This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

used laptop.not sure if its clean

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i just purchased a used dell inspiron from a friend and im not sure if its as clean as it should be. seems like it lags on start up an sometimes during browsing. other than that it seems ok. not familiar with the anti-virus program. used to running AVG. any suggestions on how to check everything out?
Hi electriccrayon,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

any suggestions on how to check everything out?

Yep. :D

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Also please describe how your computer behaves at the moment.
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 5184 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18975 11/24/2010 6:33:46 PM mbam-log-2010-11-24 (18-33-46).txt Scan type: Quick scan Objects scanned: 140504 Time elapsed: 8 minute(s), 23 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) DDS (Ver_10-11-10.01) - NTFSx86 Run by [removed] at 19:15:48.42 on Wed 11/24/2010 Internet Explorer: 8.0.6001.18975 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1013.238 [GMT -5:00] AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A} FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch c:\windows\system32\servicescache.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\WLTRYSVC.EXE C:\Windows\system32\WLANExt.exe C:\Windows\System32\bcmwltry.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\DellTPad\Apoint.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\aestsrv.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\STacSV.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Rent America\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://facebook.com/ uWindow Title = Internet Explorer provided by Dell uInternet Settings,ProxyOverride = *.local BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [ECenter] c:\dell\e-center\EULALauncher.exe mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe" mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [PAC207_Monitor] c:\windows\pixart\pac207\Monitor.exe mRun: [Monitor] c:\windows\pixart\pac207\Monitor.exe mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [Mightymagoo] c:\program files\mighty magoo\mightymagoo32.exe a mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Notify: igfxcui - igfxdev.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\rentam~1\appdata\roaming\mozilla\firefox\profiles\t42efsbo.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/ FF - component: c:\users\rent america\appdata\roaming\mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\mmagootlf.dll FF - plugin: c:\program files\java\jre1.6.0\bin\npjpi160.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ —- FIREFOX POLICIES —- FF - user.js: general.useragent.extra.brc - c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified ============= SERVICES / DRIVERS =============== R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-5-11 165584] R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-4-2 73728] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-11 17744] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-5-11 50768] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-8 40384] R2 systemCheck;SystemWindows;c:\windows\system32\servicescache.exe [2008-10-7 6160384] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-8 40384] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-8 40384] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2008-4-3 111616] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 MicrosoftHardwareDriver;MicrosoftHardwareDriver; [x] S2 SysCacheDriver;SysCacheDriver;c:\windows\system32\sysSecurityCheck.exe [2010-4-4 6291456] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-17 21504] S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2008-4-2 1174664] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] =============== Created Last 30 ================ 2010-11-24 23:22:28 ——– d—–w- c:\users\rentam~1\appdata\roaming\Malwarebytes 2010-11-24 23:22:15 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-11-24 23:22:14 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-11-24 23:22:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-11-24 23:22:14 ——– d—–w- c:\progra~2\Malwarebytes 2010-11-24 04:11:32 ——– d—–w- c:\program files\Microsoft 2010-11-24 03:27:10 7680 —-a-w- c:\program files\internet explorer\iecompat.dll 2010-11-23 09:28:15 6273872 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{6677c774-fc0b-42b3-9ff8-53f465133b4a}\mpengine.dll 2010-11-20 00:12:13 ——– d—–w- c:\users\rentam~1\appdata\local\Mozilla 2010-11-20 00:12:02 553696 —-a-w- c:\program files\mozilla firefox\uninstall\helper.exe 2010-11-20 00:12:00 25048 —-a-w- c:\program files\mozilla firefox\components\browserdirprovider.dll 2010-11-20 00:12:00 140248 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll 2010-11-12 04:11:18 98304 —h–r- c:\windows\system32\FireWallDart.exe 2010-11-12 04:11:18 8007680 —-a-w- c:\windows\system32\Microsoft.mshtml.dll 2010-11-12 04:11:17 726016 —h–r- c:\windows\system32\7z.dll 2010-11-12 04:11:17 256000 —h–r- c:\windows\system32\SevenZipSharp.dll 2010-11-12 04:11:17 200704 —-a-w- c:\windows\system32\ICSharpCode.SharpZipLib.dll 2010-11-12 04:11:17 126976 —-a-w- c:\windows\system32\Interop.SHDocVw.dll 2010-11-11 19:15:03 ——– d—–w- C:\Nexon 2010-11-11 19:14:57 ——– d—–w- c:\progra~2\NexonUS 2010-11-11 18:15:14 ——– d—–w- c:\users\rentam~1\appdata\local\PMB Files 2010-11-11 18:15:13 ——– d—–w- c:\progra~2\PMB Files 2010-11-10 00:33:08 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2010-11-03 22:48:51 ——– d—–w- c:\program files\Mighty Magoo 2010-11-03 03:08:02 ——– d—–w- c:\users\rentam~1\appdata\local\SecondLife 2010-10-27 14:32:21 1696256 —-a-w- c:\windows\system32\gameux.dll 2010-10-27 14:32:19 28672 —-a-w- c:\windows\system32\Apphlpdm.dll 2010-10-27 14:32:17 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll ==================== Find3M ==================== 2010-11-12 16:07:47 6160384 —h–r- c:\windows\system32\servicescache.exe 2010-11-12 16:05:44 6291456 —h–r- c:\windows\system32\sysSecurityCheck.exe 2010-10-19 15:41:44 222080 ——w- c:\windows\system32\MpSigStub.exe 2010-09-25 16:03:07 421888 —h–w- c:\windows\system32\Internet Explorer 5.0.exe 2010-09-13 13:56:41 8147456 —-a-w- c:\windows\system32\wmploc.DLL 2010-09-08 06:01:28 916480 —-a-w- c:\windows\system32\wininet.dll 2010-09-08 05:57:18 43520 —-a-w- c:\windows\system32\licmgr10.dll 2010-09-08 05:57:05 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2010-09-08 05:56:53 71680 —-a-w- c:\windows\system32\iesetup.dll 2010-09-08 05:56:53 109056 —-a-w- c:\windows\system32\iesysprep.dll 2010-09-08 05:04:36 385024 —-a-w- c:\windows\system32\html.iec 2010-09-08 04:26:46 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2010-09-08 04:25:15 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2010-09-07 15:12:17 38848 —-a-w- c:\windows\avastSS.scr 2010-09-06 16:20:29 125952 —-a-w- c:\windows\system32\srvsvc.dll 2010-09-06 16:19:06 17920 —-a-w- c:\windows\system32\netevent.dll 2010-08-31 15:46:37 954752 —-a-w- c:\windows\system32\mfc40.dll 2010-08-31 15:46:37 954288 —-a-w- c:\windows\system32\mfc40u.dll 2010-08-31 15:44:31 531968 —-a-w- c:\windows\system32\comctl32.dll 2010-08-31 13:27:38 2038272 —-a-w- c:\windows\system32\win32k.sys ============= FINISH: 19:16:19.12 ===============

Attachments:

electriccrayon,

I'm not seeing anything "bad" in there. Let's get an online scan as a doublecheck.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
here is the requested logfile. happy thanksgiving to all of you at whatthetech!!! ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=0dc99feaf4d3404db58704765e811140 # end=stopped # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-11-25 04:53:10 # local_time=2010-11-24 11:53:10 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=768 16777215 100 0 6582116 6582116 0 0 # compatibility_mode=5892 16776573 100 100 0 127265804 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=97928 # found=1 # cleaned=0 # scan_time=2558 C:\Program Files\Mighty Magoo\mightymagoo32.exe a variant of Win32/Adware.Gamevance.AJ application 00000000000000000000000000000000 I ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=0dc99feaf4d3404db58704765e811140 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-11-25 07:24:38 # local_time=2010-11-25 02:24:38 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=768 16777215 100 0 6590706 6590706 0 0 # compatibility_mode=5892 16776573 100 100 0 127274394 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=116121 # found=1 # cleaned=0 # scan_time=3056 C:\Program Files\Mighty Magoo\mightymagoo32.exe a variant of Win32/Adware.Gamevance.AJ application 00000000000000000000000000000000 I ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=0dc99feaf4d3404db58704765e811140 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-11-25 10:02:41 # local_time=2010-11-25 05:02:41 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=768 16777215 100 0 6599467 6599467 0 0 # compatibility_mode=5892 16776573 100 100 0 127283155 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=116114 # found=1 # cleaned=0 # scan_time=3778 C:\Program Files\Mighty Magoo\mightymagoo32.exe a variant of Win32/Adware.Gamevance.AJ application 00000000000000000000000000000000 I
electriccrayon,

Please download the OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
    (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    
    :Files
    C:\Program Files\Mighty Magoo\mightymagoo32.exe
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
All processes killed ========== PROCESSES ========== ========== FILES ========== C:\Program Files\Mighty Magoo\mightymagoo32.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: Rent America ->Temp folder emptied: 47639 bytes ->Temporary Internet Files folder emptied: 86220 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 103290116 bytes ->Flash cache emptied: 3683 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 15987 bytes Total Files Cleaned = 99.00 mb OTM by OldTimer - Version 3.1.17.2 log created on 11262010_010118 Files moved on Reboot… File move failed. C:\Windows\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot. Registry entries deleted on Reboot…
Alright. I think you're good to go.

Let's clean up my mess.

Cleanup

  • Double click on OTM to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
start-up went ALOT smoother and quicker! everything seems to be tip top. thank you very much for your time. have a blessed holiday season! "resolved"

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI