Jump to content

987Bytes

Members
  • Posts

    5
  • Joined

  • Last visited

Posts posted by 987Bytes

  1. Before running AdwCleaner I managed to reduce the PUP's to the original 4 that I started with:

     

    PUP.Optional.OpenCandy  (Folder)
    PUP.Optional.OpenCandy  (Folder)
    PUP.Optional.OpenCandy  (Folder)
    PUP.Optional.FileScout.A   (Folder)

     

    AdwCleaner found the first and last folder, which I figured was OK as the middle two folders were located under the first folder and would go away with the first folder:  AdwCleaner also found 11 other Files/Folders which I elected to not delete - for the moment.

     

    AdwCleaner[s0].txt

    -------------------------------------------------------------------------------------------------------

     

    # AdwCleaner v3.006 - Report created 07/10/2013 at 09:30:27
    # Updated 01/10/2013 by Xplode
    # Operating System : Windows Vista Home Premium Service Pack 2 (32 bits)
    # Username : Tom Young - TOMYOUNGPC
    # Running from : C:\Users\Tom Young\Desktop\AdwCleaner.exe
    # Option : Clean

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    [x] Not Deleted : C:\ProgramData\Conduit
    [x] Not Deleted : C:\Program Files\Conduit
    [x] Not Deleted : C:\Users\Tom Young\AppData\LocalLow\Conduit
    Folder Deleted : C:\Users\Tom Young\AppData\Roaming\file scout
    Folder Deleted : C:\Users\Tom Young\AppData\Roaming\OpenCandy
    [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\PerformerSoft
    [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\CT3298566
    [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\CT3279411
    [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\Extensions\{1122b43d-30ee-403f-9bfa-3cc99b0caddd}
    [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\Extensions\{1122b43d-30ee-403f-9bfa-3cc99b0caddd}
    [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\Extensions\{465fcfbb-47a4-4866-a5d5-d12f9a77da00}
    [x] Not Deleted : C:\Program Files\Mozilla Firefox\searchplugins\safesearch.xml
    [x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\user.js

    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
    Key Deleted : HKCU\Software\Conduit
    Key Deleted : HKCU\Software\Softonic
    Key Deleted : HKCU\Software\YahooPartnerToolbar
    Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
    Key Deleted : HKCU\Software\AppDataLow\Software\smartbar
    Key Deleted : HKLM\Software\Conduit
    Key Deleted : HKLM\Software\Tarma Installer
    Key Deleted : HKLM\Software\TENCENT
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

    ***** [ Browsers ] *****

    -\\ Internet Explorer v9.0.8112.16506


    -\\ Mozilla Firefox v24.0 (en-US)

    [ File : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\prefs.js ]

    Line Deleted : user_pref("CT3279411.FF19Solved", "true");
    Line Deleted : user_pref("CT3279411.UserID", "UN31874844020442146");
    Line Deleted : user_pref("CT3279411.browser.search.defaultthis.engineName", "true");
    Line Deleted : user_pref("CT3279411.fullUserID", "UN31874844020442146.IN.20130831082551");
    Line Deleted : user_pref("CT3279411.installDate", "31/08/2013 08:26:27");
    Line Deleted : user_pref("CT3279411.installSessionId", "{EAE31452-568B-4F4A-AB2B-FC0E8237587E}");
    Line Deleted : user_pref("CT3279411.installSp", "TRUE");
    Line Deleted : user_pref("CT3279411.installerVersion", "1.6.1.2");
    Line Deleted : user_pref("CT3279411.keyword", "true");

    Line Deleted : user_pref("CT3279411.originalSearchAddressUrl", "");
    Line Deleted : user_pref("CT3279411.originalSearchEngine", "");
    Line Deleted : user_pref("CT3279411.originalSearchEngineName", "");
    Line Deleted : user_pref("CT3279411.searchRevert", "false");
    Line Deleted : user_pref("CT3279411.searchUserMode", "2");
    Line Deleted : user_pref("CT3279411.smartbar.homepage", "true");
    Line Deleted : user_pref("CT3279411.versionFromInstaller", "10.19.2.5");
    Line Deleted : user_pref("CT3279411.xpeMode", "0");
    Line Deleted : user_pref("CT3298566.FF19Solved", "true");
    Line Deleted : user_pref("CT3298566.UserID", "UN28866691762694183");
    Line Deleted : user_pref("CT3298566.browser.search.defaultthis.engineName", "true");
    Line Deleted : user_pref("CT3298566.fullUserID", "UN28866691762694183.IN.20131004055648");
    Line Deleted : user_pref("CT3298566.installDate", "04/10/2013 05:56:53");
    Line Deleted : user_pref("CT3298566.installSessionId", "{526C4219-A26C-4226-A5CC-AFEF01A4A1A9}");
    Line Deleted : user_pref("CT3298566.installSp", "TRUE");
    Line Deleted : user_pref("CT3298566.installerVersion", "1.7.1.7");
    Line Deleted : user_pref("CT3298566.keyword", "true");


    Line Deleted : user_pref("CT3298566.originalSearchEngine", "appbario12 Customized Web Search");
    Line Deleted : user_pref("CT3298566.originalSearchEngineName", "appbario12 Customized Web Search");
    Line Deleted : user_pref("CT3298566.searchRevert", "false");
    Line Deleted : user_pref("CT3298566.searchUserMode", "2");
    Line Deleted : user_pref("CT3298566.smartbar.homepage", "true");
    Line Deleted : user_pref("CT3298566.versionFromInstaller", "10.20.1.8");
    Line Deleted : user_pref("CT3298566.xpeMode", "0");


    Line Deleted : user_pref("browser.search.defaultthis.engineName", "MixiDJ V30 Customized Web Search");


    Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3298566");


    Line Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3298566");
    Line Deleted : user_pref("smartbar.homePageOwnerCTID", "CT3298566");
    Line Deleted : user_pref("smartbar.machineId", "TQGAELERG/ZFC61CIRJIY0OB6GU88TK8U+Y3HFFROFHLGVVY5DEVZZYWPSGNUOELHL2O5/N2ZSYXLQK4TO2H5G");


    *************************

    AdwCleaner[R0].txt - [7997 octets] - [07/10/2013 09:18:39]
    AdwCleaner[s0].txt - [8115 octets] - [07/10/2013 09:30:27]

    ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [8175 octets] ##########

    -------------------------------------------------------------------------------------------------------

     

    Running Malwarebytes resulted in no items found.

    -------------------------------------------------------------------------------------------------------

    mbam-log-2013-10-07 (10-16-03)

     

    Malwarebytes Anti-Malware 1.75.0.1300
    www.malwarebytes.org

    Database version: v2013.10.07.08

    Windows Vista Service Pack 2 x86 NTFS
    Internet Explorer 9.0.8112.16421
    Tom Young :: TOMYOUNGPC [administrator]

    10/7/2013 10:16:03 AM
    mbam-log-2013-10-07 (10-16-03).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 281060
    Time elapsed: 14 minute(s), 16 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
    -------------------------------------------------------------------------------------------------------

     

    Things seem to be working OK in the few minutes I've been using the computer.

     

    Thank you for your help.

     

  2. Hmmm... Well that was "interesting."

     

    I had a bad feeling about AdwCleaner when it told me that it was ad supported and would try to load additional programs as part of the installation.  I went ahead anyway, declined the additional programs, (first one was some kind of game), but took comfort in the declaration that the programs could be removed in the usual fashion via Control Panel.  However, SpyBot flagged one item as malware, which I told it to block, and then let the install program run.  When that was done I immediately went to the control panel and deleted the 2 programs, but it was too late.  My browser had been hacked; home page was a new "search" site, default "search" has also been altered, and I was warned off any attempt to go to Google by the declaration the site was unsafe.  My PUP's had expanded from 4 to something like 55(!) and in attempting to remove them additional changes to the browser settings were made (proxy server, etc.).  After a lot of thrashing around here I've reduced the PUP's to 9 (original 4 plus additional "conduit" entries which came from AdwCleaner).

     

    All in all that's quite disturbing.  Did I download the correct product?  Is any of what I described expected behavior?

  3. Hi:

     

    Malwarebytes has found the following folders on my Win Vista machine:

     

    PUP.Optional.OpenCandy  (Folder)
    PUP.Optional.OpenCandy  (Folder)
    PUP.Optional.OpenCandy  (Folder)
    PUP.Optional.FileScout.A   (Folder)

     

    and they refuse to be deleted or renamed.

     

     

    DDS.txt

    -------------------------------------------------------------------------------------------

    DDS (Ver_2012-11-20.01) - NTFS_x86
    Internet Explorer: 9.0.8112.16506  BrowserJavaVersion: 10.25.2
    Run by Tom Young at 16:39:45 on 2013-10-03
    Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3326.1377 [GMT -7:00]
    .
    AV: Norton Security Suite *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: Norton Security Suite *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
    FW: Norton Security Suite *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
    .
    ============== Running Processes ================
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Program Files\Creative\Shared Files\CTAudSvc.exe
    C:\Windows\system32\SLsvc.exe
    C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Hawking\Control Center\Control Center.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Quicken\billmind.exe
    C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
    C:\Program Files\ContourStoryteller\ContourAutoplay.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\MyTomTom 3\MyTomTomSA.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\GameTracker\GSInGameService.exe
    c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe
    C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe
    C:\Windows\system32\PnkBstrA.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
    C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Windows\System32\WUDFHost.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
    C:\Windows\System32\calc.exe
    C:\Program Files\Quicken\qw.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Users\TOMYOU~1\AppData\Local\Temp\nsnDE45.tmp\nsE5E4.tmp
    C:\Users\TOMYOU~1\AppData\Local\Temp\nsnDE45.tmp\MBR.DAT
    C:\Windows\system32\Taskmgr.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    .
    ============== Pseudo HJT Report ===============
    .

    uWindow Title = Windows Internet Explorer provided by Comcast

    mWindow Title = Windows Internet Explorer provided by Comcast

    BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    BHO: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\program files\norton security suite\engine\5.2.2.3\coieplg.dll
    BHO: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - c:\program files\norton security suite\engine\5.2.2.3\ips\ipsbho.dll
    BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
    BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
    TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\program files\norton security suite\engine\5.2.2.3\coieplg.dll
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [spybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [QuickenBillminder] c:\program files\quicken\Billmind.exe -startup
    uRun: [ContourCameraFinder] "c:\program files\contourstoryteller\ContourAutoplay.exe"
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    uRun: [MyTomTomSA.exe] "c:\program files\mytomtom 3\MyTomTomSA.exe"
    mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [Hawking UDS Control Center] c:\program files\hawking\control center\Control Center.exe -mini
    mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
    dRun: [CtxfiReg] CTXFIREG.exe /FAIL2
    uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
    mPolicies-System: EnableLUA = dword:0
    mPolicies-System: EnableUIADesktopToggle = dword:0
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    Trusted Zone: internet
    Trusted Zone: mcafee.com
    Trusted Zone: mcafee.com
    Trusted Zone: turbotax.com













    TCP: NameServer = 192.168.2.1 192.168.2.1
    TCP: Interfaces\{386A2D13-A973-42B1-ADFE-A2BE676694D7} : DHCPNameServer = 192.168.2.1 192.168.2.1
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
    LSA: Authentication Packages =  msv1_0 relog_ap
    LSA: Security Packages =  kerberos msv1_0 schannel wdigest tspkg
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\users\tom young\appdata\roaming\mozilla\firefox\profiles\k0kb9aew.default\

    FF - prefs.js: browser.search.selectedEngine - appbario12 Customized Web Search


    FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
    FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
    FF - plugin: c:\program files\amazon\mp3 downloader\npAmazonMP3DownloaderPlugin101752.dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\update\1.3.21.153\npGoogleUpdate3.dll
    FF - plugin: c:\program files\ign\download manager\npfpdlm.dll
    FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
    FF - plugin: c:\program files\microsoft silverlight\5.1.20513.0\npctrlui.dll
    FF - plugin: c:\program files\nitro\reader 3\npdf.dll
    FF - plugin: c:\program files\nitro\reader 3\npnitroie.dll
    FF - plugin: c:\program files\nitro\reader 3\npnitromozilla.dll
    FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\programdata\id software\quakelive\npquakezero.dll
    FF - plugin: c:\users\tom young\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
    FF - plugin: c:\users\tom young\appdata\roaming\move networks\plugins\npqmp071505000010.dll
    FF - plugin: c:\users\tom young\appdata\roaming\move networks\plugins\npqmp071505000011.dll
    FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_8_800_168.dll
    FF - plugin: c:\windows\system32\npDeployJava1.dll
    FF - plugin: c:\windows\system32\npmproxy.dll
    FF - ExtSQL: 2013-08-30 16:02; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\coFFPlgn_2011_7_13_2
    FF - ExtSQL: 2013-08-31 08:26; {465fcfbb-47a4-4866-a5d5-d12f9a77da00}; c:\users\tom young\appdata\roaming\mozilla\firefox\profiles\k0kb9aew.default\extensions\{465fcfbb-47a4-4866-a5d5-d12f9a77da00}
    .
    ============= SERVICES / DRIVERS ===============
    .
    .
    =============== Created Last 30 ================
    .
    2013-09-30 13:59:36    40776    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
    2013-09-20 04:46:09    27152    ----a-w-    c:\windows\system32\nitrolocalmon2.dll
    2013-09-20 04:46:09    18448    ----a-w-    c:\windows\system32\nitrolocalui2.dll
    2013-09-20 04:46:01    --------    d-----w-    c:\program files\Nitro
    2013-09-20 04:46:01    --------    d-----w-    c:\program files\common files\Nitro
    2013-09-19 18:06:53    --------    d-----w-    c:\users\tom young\appdata\roaming\Downloaded Installations
    2013-09-16 19:30:40    4806016    ----a-w-    c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
    2013-09-16 19:30:40    4806016    ----a-w-    c:\program files\mozilla firefox\browser\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
    2013-09-11 03:44:51    2049536    ----a-w-    c:\windows\system32\win32k.sys
    2013-09-11 03:44:49    615936    ----a-w-    c:\windows\system32\themeui.dll
    .
    ==================== Find3M  ====================
    .
    2013-09-20 13:57:06    71048    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
    2013-09-20 13:57:06    692616    ----a-w-    c:\windows\system32\FlashPlayerApp.exe
    2013-08-02 04:09:35    1548288    ----a-w-    c:\windows\system32\WMVDECOD.DLL
    2013-07-31 10:00:20    1800704    ----a-w-    c:\windows\system32\jscript9.dll
    2013-07-31 09:52:44    1129472    ----a-w-    c:\windows\system32\wininet.dll
    2013-07-31 09:52:34    1427968    ----a-w-    c:\windows\system32\inetcpl.cpl
    2013-07-31 09:48:43    142848    ----a-w-    c:\windows\system32\ieUnatt.exe
    2013-07-31 09:48:09    420864    ----a-w-    c:\windows\system32\vbscript.dll
    2013-07-31 09:45:42    2382848    ----a-w-    c:\windows\system32\mshtml.tlb
    2013-07-17 19:41:34    2048    ----a-w-    c:\windows\system32\tzres.dll
    2013-07-10 09:47:00    783360    ----a-w-    c:\windows\system32\rpcrt4.dll
    2013-07-09 12:10:36    1205168    ----a-w-    c:\windows\system32\ntdll.dll
    2013-07-08 04:55:51    3603904    ----a-w-    c:\windows\system32\ntkrnlpa.exe
    2013-07-08 04:55:51    3551680    ----a-w-    c:\windows\system32\ntoskrnl.exe
    2013-07-08 04:20:04    172544    ----a-w-    c:\windows\system32\wintrust.dll
    2013-07-08 04:16:55    98304    ----a-w-    c:\windows\system32\cryptnet.dll
    2013-07-08 04:16:55    133120    ----a-w-    c:\windows\system32\cryptsvc.dll
    2013-07-08 04:16:54    992768    ----a-w-    c:\windows\system32\crypt32.dll
    .
    ============= FINISH: 16:40:06.69 ===============

     

     

     

     

     

    Attach.txt

    -------------------------------------------------------------------------------------------

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-11-20.01)
    .
    Microsoft® Windows Vista™ Home Premium
    Boot Device: \Device\HarddiskVolume3
    Install Date: 4/12/2007 3:17:23 AM
    System Uptime: 10/3/2013 11:10:58 AM (5 hours ago)
    .
    Motherboard: ECS  |  | Nettle
    Processor: AMD Athlon 64 X2 Dual Core Processor 4800+ | Socket AM2  | 2500/201mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 290 GiB total, 192.584 GiB free.
    D: is FIXED (NTFS) - 8 GiB total, 0.59 GiB free.
    E: is CDROM ()
    G: is Removable
    H: is Removable
    I: is Removable
    J: is FIXED (NTFS) - 128 GiB total, 74.59 GiB free.
    K: is FIXED (NTFS) - 62 GiB total, 57.027 GiB free.
    L: is FIXED (NTFS) - 279 GiB total, 240.082 GiB free.
    M: is Removable
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP2130: 10/3/2013 1:46:54 PM - Scheduled Checkpoint
    .
    ==== Installed Programs ======================
    .
    Acrobat.com
    ActiveCheck component for HP Active Support Library
    Adobe AIR
    Adobe Digital Editions
    Adobe Flash Player 11 ActiveX
    Adobe Flash Player 11 Plugin
    Adobe Reader X (10.1.8)
    Amazon MP3 Downloader 1.0.17
    AmodGPSTracker
    AnswerWorks 4.0 Runtime - English
    AnswerWorks 5.0 English Runtime
    Apple Application Support
    ArcSoft PhotoStudio 5.5
    ArcSoft Print Creations
    ArcSoft Print Creations - Album Page
    ArcSoft Print Creations - Funhouse
    ArcSoft Print Creations - Greeting Card
    ArcSoft Print Creations - Photo Book
    ArcSoft Print Creations - Photo Calendar
    ArcSoft Print Creations - Scrapbook
    ArcSoft Print Creations - Slimline Card
    AutoUpdate
    Bonjour
    Canon Auto Update Service
    Canon Camera Window DC_DV 6 for ZoomBrowser EX
    Canon G.726 WMP-Decoder
    Canon MOV Decoder
    Canon MOV Encoder
    Canon MovieEdit Task for ZoomBrowser EX
    Canon MP Navigator EX 2.0
    Canon RAW Image Task for ZoomBrowser EX
    Canon RemoteCapture Task for ZoomBrowser EX
    Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX
    Canon Utilities PhotoStitch
    Canon Utilities Solution Menu
    Canon Utilities ZoomBrowser EX
    Canon ZoomBrowser EX Memory Card Utility
    CanoScan LiDE 200 Scanner Driver
    CCScore
    CDDRV_Installer
    CoffeeCup HTML Editor
    CoffeeCup LockBox
    Comcast High-Speed Internet Install Wizard
    Comcast Rhapsody
    Compatibility Pack for the 2007 Office system
    Contour Storyteller
    Creative Audio Control Panel
    Creative Sound Blaster Properties
    D3DX10
    Desktop Doctor
    DHTML Editing Component
    DivX
    Download Manager 2.3.6
    Dropbox
    Dual-Core Optimizer
    Easy Picture2Icon 2.1
    Enhanced Multimedia Keyboard Solution
    EPSON Printer Software
    Eraser 6.0.6.1376
    erLT
    ESSBrwr
    ESSCDBK
    ESScore
    ESSgui
    ESSini
    ESSPCD
    ESSPDock
    ESSTOOLS
    essvatgt
    FileZilla Client 3.1.1.1
    GameCenter
    GameSpy Arcade
    GameTracker Lite
    GIMP 2.6.11
    Google Earth
    Google SketchUp 8
    Google Update Helper
    Hardware Diagnostic Tools
    Hawking Control Center
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    HP Active Support Library
    HP Active Support Library 32 bit components
    HP Connections (remove only)
    HP Customer Feedback
    HP Easy Setup - Core
    HP On-Screen Caps/Num/Scroll Lock Indicator
    HP Photosmart Essential 2.01
    HP Photosmart Essential2.01
    HP Picasso Media Center Add-In
    HPAsset component for HP Active Support Library
    IGN Download Manager 2.3.2
    iSEEK AnswerWorks English Runtime
    Java 7 Update 25
    Java Auto Updater
    JavaFX 2.1.1
    KhalInstallWrapper
    Kodak EasyShare software
    LG United Mobile Driver
    LightScribe  1.4.136.1
    Logitech SetPoint
    Logitech Vid
    Logitech Webcam Software
    Logitech Webcam Software Driver Package
    MagicTunePremium
    Malwarebytes Anti-Malware version 1.75.0.1300
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 4 Client Profile
    Microsoft Application Error Reporting
    Microsoft Office File Validation Add-In
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Standard Edition 2003
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Works
    MobileMe Control Panel
    Move Media Player
    Mozilla Firefox 24.0 (x86 en-US)
    Mozilla Maintenance Service
    MSN Money Investment Toolbox
    MSVCRT
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB941833)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    muvee autoProducer 5.0
    My HP Games
    MyTomTom 3.2.0.1220
    netbrdg
    Nitro Reader 3
    Nolo's Encyclopedia of Everyday Law
    Norton Security Suite
    NVIDIA 3D Vision Controller Driver 314.22
    NVIDIA Control Panel 314.22
    NVIDIA Graphics Driver 314.22
    NVIDIA Install Application
    NVIDIA PhysX
    NVIDIA PhysX System Software 9.12.1031
    NVIDIA Update 1.12.12
    NVIDIA Update Components
    Octoshape add-in for Adobe Flash Player
    OfotoXMI
    OGA Notifier 2.0.0048.0
    OpenAL
    Paint.NET v3.5.11
    PDF reDirect (remove only)
    Ping Plotter Freeware
    PowerDVD
    PrimoPDF -- brought to you by Nitro PDF Software
    Pro Cycling Manager - Season 2008 1.0.2.3
    PSSWCORE
    PunkBuster Services
    PVSonyDll
    Python 2.4.3
    Quake III Arena
    Quake III Arena Point Release 1.32
    Quake Live Internet Explorer Plugin
    Quake Live Mozilla Plugin
    Quicken 2013
    Quicken WillMaker Plus 2011
    QuickTime
    RealPlayer
    Rhapsody
    Rhapsody Player Engine
    Rocket Arena 3 Upgrade 1.76 (remove only)
    Roxio Creator Audio
    Roxio Creator Basic v9
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator EasyArchive
    Roxio Creator Tools
    Roxio Express Labeler 3
    Roxio MyDVD Basic v9
    Seagate DiscWizard
    SecureZIP for Windows 12.30.0016
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2832407)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
    Segoe UI
    Seismovision 3 (remove only)
    SFR
    SHASTA
    SketchUp Viewer
    skin0001
    SKINXSDK
    Skype Click to Call
    Skype™ 6.5
    Soft Data Fax Modem with SmartCP
    Sound Blaster X-Fi
    Spybot - Search & Destroy
    SSA Benefit Calculator
    staticcr
    swMSM
    System Requirements Lab
    TaxCut Premium + State + Efile 2008
    Threewave 1.6
    Turbo Lister 2
    TurboCAD Deluxe 16
    TurboCAD Designer 14
    TurboCAD Designer 15
    TurboCAD Designer 16
    TurboCAD Symbols
    TurboFLOORPLAN Home & Landscape Pro
    TurboTax 2008
    TurboTax 2008 wcaiper
    TurboTax 2008 WinPerFedFormset
    TurboTax 2008 WinPerProgramHelp
    TurboTax 2008 WinPerReleaseEngine
    TurboTax 2008 WinPerTaxSupport
    TurboTax 2008 WinPerUserEducation
    TurboTax 2008 wrapper
    TurboTax 2009
    TurboTax 2009 wcaiper
    TurboTax 2009 WinPerFedFormset
    TurboTax 2009 WinPerReleaseEngine
    TurboTax 2009 WinPerTaxSupport
    TurboTax 2009 wrapper
    TurboTax 2010
    TurboTax 2010 wcaiper
    TurboTax 2010 WinPerFedFormset
    TurboTax 2010 WinPerReleaseEngine
    TurboTax 2010 WinPerTaxSupport
    TurboTax 2010 wrapper
    TurboTax 2011
    TurboTax 2011 wcaiper
    TurboTax 2011 WinPerFedFormset
    TurboTax 2011 WinPerReleaseEngine
    TurboTax 2011 WinPerTaxSupport
    TurboTax 2011 wrapper
    TurboTax 2012
    TurboTax 2012 waliper
    TurboTax 2012 waziper
    TurboTax 2012 wcaiper
    TurboTax 2012 wcoiper
    TurboTax 2012 wctiper
    TurboTax 2012 wdciper
    TurboTax 2012 wdeiper
    TurboTax 2012 wgaiper
    TurboTax 2012 wiliper
    TurboTax 2012 WinPerFedFormset
    TurboTax 2012 WinPerReleaseEngine
    TurboTax 2012 WinPerTaxSupport
    TurboTax 2012 wlaiper
    TurboTax 2012 wrapper
    TurboTax Deluxe 2007
    TurboTax Deluxe Deduction Maximizer 2006
    TurboTax ItsDeductible 2006
    Unity Web Player
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    VideoToolkit01
    Virtual Earth 3D (Beta)
    Visual Studio C++ 10.0 Runtime
    Volume Panel
    VPRINTOL
    WexTech AnswerWorks
    WinDirStat 1.1.2
    Windows 7 Upgrade Advisor
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live ID Sign-in Assistant
    Windows Live Installer
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live Sync
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Media Player Firefox Plugin
    WIRELESS
    World of Padman
    .
    ==== Event Viewer Messages From Past Week ========
    .
    9/26/2013 10:11:38 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TrkWks service.
    9/26/2013 10:11:08 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SysMain service.
    10/3/2013 7:18:49 AM, Error: bowser [8003]  - The master browser has received a server announcement from the computer DELL-BOX that believes that it is the master browser for the domain on transport NetBT_Tcpip_{386A2D13-A973-42B1-ADFE-A2BE67669. The master browser is stopping or an election is being forced.
    10/3/2013 11:14:54 AM, Error: Service Control Manager [7038]  - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error:  Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
    10/3/2013 11:14:54 AM, Error: Service Control Manager [7000]  - The NVIDIA Update Service Daemon service failed to start due to the following error:  The service did not start due to a logon failure.
    10/3/2013 11:11:36 AM, Error: EventLog [6008]  - The previous system shutdown at 11:08:44 AM on 10/3/2013 was unexpected.
    10/3/2013 1:44:43 PM, Error: volsnap [14]  - The shadow copies of volume C: were aborted because of an IO failure on volume C:.
    .
    ==== End Of File ===========================

    Thanks in advance for any help!
     

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.