Computer Security & Viruses/Can NOT get rid of Security Master AV
Expert: Brian Benosky - 7/21/2010
QuestionQUESTION: Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:09:20 PM, on 7/16/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Program Files\Dell DataSafe Local Backup\Toaster.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\SGPSA\ie3sh.exe
C:\Program Files\MyWebSearch\bar\2.bin\M3SRCHMN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\ProgramData\41e68d4\SM41e6.exe
C:\Program Files\Dell Remote Access\ezi_ra.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskeng.exe
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
O2 - BHO: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Gamevance Text - {BEAC7DC8-E106-4C6A-931E-5A42E7362883} - (no file)
O2 - BHO: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
O3 - Toolbar: &Inbox Toolbar - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O3 - Toolbar: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\RunOnce: [DSUpdateLauncher] "c:\Program Files\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="c:\Program Files\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "c:\Program Files\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe"
O4 - HKLM\..\RunOnce: [STToasterLauncher] C:\Program Files\Dell DataSafe Local Backup\toasterLauncher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [05034921] C:\ProgramData\05034921\05034921.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Security Master AV] "C:\ProgramData\41e68d4\SM41e6.exe" /s /d
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Dell Remote Access.lnk = ?
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKxdm011VRUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) -
http://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} (TPIR Control) -
http://www.worldwinner.com/games/v50/tpir/tpir.cab
O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} (SolitaireRush Control) -
http://www.worldwinner.com/games/v47/solitairerush/solitairerush.cab
O16 - DPF: {64CD313F-F079-4D93-959F-4D28B5519449} (Jeopardy Control) -
http://www.worldwinner.com/games/v56/jeopardy/jeopardy.cab
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) -
http://www.worldwinner.com/games/v41/freecell/freecell.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) -
http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} (WorldWinner ActiveX Launcher Control) -
http://www.worldwinner.com/games/launcher/ie/v2.22.01.0/iewwload.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) -
http://www.worldwinner.com/games/v57/wof/wof.cab
O18 - Protocol: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Advanced Networking Service (hnmsvc) - Dell Inc. - c:\Program Files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks - C:\Program Files\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
O23 - Service: Marvell Yukon Service (yksvc) - Unknown owner - RUNDLL32.EXE (file missing)
--
End of file - 14256 bytes
Hi Brian,
As you can see, I'm having one hell of a time with this virus. It seems to have completely wiped out/disabled my McAfee anti-virus software. Any help you can offer would be greatly appreciated. Thank You.
ANSWER: Hi Jax
There is quite a bit of malware on your computer, so we need to work in Safe Mode to start fixing it. Reboot your computer and keep tapping the F8 key on boot until a black screen with a menu appears. Use the arrow keys to highlight and choose Start Windows in Safe Mode With Networking. Log on as usual. Open a browser and download Malwarebytes Anti-Malware from here:
http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe
Double-click mbam-setup.exe and follow the prompts to install the program.
* You will be prompted to update Malwarebytes' Anti-Malware, so please do so.
* Run a FULL SCAN.
* When the scan is complete, click Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Save that log and reboot normally.
Finally, copy that MBAM scan and a new HJT scan log to me in a follow-up.
Brian
---------- FOLLOW-UP ----------
QUESTION: MBAM scan (3) Files Infected:
C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\ProgramData\41e68d4\SM41e6.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\auslots.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\bj.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\casino.exe (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\directsound.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\extgame.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\lbyinst.exe (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\miniprocess.exe (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\plibc32.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\slots.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\winsound.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3AUXSTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3DLGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3REGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3AUXSTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\Windows Live\Messenger\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\Windows Live\Messenger\riched20.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Windows\System32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\Gamevance\ars.cfg (Adware.Gamevance) -> Quarantined and deleted successfully.
C:\Program Files\Gamevance\icon.ico (Adware.Gamevance) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\casino.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\casino.ico (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\casino.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\Gold VIP Club Casino.ico (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\lobby.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\lobby.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\menu.txt (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\msvcp60.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\msvcrt.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\unicows.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\zlib.dll (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\fonts\albw.ttf (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Australian Slots - Base Slots (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Australian Slots - Base Slots.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Australian Slots - Coyote Cash (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Australian Slots - Coyote Cash.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Australian Slots - Fame and Fortune (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Australian Slots - Fame and Fortune.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Australian Slots - Funky Monkey (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Australian Slots - Funky Monkey.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Australian Slots - Penguin Power (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Australian Slots - Penguin Power.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Australian Slots - Prince of Sherwood (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Australian Slots - Prince of Sherwood.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Blackjack - Common (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Blackjack - Common.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Blackjack - Standard (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Blackjack - Standard.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Extgame (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Extgame.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Fonts - Latin (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Fonts - Latin.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Lobby (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Lobby.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\packages (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Slots - Base (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Slots - Base.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Slots - Common (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Slots - Common.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Slots - Five Reel Common (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Slots - Five Reel Common.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Slots - Food Fight (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\Slots - Food Fight.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\SmartDownload (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\installed\SmartDownload.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\5reel.bd1.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\5reel.cny.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\5reel.en.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\5reel.eur.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\5reel.gbp.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\5reel.myr.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\5reel.php.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\5reel.pln.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\5reel.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\5reel.usd.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\5reel.zar.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\action_button.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\bj.en.st.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\blackjack32.en.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\card.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\cards32.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.bd1.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.chf.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.cny.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.en.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.en.st.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.eur.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.gbp.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.myr.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.pen.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.php.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.pln.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.rub.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.usd.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino.zar.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino32.en.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\casino32.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips.bd1.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips.chf.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips.cny.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips.eur.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips.gbp.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips.myr.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips.pen.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips.php.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips.pln.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips.rub.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips.usd.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips.zar.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips32.chf.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips32.cny.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips32.eur.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips32.myr.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips32.pen.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips32.php.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips32.pln.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips32.rub.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips32.usd.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\chips32.zar.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\dgcommon.en.st.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\DM-Common.en.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\DM-Common.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\DM-CoyoteCash-msg.en.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\DM-CoyoteCash-msg.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\DM-CoyoteCash.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\DM-fame.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\DM-funkymonkey.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\DM-lote-gold-small.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\DM-Lote-gold.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\DM-lote-silver-small.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\DM-Lote-silver.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\DM-penguin.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\dm-sherwood.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\downloaddlg.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\exit.en.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\extgame.en.st.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\foodfight.en.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\foodfight.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\history.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\lobby.en.st.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\lobby.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\logos.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\options_new.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\rings.en.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\slots.en.st.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\table.en.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\table.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\tables32.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\rsc\tbslot.en.rsc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\Blackjack.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\Bust.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\cmn000.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\cmn001.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\cmn002.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\cmn003.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\cmn004.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\cmn005.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\cmn007.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_00.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_01.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_02.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_03.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_04.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_05.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_06.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_07.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_08.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_09.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_10.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_11.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_12.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_13.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_14.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_15.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_16.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_17.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_18.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_19.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_20.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_21.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_22.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_23.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_24.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_25.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_26.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_27.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_28.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_29.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_30.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_31.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_32.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_33.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_34.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_35.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\HandScore_36.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\Insurance.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\jkp000.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\jkp001.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\PlayerWins.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\Push.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\ShoeCardSound.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt000.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt001.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt002.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt003.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt004.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt005.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt006.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt007.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt008.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt009.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt010.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt019.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt020.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt021.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt022.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt023.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt025.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt026.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt027.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt028.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt049.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt050.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt152.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt154.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt155.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt156.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt157.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt158.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt159.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt162.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt163.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt164.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt165.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt166.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\slt167.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltCoyoteCashFreeLoop.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltCoyoteCashSymbolCoyote.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltCoyoteCashSymbolCoyoteFXBoom.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltCoyoteCashSymbolCoyoteFXSwoosh.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltCoyoteCashSymbolLoot.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltCoyoteCashSymbolLootFXCoinHit.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltCoyoteCashSymbolLootFXCoins.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltCoyoteCashSymbolLootFXCoinUp.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltFameAndFortuneFreeLoop.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltFameAndFortuneSymbolGlamourGirl.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltFunkyMonkeyFeatureApplause.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltFunkyMonkeyFeatureBongoIntro.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltFunkyMonkeyFeatureBongoLoop.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltFunkyMonkeyFeatureGuitarIntro.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltFunkyMonkeyFeatureGuitarLoop.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltFunkyMonkeyFeatureKeyboardIntro.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltFunkyMonkeyFeatureKeyboardLoop.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltFunkyMonkeyFreeLoop.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltFunkyMonkeySymbolBanana.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltFunkyMonkeySymbolFunkyMonkey.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltPenguinPowerFeatureHit1.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltPenguinPowerFeatureHit2.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltPenguinPowerFreeLoop.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltPenguinPowerSymbolBabyPenguin.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltPenguinPowerSymbolIgloo.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltprinceofsherwoodarrowhit.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltprinceofsherwoodarrowshoot.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltprinceofsherwoodcrowd.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltprinceofsherwoodfreeloop.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltprinceofsherwoodstart.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltprinceofsherwoodsymbolcastle.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltprinceofsherwoodsymbolrobinhood.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltprinceofsherwoodwin1.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltprinceofsherwoodwin2.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\sltprinceofsherwoodwin3.wav (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\sounds\Win.ogg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\temp\loading.html (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\temp\redirect.html (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\_patch\package_list.ini (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\Gold VIP Club Casino\_patch\package_list.ini.crc (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3FFXTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin\M3NTSTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\linda\Desktop\Security Master AV.LNK (Rogue.SecurityMasterAV) -> Quarantined and deleted successfully.
C:\Users\linda\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Security Master AV.LNK (Rogue.SecurityMasterAV) -> Quarantined and deleted successfully.
C:\Users\linda\AppData\Roaming\Microsoft\Windows\Start Menu\Security Master AV.LNK (Rogue.SecurityMasterAV) -> Quarantined and deleted successfully.
C:\Users\linda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Master AV.lnk (Rogue.SecurityMaster) -> Quarantined and deleted successfully.
AnswerHi Jax
I did say that there was quite a bit of malware on there. Because of the amount and the type of malware, we will need to do some more cleaning before we can say for certain your computer is malware-free. Next, I would like for you to run a ComboFix scan as follows:
Please download ComboFix from this link:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
*Important*-Save it to your desktop.
Double-click on the ComboFix icon found on your desktop. Please note, that once you start ComboFix you should not click anywhere on the ComboFix window as it can cause the program to stall. If asked to install the Windows Recovery Console, please allow the program to do so. ComboFix will now start scanning your computer for known infections. This procedure can take some time, so please be patient. If you see your Windows desktop disappear, do not worry. This is normal and ComboFix will restore your desktop before it is finished. ComboFix may also restart your computer. Do not intervene. Eventually you will see a new screen that states the program is almost finished and telling you the programs log file, or report, will be located at C:\ComboFix.txt. It will then display the log file automatically for you. Post me that log and a new HJT scan log in your next follow-up.
Brian