Jump to content

987Bytes

Members
  • Posts

    5
  • Joined

  • Last visited

Everything posted by 987Bytes

  1. Well, things seem a little slow, but it's always difficult to asses that. I didn't really focus on Registry entries like I should have so things are not working normally - I assume - because of deletions there, so I'll be working on reversing some of those deletions. But the 4 PUPS are gone, and that's what I was really gunning for. Thanks again.
  2. Before running AdwCleaner I managed to reduce the PUP's to the original 4 that I started with: PUP.Optional.OpenCandy (Folder) PUP.Optional.OpenCandy (Folder) PUP.Optional.OpenCandy (Folder) PUP.Optional.FileScout.A (Folder) AdwCleaner found the first and last folder, which I figured was OK as the middle two folders were located under the first folder and would go away with the first folder: AdwCleaner also found 11 other Files/Folders which I elected to not delete - for the moment. AdwCleaner[s0].txt ------------------------------------------------------------------------------------------------------- # AdwCleaner v3.006 - Report created 07/10/2013 at 09:30:27 # Updated 01/10/2013 by Xplode # Operating System : Windows Vista Home Premium Service Pack 2 (32 bits) # Username : Tom Young - TOMYOUNGPC # Running from : C:\Users\Tom Young\Desktop\AdwCleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** [x] Not Deleted : C:\ProgramData\Conduit [x] Not Deleted : C:\Program Files\Conduit [x] Not Deleted : C:\Users\Tom Young\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Tom Young\AppData\Roaming\file scout Folder Deleted : C:\Users\Tom Young\AppData\Roaming\OpenCandy [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\PerformerSoft [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\CT3298566 [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\CT3279411 [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\Extensions\{1122b43d-30ee-403f-9bfa-3cc99b0caddd} [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\Extensions\{1122b43d-30ee-403f-9bfa-3cc99b0caddd} [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\Extensions\{465fcfbb-47a4-4866-a5d5-d12f9a77da00} [x] Not Deleted : C:\Program Files\Mozilla Firefox\searchplugins\safesearch.xml [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\user.js ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\YahooPartnerToolbar Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Deleted : HKCU\Software\AppDataLow\Software\smartbar Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\Tarma Installer Key Deleted : HKLM\Software\TENCENT Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} ***** [ Browsers ] ***** -\\ Internet Explorer v9.0.8112.16506 -\\ Mozilla Firefox v24.0 (en-US) [ File : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\prefs.js ] Line Deleted : user_pref("CT3279411.FF19Solved", "true"); Line Deleted : user_pref("CT3279411.UserID", "UN31874844020442146"); Line Deleted : user_pref("CT3279411.browser.search.defaultthis.engineName", "true"); Line Deleted : user_pref("CT3279411.fullUserID", "UN31874844020442146.IN.20130831082551"); Line Deleted : user_pref("CT3279411.installDate", "31/08/2013 08:26:27"); Line Deleted : user_pref("CT3279411.installSessionId", "{EAE31452-568B-4F4A-AB2B-FC0E8237587E}"); Line Deleted : user_pref("CT3279411.installSp", "TRUE"); Line Deleted : user_pref("CT3279411.installerVersion", "1.6.1.2"); Line Deleted : user_pref("CT3279411.keyword", "true"); Line Deleted : user_pref("CT3279411.originalSearchAddressUrl", ""); Line Deleted : user_pref("CT3279411.originalSearchEngine", ""); Line Deleted : user_pref("CT3279411.originalSearchEngineName", ""); Line Deleted : user_pref("CT3279411.searchRevert", "false"); Line Deleted : user_pref("CT3279411.searchUserMode", "2"); Line Deleted : user_pref("CT3279411.smartbar.homepage", "true"); Line Deleted : user_pref("CT3279411.versionFromInstaller", "10.19.2.5"); Line Deleted : user_pref("CT3279411.xpeMode", "0"); Line Deleted : user_pref("CT3298566.FF19Solved", "true"); Line Deleted : user_pref("CT3298566.UserID", "UN28866691762694183"); Line Deleted : user_pref("CT3298566.browser.search.defaultthis.engineName", "true"); Line Deleted : user_pref("CT3298566.fullUserID", "UN28866691762694183.IN.20131004055648"); Line Deleted : user_pref("CT3298566.installDate", "04/10/2013 05:56:53"); Line Deleted : user_pref("CT3298566.installSessionId", "{526C4219-A26C-4226-A5CC-AFEF01A4A1A9}"); Line Deleted : user_pref("CT3298566.installSp", "TRUE"); Line Deleted : user_pref("CT3298566.installerVersion", "1.7.1.7"); Line Deleted : user_pref("CT3298566.keyword", "true"); Line Deleted : user_pref("CT3298566.originalSearchEngine", "appbario12 Customized Web Search"); Line Deleted : user_pref("CT3298566.originalSearchEngineName", "appbario12 Customized Web Search"); Line Deleted : user_pref("CT3298566.searchRevert", "false"); Line Deleted : user_pref("CT3298566.searchUserMode", "2"); Line Deleted : user_pref("CT3298566.smartbar.homepage", "true"); Line Deleted : user_pref("CT3298566.versionFromInstaller", "10.20.1.8"); Line Deleted : user_pref("CT3298566.xpeMode", "0"); Line Deleted : user_pref("browser.search.defaultthis.engineName", "MixiDJ V30 Customized Web Search"); Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3298566"); Line Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3298566"); Line Deleted : user_pref("smartbar.homePageOwnerCTID", "CT3298566"); Line Deleted : user_pref("smartbar.machineId", "TQGAELERG/ZFC61CIRJIY0OB6GU88TK8U+Y3HFFROFHLGVVY5DEVZZYWPSGNUOELHL2O5/N2ZSYXLQK4TO2H5G"); ************************* AdwCleaner[R0].txt - [7997 octets] - [07/10/2013 09:18:39] AdwCleaner[s0].txt - [8115 octets] - [07/10/2013 09:30:27] ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [8175 octets] ########## ------------------------------------------------------------------------------------------------------- Running Malwarebytes resulted in no items found. ------------------------------------------------------------------------------------------------------- mbam-log-2013-10-07 (10-16-03) Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.10.07.08 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Tom Young :: TOMYOUNGPC [administrator] 10/7/2013 10:16:03 AM mbam-log-2013-10-07 (10-16-03).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 281060 Time elapsed: 14 minute(s), 16 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ------------------------------------------------------------------------------------------------------- Things seem to be working OK in the few minutes I've been using the computer. Thank you for your help.
  3. I'll be back to that computer on Monday and I'll give it a try then. Thanks.
  4. Hmmm... Well that was "interesting." I had a bad feeling about AdwCleaner when it told me that it was ad supported and would try to load additional programs as part of the installation. I went ahead anyway, declined the additional programs, (first one was some kind of game), but took comfort in the declaration that the programs could be removed in the usual fashion via Control Panel. However, SpyBot flagged one item as malware, which I told it to block, and then let the install program run. When that was done I immediately went to the control panel and deleted the 2 programs, but it was too late. My browser had been hacked; home page was a new "search" site, default "search" has also been altered, and I was warned off any attempt to go to Google by the declaration the site was unsafe. My PUP's had expanded from 4 to something like 55(!) and in attempting to remove them additional changes to the browser settings were made (proxy server, etc.). After a lot of thrashing around here I've reduced the PUP's to 9 (original 4 plus additional "conduit" entries which came from AdwCleaner). All in all that's quite disturbing. Did I download the correct product? Is any of what I described expected behavior?
  5. Hi: Malwarebytes has found the following folders on my Win Vista machine: PUP.Optional.OpenCandy (Folder) PUP.Optional.OpenCandy (Folder) PUP.Optional.OpenCandy (Folder) PUP.Optional.FileScout.A (Folder) and they refuse to be deleted or renamed. DDS.txt ------------------------------------------------------------------------------------------- DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 9.0.8112.16506 BrowserJavaVersion: 10.25.2 Run by Tom Young at 16:39:45 on 2013-10-03 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3326.1377 [GMT -7:00] . AV: Norton Security Suite *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton Security Suite *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Security Suite *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\nvvsvc.exe C:\Program Files\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\SLsvc.exe C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Hawking\Control Center\Control Center.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Quicken\billmind.exe C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Program Files\ContourStoryteller\ContourAutoplay.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\MyTomTom 3\MyTomTomSA.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\GameTracker\GSInGameService.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe C:\Windows\system32\PnkBstrA.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\System32\WUDFHost.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe C:\Windows\System32\calc.exe C:\Program Files\Quicken\qw.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\TOMYOU~1\AppData\Local\Temp\nsnDE45.tmp\nsE5E4.tmp C:\Users\TOMYOU~1\AppData\Local\Temp\nsnDE45.tmp\MBR.DAT C:\Windows\system32\Taskmgr.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation . ============== Pseudo HJT Report =============== . uWindow Title = Windows Internet Explorer provided by Comcast mWindow Title = Windows Internet Explorer provided by Comcast BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\program files\norton security suite\engine\5.2.2.3\coieplg.dll BHO: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - c:\program files\norton security suite\engine\5.2.2.3\ips\ipsbho.dll BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\program files\norton security suite\engine\5.2.2.3\coieplg.dll uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [spybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [QuickenBillminder] c:\program files\quicken\Billmind.exe -startup uRun: [ContourCameraFinder] "c:\program files\contourstoryteller\ContourAutoplay.exe" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [MyTomTomSA.exe] "c:\program files\mytomtom 3\MyTomTomSA.exe" mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Hawking UDS Control Center] c:\program files\hawking\control center\Control Center.exe -mini mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon dRun: [CtxfiReg] CTXFIREG.exe /FAIL2 uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0 mPolicies-System: EnableLUA = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000 IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll Trusted Zone: internet Trusted Zone: mcafee.com Trusted Zone: mcafee.com Trusted Zone: turbotax.com TCP: NameServer = 192.168.2.1 192.168.2.1 TCP: Interfaces\{386A2D13-A973-42B1-ADFE-A2BE676694D7} : DHCPNameServer = 192.168.2.1 192.168.2.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll LSA: Authentication Packages = msv1_0 relog_ap LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg . ================= FIREFOX =================== . FF - ProfilePath - c:\users\tom young\appdata\roaming\mozilla\firefox\profiles\k0kb9aew.default\ FF - prefs.js: browser.search.selectedEngine - appbario12 Customized Web Search FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\amazon\mp3 downloader\npAmazonMP3DownloaderPlugin101752.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.153\npGoogleUpdate3.dll FF - plugin: c:\program files\ign\download manager\npfpdlm.dll FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\program files\microsoft silverlight\5.1.20513.0\npctrlui.dll FF - plugin: c:\program files\nitro\reader 3\npdf.dll FF - plugin: c:\program files\nitro\reader 3\npnitroie.dll FF - plugin: c:\program files\nitro\reader 3\npnitromozilla.dll FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\programdata\id software\quakelive\npquakezero.dll FF - plugin: c:\users\tom young\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\users\tom young\appdata\roaming\move networks\plugins\npqmp071505000010.dll FF - plugin: c:\users\tom young\appdata\roaming\move networks\plugins\npqmp071505000011.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_8_800_168.dll FF - plugin: c:\windows\system32\npDeployJava1.dll FF - plugin: c:\windows\system32\npmproxy.dll FF - ExtSQL: 2013-08-30 16:02; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\coFFPlgn_2011_7_13_2 FF - ExtSQL: 2013-08-31 08:26; {465fcfbb-47a4-4866-a5d5-d12f9a77da00}; c:\users\tom young\appdata\roaming\mozilla\firefox\profiles\k0kb9aew.default\extensions\{465fcfbb-47a4-4866-a5d5-d12f9a77da00} . ============= SERVICES / DRIVERS =============== . . =============== Created Last 30 ================ . 2013-09-30 13:59:36 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2013-09-20 04:46:09 27152 ----a-w- c:\windows\system32\nitrolocalmon2.dll 2013-09-20 04:46:09 18448 ----a-w- c:\windows\system32\nitrolocalui2.dll 2013-09-20 04:46:01 -------- d-----w- c:\program files\Nitro 2013-09-20 04:46:01 -------- d-----w- c:\program files\common files\Nitro 2013-09-19 18:06:53 -------- d-----w- c:\users\tom young\appdata\roaming\Downloaded Installations 2013-09-16 19:30:40 4806016 ----a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll 2013-09-16 19:30:40 4806016 ----a-w- c:\program files\mozilla firefox\browser\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll 2013-09-11 03:44:51 2049536 ----a-w- c:\windows\system32\win32k.sys 2013-09-11 03:44:49 615936 ----a-w- c:\windows\system32\themeui.dll . ==================== Find3M ==================== . 2013-09-20 13:57:06 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-09-20 13:57:06 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-08-02 04:09:35 1548288 ----a-w- c:\windows\system32\WMVDECOD.DLL 2013-07-31 10:00:20 1800704 ----a-w- c:\windows\system32\jscript9.dll 2013-07-31 09:52:44 1129472 ----a-w- c:\windows\system32\wininet.dll 2013-07-31 09:52:34 1427968 ----a-w- c:\windows\system32\inetcpl.cpl 2013-07-31 09:48:43 142848 ----a-w- c:\windows\system32\ieUnatt.exe 2013-07-31 09:48:09 420864 ----a-w- c:\windows\system32\vbscript.dll 2013-07-31 09:45:42 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2013-07-17 19:41:34 2048 ----a-w- c:\windows\system32\tzres.dll 2013-07-10 09:47:00 783360 ----a-w- c:\windows\system32\rpcrt4.dll 2013-07-09 12:10:36 1205168 ----a-w- c:\windows\system32\ntdll.dll 2013-07-08 04:55:51 3603904 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-07-08 04:55:51 3551680 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-07-08 04:20:04 172544 ----a-w- c:\windows\system32\wintrust.dll 2013-07-08 04:16:55 98304 ----a-w- c:\windows\system32\cryptnet.dll 2013-07-08 04:16:55 133120 ----a-w- c:\windows\system32\cryptsvc.dll 2013-07-08 04:16:54 992768 ----a-w- c:\windows\system32\crypt32.dll . ============= FINISH: 16:40:06.69 =============== Attach.txt ------------------------------------------------------------------------------------------- . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume3 Install Date: 4/12/2007 3:17:23 AM System Uptime: 10/3/2013 11:10:58 AM (5 hours ago) . Motherboard: ECS | | Nettle Processor: AMD Athlon 64 X2 Dual Core Processor 4800+ | Socket AM2 | 2500/201mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 290 GiB total, 192.584 GiB free. D: is FIXED (NTFS) - 8 GiB total, 0.59 GiB free. E: is CDROM () G: is Removable H: is Removable I: is Removable J: is FIXED (NTFS) - 128 GiB total, 74.59 GiB free. K: is FIXED (NTFS) - 62 GiB total, 57.027 GiB free. L: is FIXED (NTFS) - 279 GiB total, 240.082 GiB free. M: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP2130: 10/3/2013 1:46:54 PM - Scheduled Checkpoint . ==== Installed Programs ====================== . Acrobat.com ActiveCheck component for HP Active Support Library Adobe AIR Adobe Digital Editions Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader X (10.1.8) Amazon MP3 Downloader 1.0.17 AmodGPSTracker AnswerWorks 4.0 Runtime - English AnswerWorks 5.0 English Runtime Apple Application Support ArcSoft PhotoStudio 5.5 ArcSoft Print Creations ArcSoft Print Creations - Album Page ArcSoft Print Creations - Funhouse ArcSoft Print Creations - Greeting Card ArcSoft Print Creations - Photo Book ArcSoft Print Creations - Photo Calendar ArcSoft Print Creations - Scrapbook ArcSoft Print Creations - Slimline Card AutoUpdate Bonjour Canon Auto Update Service Canon Camera Window DC_DV 6 for ZoomBrowser EX Canon G.726 WMP-Decoder Canon MOV Decoder Canon MOV Encoder Canon MovieEdit Task for ZoomBrowser EX Canon MP Navigator EX 2.0 Canon RAW Image Task for ZoomBrowser EX Canon RemoteCapture Task for ZoomBrowser EX Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX Canon Utilities PhotoStitch Canon Utilities Solution Menu Canon Utilities ZoomBrowser EX Canon ZoomBrowser EX Memory Card Utility CanoScan LiDE 200 Scanner Driver CCScore CDDRV_Installer CoffeeCup HTML Editor CoffeeCup LockBox Comcast High-Speed Internet Install Wizard Comcast Rhapsody Compatibility Pack for the 2007 Office system Contour Storyteller Creative Audio Control Panel Creative Sound Blaster Properties D3DX10 Desktop Doctor DHTML Editing Component DivX Download Manager 2.3.6 Dropbox Dual-Core Optimizer Easy Picture2Icon 2.1 Enhanced Multimedia Keyboard Solution EPSON Printer Software Eraser 6.0.6.1376 erLT ESSBrwr ESSCDBK ESScore ESSgui ESSini ESSPCD ESSPDock ESSTOOLS essvatgt FileZilla Client 3.1.1.1 GameCenter GameSpy Arcade GameTracker Lite GIMP 2.6.11 Google Earth Google SketchUp 8 Google Update Helper Hardware Diagnostic Tools Hawking Control Center HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Active Support Library HP Active Support Library 32 bit components HP Connections (remove only) HP Customer Feedback HP Easy Setup - Core HP On-Screen Caps/Num/Scroll Lock Indicator HP Photosmart Essential 2.01 HP Photosmart Essential2.01 HP Picasso Media Center Add-In HPAsset component for HP Active Support Library IGN Download Manager 2.3.2 iSEEK AnswerWorks English Runtime Java 7 Update 25 Java Auto Updater JavaFX 2.1.1 KhalInstallWrapper Kodak EasyShare software LG United Mobile Driver LightScribe 1.4.136.1 Logitech SetPoint Logitech Vid Logitech Webcam Software Logitech Webcam Software Driver Package MagicTunePremium Malwarebytes Anti-Malware version 1.75.0.1300 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Office File Validation Add-In Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Standard Edition 2003 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Works MobileMe Control Panel Move Media Player Mozilla Firefox 24.0 (x86 en-US) Mozilla Maintenance Service MSN Money Investment Toolbox MSVCRT MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) muvee autoProducer 5.0 My HP Games MyTomTom 3.2.0.1220 netbrdg Nitro Reader 3 Nolo's Encyclopedia of Everyday Law Norton Security Suite NVIDIA 3D Vision Controller Driver 314.22 NVIDIA Control Panel 314.22 NVIDIA Graphics Driver 314.22 NVIDIA Install Application NVIDIA PhysX NVIDIA PhysX System Software 9.12.1031 NVIDIA Update 1.12.12 NVIDIA Update Components Octoshape add-in for Adobe Flash Player OfotoXMI OGA Notifier 2.0.0048.0 OpenAL Paint.NET v3.5.11 PDF reDirect (remove only) Ping Plotter Freeware PowerDVD PrimoPDF -- brought to you by Nitro PDF Software Pro Cycling Manager - Season 2008 1.0.2.3 PSSWCORE PunkBuster Services PVSonyDll Python 2.4.3 Quake III Arena Quake III Arena Point Release 1.32 Quake Live Internet Explorer Plugin Quake Live Mozilla Plugin Quicken 2013 Quicken WillMaker Plus 2011 QuickTime RealPlayer Rhapsody Rhapsody Player Engine Rocket Arena 3 Upgrade 1.76 (remove only) Roxio Creator Audio Roxio Creator Basic v9 Roxio Creator Copy Roxio Creator Data Roxio Creator EasyArchive Roxio Creator Tools Roxio Express Labeler 3 Roxio MyDVD Basic v9 Seagate DiscWizard SecureZIP for Windows 12.30.0016 Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576) Security Update for Microsoft .NET Framework 4 Client Profile (KB2832407) Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2) Segoe UI Seismovision 3 (remove only) SFR SHASTA SketchUp Viewer skin0001 SKINXSDK Skype Click to Call Skype™ 6.5 Soft Data Fax Modem with SmartCP Sound Blaster X-Fi Spybot - Search & Destroy SSA Benefit Calculator staticcr swMSM System Requirements Lab TaxCut Premium + State + Efile 2008 Threewave 1.6 Turbo Lister 2 TurboCAD Deluxe 16 TurboCAD Designer 14 TurboCAD Designer 15 TurboCAD Designer 16 TurboCAD Symbols TurboFLOORPLAN Home & Landscape Pro TurboTax 2008 TurboTax 2008 wcaiper TurboTax 2008 WinPerFedFormset TurboTax 2008 WinPerProgramHelp TurboTax 2008 WinPerReleaseEngine TurboTax 2008 WinPerTaxSupport TurboTax 2008 WinPerUserEducation TurboTax 2008 wrapper TurboTax 2009 TurboTax 2009 wcaiper TurboTax 2009 WinPerFedFormset TurboTax 2009 WinPerReleaseEngine TurboTax 2009 WinPerTaxSupport TurboTax 2009 wrapper TurboTax 2010 TurboTax 2010 wcaiper TurboTax 2010 WinPerFedFormset TurboTax 2010 WinPerReleaseEngine TurboTax 2010 WinPerTaxSupport TurboTax 2010 wrapper TurboTax 2011 TurboTax 2011 wcaiper TurboTax 2011 WinPerFedFormset TurboTax 2011 WinPerReleaseEngine TurboTax 2011 WinPerTaxSupport TurboTax 2011 wrapper TurboTax 2012 TurboTax 2012 waliper TurboTax 2012 waziper TurboTax 2012 wcaiper TurboTax 2012 wcoiper TurboTax 2012 wctiper TurboTax 2012 wdciper TurboTax 2012 wdeiper TurboTax 2012 wgaiper TurboTax 2012 wiliper TurboTax 2012 WinPerFedFormset TurboTax 2012 WinPerReleaseEngine TurboTax 2012 WinPerTaxSupport TurboTax 2012 wlaiper TurboTax 2012 wrapper TurboTax Deluxe 2007 TurboTax Deluxe Deduction Maximizer 2006 TurboTax ItsDeductible 2006 Unity Web Player Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) VideoToolkit01 Virtual Earth 3D (Beta) Visual Studio C++ 10.0 Runtime Volume Panel VPRINTOL WexTech AnswerWorks WinDirStat 1.1.2 Windows 7 Upgrade Advisor Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live UX Platform Windows Live UX Platform Language Pack Windows Media Player Firefox Plugin WIRELESS World of Padman . ==== Event Viewer Messages From Past Week ======== . 9/26/2013 10:11:38 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TrkWks service. 9/26/2013 10:11:08 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SysMain service. 10/3/2013 7:18:49 AM, Error: bowser [8003] - The master browser has received a server announcement from the computer DELL-BOX that believes that it is the master browser for the domain on transport NetBT_Tcpip_{386A2D13-A973-42B1-ADFE-A2BE67669. The master browser is stopping or an election is being forced. 10/3/2013 11:14:54 AM, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC). 10/3/2013 11:14:54 AM, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure. 10/3/2013 11:11:36 AM, Error: EventLog [6008] - The previous system shutdown at 11:08:44 AM on 10/3/2013 was unexpected. 10/3/2013 1:44:43 PM, Error: volsnap [14] - The shadow copies of volume C: were aborted because of an IO failure on volume C:. . ==== End Of File =========================== Thanks in advance for any help!
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.