Solved Windows Activation Technologies Pop-up

tjg79

New member
Power User
VIP
Local time
10:59 AM
Messages
512
Windows Activation Technologies Pop-up - VIRUS

I just started getting the pop-up depicted below. I haven't made any changes to my system in months.

User Account Control - Do you want to allow the following program to make
changes to this computer?

Is anyone getting this?

User Account Control Pop-up.jpg

I'm reluctant to click yes.

Regards
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
Check and see if your system has KB971033 installed.
It might be asking to install KB971033 which your Windows 7 should have.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
I don't get that pop up but UAC is off. (Not recommended) - I use an alternative to UAC.

If UAC was switched on I'd expect to see that pop up every 3 months (90 days)

Check scheduled tasks and you can see details. On my machine it last ran on 11th September.

WAT Task Scheduler.jpg

Other logs show the same date:

WAT 2.jpg

WAT 3.jpg
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
I think I was hit with a virus. I ultimately clicked yes, because it kept popping up and then the fun started. Now I'm trying to clean my system.

ESET Alert.jpg

I clicked "Delete," but now I get the small pop-up every time I reboot.

Does anyone know a solution to clean this up?

Does anyone recognized that file and path? I did a Google, but nothing came up.

I'm considering going into the registry and deleting all references to it.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
SuperAntiSpyware detected a Trojan.

SuperAntiSpyware Detect.jpg
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
I don't believe that the two are related. Your first screenshot shows UAC asking to allow:

"C:\Windows\System32\Wat\WatAdminSvc.exe"

That is a legitimate process.

ESET has detected something else.

I'm not a malware removal expert exactly but if you like you can download and run UVK then scan and create a log.

Also you could navigate to C:\Users\TJG\AppData\Roaming\Gayux\Devod.dll and check the file information.

If you decide to download UVK - install it and from the welcome screen choose "Scan and create log" then upload the result.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
I suspect the two are related. I just deleted that directory in the users folder. Now I'm going to a complete disk clean-up and reboot to see what happens.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
You never did answer the question I asked in post #2

Check and see if your system has KB971033 installed.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Okay so upload "C:\Windows\System32\Wat\WatAdminSvc.exe" to virus total and see if it is the leigitimate file from microsoft or an imposter.

WAT 4.jpg

WAT 5.jpg
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
Okay so upload "C:\Windows\System32\Wat\WatAdminSvc.exe" to virus total and see if it is the leigitimate file from microsoft or an imposter.
View attachment 373159

I checked the file with my ESET Smart Security 8 and SuperAntiSpyware Pro. I also checked the properties and it appears to be digitally signed by Microsoft.

I'm not familiar with Virus Total. Is it on my system?

Other than that the file appears to be good.

The main issues I'm experiencing at the moment are that when I click on any folder or the start menu button, the system is very sluggish to respond and extremely slow when navigating between different folders. Also, when I do a shutdown, I see a webpage that the system is or has tried to connect to. It appears to be an adware type virus from hell. Also, my ESET Smart Security 8 is giving me lots of alerts about blocking the address in the picture below. So, what ever is on this system still has a remnant that wants to connect to that address.

ESET Warning.jpg

I've started a re-indexing for Windows Explorer and I did a SFC /SCANNOW. There were no issues with the SFC.

This was definitely a virus attack.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
I don't believe that the two are related. Your first screenshot shows UAC asking to allow:

"C:\Windows\System32\Wat\WatAdminSvc.exe"

That is a legitimate process.

ESET has detected something else.

I'm not a malware removal expert exactly but if you like you can download and run UVK then scan and create a log.

Also you could navigate to C:\Users\TJG\AppData\Roaming\Gayux\Devod.dll and check the file information.

If you decide to download UVK - install it and from the welcome screen choose "Scan and create log" then upload the result.

I'm downloading UVK now.

The UVK log file is over 2MB.

UVK - Ultra Virus Killer Log.txt

You can download the UVK log file from the file drop site on the link above.

Let me know if you see something.

Regards
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
14 posts and NO MGADiag??
SHAME ON YOU! ;)

ESET has been known to flag the WAT tools in the past - it's a false positive, but semi-legitimate, since the tool will phone home every so often to pick up the latest definitions.

Please follow this tutorial and post an MGADiag report - then we can see what the problem is.

http://www.sevenforums.com/windows-...ne-activation-issue-posting-instructions.html

Ignore errors produced when clicking on the Copy button - they simply mean that the tool could not create the backup files for some reason. The data is still copied to the clipboard for pasting to your response.

Please also state the Version and Edition of Windows quoted on your COA sticker (if you have one) on the case of your machine (or inside the battery compartment), but do NOT quote the Key on the sticker!
https://www.microsoft.com/en-gb/howtotell/Hardware.aspx#PCPurchase
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
It's a virus, but I'm not sure it's been completely removed, because the system doesn't behave as if the virus is completely removed. I downloaded and ran the Microsoft Safety Scanner for my Win 7 Pro x64 system. The MS Safety Scanner detected a Trojan Dynamater virus. I'm not sure about the spelling. The symptoms were constant downloading of temp files, very sluggish system when attempting to navigate between different folders in Windows Explorer. Windows Task Manger indicated significantly higher than normal system resource utilization, cpu and memory. Presently, I'm running ESET Smart Security 8 Smart Scan. It doesn't appear to be detecting anything yet and it's been running for an hour and twenty minutes. I don't know how long it will take to complete the ESET virus scan. I'm not sure if the virus software can scan the boot sectors. I will check the scan logs when the scan completes. This is a virus issue.

From the Certificate of Authenticity Sticker:
Windows 7 Pro OEM Software
FQC-04849 (the 8 could be a 6, the print is illegible)
X16-93649
00180-451-841-077

The ESET Smart Security 8 Smart Scan completed, but the scan logs indicate that it had errors when attempting to open the boot sectors of C:\, D:\, E:\, & O:\. Therefore, I don't think ESET SS 8 successfully scanned the boot sectors and I suspect this virus is hiding in the boot sectors and will reload when I reboot.
Code:
Diagnostic Report 
(1.9.0027.0):
-----------------------------------------
Windows Validation 
Data-->

 
Validation Code: 0
Cached Online Validation Code: 0x0
Windows Product 
Key: *****-*****-9CBQQ-CBRDX-4VBW4
Windows Product Key Hash: 
4o79yMzf+5/lHKmwIiotxng2nPc=
Windows Product ID: 
00371-OEM-9045181-41077
Windows Product ID Type: 3
Windows License Type: 
OEM System Builder
Windows OS version: 6.1.7601.2.00010100.1.0.048
ID: 
{88569B0E-21CB-4760-A2CC-9595DA52037D}(3)
Is Admin: Yes
TestCab: 
0x0
LegitcheckControl ActiveX: Registered, 1.9.42.0
Signed By: 
Microsoft
Product Name: Windows 7 Professional
Architecture: 
0x00000009
Build lab: 7601.win7sp1_gdr.150722-0600
TTS Error: 

Validation Diagnostic: 
Resolution Status: N/A

 
Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, 
hr = 0x80070002

 
Windows XP Notifications Data-->
Cached Result: N/A, hr = 
0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe 
Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 
0x80070002

 
OGA Notifications Data-->
Cached Result: N/A, hr = 
0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 
0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

 
OGA Data-->
Office Status: 100 Genuine
Microsoft Office Professional 
2007 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 
0x80070002
Office Diagnostics: 
77F760FE-153-80070002_7E90FEE8-175-80070002_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-b01a_E2AD56EA-766-0_E2AD56EA-148-80004005_16E0B333-89-80004005_B4D0AA8B-1029-80004005

 
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 
(compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files\Internet 
Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download 
unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: 
Allowed
Initialize and script ActiveX controls not marked as safe: 
Disabled
Allow scripting of Internet Explorer Webbrowser control: 
Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe 
for scripting: Allowed

 
File Scan Data-->

 
Other data-->
Office Details: 
<GenuineResults><MachineData><UGUID>{88569B0E-21CB-4760-A2CC-9595DA52037D}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-4VBW4</PKey><PID>00371-OEM-9045181-41077</PID><PIDType>3</PIDType><SID>S-1-5-21-764048772-141219837-185285450</SID><SYSTEM><Manufacturer>INTEL_</Manufacturer><Model>DX58SO__</Model></SYSTEM><BIOS><Manufacturer>Intel 
Corp.</Manufacturer><Version>SOX5810J.86A.5600.2013.0729.2250</Version><SMBIOSVersion 
major="2" 
minor="5"/><Date>20130729000000.000000+000</Date></BIOS><HWID>92BD3107018400F4</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern 
Standard 
Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product 
GUID="{91120000-0014-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft 
Office Professional 
2007</Name><Ver>12</Ver><Val>1B16FCA35E8C714</Val><Hash>Ox0izo7MjcnLKUdV4ul5G/4OhBY=</Hash><Pid>81605-906-5273533-65430</Pid><PidType>1</PidType></Product></Products><Applications><App 
Id="15" Version="12" Result="100"/><App Id="16" Version="12" 
Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" 
Version="12" Result="100"/><App Id="1A" Version="12" 
Result="100"/><App Id="1B" Version="12" 
Result="100"/></Applications></Office></Software></GenuineResults>  


 
Spsys.log Content: 0x80070002

 
Licensing Data-->
Software licensing service version: 
6.1.7601.17514

 
Name: Windows(R) 7, Professional edition
Description: Windows Operating 
System - Windows(R) 7, OEM_COA_NSLP channel
Activation ID: 
e120e868-3df2-464a-95a0-b52fa5ada4bf
Application ID: 
55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 
00371-00180-451-841077-02-1033-7601.0000-0732015
Installation ID: 
012201651040681403614155510252839633960930028731337932
Processor Certificate 
URL: [url=http://go.microsoft.com/fwlink/?LinkID=88338]SpcService Web Service[/url]
Machine 
Certificate URL: [url=http://go.microsoft.com/fwlink/?LinkID=88339]RacService Web Service[/url]
Use 
License URL: [url=http://go.microsoft.com/fwlink/?LinkID=88341]UseLicenseService Web Service[/url]
Product 
Key Certificate URL: [url=http://go.microsoft.com/fwlink/?LinkID=88340]PkcService Web Service[/url]
Partial 
Product Key: 4VBW4
License Status: Licensed
Remaining Windows rearm count: 
3
Trusted time: 08-Oct-15 09:26:18

 
Windows Activation Technologies-->
HrOffline: 0x00000000
HrOnline: 
0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 9:11:2015 
06:15
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: 
Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:

 

HWID Data-->
HWID Hash Current: 
MgAAAAMAAAABAAEAAQADAAAAAQABAAEACrYw0kNG2mNsQ1D3xOAOLEaUnJ+9IKaegig=

 
OEM Activation 1.0 Data-->
N/A

 
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes, but no SLIC 
table
Windows marker version: N/A
OEMID and OEMTableID Consistent: 
N/A
BIOS Information: 
  ACPI Table Name OEMID 
Value OEMTableID Value
  APIC   INTEL 
  DX58SO  
  FACP   INTEL 
  DX58SO  
  HPET   INTEL 
  DX58SO  
  MCFG   INTEL 
  DX58SO  
  WDDT   INTEL 
  DX58SO  
  ASF!   INTEL 
  DX58SO  
  SSDT   INTEL 
  SSDT  PM
  DMAR   INTEL 
  DX58SO  
  WDTT   INTEL 
  DX58SO  
  ASPT   INTEL 
  PerfTune
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
Posting the MGADiag log as Noel has requested after your security scan will let Noel see if your infection has effected your MGADiag.

Please complete the instruction Noel has given.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Do you need any additional information?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
I looked at your log. Can you confirm what is in this folder?

C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Will check here later!
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Back
Top