H Kuttusi. Hope all is well. Finally have the one log but many hours of work. A clean computer is worth it.
I set Eset to include potential damaging or unwanted files programs. Eset scan process took about 7 hours. The first scan slowed to a crawl at 44% and at 47% it took about 1 and ½ hours to get through there. The area was around Wild Tangent games in the App data\Local Low. I wrote the area files down but need to find it. Let me know if you want it. It began with WTA followed by numbers and letters. Eset flagged 5 threats in this area, two of them were OpenCandy files the other two I never got names of because the computer crashed at 50% while I was away from screen. I checked events and it was a minidump caused by S&D update . I thought I had S&D shut down but, guess I didn’t.
Getting Eset to continue was impossible as it refused to do anything because it needed to update and wanted the settings for my proxy. I don’t have a proxy nor am I set up for one. Weird? After several hours of trouble shooting I gave up and did an uninstall and reinstall of Eset. It took 3 hours and slowed at same area and same way as the other scan did but it finished the scan and found no threats . As for the 5 threats I’m guessing that they are somewhere quarantined in Eset’s modules unreadable for me but, removed. I stil have those modules and figure I should just destroy them?
Wild Tangent came preinstalled on my notebook. I’ve tried to remove both it with it's games and remove OpenCandy . No luck so I just deleted what I could of OpenCandy.
I’ve had HitmanPro on my computer for some time and am past the 30 days for it to remove stuff. It seems that all I have on computer are some cookies from safe sites. The two other traces are SearchQue. SearchQue along with Incredibar, Claro and Smart bar haunted me for some time.
There is something I want to check with you on. One of my scans over last 6 weeks from I believe TDSS said I had Trojan:JS/IframeRef . I don’t think I did anything except figure it was a false positive because it never showed up again in any scam. I still have scan logs and they are from multiple programs.
Because one of the programs you had me use removed C:\user.js from the computer. User.js was somthing I had wondered where the file came from. Also had wondered why in different directories my permissions keep changing and were not how I sat them. New users get added. This changes depending on the directory or file. The S-1-5-18 that Hitman Pro flagged is one of them. I read that Windows does this so my suspicions may be needless. My next connection is that I also have this directory that is full of a dumped js and htm files. They were a website page of a book I was looking . This is in my download directory. I don’t think there wasn’t anything I did to download that page. So this all may be unrelated as I am a bit malware spooked at the moment.
Log attached
[attachment=3475]