1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive [InActive] Slow Computer

Discussion in 'Malware and Virus Removal Archive' started by deester, 2008/12/28.

  1. 2008/12/28
    deester

    deester Inactive Alumni Thread Starter

    Joined:
    2008/07/08
    Messages:
    633
    Likes Received:
    0
    My computer is running slower than normal , ran Malwarebytes scan and it is clean. Have run a Deckard's System scan , will someone look at for me please? I have a Dell laptop with XP, running on DSL wireless. Thanks for your help.
    Deckard's System Scanner v20071014.68
    Run by Dell on 2008-12-25 11:03:50
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------



    -- HijackThis (run as Dell.exe) ------------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:04:00 AM, on 12/25/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\iWin Games\iWinGamesInstaller.exe
    C:\Program Files\iWin Games\iWinTrusted.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\ScsiAccess.EXE
    C:\Program Files\PermissionResearch\prmrsr.exe
    C:\WINDOWS\Explorer.EXE
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Common Files\AOL\1211762669\ee\AOLSoftware.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
    C:\Program Files\AOL 9.1a\waol.exe
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    C:\Program Files\Ocucom\PreCast\tmon.exe
    C:\Program Files\MostFun\Bin\MostFun.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Common Files\AOL\1211762669\ee\AOLDesktop.exe
    C:\Program Files\Common Files\AOL\Loader\aolload.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\AOL 9.1a\shellmon.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Documents and Settings\Dell\Desktop\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\Dell.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.jzip.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - URLSearchHook: NetAssistantBHO Class - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\My.Freeze.com Toolbar with NetAssistant\NetAssistant.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Smart-Shopper - {4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: EmailBHO - {647FD14A-C4F1-46F4-8FC3-0B40F54226F7} - C:\Program Files\jZip\WebmailPlugin.dll
    O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: iWin Toolbar - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - C:\Program Files\iWin\tbiWin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: NetAssistantBHO - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\My.Freeze.com Toolbar with NetAssistant\NetAssistant.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
    O3 - Toolbar: (no name) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)
    O4 - HKLM\..\Run: [PermissionResearch] C:\Program Files\PermissionResearch\prmrsr.exe -boot
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1211762669\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe "
    O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1a\AOL.EXE" -b
    O4 - Startup: AOL Desktop.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe
    O4 - Startup: MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe
    O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    O4 - Global Startup: PreCast Monitor.lnk = C:\Program Files\Ocucom\PreCast\tmon.exe
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
    O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
    O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll
    O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.nl/scanforvirus-en/kavwebscan_unicode.cab
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Amazing%20Adventures%20The%20Lost%20Tomb/Images/stg_drm.ocx
    O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab
    O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com.../en/x86/MuCatalogWebControl.cab?1221952782890
    O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
    O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
    O16 - DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} (WNICheck2 Class) - http://www.convergysworkathome.com/AppHardT.CAB
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Amazing%20Adventures%20The%20Lost%20Tomb/Images/armhelper.ocx
    O16 - DPF: {D8AA889B-2C65-47C3-8C16-3DCD4EF76A47} (Invoke Solutions Participant Control(MR)) - http://rms2.invokesolutions.com/events/bin/6.2.0.1450/MILive.cab
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
    O20 - Winlogon Notify: PermissionResearch - C:\Program Files\PermissionResearch\prls.dll
    O23 - Service: McAfee Application Installer Cleanup (0096691229613516) (0096691229613516mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\009669~1.EXE (file missing)
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe
    O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe
    O23 - Service: iWinTrusted - iWin Inc. - C:\Program Files\iWin Games\iWinTrusted.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
    O23 - Service: Seekeen Service - Seekeen.com - C:\Program Files\Seekeen\seekeen.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    --
    End of file - 12155 bytes

    -- Files created between 2008-11-25 and 2008-12-25 -----------------------------

    2008-12-25 10:56:42 0 dr-h----- C:\Documents and Settings\Dell\Recent
    2008-12-23 21:33:08 0 d-------- C:\Program Files\Agatha Christie - Murder on the Orient Express
    2008-12-23 19:38:38 0 d-------- C:\Program Files\Fairy Jewels 2
    2008-12-22 17:02:56 0 d-------- C:\WINDOWS\Prefetch
    2008-12-22 16:44:09 0 d-------- C:\WINDOWS\ServicePackFiles
    2008-12-21 16:54:53 0 d-------- C:\Documents and Settings\All Users\Application Data\Media Art
    2008-12-21 16:00:41 0 d-------- C:\Documents and Settings\Dell\Application Data\Smart-Shopper
    2008-12-21 16:00:39 0 d-------- C:\Program Files\Smart-Shopper
    2008-12-21 16:00:29 0 d-------- C:\Program Files\jZip
    2008-12-21 14:35:34 0 d-------- C:\Program Files\Unicorn Castle
    2008-12-21 14:00:06 0 d-------- C:\Documents and Settings\All Users\Application Data\WinZip
    2008-12-20 20:34:36 0 d-------- C:\WINDOWS\Super Collapse Puzzle Gallery 4
    2008-12-20 20:34:36 0 d-------- C:\Program Files\Super Collapse Puzzle Gallery 4
    2008-12-20 08:16:53 0 d-------- C:\Program Files\Microsoft Silverlight
    2008-12-19 19:09:24 0 d-------- C:\Documents and Settings\Dell\Application Data\WildTangent
    2008-12-19 18:58:47 0 d-------- C:\Program Files\WildGames
    2008-12-19 17:25:17 0 d-------- C:\Documents and Settings\Dell\Application Data\Suspects and Clues Prefs
    2008-12-19 17:25:17 0 d-------- C:\Documents and Settings\Dell\Application Data\Suspects and Clues Players
    2008-12-19 17:25:15 0 d-------- C:\Documents and Settings\Dell\Application Data\Spinapse
    2008-12-19 17:25:15 0 d-------- C:\Documents and Settings\Dell\Application Data\IOMediaSupport6SZZ001s
    2008-12-18 05:12:05 0 d-------- C:\Documents and Settings\Dell\Application Data\Cat's Eye Games
    2008-12-17 10:26:09 0 d-------- C:\Documents and Settings\Dell\Application Data\Meridian93
    2008-12-17 00:30:22 0 d-------- C:\Documents and Settings\All Users\Application Data\PlayPond
    2008-12-16 00:56:39 0 d-------- C:\Documents and Settings\All Users\Application Data\GameXzone
    2008-12-16 00:35:10 0 d-------- C:\Documents and Settings\All Users\Application Data\DivoGames
    2008-12-13 21:33:02 0 d-------- C:\Documents and Settings\Dell\Application Data\WinRAR
    2008-12-12 15:35:20 0 d-------- C:\Documents and Settings\All Users\Application Data\Escape From Paradise
    2008-12-11 20:45:18 0 d-------- C:\Documents and Settings\Dell\Application Data\Ancient Quest of Saqqarah__cminion
    2008-12-11 20:45:10 0 d-------- C:\Documents and Settings\Dell\Application Data\Saqqarah
    2008-12-11 02:56:46 0 d-------- C:\Documents and Settings\Dell\Application Data\Anabel
    2008-12-11 01:52:04 0 d-------- C:\Documents and Settings\Dell\Application Data\PlanetPlayMore
    2008-12-10 20:08:58 0 d-------- C:\Program Files\Tropicabana
    2008-12-10 18:38:26 0 d-------- C:\Program Files\Invoke Solutions
    2008-12-10 18:14:16 0 d-------- C:\Documents and Settings\Dell\Application Data\JewelMatch2
    2008-12-08 22:30:00 0 d-------- C:\Program Files\GameTop.com
    2008-12-08 17:21:11 0 d-------- C:\Program Files\Hoteis Jewels
    2008-12-08 13:58:12 0 d-------- C:\Documents and Settings\All Users\Application Data\Black Blob Studios
    2008-12-08 10:37:13 0 d-------- C:\Program Files\Hawaiian Explorer Lost Island
    2008-12-07 21:27:53 0 d-------- C:\Documents and Settings\Dell\Application Data\Shape games
    2008-12-07 21:04:03 0 d-------- C:\Program Files\IWON Games
    2008-12-07 19:54:11 0 d-------- C:\Program Files\Yard Sale Hidden Treasures Sunnyville
    2008-12-07 10:26:22 0 d-------- C:\Program Files\Adobe Media Player
    2008-12-07 09:54:28 0 d-------- C:\Program Files\Concentration
    2008-12-06 16:22:13 0 d-------- C:\Documents and Settings\Ted\Application Data\AOL
    2008-12-06 15:55:56 0 d-------- C:\Documents and Settings\All Users\Application Data\AlawarWrapper
    2008-12-06 02:35:01 0 d-------- C:\Program Files\The Lost Treasures Of Alexandria
    2008-12-05 03:49:21 0 d-------- C:\Program Files\Alawar
    2008-12-05 03:23:26 0 d-------- C:\Program Files\Hidden Expedition Everest
    2008-12-05 00:54:45 0 d-------- C:\Documents and Settings\All Users\Application Data\Kristanix Games
    2008-12-05 00:40:54 10 --a------ C:\WINDOWS\popcinfo.dat
    2008-12-05 00:39:21 0 d-------- C:\GameHouse Games
    2008-12-04 22:48:18 0 --a------ C:\WINDOWS\popcreg.dat
    2008-12-04 22:48:18 0 --a------ C:\WINDOWS\popcinfot.dat
    2008-12-04 22:48:18 0 d-------- C:\Program Files\PopCap Games
    2008-12-04 22:20:13 0 d-------- C:\Documents and Settings\Dell\Application Data\GameInvest
    2008-12-04 22:17:41 0 d-------- C:\Program Files\Enigma 7
    2008-12-04 20:48:46 0 d-------- C:\Program Files\Mystery Case Files Huntsville
    2008-12-04 20:39:25 0 d-------- C:\Program Files\Lost Secrets Bermuda Triangle
    2008-12-03 04:33:25 0 d-------- C:\Program Files\Amazing Adventures The Lost Tomb
    2008-11-29 19:16:14 0 d-------- C:\Program Files\Games
    2008-11-27 20:29:44 0 d-------- C:\Documents and Settings\Dell\Application Data\Boomzap
    2008-11-27 20:29:29 0 d-------- C:\Program Files\Jewels of Cleopatra
    2008-11-26 22:07:02 0 d-------- C:\Documents and Settings\All Users\Application Data\Slapdash Games
    2008-11-26 16:24:50 0 d-------- C:\Documents and Settings\TEST\Application Data\PreCast
    2008-11-26 16:24:47 0 d-------- C:\Documents and Settings\TEST\Application Data\Real
    2008-11-26 00:43:40 0 d-------- C:\Documents and Settings\All Users\Application Data\ScreenSeven
    2008-11-26 00:43:40 0 d-------- C:\Documents and Settings\All Users\Application Data\Intenium
    2008-11-26 00:42:36 0 d-------- C:\Program Files\Diamond Drop 2
    2008-11-25 06:02:08 0 d--h---c- C:\Documents and Settings\All Users\Application Data\{5F2CE881-C7A5-4F1A-A1C0-A5BFC9A36913}
    2008-11-25 03:44:03 0 d-------- C:\Documents and Settings\NetworkService\Application Data\SACore


    -- Find3M Report ---------------------------------------------------------------

    2008-12-25 10:58:45 0 d-------- C:\Documents and Settings\Dell\Application Data\PreCast
    2008-12-24 21:59:46 0 d-------- C:\Program Files\iWin Games
    2008-12-22 21:08:43 0 d-------- C:\Program Files\RealArcade
    2008-12-22 17:02:27 0 d-------- C:\Program Files\Messenger
    2008-12-22 16:47:17 0 d-------- C:\Program Files\Movie Maker
    2008-12-22 16:43:49 0 d-------- C:\Program Files\Windows NT
    2008-12-22 16:01:57 952 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
    2008-12-22 15:58:00 0 d-------- C:\Program Files\MSECache
    2008-12-21 17:05:57 0 d-------- C:\Program Files\7-Zip
    2008-12-21 14:12:09 0 d-------- C:\Documents and Settings\Dell\Application Data\Zango
    2008-12-21 13:49:43 0 d-------- C:\Program Files\Zango Programs
    2008-12-21 12:33:03 0 d-------- C:\Documents and Settings\Dell\Application Data\cerasus.media
    2008-12-18 10:17:48 0 d-------- C:\Program Files\McAfee
    2008-12-16 16:21:07 0 d-------- C:\Program Files\Between the Worlds
    2008-12-16 15:59:29 0 d-------- C:\Program Files\iWin.com
    2008-12-16 15:11:13 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-12-15 22:50:54 0 d-------- C:\Documents and Settings\Dell\Application Data\Digital Support
    2008-12-14 16:07:00 0 d-------- C:\Documents and Settings\Dell\Application Data\iWin
    2008-12-13 21:37:48 0 d-------- C:\Documents and Settings\Dell\Application Data\GameHouse
    2008-12-13 13:11:47 0 d-------- C:\Program Files\GameHouse
    2008-12-13 12:47:58 0 d-------- C:\Program Files\Oberon Media
    2008-12-13 12:47:53 0 d-------- C:\Program Files\Common Files\Oberon Media
    2008-12-12 18:36:20 0 d-------- C:\Program Files\Common Files\AOL
    2008-12-07 10:26:15 0 d-------- C:\Program Files\Common Files\Adobe AIR
    2008-12-01 18:09:54 0 d-------- C:\Program Files\PermissionResearch
    2008-11-30 14:04:53 0 d-------- C:\Documents and Settings\Dell\Application Data\Azureus
    2008-11-27 15:02:29 0 d-------- C:\Documents and Settings\Dell\Application Data\PlayFirst
    2008-11-26 22:33:15 0 d-------- C:\Documents and Settings\Dell\Application Data\Games
    2008-11-26 01:51:04 0 d-------- C:\Program Files\El Dorado Quest
    2008-11-25 13:16:55 0 d-------- C:\Program Files\Spirit of Wandering - The Legend
    2008-11-25 13:16:04 0 d-------- C:\Program Files\Mystery P.I. - The Vegas Heist
    2008-11-24 23:15:19 0 d-------- C:\Program Files\AOL 9.1a
    2008-11-24 22:17:27 0 d-------- C:\Program Files\Freeze.com
    2008-11-24 22:17:20 0 d-------- C:\Program Files\My.Freeze.com Toolbar with NetAssistant
    2008-11-24 22:14:02 0 d-------- C:\Documents and Settings\Dell\Application Data\SiteAdvisor
    2008-11-24 19:48:08 0 d-------- C:\Program Files\Common Files\McAfee
    2008-11-24 19:47:27 0 d-------- C:\Program Files\McAfee.com
    2008-11-24 19:47:14 0 d-------- C:\Program Files\Common Files
    2008-11-24 19:34:33 0 d-------- C:\Documents and Settings\Dell\Application Data\AOL
    2008-11-24 19:33:40 0 d-------- C:\Program Files\Common Files\aolshare
    2008-11-24 16:56:35 0 d-------- C:\Program Files\Rainforest Adventure
    2008-11-24 16:11:14 0 d-------- C:\Program Files\Nancy Drew
    2008-11-24 11:39:52 0 d-------- C:\Documents and Settings\Dell\Application Data\Real
    2008-11-24 11:39:36 0 d-------- C:\Program Files\Common Files\xing shared
    2008-11-24 11:39:32 0 d-------- C:\Program Files\Common Files\Real
    2008-11-24 11:39:21 0 d-------- C:\Program Files\Real
    2008-11-24 11:26:39 0 d-------- C:\Program Files\MostFun
    2008-11-24 11:10:35 0 d-------- C:\Program Files\Java
    2008-11-24 10:42:59 0 d-------- C:\Documents and Settings\Dell\Application Data\aAvgApi
    2008-11-24 10:28:19 0 d-------- C:\Program Files\Common Files\Panda Security
    2008-11-24 10:28:08 0 d-------- C:\Program Files\CCleaner
    2008-11-24 10:26:44 0 d-------- C:\Program Files\Mysteryville
    2008-11-24 10:21:39 0 d-------- C:\Program Files\Windows Installer Clean Up
    2008-11-24 10:21:32 0 d--h----- C:\Program Files\InstallShield Installation Information
    2008-11-23 10:43:18 0 d-------- C:\Documents and Settings\Dell\Application Data\LizardSystems
    2008-11-23 10:43:17 0 d-------- C:\Program Files\LizardSystems
    2008-11-19 20:17:28 0 d-------- C:\Program Files\LeeGTs Games
    2008-11-19 12:38:55 0 d-------- C:\Documents and Settings\Dell\Application Data\Gold Casual Games
    2008-11-18 20:57:48 0 d-------- C:\Program Files\10 Days Under The Sea
    2008-11-18 20:10:47 0 d-------- C:\Documents and Settings\Dell\Application Data\FunWebProducts
    2008-11-18 10:17:22 0 d-------- C:\Documents and Settings\Dell\Application Data\SultanofPersia
    2008-11-18 10:16:46 0 d-------- C:\Program Files\Sultan of Persia
    2008-11-18 05:38:18 0 d-------- C:\Documents and Settings\Dell\Application Data\Abra Academy2
    2008-11-17 22:04:03 0 d-------- C:\Program Files\Forgotten Riddles
    2008-11-17 19:50:04 2868 --a------ C:\Documents and Settings\Dell\Application Data\Settings.xml
    2008-11-17 19:49:21 0 d-------- C:\Documents and Settings\Dell\Application Data\Sexy Dreams
    2008-11-17 15:38:42 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
    2008-11-16 16:34:29 0 d-------- C:\Program Files\Windows Update Remover
    2008-11-16 08:37:29 0 d-------- C:\Program Files\ParetoLogic
    2008-11-16 08:37:29 0 d-------- C:\Program Files\Common Files\ParetoLogic
    2008-11-15 19:10:41 64 --a------ C:\WINDOWS\GPlrLanc.dat
    2008-11-15 15:29:24 0 d-------- C:\Program Files\Seekeen
    2008-11-14 16:03:58 0 d-------- C:\Documents and Settings\Dell\Application Data\SpinTop Games
    2008-11-14 12:50:58 0 d-------- C:\Documents and Settings\Dell\Application Data\.wyzo
    2008-11-12 20:08:45 0 d-------- C:\Program Files\Digital Support
    2008-11-11 11:05:34 0 d-------- C:\Program Files\Mysterious Travel - beta
    2008-11-10 22:33:21 0 d-------- C:\Documents and Settings\Dell\Application Data\Dragon Altar Games
    2008-11-10 21:34:42 0 d-------- C:\Documents and Settings\Dell\Application Data\Flood Light Games
    2008-11-10 16:57:45 0 d-------- C:\Documents and Settings\Dell\Application Data\Artogon
    2008-11-08 22:55:08 0 d-------- C:\Documents and Settings\Dell\Application Data\AJ SQUARE INC
    2008-11-08 05:50:00 0 d-------- C:\Program Files\OpinionSquare
    2008-11-06 23:48:36 0 d-------- C:\Documents and Settings\Dell\Application Data\Big Fish Games
    2008-11-06 09:54:48 0 d-------- C:\Documents and Settings\Dell\Application Data\JoyBits
    2008-11-05 20:49:02 0 d-------- C:\Program Files\Hidden Mysteries Civil War
    2008-11-05 12:30:15 0 d-------- C:\Documents and Settings\Dell\Application Data\Macromedia
    2008-11-05 11:16:44 0 d-------- C:\Documents and Settings\Dell\Application Data\Gaijin Ent
    2008-11-02 10:06:36 0 d-------- C:\Documents and Settings\Dell\Application Data\acccore
    2008-10-31 03:46:47 0 d-------- C:\Program Files\AOL 9.1
    2008-10-31 03:46:04 0 d-------- C:\Program Files\AOL 9(2).1
    2008-10-31 03:45:50 0 d-------- C:\Program Files\Common Files\aolshare(2)
    2008-10-31 00:55:07 0 d-------- C:\Documents and Settings\Dell\Application Data\Mozilla
    2008-10-30 13:54:03 0 d-------- C:\Program Files\BFG
    2008-10-26 16:14:54 0 d-------- C:\Documents and Settings\Dell\Application Data\WeatherDPA
    2008-10-25 17:25:12 0 d-------- C:\Program Files\Ss-Tools
    2008-10-25 17:00:40 0 d-------- C:\Documents and Settings\Dell\Application Data\AVGTOOLBAR
    2008-10-25 15:32:34 0 d-------- C:\Program Files\LimeWire
    2008-10-25 15:23:04 0 d-------- C:\Documents and Settings\Dell\Application Data\LimeWire
    2008-10-25 15:23:03 0 d-------- C:\Documents and Settings\Dell\Application Data\Sammsoft
    2008-10-25 09:45:58 0 d-------- C:\Program Files\Siber Systems
    2008-10-25 09:45:58 0 d-------- C:\Documents and Settings\Dell\Application Data\GoodSync
    2008-10-25 09:43:22 0 d-------- C:\Program Files\Uniblue
    2008-10-25 09:33:32 0 d-------- C:\Program Files\COMODO
    2008-10-25 09:33:32 0 d-------- C:\Documents and Settings\Dell\Application Data\Comodo
    2008-10-25 04:54:38 0 d-------- C:\Documents and Settings\Dell\Application Data\Gogii Games
    2008-10-16 10:10:48 57344 --a------ C:\WINDOWS\system32\Big Kahuna Reef.scr <Not Verified; Reflexive; Reflexive BKRSaver>


    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
    06/11/2008 09:33 PM 75128 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E}]
    10/07/2008 10:50 AM 1172952 --a------ C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{647FD14A-C4F1-46F4-8FC3-0B40F54226F7}]
    10/28/2008 07:36 AM 591296 --a------ C:\Program Files\jZip\WebmailPlugin.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
    11/14/2008 12:25 PM 150032 --a------ c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ce0c2586-da36-452b-acdb-320d9bcb19bf}]
    08/20/2008 10:03 PM 1780248 --a------ C:\Program Files\iWin\tbiWin.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    11/24/2008 11:10 AM 34816 --a------ C:\Program Files\Java\jre6\bin\jp2ssv.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}]
    11/12/2008 04:55 PM 253048 --a------ C:\Program Files\My.Freeze.com Toolbar with NetAssistant\NetAssistant.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    11/24/2008 11:10 AM 73728 --a------ C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
    "{CE0C2586-DA36-452B-ACDB-320D9BCB19BF} "= C:\Program Files\iWin\tbiWin.dll [08/20/2008 10:03 PM 1780248]

    [-HKEY_CLASSES_ROOT\CLSID\{CE0C2586-DA36-452B-ACDB-320D9BCB19BF}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "PermissionResearch "= "C:\Program Files\PermissionResearch\prmrsr.exe" [12/10/2008 02:42 PM]
    "ISUSScheduler "= "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [08/11/2005 02:30 PM]
    "SynTPLpr "= "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [05/13/2004 06:23 PM]
    "SynTPEnh "= "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [05/14/2004 08:35 AM]
    "HostManager "= "C:\Program Files\Common Files\AOL\1211762669\ee\AOLSoftware.exe" [06/24/2008 01:34 PM]
    "TkBellExe "= "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [11/24/2008 11:39 AM]
    "mcagent_exe "= "C:\Program Files\McAfee.com\Agent\mcagent.exe" [07/11/2008 04:48 PM]
    "ISUSPM Startup "= "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [08/11/2005 02:30 PM]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg "= "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [06/07/2008 03:54 AM]
    "MSMSGS "= "C:\Program Files\Messenger\msmsgs.exe" [04/13/2008 07:12 PM]
    "ctfmon.exe "= "C:\WINDOWS\system32\ctfmon.exe" [04/13/2008 07:12 PM]
    "RoboForm "= "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [09/28/2008 04:20 AM]
    "AOL Fast Start "= "C:\Program Files\AOL 9.1a\AOL.exe" [10/27/2007 12:44 PM]

    C:\Documents and Settings\Dell\Start Menu\Programs\Startup\
    AOL Desktop.lnk - C:\Program Files\Common Files\AOL\Launch\aollaunch.exe [5/25/2007 12:16:09 PM]
    MostFun.lnk - C:\Program Files\MostFun\Bin\MostFun.exe [8/28/2007 4:47:20 PM]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe [6/8/2003 4:48:18 PM]
    PreCast Monitor.lnk - C:\Program Files\Ocucom\PreCast\tmon.exe [2/12/2008 12:24:26 PM]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "DisableRegistryTools "=0 (0x0)
    "HideLegacyLogonScripts "=0 (0x0)
    "HideLogoffScripts "=0 (0x0)
    "RunLogonScriptSync "=1 (0x1)
    "RunStartupScriptSync "=0 (0x0)
    "HideStartupScripts "=0 (0x0)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "HideLegacyLogonScripts "=0 (0x0)
    "HideLogoffScripts "=0 (0x0)
    "RunLogonScriptSync "=1 (0x1)
    "RunStartupScriptSync "=0 (0x0)
    "HideStartupScripts "=0 (0x0)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoResolveSearch "=1 (0x1)
    "ClearRecentDocsOnExit "=1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
    C:\WINDOWS\System32\dimsntfy.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
    C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll 05/28/2008 03:48 PM 10536 C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PermissionResearch]
    C:\Program Files\PermissionResearch\prls.dll 10/23/2008 03:02 PM 372736 C:\Program Files\PermissionResearch\prls.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Notification Packages "= scecli scecli

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=" "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=" "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @= "Volume shadow copy "

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
    backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Dee^Start Menu^Programs^Startup^AOL Desktop.lnk]
    path=C:\Documents and Settings\Dee\Start Menu\Programs\Startup\AOL Desktop.lnk
    backup=C:\WINDOWS\pss\AOL Desktop.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    eapsvcs eaphost
    dot3svc dot3svc

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    napagent
    hkmsvc




    -- End of Deckard's System Scanner: finished at 2008-12-25 11:05:17 ------------
     
  2. 2008/12/30
    PX5

    PX5 Inactive

    Joined:
    2008/12/27
    Messages:
    13
    Likes Received:
    0
    Hi deester and Welcome to the Forums.

    A quick lookover of your log doesnt present anything overly alarming.

    Fortunate enough,I have a neighbor that adores IWin Games and Ive found that this program will clutter up a computer worse than most malware.

    I would suspect if you uninstalled the program and then went through your list of programs in Add/Remove Programs,then remove all these games and such that came with iWin,you will free up some space on the hard drive.

    After this,you will need to run the Windows Cleanup tools

    Click Start>>All Programs>>Accessories>>System Tools

    Run the DiskCleanUp Tool and the Disk Defragmenter tool,both will probably take some time to complete.

    A reboot should yield a much more friendly and perky computer.

    Do post back and let me know how these steps go please.
     
    PX5,
    #2

  3. to hide this advert.

  4. 2008/12/30
    deester

    deester Inactive Alumni Thread Starter

    Joined:
    2008/07/08
    Messages:
    633
    Likes Received:
    0
    Thanks PX5 for your suggestions, I will follow and get back to you.
    Deester
     
  5. 2008/12/30
    Dragon30655

    Dragon30655 Inactive

    Joined:
    2008/12/28
    Messages:
    19
    Likes Received:
    1
    Hi deester,
    As with the other post, getting rid of the Iwin games should speed things up, however I am also curious as to why you are running two antivirus programs. Antivirus programs tend to interfere with each other. I would choose one and eliminate the other. Also I personally have had issues with Wildtangent and Popcap games being a path for trojan downloaders to come in. I do not know if anyone else has had this issue with them but I have banned these from my network. Also If you are using a DSL connection I would either shut down or eliminate the AOL files. A good thorough cleaning using the tools recommended by this site should yield a much faster computer. Good luck and have a great day.
     
  6. 2008/12/30
    deester

    deester Inactive Alumni Thread Starter

    Joined:
    2008/07/08
    Messages:
    633
    Likes Received:
    0
    Thanks Dragon for your advice. I use AOL for all my Emails. Please tell me what cleansing tools you are referring to. Thanks,
    Deester
     
  7. 2009/01/01
    deester

    deester Inactive Alumni Thread Starter

    Joined:
    2008/07/08
    Messages:
    633
    Likes Received:
    0
    PX5 and Dragon, I haven't done things like I said I would and I apologize. I have had my Iwin games for several years and have made great progress in many of the games. I did virus scan each game. I virus scan all Popcap games before I install them. I did unistall Tangert. Still being concerned that my machine was not clean, I ran Kaspersky virus scan,Combofix, Kaspersky virus Scan. I'm including them in the order I ran them. Will you take a look please? ThanksKASPERSKY ONLINE SCANNER 7 REPORT
    Wednesday, December 31, 2008
    Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Wednesday, December 31, 2008 19:50:57
    Records in database: 1539625


    Scan settings
    Scan using the following database extended
    Scan archives yes
    Scan mail databases yes

    Scan area My Computer
    C:\
    D:\

    Scan statistics
    Files scanned 178831
    Threat name 4
    Infected objects 4
    Suspicious objects 0
    Duration of the scan 04:23:47

    File name Threat name Threats count
    C:\games\Amazing Adventures Around the World\AmazingAdventures2.exe Infected: Packed.Win32.****.b 1

    C:\Program Files\Internet Explorer\msimg32.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cv 1

    C:\Program Files\iWin.com\Polly Pride Pet Detective\GameLauncher.exe Infected: Trojan-Dropper.Win32.Irsd.v 1

    C:\Program Files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll Infected: not-a-virus:WebToolbar.Win32.Zango.bd 1

    The selected area was scanned.
    KASPERSKY ONLINE SCANNER 7 REPORT
    Wednesday, December 31, 2008
    Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Wednesday, December 31, 2008 19:50:57
    Records in database: 1539625


    Scan settings
    Scan using the following database extended
    Scan archives yes
    Scan mail databases yes

    Scan area My Computer
    C:\
    D:\

    Scan statistics
    Files scanned 178831
    Threat name 4
    Infected objects 4
    Suspicious objects 0
    Duration of the scan 04:23:47

    File name Threat name Threats count
    C:\games\Amazing Adventures Around the World\AmazingAdventures2.exe Infected: Packed.Win32.****.b 1

    C:\Program Files\Internet Explorer\msimg32.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cv 1

    C:\Program Files\iWin.com\Polly Pride Pet Detective\GameLauncher.exe Infected: Trojan-Dropper.Win32.Irsd.v 1

    C:\Program Files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll Infected: not-a-virus:WebToolbar.Win32.Zango.bd 1

    The selected area was scanned.
    KASPERSKY ONLINE SCANNER 7 REPORT
    Wednesday, December 31, 2008
    Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Wednesday, December 31, 2008 19:50:57
    Records in database: 1539625


    Scan settings
    Scan using the following database extended
    Scan archives yes
    Scan mail databases yes

    Scan area My Computer
    C:\
    D:\

    Scan statistics
    Files scanned 178831
    Threat name 4
    Infected objects 4
    Suspicious objects 0
    Duration of the scan 04:23:47

    File name Threat name Threats count
    C:\games\Amazing Adventures Around the World\AmazingAdventures2.exe Infected: Packed.Win32.****.b 1

    C:\Program Files\Internet Explorer\msimg32.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cv 1

    C:\Program Files\iWin.com\Polly Pride Pet Detective\GameLauncher.exe Infected: Trojan-Dropper.Win32.Irsd.v 1

    C:\Program Files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll Infected: not-a-virus:WebToolbar.Win32.Zango.bd 1

    The selected area was scanned.
    KASPERSKY ONLINE SCANNER 7 REPORT
    Wednesday, December 31, 2008
    Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Wednesday, December 31, 2008 19:50:57
    Records in database: 1539625


    Scan settings
    Scan using the following database extended
    Scan archives yes
    Scan mail databases yes

    Scan area My Computer
    C:\
    D:\

    Scan statistics
    Files scanned 178831
    Threat name 4
    Infected objects 4
    Suspicious objects 0
    Duration of the scan 04:23:47

    File name Threat name Threats count
    C:\games\Amazing Adventures Around the World\AmazingAdventures2.exe Infected: Packed.Win32.****.b 1

    C:\Program Files\Internet Explorer\msimg32.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cv 1

    C:\Program Files\iWin.com\Polly Pride Pet Detective\GameLauncher.exe Infected: Trojan-Dropper.Win32.Irsd.v 1

    C:\Program Files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll Infected: not-a-virus:WebToolbar.Win32.Zango.bd 1

    The selected area was scanned.
     
  8. 2009/01/01
    deester

    deester Inactive Alumni Thread Starter

    Joined:
    2008/07/08
    Messages:
    633
    Likes Received:
    0
    KASPERSKY ONLINE SCANNER 7 REPORT
    Wednesday, December 31, 2008
    Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Wednesday, December 31, 2008 19:50:57
    Records in database: 1539625


    Scan settings
    Scan using the following database extended
    Scan archives yes
    Scan mail databases yes

    Scan area My Computer
    C:\
    D:\

    Scan statistics
    Files scanned 178831
    Threat name 4
    Infected objects 4
    Suspicious objects 0
    Duration of the scan 04:23:47

    File name Threat name Threats count
    C:\games\Amazing Adventures Around the World\AmazingAdventures2.exe Infected: Packed.Win32.****.b 1

    C:\Program Files\Internet Explorer\msimg32.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cv 1

    C:\Program Files\iWin.com\Polly Pride Pet Detective\GameLauncher.exe Infected: Trojan-Dropper.Win32.Irsd.v 1

    C:\Program Files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll Infected: not-a-virus:WebToolbar.Win32.Zango.bd 1

    The selected area was scanned.
    KASPERSKY ONLINE SCANNER 7 REPORT
    Wednesday, December 31, 2008
    Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Wednesday, December 31, 2008 19:50:57
    Records in database: 1539625


    Scan settings
    Scan using the following database extended
    Scan archives yes
    Scan mail databases yes

    Scan area My Computer
    C:\
    D:\

    Scan statistics
    Files scanned 178831
    Threat name 4
    Infected objects 4
    Suspicious objects 0
    Duration of the scan 04:23:47

    File name Threat name Threats count
    C:\games\Amazing Adventures Around the World\AmazingAdventures2.exe Infected: Packed.Win32.****.b 1

    C:\Program Files\Internet Explorer\msimg32.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cv 1

    C:\Program Files\iWin.com\Polly Pride Pet Detective\GameLauncher.exe Infected: Trojan-Dropper.Win32.Irsd.v 1

    C:\Program Files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll Infected: not-a-virus:WebToolbar.Win32.Zango.bd 1

    The selected area was scanned.
     
  9. 2009/01/02
    Dragon30655

    Dragon30655 Inactive

    Joined:
    2008/12/28
    Messages:
    19
    Likes Received:
    1
    Hi deester,

    sorry it took so long to get back to you.

    the list includes:

    Malwarebytes

    Spybot S&D

    Ad-Aware

    I also run

    Combofix

    Cleanup

    and most recently the free version of

    Bitdefender

    As with all of these types of programs always update the definitions files before running
    them to make sure you have the most up-to-date files

    hope this helps have a great day.
     
  10. 2009/01/02
    deester

    deester Inactive Alumni Thread Starter

    Joined:
    2008/07/08
    Messages:
    633
    Likes Received:
    0
    Dragon, As you can see, I have already used Combofix and Malwarebytes. I have also used C Cleaner and ATF cleaner. Which of these clearners should I use next? I just ordered a new laptop and want to make sure my files are clean before I transfer them. Thanks,
    Dee
    PS By the way, did you look at my reports?
     
  11. 2009/01/04
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    First, @Dragon

    We prefer not to have members posting advice in the Malware Removal forum unless trained in malware removal. This topic was responded to by a trained Malware Analyst and I would appreciate you allowing that analyst to guide the user.

    @deester

    PX5 did not suggest that your IWin games are infected (though Kaspersky scan shows otherwise), nor was it recommended to run ComboFix. Such tools are best run only when recommended. I recommend you re-read PX5's post and try to understand his recommendation regarding IWin.
     
  12. 2009/01/04
    deester

    deester Inactive Alumni Thread Starter

    Joined:
    2008/07/08
    Messages:
    633
    Likes Received:
    0
    Well hello Noah, long time no talk to . Seems I've done things wrong again. I read PX5 again. Very tactfully, he is telling me Iwin games should be removed because they are not good for my machine and also to defrag and clean up. I removed the 2 games mentioned in the Kaspersky report, have recently run a defrag and cleaned my disk. I was running combofix because I had run in a previous issue, so really I was really I was just checking out my computer.Today I purchased a new laptop and want to have clean files before they are transferred tomorrow, do you have any suggestions?
    Thanks,
    Deester
     
  13. 2009/01/04
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    I will leave further recommendations regarding your machine to PX5 since that is the original responder. :)
     
  14. 2009/01/04
    PX5

    PX5 Inactive

    Joined:
    2008/12/27
    Messages:
    13
    Likes Received:
    0
    No worries folks,just fill me in on where we are at and let me know the state of the PC.

    There was or is some other Adwares brought onto the machine from Iwin most likely.

    So we can have a mini do over if ya like. ;)
     
    PX5,
    #13
  15. 2009/01/04
    deester

    deester Inactive Alumni Thread Starter

    Joined:
    2008/07/08
    Messages:
    633
    Likes Received:
    0
    PX5,
    I found the infected files in the Kaspersky report,there were 4 I removed the 2 Iwin files. Here are 2 that I do how to find.C:\Qoobox\Quarantine\C\Program Files\Internet Explorer\msimg32.dll.vir Infected: not-a-virus:AdTool.Win32.MyWebSearch.cv 1

    C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll.vir
    I hope I'm doing the right thing, I'm removing the files but I can't find these 2. I need to have mt files as clean as possible.
    Thanks for your help.
    Deester
     
  16. 2009/01/04
    deester

    deester Inactive Alumni Thread Starter

    Joined:
    2008/07/08
    Messages:
    633
    Likes Received:
    0
    PX5,
    As painful as it was, I just deleted my Iwin games and game manager. Hope this helps. Getting ready for my new computer.
    Deester
     
  17. 2009/01/04
    PX5

    PX5 Inactive

    Joined:
    2008/12/27
    Messages:
    13
    Likes Received:
    0
    OK,the last 2 files you need not worry about,they are in the ComboFix Quaratine.

    Can you post a fresh HijackThis log and lets see how things look now.
     
    PX5,
    #16
  18. 2009/01/04
    deester

    deester Inactive Alumni Thread Starter

    Joined:
    2008/07/08
    Messages:
    633
    Likes Received:
    0
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:13:31 PM, on 1/4/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\ScsiAccess.EXE
    C:\Program Files\PermissionResearch\prmrsr.exe
    C:\WINDOWS\Explorer.EXE
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Common Files\AOL\1211762669\ee\AOLSoftware.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    C:\Program Files\Ocucom\PreCast\tmon.exe
    C:\Program Files\MostFun\Bin\MostFun.exe
    C:\Program Files\Common Files\AOL\1211762669\ee\AOLDesktop.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    c:\program files\common files\installshield\updateservice\isuspm.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
    C:\Program Files\AOL 9.1a\waol.exe
    C:\Program Files\AOL 9.1a\shellmon.exe
    C:\Program Files\Mystery P.I. - The Vegas Heist\MysteryPIVegas.exe
    C:\Program Files\Mystery P.I. - The Vegas Heist\MysteryPIVegas.exe
    C:\Program Files\Mystery P.I. - The Vegas Heist\MysteryPIVegas.exe
    C:\Program Files\Mystery P.I. - The Vegas Heist\MysteryPIVegas.exe
    C:\Program Files\Mystery P.I. - The Vegas Heist\MysteryPIVegas.exe
    C:\Program Files\Mystery P.I. - The Vegas Heist\MysteryPIVegas.exe
    C:\Program Files\Mystery P.I. - The Vegas Heist\MysteryPIVegas.exe
    C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.jzip.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - URLSearchHook: NetAssistantBHO Class - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\My.Freeze.com Toolbar with NetAssistant\NetAssistant.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Smart-Shopper - {4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: EmailBHO - {647FD14A-C4F1-46F4-8FC3-0B40F54226F7} - C:\Program Files\jZip\WebmailPlugin.dll
    O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: NetAssistantBHO - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\My.Freeze.com Toolbar with NetAssistant\NetAssistant.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
    O4 - HKLM\..\Run: [PermissionResearch] C:\Program Files\PermissionResearch\prmrsr.exe -boot
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1211762669\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\RunOnce: [iWinArcadeIECleanup] C:\DOCUME~1\Dell\LOCALS~1\Temp\iWinArcadeAutocleanup.bat
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe "
    O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1a\AOL.EXE" -b
    O4 - Startup: AOL Desktop.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe
    O4 - Startup: MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe
    O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    O4 - Global Startup: PreCast Monitor.lnk = C:\Program Files\Ocucom\PreCast\tmon.exe
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
    O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
    O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.nl/scanforvirus-en/kavwebscan_unicode.cab
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Amazing%20Adventures%20The%20Lost%20Tomb/Images/stg_drm.ocx
    O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab
    O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com.../en/x86/MuCatalogWebControl.cab?1221952782890
    O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
    O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
    O16 - DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} (WNICheck2 Class) - http://www.convergysworkathome.com/AppHardT.CAB
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Amazing%20Adventures%20The%20Lost%20Tomb/Images/armhelper.ocx
    O16 - DPF: {D8AA889B-2C65-47C3-8C16-3DCD4EF76A47} (Invoke Solutions Participant Control(MR)) - http://rms2.invokesolutions.com/events/bin/6.2.0.1450/MILive.cab
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
    O20 - Winlogon Notify: PermissionResearch - C:\Program Files\PermissionResearch\prls.dll
    O23 - Service: McAfee Application Installer Cleanup (0096691229613516) (0096691229613516mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\009669~1.EXE (file missing)
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
    O23 - Service: Seekeen Service - Seekeen.com - C:\Program Files\Seekeen\seekeen.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    --
    End of file - 11877 bytes
     
  19. 2009/01/05
    PX5

    PX5 Inactive

    Joined:
    2008/12/27
    Messages:
    13
    Likes Received:
    0
    OK deester,I need to see an uninstall log from HijackThis.

    Run HijackThis and Select "Open The Misc Tools Section" then select "Open Uninstall Manager... "

    Now click "Save List ",Copy and Paste the contents of that list in the next reply.

    Please do understand,even on the internet there is really nothing for free.

    Rather its actually not Free but for a Fee

    The fee is the cost of your computers performance and more often than not,unwanted adwares for the free game or games.

    Either way its not worth it,it destroys a PCs life and can make browsing and other simple computer task a complete headache.
     
    PX5,
    #18
  20. 2009/01/05
    deester

    deester Inactive Alumni Thread Starter

    Joined:
    2008/07/08
    Messages:
    633
    Likes Received:
    0
    PX5, In the past, this is the only log I have ever posted. I have no idea what a uninstall log is. I realize every thing is not free, that's why I subscribe to this forum and pay to download game. After today, I will not be using this computer and was attempting to make sure my files were clean.
    Really appreciate your help and all the help and advice I get from you guys
    Deester
     
  21. 2009/01/15
    deester

    deester Inactive Alumni Thread Starter

    Joined:
    2008/07/08
    Messages:
    633
    Likes Received:
    0
    I am still using my old laptop, there was a problem with my new laptop and I had to return it. Hope to pick it up any day. I am continuing to monitor my old laptop before I transfer my files. Please take a look at this and let me know if I need to do any thing. Thanks for your help.
    KASPERSKY ONLINE SCANNER 7 REPORT
    Thursday, January 15, 2009
    Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Thursday, January 15, 2009 07:07:23
    Records in database: 1624087


    Scan settings
    Scan using the following database extended
    Scan archives yes
    Scan mail databases yes

    Scan area My Computer
    C:\
    D:\

    Scan statistics
    Files scanned 150495
    Threat name 1
    Infected objects 1
    Suspicious objects 0
    Duration of the scan 03:15:00

    File name Threat name Threats count
    C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll.vir Infected: not-a-virus:WebToolbar.Win32.Zango.bd 1

    The selected area was scanned.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.