore point in system.

.

==== Installed Programs ======================

.

@BIOS

Adobe Reader XI (11.0.02) - Español

AMD Accelerated Video Transcoding

AMD Catalyst Install Manager

AMD Drag and Drop Transcoding

AMD Fuel

AMD Media Foundation Decoders

AMD VISION Engine Control Center

Aplicación para detectar Winamp

µTorrent

Bitdefender Total Security 2013

Catalyst Control Center - Branding

Catalyst Control Center Graphics Previews Common

Catalyst Control Center Localization All

ccc-utility64

CCC Help Chinese Standard

CCC Help Chinese Traditional

CCC Help Czech

CCC Help Danish

CCC Help Dutch

CCC Help English

CCC Help Finnish

CCC Help French

CCC Help German

CCC Help Greek

CCC Help Hungarian

CCC Help Italian

CCC Help Japanese

CCC Help Korean

CCC Help Norwegian

CCC Help Polish

CCC Help Portuguese

CCC Help Russian

CCC Help Spanish

CCC Help Swedish

CCC Help Thai

CCC Help Turkish

CCleaner

Compresor WinRAR

Core Temp 1.0 RC5

CPUID HWMonitor 1.22

DAEMON Tools Pro

Etron USB3.0 Host Controller

F.lux

Full Tilt Poker

Glary Utilities 2.55.0.1790

Google Chrome

Google Update Helper

Holdem Manager

K-Lite Codec Pack 5.4.4 (Full)

KeePass Password Safe 2.22

KeyScrambler

Malwarebytes Anti-Malware versión 1.75.0.1300

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Client Profile ESN Language Pack

Microsoft .NET Framework 4 Extended

Microsoft .NET Framework 4 Extended ESN Language Pack

Microsoft Office Access MUI (English) 2010

Microsoft Office Access Setup Metadata MUI (English) 2010

Microsoft Office Excel MUI (English) 2010

Microsoft Office Groove MUI (English) 2010

Microsoft Office InfoPath MUI (English) 2010

Microsoft Office Office 64-bit Components 2010

Microsoft Office OneNote MUI (English) 2010

Microsoft Office Outlook MUI (English) 2010

Microsoft Office PowerPoint MUI (English) 2010

Microsoft Office Professional Plus 2010

Microsoft Office Proof (English) 2010

Microsoft Office Proof (French) 2010

Microsoft Office Proof (Spanish) 2010

Microsoft Office Proofing (English) 2010

Microsoft Office Publisher MUI (English) 2010

Microsoft Office Shared 64-bit MUI (English) 2010

Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010

Microsoft Office Shared MUI (English) 2010

Microsoft Office Shared Setup Metadata MUI (English) 2010

Microsoft Office Word MUI (English) 2010

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

Neo's SafeKeys 2008

ON_OFF Charge B11.0110.1

Paint.NET v3.5.10

Panda USB Vaccine 1.0.1.16

Paquete de idioma de Microsoft .NET Framework 4 Client Profile ESN

Paquete de idioma de Microsoft .NET Framework 4 Extended ESN

PokerStars

PokerStrategy.com Equilab

PostgreSQL 9.2

Rainmeter

Realtek Ethernet Controller Driver

Realtek HDMI Audio Driver for ATI

Realtek High Definition Audio Driver

Revo Uninstaller Pro 3.0.5

Samsung Magician

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Security Update for Microsoft .NET Framework 4 Extended (KB2736428)

Security Update for Microsoft .NET Framework 4 Extended (KB2742595)

Skype™ 6.3

Spybot - Search & Destroy

SpywareBlaster 5.0

SUPERAntiSpyware

TableNinja

TableScan Turbo v1.0.3

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Winamp

.

==== Event Viewer Messages From Past Week ========

.

03/06/2013 13:05:52, Error: Service Control Manager [7001] - El servicio Examinador de equipos depende del servicio Servidor, el cual no pudo iniciarse debido al siguiente error: No se puede iniciar el servicio o grupo de dependencia.

03/06/2013 13:05:49, Error: Microsoft-Windows-DistributedCOM [10005] - Error de DCOM "1084" al intentar iniciar el servicio EventSystem con argumentos "" para ejecutar el servidor: {1BE1F766-5536-11D1-B726-00C04FB926AF}

03/06/2013 13:05:44, Error: Microsoft-Windows-DistributedCOM [10005] - Error de DCOM "1084" al intentar iniciar el servicio ShellHWDetection con argumentos "" para ejecutar el servidor: {DD522ACC-F821-461A-A407-50B198B896DC}

03/06/2013 13:05:40, Error: Service Control Manager [7026] - El siguiente controlador de inicio del sistema o de inicio del arranque no se cargó correctamente: AppleCharger avc3 BDVEDISK discache gzflt SASDIFSV SASKUTIL spldr trufos Wanarpv6

03/06/2013 13:01:49, Error: Service Control Manager [7031] - El servicio SAS Core Service terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 1000 milisegundos: Reiniciar el servicio.

03/06/2013 13:00:34, Error: Service Control Manager [7026] - El siguiente controlador de inicio del sistema o de inicio del arranque no se cargó correctamente: AppleCharger avc3 BDVEDISK discache gzflt SASDIFSV SASKUTIL spldr trufos Wanarpv6

03/06/2013 12:41:19, Error: Service Control Manager [7026] - El siguiente controlador de inicio del sistema o de inicio del arranque no se cargó correctamente: AppleCharger avc3 BDVEDISK discache gzflt SASDIFSV SASKUTIL spldr trufos Wanarpv6

.

==== End Of File ===========================

DDS (Ver_2012-11-20.01) - NTFS_AMD64

Internet Explorer: 8.0.7601.17514

Run by Chifo at 17:44:43 on 2013-06-03

Microsoft Windows 7 Ultimate 6.1.7601.1.1252.54.3082.18.4094.2220 [GMT -3:00]

.

AV: Bitdefender Antivirus *Enabled/Updated* {9B5F5313-CAF9-DD97-C460-E778420237B4}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

SP: Bitdefender Antispyware *Enabled/Updated* {203EB2F7-ECC3-D219-FED0-DC0A39857D09}

FW: Bitdefender Cortafuegos *Disabled* {A364D236-8096-DCCF-EF3F-4E4DBCD170CF}

.

============== Running Processes ===============

.

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\system32\atieclxx.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE

C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe

C:\Program Files\PostgreSQL\9.2\bin\pg_ctl.exe

C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe

C:\Program Files\PostgreSQL\9.2\bin\postgres.exe

C:\Program Files\PostgreSQL\9.2\bin\postgres.exe

C:\Program Files\PostgreSQL\9.2\bin\postgres.exe

C:\Program Files\PostgreSQL\9.2\bin\postgres.exe

C:\Program Files\PostgreSQL\9.2\bin\postgres.exe

C:\Program Files\PostgreSQL\9.2\bin\postgres.exe

C:\Program Files\PostgreSQL\9.2\bin\postgres.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe

C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe

C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\System32\WUDFHost.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe

C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe

C:\Users\Chifo\Local Settings\Apps\F.lux\flux.exe

C:\Program Files\Rainmeter\Rainmeter.exe

C:\Program Files (x86)\Panda USB Vaccine\USBVaccine.exe

C:\Program Files (x86)\KeyScrambler\KeyScrambler.exe

C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\Program Files (x86)\KeyScrambler\x64\KeyScrambler.exe

C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files (x86)\RVG Software\Holdem Manager\HoldemManager.exe

C:\Program Files\PostgreSQL\9.2\bin\postgres.exe

C:\Program Files (x86)\RVG Software\Holdem Manager\HMImport.exe

C:\Program Files\PostgreSQL\9.2\bin\postgres.exe

C:\Program Files (x86)\RVG Software\Holdem Manager\HMHud.exe

C:\Program Files (x86)\TableNinja\TableNinja.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\system32\sppsvc.exe

C:\Program Files (x86)\TableScan Turbo\TableScan.exe

C:\Program Files (x86)\PokerStrategy.com\PokerStrategy.com Equilab\Equilab.exe

C:\Program Files (x86)\PokerStars\PokerStars.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

\\?\C:\Windows\system32\wbem\WMIADAP.EXE

C:\Program Files\Bitdefender\Bitdefender 2013\seccenter.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\System32\cscript.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = www.google.com

mStart Page = www.google.com

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll

BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL

BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL

uRun: [F.lux] "C:\Users\Chifo\Local Settings\Apps\F.lux\flux.exe" /noshow

mRun: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload

mRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun: [KeyScrambler] C:\Program Files (x86)\KeyScrambler\keyscrambler.exe /a

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\RAINME~1.LNK - C:\Program Files\Rainmeter\Rainmeter.exe

uPolicies-Explorer: NoDriveTypeAutoRun = dword:145

uPolicies-Explorer: NoDriveAutoRun = dword:3

uPolicies-Explorer: NoDrives = dword:0

mPolicies-Explorer: NoDriveTypeAutoRun = dword:0

mPolicies-Explorer: NoDriveAutoRun = dword:3

mPolicies-Explorer: NoDrives = dword:0

mPolicies-System: ConsentPromptBehaviorAdmin = dword:0

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableLUA = dword:0

mPolicies-System: EnableUIADesktopToggle = dword:0

mPolicies-System: PromptOnSecureDesktop = dword:0

IE: E&xport to Microsoft Excel - C:\PROGRA~2\Microsoft Office\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - C:\PROGRA~2\Microsoft Office\Office14\ONBttnIE.dll/105

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll

.

INFO: HKCU has more than 50 listed domains.

If you wish to scan all of them, select the 'Force scan all domains' option.

.

.

INFO: HKLM has more than 50 listed domains.

If you wish to scan all of them, select the 'Force scan all domains' option.

.

TCP: NameServer = 200.42.4.207 200.49.130.44

TCP: Interfaces\{0F13615F-A536-479E-BDD8-6C040B01ABAF} : DHCPNameServer = 200.42.4.207 200.49.130.44

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

SSODL: WebCheck - <orphaned>

SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL

mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

x64-mStart Page = www.google.com

x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL

x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL

x64-Run: [bdagent] C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe

x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

.

INFO: x64-HKLM has more than 50 listed domains.

If you wish to scan all of them, select the 'Force scan all domains' option.

.

x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>

x64-SSODL: WebCheck - <orphaned>

x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL

.

============= SERVICES / DRIVERS ===============

.

R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2012-10-11 82600]

R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2012-10-11 42664]

R0 avc3;avc3;C:\Windows\System32\drivers\avc3.sys [2013-5-16 718840]

R0 gzflt;gzflt;C:\Windows\System32\drivers\gzflt.sys [2013-5-16 147232]

R1 AppleCharger;AppleCharger;C:\Windows\System32\drivers\AppleCharger.sys [2013-4-26 21104]

R1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [2013-5-16 93600]

R1 bdfwfpf;bdfwfpf;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [2013-5-16 103504]

R1 BDVEDISK;BDVEDISK;C:\Windows\System32\drivers\bdvedisk.sys [2013-5-16 76944]

R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]

R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]

R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2012-7-11 140672]

R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2013-3-28 241152]

R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-3-28 361984]

R2 AODDriver4.2;AODDriver4.2;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-4-9 57472]

R2 postgresql-x64-9.2;postgresql-x64-9.2 - PostgreSQL Server 9.2;C:/Program Files/PostgreSQL/9.2/bin/pg_ctl.exe runservice -N "postgresql-x64-9.2" -D "C:/Program Files/PostgreSQL/9.2/data" -w --> C:/Program Files/PostgreSQL/9.2/bin/pg_ctl.exe runservice -N postgresql-x64-9.2 [?]

R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-4-28 1103392]

R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-4-28 1369624]

R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-4-28 168384]

R2 UPDATESRV;Bitdefender Desktop Update Service;C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [2013-5-16 68856]

R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2013-2-14 96768]

R3 avchv;avchv Function Driver;C:\Windows\System32\drivers\avchv.sys [2013-4-26 261056]

R3 avckf;avckf;C:\Windows\System32\drivers\avckf.sys [2013-5-16 593144]

R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2013-4-27 283200]

R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\System32\drivers\EtronHub3.sys [2011-1-26 39808]

R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\System32\drivers\EtronXHCI.sys [2011-1-26 64256]

R3 KeyScrambler;KeyScrambler;C:\Windows\System32\drivers\keyscrambler.sys [2013-5-5 222232]

R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-4-26 413800]

R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2013-4-26 58536]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 SafeBox;SafeBox;C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe [2013-5-16 95184]

S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-2-28 161384]

S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]

S3 BDSandBox;BDSandBox;C:\Windows\System32\drivers\bdsandbox.sys [2013-5-16 82384]

S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2013-4-26 30528]

S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-4-26 20992]

S3 Revoflt;Revoflt;C:\Windows\System32\drivers\revoflt.sys [2013-5-4 31800]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-4-27 59392]

S3 WatAdminSvc;Servicio de tecnologías de activación de Windows;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-4-27 1255736]

S4 BdDesktopParental;Bitdefender Desktop Parental Control;C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [2013-5-16 69392]

.

=============== Created Last 30 ================

.

2013-06-03 16:01:14 -------- d-----w- C:\_AT-Destroyer

2013-06-01 17:12:19 -------- dc----w- C:\Users\Chifo\AppData\Local\MigWiz

2013-05-30 17:04:38 -------- d-sh--w- C:\$RECYCLE.BIN

2013-05-30 16:10:37 98816 ----a-w- C:\Windows\sed.exe

2013-05-30 16:10:37 256000 ----a-w- C:\Windows\PEV.exe

2013-05-30 16:10:37 208896 ----a-w- C:\Windows\MBR.exe

2013-05-29 21:34:34 866720 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll

2013-05-29 21:34:34 788896 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2013-05-16 21:32:40 76944 ----a-w- C:\Windows\System32\drivers\bdvedisk.sys

2013-05-16 21:32:34 93600 ----a-w- C:\Windows\System32\drivers\BdfNdisf6.sys

2013-05-16 21:32:34 82384 ----a-w- C:\Windows\System32\drivers\bdsandbox.sys

2013-05-16 21:32:31 718840 ----a-w- C:\Windows\System32\drivers\avc3.sys

2013-05-16 21:32:31 593144 ----a-w- C:\Windows\System32\drivers\avckf.sys

2013-05-16 21:29:44 -------- d-----w- C:\Users\Chifo\AppData\Roaming\Bitdefender

2013-05-16 21:29:41 -------- d-----w- C:\ProgramData\Bitdefender

2013-05-16 21:24:26 147232 ----a-w- C:\Windows\System32\drivers\gzflt.sys

2013-05-16 21:24:25 350160 ----a-w- C:\Windows\System32\drivers\trufos.sys

2013-05-16 21:23:57 -------- d-----w- C:\Program Files (x86)\Common Files\Bitdefender

2013-05-16 16:23:11 -------- d-----w- C:\Users\Chifo\AppData\Local\Paint.NET

2013-05-16 16:23:11 -------- d-----w- C:\Program Files\Paint.NET

2013-05-14 21:06:51 1930752 ----a-w- C:\Windows\System32\authui.dll

2013-05-14 21:06:50 70144 ----a-w- C:\Windows\System32\appinfo.dll

2013-05-14 21:06:50 1796096 ----a-w- C:\Windows\SysWow64\authui.dll

2013-05-14 21:06:50 111448 ----a-w- C:\Windows\System32\consent.exe

2013-05-14 21:06:34 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll

2013-05-14 21:06:34 230400 ----a-w- C:\Windows\System32\wwansvc.dll

2013-05-11 00:41:23 -------- d-----w- C:\UsbFix

2013-05-11 00:00:29 -------- d-----w- C:\ProgramData\Panda Security

2013-05-11 00:00:26 -------- d-----w- C:\Program Files (x86)\Panda USB Vaccine

2013-05-10 23:57:54 -------- d-----w- C:\ProgramData\Licenses

2013-05-10 23:57:53 129872 ----a-w- C:\Windows\SysWow64\MSSTDFMT.DLL

2013-05-10 23:57:52 -------- d-----w- C:\Program Files (x86)\SpywareBlaster

2013-05-10 20:43:28 -------- d-----w- C:\Users\Chifo\AppData\Roaming\GlarySoft

2013-05-10 20:40:48 -------- d-----w- C:\Program Files (x86)\Glary Utilities

2013-05-07 17:59:04 -------- d-----w- C:\Program Files\CPUID

2013-05-06 21:55:15 -------- d-----w- C:\Program Files\Core Temp

2013-05-06 21:08:33 231376 ----a-w- C:\Windows\System32\drivers\truecrypt.sys

2013-05-06 17:28:17 -------- d-----w- C:\Program Files (x86)\Samsung SSD Magician

2013-05-05 22:34:29 -------- d-----w- C:\Users\Chifo\AppData\Roaming\QFX Software

2013-05-05 22:34:29 -------- d-----w- C:\ProgramData\QFX Software

2013-05-05 21:18:09 222232 ----a-w- C:\Windows\System32\drivers\keyscrambler.sys

2013-05-05 21:18:08 -------- d-----w- C:\Program Files (x86)\KeyScrambler

2013-05-05 21:14:18 -------- d-----w- C:\Program Files (x86)\Neo's SafeKeys 2008

2013-05-05 02:03:46 -------- d-----w- C:\Users\Chifo\AppData\Roaming\postgresql

2013-05-05 01:22:18 22752 ----a-w- C:\Windows\System32\PCloudBroom64.exe

2013-05-05 01:17:51 -------- d-----w- C:\Program Files (x86)\Panda Security

.

==================== Find3M ====================

.

2013-05-03 23:00:49 25640 ----a-w- C:\Windows\gdrv.sys

2013-04-28 02:22:09 113629 ----a-w- C:\Windows\System32\slmgr.vbs

2013-04-28 01:30:43 283200 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys

2013-04-27 16:51:34 175616 ----a-w- C:\Windows\System32\msclmd.dll

2013-04-27 16:51:34 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll

2013-04-26 23:46:08 30528 ----a-w- C:\Windows\GVTDrv64.sys

2013-04-26 23:09:36 0 ----a-w- C:\Windows\ativpsrm.bin

2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll

2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll

2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll

2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll

2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll

2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll

2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys

2013-04-10 06:01:54 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys

2013-04-10 06:01:53 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys

2013-04-10 05:51:43 1188864 ----a-w- C:\Windows\System32\wininet.dll

2013-04-10 05:08:12 981504 ----a-w- C:\Windows\SysWow64\wininet.dll

2013-04-10 03:30:50 3153920 ----a-w- C:\Windows\System32\win32k.sys

2013-04-04 17:50:32 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys

2013-03-29 02:37:10 78432 ----a-w- C:\Windows\System32\atimpc64.dll

2013-03-29 02:37:10 78432 ----a-w- C:\Windows\System32\amdpcom64.dll

2013-03-29 02:37:10 71704 ----a-w- C:\Windows\SysWow64\atimpc32.dll

2013-03-29 02:37:10 71704 ----a-w- C:\Windows\SysWow64\amdpcom32.dll

2013-03-29 02:37:06 139696 ----a-w- C:\Windows\System32\atiuxp64.dll

2013-03-29 02:37:04 92304 ----a-w- C:\Windows\SysWow64\atiu9pag.dll

2013-03-29 02:37:04 118584 ----a-w- C:\Windows\SysWow64\atiuxpag.dll

2013-03-29 02:37:04 112440 ----a-w- C:\Windows\System32\atiu9p64.dll

2013-03-29 02:37:02 1155264 ----a-w- C:\Windows\System32\aticfx64.dll

2013-03-29 02:37:00 970912 ----a-w- C:\Windows\SysWow64\aticfx32.dll

2013-03-29 02:36:56 8272136 ----a-w- C:\Windows\System32\atidxx64.dll

2013-03-29 02:36:54 7233336 ----a-w- C:\Windows\SysWow64\atidxx32.dll

2013-03-29 02:36:50 4450264 ----a-w- C:\Windows\SysWow64\atiumdva.dll

2013-03-29 02:36:44 5944264 ----a-w- C:\Windows\SysWow64\atiumdag.dll

2013-03-29 02:36:40 5000320 ----a-w- C:\Windows\System32\atiumd6a.dll

2013-03-29 02:36:38 6985624 ----a-w- C:\Windows\System32\atiumd64.dll

2013-03-29 02:35:02 11658752 ----a-w- C:\Windows\System32\drivers\atikmdag.sys

2013-03-29 02:13:28 222720 ----a-w- C:\Windows\System32\clinfo.exe

2013-03-29 02:13:14 798734 ----a-w- C:\Windows\SysWow64\amdocl_ld32.exe

2013-03-29 02:13:14 1187342 ----a-w- C:\Windows\System32\amdocl_as64.exe

2013-03-29 02:13:14 1061902 ----a-w- C:\Windows\System32\amdocl_ld64.exe

2013-03-29 02:13:12 995342 ----a-w- C:\Windows\SysWow64\amdocl_as32.exe

2013-03-29 02:13:08 76288 ----a-w- C:\Windows\System32\OpenVideo64.dll

2013-03-29 02:13:04 65536 ----a-w- C:\Windows\SysWow64\OpenVideo.dll

2013-03-29 02:13:00 64000 ----a-w- C:\Windows\System32\OVDecode64.dll

2013-03-29 02:12:56 56320 ----a-w- C:\Windows\SysWow64\OVDecode.dll

2013-03-29 02:12:48 29150720 ----a-w- C:\Windows\System32\amdocl64.dll

2013-03-29 02:10:52 23810560 ----a-w- C:\Windows\SysWow64\amdocl.dll

2013-03-29 02:09:04 54784 ----a-w- C:\Windows\System32\OpenCL.dll

2013-03-29 02:09:00 50176 ----a-w- C:\Windows\SysWow64\OpenCL.dll

2013-03-29 02:04:42 24229376 ----a-w- C:\Windows\System32\atio6axx.dll

2013-03-29 02:00:54 76800 ----a-w- C:\Windows\System32\coinst_12.104.dll

2013-03-29 01:57:54 163840 ----a-w- C:\Windows\System32\atiapfxx.exe

2013-03-29 01:55:36 51200 ----a-w- C:\Windows\System32\aticalrt64.dll

2013-03-29 01:55:34 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll

2013-03-29 01:55:28 44544 ----a-w- C:\Windows\System32\aticalcl64.dll

2013-03-29 01:55:28 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll

2013-03-29 01:55:16 16082944 ----a-w- C:\Windows\System32\aticaldd64.dll

2013-03-29 01:51:04 13703168 ----a-w- C:\Windows\SysWow64\aticaldd.dll

2013-03-29 01:48:26 19870720 ----a-w- C:\Windows\SysWow64\atioglxx.dll

2013-03-29 01:35:14 442368 ----a-w- C:\Windows\System32\atidemgy.dll

2013-03-29 01:35:06 562688 ----a-w- C:\Windows\System32\atieclxx.exe

2013-03-29 01:34:18 241152 ----a-w- C:\Windows\System32\atiesrxx.exe

2013-03-29 01:33:00 120320 ----a-w- C:\Windows\System32\atitmm64.dll

2013-03-29 01:32:46 26112 ----a-w- C:\Windows\System32\atimuixx.dll

2013-03-29 01:32:42 59392 ----a-w- C:\Windows\System32\atiedu64.dll

2013-03-29 01:32:36 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll

2013-03-29 01:10:30 636416 ----a-w- C:\Windows\System32\atiadlxx.dll

2013-03-29 01:10:20 430080 ----a-w- C:\Windows\SysWow64\atiadlxy.dll

2013-03-29 01:10:08 17920 ----a-w- C:\Windows\System32\atig6pxx.dll

2013-03-29 01:10:04 14848 ----a-w- C:\Windows\SysWow64\atiglpxx.dll

2013-03-29 01:10:04 14848 ----a-w- C:\Windows\System32\atiglpxx.dll

2013-03-29 01:10:00 44032 ----a-w- C:\Windows\System32\atig6txx.dll

2013-03-29 01:09:52 34816 ----a-w- C:\Windows\SysWow64\atigktxx.dll

2013-03-29 01:09:44 581120 ----a-w- C:\Windows\System32\drivers\atikmpag.sys

2013-03-29 01:07:52 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll

2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe

2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll

2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll

2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe

.

============= FINISH: 17:44:58,38 ===============

Link to post
Share on other sites

Hi there,

my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

Download GMER Rootkit Scanner from here or here. Unzip it to your Desktop.

========================================================

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

========================================================

Double-click gmer.exe. The program will begin to run.

**Caution**

These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised by a trained Security Analyst

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.

  • Click Yes.
  • Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.

If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.

  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.

Pleae attach the gmer.txt to your reply:

  1. Click the[Manage Attachments] button under Additional Options > Attach Files on the post composition page, browse to where you saved the file, and
  2. Click Upload.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

Link to post
Share on other sites

Here the log of MBAM , and i attach the log of Gmer

Malwarebytes Anti-Malware 1.75.0.1300

www.malwarebytes.org

Versión de la Base de Datos: v2013.06.04.06

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 8.0.7601.17514

Chifo :: CHIFO-PC [administrador]

04/06/2013 13:29:47

mbam-log-2013-06-04 (13-29-47).txt

Tipos de Análisis: Análisis Rápido

Opciones de análisis activado: Memoria | Inicio | Registro | Sistema de archivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM

Opciones de análisis desactivados: P2P

Objetos examinados: 220918

Tiempo transcurrido: 1 minuto(s), 34 segundo(s)

Procesos en Memoria Detectados: 0

(No se han detectado elementos maliciosos)

Módulos de Memoria Detectados: 0

(No se han detectado elementos maliciosos)

Claves del Registro Detectados: 0

(No se han detectado elementos maliciosos)

Valores del Registro Detectados: 0

(No se han detectado elementos maliciosos)

Elementos de Datos del Registro Detectados: 0

(No se han detectado elementos maliciosos)

Carpetas Detectadas: 0

(No se han detectado elementos maliciosos)

Archivos Detectados: 0

(No se han detectado elementos maliciosos)

fin)

Gmer.txt

Link to post
Share on other sites

Nothing to see...

Please go to here to run the online scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth Technology

[*]Click Scan[*]Wait for the scan to finish[*]If any threats were found, click the 'List of found threats' , then click Export to text file.... [*]Save it to your desktop, then please copy and paste that log as a reply to this topic.

Link to post
Share on other sites

Fine!

Scan with adwCleaner

Please download AdwCleaner to your desktop.

  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[s1].txt also.

SecurityCheck

Please download SecurityCheck from one of the following mirrors: LINK1 LINK2

  • Save the file to your desktop.
  • Run Securitycheck.exe and follow the instructions within the DOS-Box.
  • When the scan is finished it will open up a text file (checkup.txt).

Post its content within your next reply.

Link to post
Share on other sites

# AdwCleaner v2.301 - Fichero creado el 05/06/2013 a 12:06:59

# Actualizado el 16/05/2013 por Xplode

# Sistema operativo : Windows 7 Ultimate Service Pack 1 (64 bits)

# Usuario : Chifo - CHIFO-PC

# Modo de inicio : Normal

# Ejecutado desde : C:\Users\Chifo\Desktop\adwcleaner.exe

# Opción [supresión]

***** [servicios] *****

***** [Ficheros / Carpetas] *****

***** [Registro] *****

***** [Navegadores] *****

-\\ Internet Explorer v8.0.7601.17514

[OK] El registro no contiene ninguna entrada ilegítima.

-\\ Google Chrome v27.0.1453.110

Fichero : C:\Users\Chifo\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] El fichero no contiene ninguna entrada ilegítima.

*************************

AdwCleaner[s1].txt - [746 octets] - [05/06/2013 12:06:59]

########## EOF - C:\AdwCleaner[s1].txt - [805 octets] ##########

SecurityCheck :

Results of screen317's Security Check version 0.99.64

Windows 7 Service Pack 1 x64 (UAC is disabled!)

``````````````Antivirus/Firewall Check:``````````````

Bitdefender Antivirus

Antivirus up to date!

`````````Anti-malware/Other Utilities Check:`````````

SpywareBlaster 5.0

Spybot - Search & Destroy

Malwarebytes Anti-Malware versión 1.75.0.1300

Adobe Reader XI

Google Chrome 27.0.1453.110

Google Chrome 27.0.1453.94

````````Process Check: objlist.exe by Laurent````````

Spybot Teatimer.exe is disabled!

Bitdefender Bitdefender 2013 vsserv.exe

Bitdefender Bitdefender 2013 updatesrv.exe

Bitdefender Bitdefender 2013 bdagent.exe

`````````````````System Health check`````````````````

Total Fragmentation on Drive C:

````````````````````End of Log``````````````````````

Link to post
Share on other sites

That´s it - your system is all clean! :)

Uninstall our tools.

Please follow these steps in order:

  1. In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  2. In the case we used Combofix. Rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  3. In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process

[*] If there is still something left please delete it manualy.

Reading Material

How to protect yourself

  • System Updates
    Beeing up to date is very important. Please be sure to activate automatic updates in your control panel.
    Windows XP | Windows Vista |
    Windows 7 | windows 8
  • Protection
    What you need is one (not more) good virus scanner with backgroud protection. Additionally I recommend a special malwarescanner that you run from time to time.
    Personally I am using the avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer you good protection for free use. But please remember: You get only the full protection if you use the payed versions of your security software.
  • Up to date Software
    Stay up to date with all the programs you use. Some of those really have to have an eye on are: your browser(s) including add-ons and plug-ins, Java, Flash Player, your virus scanner, and basically every software you use often. These link may help you to check:

    [*] Backups

    There are chances for an emergency every day. So be prepared. Back up your data on a regular basis. If you burn it to DVDs from time to time, use a cloud-drive or a professional network backup system is your choice.

    [*] Brains

    It's no joke! You really need one of those things. :) It is very important not just to click anywhere it is colored or flashing while you surfing on the web. Do not click an OK button on any popping window without reading what it says. While installing software always choose the custom mode, read what those windows says and uncheck adware that will be installed along the software you want.

Link to post
Share on other sites

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.