Infected while helping :(

Orbital Shark

New member
Guru
VIP
Local time
9:44 PM
Messages
6,298
Location
Milton Keynes, United Kingdom
While searching for a solution to a problem poster here on sevenforums I found an answer that was close to what I needed, it was on another tech forum. Only thing was as soon as I closed the page down I was informed by MSE that I was infected.

After a full system scan, and some 750,000 files checked it reported to have remove 3 severe threats.

MSE.PNG

I then thought I'd check Task Manager to see if anything untoward was running and to my surprise I was faced with several processed with an 'Installer' description. Needless to say I immediately killed all suspect processes and deleted all temporary files from both

%systemroot%\Temp
%userprofile%\Appdata\Local\Temp

I then performed a reboot and all seemed well until the processes appeared once again so I downloaded MalwareBytes and performed a Quick Scan and again, I was faced with threats.

Below Is a copy of the log...
Code:
Malwarebytes' Anti-Malware 1.50.1.1100
[URL="http://www.malwarebytes.org"]www.malwarebytes.org[/URL]
Database version: 5976
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8080.16413
06/03/2011 21:25:24
mbam-log-2011-03-06 (21-25-24).txt
Scan type: Quick scan
Objects scanned: 189694
Time elapsed: 2 minute(s), 54 second(s)
Memory Processes Infected: 12
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 16
Memory Processes Infected:
c:\Users\Jeff\AppData\Local\Temp\WinSATa.exe (Trojan.Agent) -> 4524 -> Unloaded process successfully.
c:\Users\Jeff\AppData\Local\Temp\WinSATa.exe (Trojan.Agent) -> 6004 -> Unloaded process successfully.
c:\Users\Jeff\AppData\Local\Temp\atibtmonb.exe (Trojan.Agent) -> 4028 -> Unloaded process successfully.
c:\Users\Jeff\AppData\Local\Temp\atibtmonb.exe (Trojan.Agent) -> 6092 -> Unloaded process successfully.
c:\Users\Jeff\AppData\Local\Temp\klista.exe (Trojan.Agent) -> 2368 -> Unloaded process successfully.
c:\Users\Jeff\AppData\Local\Temp\klista.exe (Trojan.Agent) -> 6068 -> Unloaded process successfully.
c:\Users\Jeff\AppData\Local\Temp\forfilesb.exe (Trojan.Agent) -> 5692 -> Unloaded process successfully.
c:\Users\Jeff\AppData\Local\Temp\forfilesb.exe (Trojan.Agent) -> 4444 -> Unloaded process successfully.
c:\Users\Jeff\AppData\Local\Temp\odbcconfb.exe (Trojan.Agent) -> 4796 -> Unloaded process successfully.
c:\Users\Jeff\AppData\Local\Temp\odbcconfb.exe (Trojan.Agent) -> 5336 -> Unloaded process successfully.
c:\Users\Jeff\AppData\Local\Temp\logagenta.exe (Trojan.Agent) -> 6048 -> Unloaded process successfully.
c:\Users\Jeff\AppData\Local\Temp\logagenta.exe (Trojan.Agent) -> 5964 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\conhost (Spyware.Passwords.XGen) -> Value: conhost -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\Jeff\AppData\Local\Temp\WinSATa.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Jeff\AppData\Local\Temp\atibtmonb.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Jeff\AppData\Local\Temp\klista.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Jeff\AppData\Local\Temp\forfilesb.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Jeff\AppData\Local\Temp\odbcconfb.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Jeff\AppData\Local\Temp\logagenta.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\System32\config\systemprofile\AppData\Roaming\microsoft\conhost.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Windows\System32\config\systemprofile\AppData\Roaming\dwm.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Users\Jeff\AppData\Local\Temp\calca.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Jeff\AppData\Local\Temp\fixmapia.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Jeff\AppData\Local\Temp\ocsetupa.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Jeff\AppData\Local\Temp\printa.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Jeff\AppData\Local\Temp\psra.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{62c40aa6-4406-467a-a5a5-dfdf1b559b7a}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

Quite a lost really as I'm a very careful browser.

I have one main question...

If MSE detected a threat file after closing the browser page why did it not detect that the file was attempting to be downloaded to c:\windows\system32?

From that stems another one...

Why did it then allow for other files to embed themselves into Task Manager Registry and my temp locations?

Is it not the job of AntiVirus & Internet Security to do exactly what their name intends? Especially as 1 of the severe threats was months old (see info below).


SecurityCritical.png
TrojanDownloader:Win32/Ponmocup.A


(?)


Encyclopedia entry
Updated: Nov 25, 2010 | Published: Jun 04, 2010



Aliases
  • Swisyn.s (McAfee)
  • Trojan.Win32.Swisyn.jyb (Kaspersky)
  • W32.Changeup!gen (Symantec)
Alert Level (?)

Severe​
 

My Computer

Computer Manufacturer/Model Number
Compaq Desktop
OS
Windows 7 Ultimate x64
CPU
AMD Sempron Dual Core
Memory
3GB
Graphics Card(s)
NVIDIA GeForce 6150SE nForce 430
Screen Resolution
1024x768
Hard Drives
150GB Sata
Holy Crap! Sorry about that.....the replies will be interesting. Did you manage to clean your system?

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
This is why I browse with firefox running the noscript plugin. It's a bit problematic but very secure if you actually know what you're doing with it.
Injections are just too easy to make...
 

My Computer

Computer Manufacturer/Model Number
Insane hobo technologies. ;-)
OS
Windows 7 x64
CPU
Intel i7 2600k
Motherboard
Asrock z68 extreme 4 gen 3
Memory
G.skill Ripjaw 16gigs @ 1866
Graphics Card(s)
Nvidia gtx580 (evga)
Sound Card
Integrated HD audio + hdmi
Monitor(s) Displays
24" ASUS widescreen + 42" insignia
Screen Resolution
1080p (1920x1080)
Hard Drives
128 Samsung 830
256 Samsung 840
3 x 1tb storage drive (various)
1 western digital 1tb (eSATA)
1 Seagate 1tb (eSATA)
PSU
1 kilowatt SLI/Crossfire rated Silverstone modular
Case
NZXT Phantom + additional 220 fan
Cooling
Zalmann
Keyboard
Microsoft wireless 3000 (v2)
Mouse
MS - wireless 5000 (bluetrack)
Internet Speed
depends on if you ask me or my provider.
Other Info
The above information is provided as is, and the author assumes no responsibility for issues it may cause with your sanity or fanboyism.
Another MSE swing and miss. It's gotta be the most over rated AV on the planet. MBAM, HMP, SAS, NPE, Housecall are what I would start with, and hopefully all of those will work.....Good luck, and time to rethink your antivirus!
 

My Computer

OS
Windows 7 Home Premium x64 SP1
Yes it is, the web of trust addon is also helpful.

This is why I browse with firefox running the noscript plugin. It's a bit problematic but very secure if you actually know what you're doing with it.
Injections are just too easy to make...

Wow, that's one hell of a attack there, I hope you get it all cleared out.
 

My Computer

Computer Manufacturer/Model Number
HP DV6 1330sa
OS
Windows 7 Professional 64 Bit SP1
CPU
INTEL DUAL CORE 2.1Ghz
Motherboard
N/A
Memory
4GB DDR3
Graphics Card(s)
INTEL
Sound Card
LAPTOP
Monitor(s) Displays
2
Screen Resolution
3200x1080
Hard Drives
250GB
PSU
LAPTOP
Case
LAPTOP
Cooling
LAPTOP
Keyboard
SOLID YEAR 260U
Mouse
USB
Internet Speed
20 MB/S
I use WOT all the time when going to new places along with the favorites MBAM, SAS, and WinPatrol.
Yes it is an overkill but you don't see me asking for BSOD help.
 

My Computer

Computer Manufacturer/Model Number
HP M9077c
OS
Windows 7 Home Premium 64bit
CPU
Intel(R)Core(TM)2 quad [email protected] 2.39GHz
Motherboard
ASUSeK
Memory
6GB DDR2 6400
Graphics Card(s)
GeForce 8500/512MB
Sound Card
Realtek High Def Audio
Monitor(s) Displays
HP w2408 LCD 24" widescreen
Screen Resolution
1920x1200
Cooling
6 pack of Bud
Keyboard
MS wireless Inteli
Mouse
MS wireless Inteli
Prevention (for the most part) is better than a cure :) WOT really helps you avoid making a bad move.

I use WOT all the time when going to new places along with the favorites MBAM, SAS, and WinPatrol.
Yes it is an overkill but you don't see me asking for BSOD help.
 

My Computer

Computer Manufacturer/Model Number
HP DV6 1330sa
OS
Windows 7 Professional 64 Bit SP1
CPU
INTEL DUAL CORE 2.1Ghz
Motherboard
N/A
Memory
4GB DDR3
Graphics Card(s)
INTEL
Sound Card
LAPTOP
Monitor(s) Displays
2
Screen Resolution
3200x1080
Hard Drives
250GB
PSU
LAPTOP
Case
LAPTOP
Cooling
LAPTOP
Keyboard
SOLID YEAR 260U
Mouse
USB
Internet Speed
20 MB/S
Greetings.................... 1st, there is no such thing as "safe surfing, just use your common sense" anymore. :shock: 2nd A/V's wont protect you like they use too anymore either.:shock: 3rd, Please for the love of pete download and use Sandboxie for all your surfing needs from now on. :D I have never ever heard of any malware being able to get past sandboxie, so dont say you werent warned.:shock: Oh yea, its good enough to use all by itself.:shock:
 

My Computer

OS
Win 7 64 premium
Other Info
7 fw, LUA, UAC on high, IE-9 w/ smartscreen on, SANDBOXIE
I had a friend who died after getting infected while helping someone. :shock:

(His wife killed him.) :eek:
 

My Computer

Computer Manufacturer/Model Number
Self
OS
Main - Windows 7 Pro SP1 64-Bit; 2nd - Windows Server 2008 R2
CPU
Main - Core i7 2600K; 2nd - Core i7 920
Motherboard
Main - Asus P8Z68-V Pro/Gen3; 2nd - Gigabyte GA-EX58-UDR3
Memory
Main - 16GB Corsair Vengeance; 2nd - 12GB Corsair Vengeance
Graphics Card(s)
Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon 4870 1GB
Sound Card
Both: Onboard Realtek Azalia
Monitor(s) Displays
Main - Hann 25" + I-INC 25" + Acer 23"; 2nd - Upgrading Soon
Screen Resolution
Main - 1920x1080 (All Three Monitors); 2nd - Upgrading Soon
Hard Drives
Main - (1) Crucial M4 128GB (Boot)
Main - (1) Seagate 2TB 64MB Cache (Data)
Main - (1) Seagate 2TB 64MB Cache (Data Backup)
2nd - (1) Intel X25-M SSD 80GB (Boot)
2nd - (3) Seagate 1TB 32MB Cache (Data Backup)
2nd - (1) Seagate 320GB (Because)
PSU
Main - OCZ 600W Modular; 2nd - OCZ 600W
Case
Main - Thermaltake Element G; 2nd - NZXT something or other
Cooling
Main - Corsair H80; 2nd - Prolimatech Megahalems
Keyboard
Main - Razer Reclusa; 2nd - Old MS Keyboard
Mouse
Main - Logitech MX Revolution; 2nd - Old MS Mouse
Internet Speed
20Mbps Time-Warner Cable
Prevention

Take the following steps to help prevent infection on your system:


  • Enable a firewall on your computer.​
  • Get the latest computer updates for all your installed software.​
  • Use up-to-date antivirus software.​
  • Use caution when opening attachments and accepting file transfers.​
  • Use caution when clicking on links to Web pages.​
  • Avoid downloading pirated software.​
  • Protect yourself against social engineering attacks.​
  • Use strong passwords.​
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Windows 10 Pro
CPU
Intel i5
Motherboard
I have a fatherboard
Memory
I'm old and lost a few chips
Graphics Card(s)
Yup
Sound Card
Yup
Monitor(s) Displays
Samsung 32" UHD
Screen Resolution
3840 x 2160
Hard Drives
Samsung 860 EVO drives
PSU
450 Watt and some fans that blow
Case
Small tower
Cooling
Yes I am cool. lol
Keyboard
Who needs a keyboard?
Mouse
Logitech Laser G7 wireless
Internet Speed
Zippy fast UP and DOWN
Antivirus
I got a shot
Browser
The new Improved EDGE 2020
You forgot " Hands on 10 and 2 " :eek::zip:
 

My Computer

OS
Win 7 64 premium
Other Info
7 fw, LUA, UAC on high, IE-9 w/ smartscreen on, SANDBOXIE
As we reported several days ago in Search Engine Results – More Malware Surprises Than Ever!, poisoned search engine results have proven to be a gold mine for the bad guys who, naturally, continue to be unrelenting in their chase to infect web searches.

Since drive-by downloads, which don’t require user action to create an infection, are resident on many of these compromised sites, this is unhappy news for the unwary Internet user.

Source

A Guy
 

My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
In answer to your questions I got it cleaned up very easily ;)

As I run a company that deals with Cleaning/Removing Viruses & Malware, and General PC/Laptop Maintenance I'm more than well aware of the dangers of hidden infection it just bugs me that no matter what AV software you use, something will always find a way in, it's inevitable.

I'll stick with MSE as I still hold it in high regard and will put this down to another forum getting hijacked.

With 20 years dealing with this sort of crap you still never get used to it ;)
 

My Computer

Computer Manufacturer/Model Number
Compaq Desktop
OS
Windows 7 Ultimate x64
CPU
AMD Sempron Dual Core
Memory
3GB
Graphics Card(s)
NVIDIA GeForce 6150SE nForce 430
Screen Resolution
1024x768
Hard Drives
150GB Sata
Nice one OS.

Out of interest, was MBAM resident when you got infected, or did you only run that manually once MSE warned you that you were infected?

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
I installed it as soon as the infection appeared the second time. Thought I'd managed it manually the first time until the processes appeared again in Task Manager...That was when the reinforcements were called in ;)
 

My Computer

Computer Manufacturer/Model Number
Compaq Desktop
OS
Windows 7 Ultimate x64
CPU
AMD Sempron Dual Core
Memory
3GB
Graphics Card(s)
NVIDIA GeForce 6150SE nForce 430
Screen Resolution
1024x768
Hard Drives
150GB Sata
OK. It would have been interesting to see if it managed to get past MBAM had it been resident.

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
The problem with MBAM is that the free version has no realtime protection :p
 

My Computer

Computer Manufacturer/Model Number
Compaq Desktop
OS
Windows 7 Ultimate x64
CPU
AMD Sempron Dual Core
Memory
3GB
Graphics Card(s)
NVIDIA GeForce 6150SE nForce 430
Screen Resolution
1024x768
Hard Drives
150GB Sata

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
True, but I can survive with the normal version as I've not found an infection yet that's beat me :geek:
 

My Computer

Computer Manufacturer/Model Number
Compaq Desktop
OS
Windows 7 Ultimate x64
CPU
AMD Sempron Dual Core
Memory
3GB
Graphics Card(s)
NVIDIA GeForce 6150SE nForce 430
Screen Resolution
1024x768
Hard Drives
150GB Sata
I've not found an infection yet that's beat me :geek:

Nice one - it must be a relief to have the skills to overcome these things.....still, I think you made a good point. MSE should have blocked the issues instead of letting them through, and then going "Oh, look I let these through, now get rid of them".

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Back
Top