Jump to content

PUP.Optional.OpenCandy folders have been found


Recommended Posts

Hi:

 

Malwarebytes has found the following folders on my Win Vista machine:

 

PUP.Optional.OpenCandy  (Folder)
PUP.Optional.OpenCandy  (Folder)
PUP.Optional.OpenCandy  (Folder)
PUP.Optional.FileScout.A   (Folder)

 

and they refuse to be deleted or renamed.

 

 

DDS.txt

-------------------------------------------------------------------------------------------

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16506  BrowserJavaVersion: 10.25.2
Run by Tom Young at 16:39:45 on 2013-10-03
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3326.1377 [GMT -7:00]
.
AV: Norton Security Suite *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Security Suite *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Security Suite *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\SLsvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Hawking\Control Center\Control Center.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Quicken\billmind.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\ContourStoryteller\ContourAutoplay.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\MyTomTom 3\MyTomTomSA.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\GameTracker\GSInGameService.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe
C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe
C:\Windows\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
C:\Windows\System32\calc.exe
C:\Program Files\Quicken\qw.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\TOMYOU~1\AppData\Local\Temp\nsnDE45.tmp\nsE5E4.tmp
C:\Users\TOMYOU~1\AppData\Local\Temp\nsnDE45.tmp\MBR.DAT
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.

uWindow Title = Windows Internet Explorer provided by Comcast

mWindow Title = Windows Internet Explorer provided by Comcast

BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\program files\norton security suite\engine\5.2.2.3\coieplg.dll
BHO: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - c:\program files\norton security suite\engine\5.2.2.3\ips\ipsbho.dll
BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\program files\norton security suite\engine\5.2.2.3\coieplg.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [spybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [QuickenBillminder] c:\program files\quicken\Billmind.exe -startup
uRun: [ContourCameraFinder] "c:\program files\contourstoryteller\ContourAutoplay.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [MyTomTomSA.exe] "c:\program files\mytomtom 3\MyTomTomSA.exe"
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Hawking UDS Control Center] c:\program files\hawking\control center\Control Center.exe -mini
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
dRun: [CtxfiReg] CTXFIREG.exe /FAIL2
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: mcafee.com
Trusted Zone: turbotax.com













TCP: NameServer = 192.168.2.1 192.168.2.1
TCP: Interfaces\{386A2D13-A973-42B1-ADFE-A2BE676694D7} : DHCPNameServer = 192.168.2.1 192.168.2.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
LSA: Authentication Packages =  msv1_0 relog_ap
LSA: Security Packages =  kerberos msv1_0 schannel wdigest tspkg
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\tom young\appdata\roaming\mozilla\firefox\profiles\k0kb9aew.default\

FF - prefs.js: browser.search.selectedEngine - appbario12 Customized Web Search


FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\amazon\mp3 downloader\npAmazonMP3DownloaderPlugin101752.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: c:\program files\ign\download manager\npfpdlm.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: c:\program files\nitro\reader 3\npdf.dll
FF - plugin: c:\program files\nitro\reader 3\npnitroie.dll
FF - plugin: c:\program files\nitro\reader 3\npnitromozilla.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\id software\quakelive\npquakezero.dll
FF - plugin: c:\users\tom young\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\tom young\appdata\roaming\move networks\plugins\npqmp071505000010.dll
FF - plugin: c:\users\tom young\appdata\roaming\move networks\plugins\npqmp071505000011.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_8_800_168.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
FF - ExtSQL: 2013-08-30 16:02; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\coFFPlgn_2011_7_13_2
FF - ExtSQL: 2013-08-31 08:26; {465fcfbb-47a4-4866-a5d5-d12f9a77da00}; c:\users\tom young\appdata\roaming\mozilla\firefox\profiles\k0kb9aew.default\extensions\{465fcfbb-47a4-4866-a5d5-d12f9a77da00}
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2013-09-30 13:59:36    40776    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2013-09-20 04:46:09    27152    ----a-w-    c:\windows\system32\nitrolocalmon2.dll
2013-09-20 04:46:09    18448    ----a-w-    c:\windows\system32\nitrolocalui2.dll
2013-09-20 04:46:01    --------    d-----w-    c:\program files\Nitro
2013-09-20 04:46:01    --------    d-----w-    c:\program files\common files\Nitro
2013-09-19 18:06:53    --------    d-----w-    c:\users\tom young\appdata\roaming\Downloaded Installations
2013-09-16 19:30:40    4806016    ----a-w-    c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
2013-09-16 19:30:40    4806016    ----a-w-    c:\program files\mozilla firefox\browser\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
2013-09-11 03:44:51    2049536    ----a-w-    c:\windows\system32\win32k.sys
2013-09-11 03:44:49    615936    ----a-w-    c:\windows\system32\themeui.dll
.
==================== Find3M  ====================
.
2013-09-20 13:57:06    71048    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-20 13:57:06    692616    ----a-w-    c:\windows\system32\FlashPlayerApp.exe
2013-08-02 04:09:35    1548288    ----a-w-    c:\windows\system32\WMVDECOD.DLL
2013-07-31 10:00:20    1800704    ----a-w-    c:\windows\system32\jscript9.dll
2013-07-31 09:52:44    1129472    ----a-w-    c:\windows\system32\wininet.dll
2013-07-31 09:52:34    1427968    ----a-w-    c:\windows\system32\inetcpl.cpl
2013-07-31 09:48:43    142848    ----a-w-    c:\windows\system32\ieUnatt.exe
2013-07-31 09:48:09    420864    ----a-w-    c:\windows\system32\vbscript.dll
2013-07-31 09:45:42    2382848    ----a-w-    c:\windows\system32\mshtml.tlb
2013-07-17 19:41:34    2048    ----a-w-    c:\windows\system32\tzres.dll
2013-07-10 09:47:00    783360    ----a-w-    c:\windows\system32\rpcrt4.dll
2013-07-09 12:10:36    1205168    ----a-w-    c:\windows\system32\ntdll.dll
2013-07-08 04:55:51    3603904    ----a-w-    c:\windows\system32\ntkrnlpa.exe
2013-07-08 04:55:51    3551680    ----a-w-    c:\windows\system32\ntoskrnl.exe
2013-07-08 04:20:04    172544    ----a-w-    c:\windows\system32\wintrust.dll
2013-07-08 04:16:55    98304    ----a-w-    c:\windows\system32\cryptnet.dll
2013-07-08 04:16:55    133120    ----a-w-    c:\windows\system32\cryptsvc.dll
2013-07-08 04:16:54    992768    ----a-w-    c:\windows\system32\crypt32.dll
.
============= FINISH: 16:40:06.69 ===============

 

 

 

 

 

Attach.txt

-------------------------------------------------------------------------------------------

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 4/12/2007 3:17:23 AM
System Uptime: 10/3/2013 11:10:58 AM (5 hours ago)
.
Motherboard: ECS  |  | Nettle
Processor: AMD Athlon 64 X2 Dual Core Processor 4800+ | Socket AM2  | 2500/201mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 290 GiB total, 192.584 GiB free.
D: is FIXED (NTFS) - 8 GiB total, 0.59 GiB free.
E: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (NTFS) - 128 GiB total, 74.59 GiB free.
K: is FIXED (NTFS) - 62 GiB total, 57.027 GiB free.
L: is FIXED (NTFS) - 279 GiB total, 240.082 GiB free.
M: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP2130: 10/3/2013 1:46:54 PM - Scheduled Checkpoint
.
==== Installed Programs ======================
.
Acrobat.com
ActiveCheck component for HP Active Support Library
Adobe AIR
Adobe Digital Editions
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.8)
Amazon MP3 Downloader 1.0.17
AmodGPSTracker
AnswerWorks 4.0 Runtime - English
AnswerWorks 5.0 English Runtime
Apple Application Support
ArcSoft PhotoStudio 5.5
ArcSoft Print Creations
ArcSoft Print Creations - Album Page
ArcSoft Print Creations - Funhouse
ArcSoft Print Creations - Greeting Card
ArcSoft Print Creations - Photo Book
ArcSoft Print Creations - Photo Calendar
ArcSoft Print Creations - Scrapbook
ArcSoft Print Creations - Slimline Card
AutoUpdate
Bonjour
Canon Auto Update Service
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon G.726 WMP-Decoder
Canon MOV Decoder
Canon MOV Encoder
Canon MovieEdit Task for ZoomBrowser EX
Canon MP Navigator EX 2.0
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX
Canon Utilities PhotoStitch
Canon Utilities Solution Menu
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
CanoScan LiDE 200 Scanner Driver
CCScore
CDDRV_Installer
CoffeeCup HTML Editor
CoffeeCup LockBox
Comcast High-Speed Internet Install Wizard
Comcast Rhapsody
Compatibility Pack for the 2007 Office system
Contour Storyteller
Creative Audio Control Panel
Creative Sound Blaster Properties
D3DX10
Desktop Doctor
DHTML Editing Component
DivX
Download Manager 2.3.6
Dropbox
Dual-Core Optimizer
Easy Picture2Icon 2.1
Enhanced Multimedia Keyboard Solution
EPSON Printer Software
Eraser 6.0.6.1376
erLT
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSPDock
ESSTOOLS
essvatgt
FileZilla Client 3.1.1.1
GameCenter
GameSpy Arcade
GameTracker Lite
GIMP 2.6.11
Google Earth
Google SketchUp 8
Google Update Helper
Hardware Diagnostic Tools
Hawking Control Center
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Active Support Library 32 bit components
HP Connections (remove only)
HP Customer Feedback
HP Easy Setup - Core
HP On-Screen Caps/Num/Scroll Lock Indicator
HP Photosmart Essential 2.01
HP Photosmart Essential2.01
HP Picasso Media Center Add-In
HPAsset component for HP Active Support Library
IGN Download Manager 2.3.2
iSEEK AnswerWorks English Runtime
Java 7 Update 25
Java Auto Updater
JavaFX 2.1.1
KhalInstallWrapper
Kodak EasyShare software
LG United Mobile Driver
LightScribe  1.4.136.1
Logitech SetPoint
Logitech Vid
Logitech Webcam Software
Logitech Webcam Software Driver Package
MagicTunePremium
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office File Validation Add-In
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Standard Edition 2003
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
MobileMe Control Panel
Move Media Player
Mozilla Firefox 24.0 (x86 en-US)
Mozilla Maintenance Service
MSN Money Investment Toolbox
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 5.0
My HP Games
MyTomTom 3.2.0.1220
netbrdg
Nitro Reader 3
Nolo's Encyclopedia of Everyday Law
Norton Security Suite
NVIDIA 3D Vision Controller Driver 314.22
NVIDIA Control Panel 314.22
NVIDIA Graphics Driver 314.22
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.12.1031
NVIDIA Update 1.12.12
NVIDIA Update Components
Octoshape add-in for Adobe Flash Player
OfotoXMI
OGA Notifier 2.0.0048.0
OpenAL
Paint.NET v3.5.11
PDF reDirect (remove only)
Ping Plotter Freeware
PowerDVD
PrimoPDF -- brought to you by Nitro PDF Software
Pro Cycling Manager - Season 2008 1.0.2.3
PSSWCORE
PunkBuster Services
PVSonyDll
Python 2.4.3
Quake III Arena
Quake III Arena Point Release 1.32
Quake Live Internet Explorer Plugin
Quake Live Mozilla Plugin
Quicken 2013
Quicken WillMaker Plus 2011
QuickTime
RealPlayer
Rhapsody
Rhapsody Player Engine
Rocket Arena 3 Upgrade 1.76 (remove only)
Roxio Creator Audio
Roxio Creator Basic v9
Roxio Creator Copy
Roxio Creator Data
Roxio Creator EasyArchive
Roxio Creator Tools
Roxio Express Labeler 3
Roxio MyDVD Basic v9
Seagate DiscWizard
SecureZIP for Windows 12.30.0016
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2832407)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Segoe UI
Seismovision 3 (remove only)
SFR
SHASTA
SketchUp Viewer
skin0001
SKINXSDK
Skype Click to Call
Skype™ 6.5
Soft Data Fax Modem with SmartCP
Sound Blaster X-Fi
Spybot - Search & Destroy
SSA Benefit Calculator
staticcr
swMSM
System Requirements Lab
TaxCut Premium + State + Efile 2008
Threewave 1.6
Turbo Lister 2
TurboCAD Deluxe 16
TurboCAD Designer 14
TurboCAD Designer 15
TurboCAD Designer 16
TurboCAD Symbols
TurboFLOORPLAN Home & Landscape Pro
TurboTax 2008
TurboTax 2008 wcaiper
TurboTax 2008 WinPerFedFormset
TurboTax 2008 WinPerProgramHelp
TurboTax 2008 WinPerReleaseEngine
TurboTax 2008 WinPerTaxSupport
TurboTax 2008 WinPerUserEducation
TurboTax 2008 wrapper
TurboTax 2009
TurboTax 2009 wcaiper
TurboTax 2009 WinPerFedFormset
TurboTax 2009 WinPerReleaseEngine
TurboTax 2009 WinPerTaxSupport
TurboTax 2009 wrapper
TurboTax 2010
TurboTax 2010 wcaiper
TurboTax 2010 WinPerFedFormset
TurboTax 2010 WinPerReleaseEngine
TurboTax 2010 WinPerTaxSupport
TurboTax 2010 wrapper
TurboTax 2011
TurboTax 2011 wcaiper
TurboTax 2011 WinPerFedFormset
TurboTax 2011 WinPerReleaseEngine
TurboTax 2011 WinPerTaxSupport
TurboTax 2011 wrapper
TurboTax 2012
TurboTax 2012 waliper
TurboTax 2012 waziper
TurboTax 2012 wcaiper
TurboTax 2012 wcoiper
TurboTax 2012 wctiper
TurboTax 2012 wdciper
TurboTax 2012 wdeiper
TurboTax 2012 wgaiper
TurboTax 2012 wiliper
TurboTax 2012 WinPerFedFormset
TurboTax 2012 WinPerReleaseEngine
TurboTax 2012 WinPerTaxSupport
TurboTax 2012 wlaiper
TurboTax 2012 wrapper
TurboTax Deluxe 2007
TurboTax Deluxe Deduction Maximizer 2006
TurboTax ItsDeductible 2006
Unity Web Player
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
VideoToolkit01
Virtual Earth 3D (Beta)
Visual Studio C++ 10.0 Runtime
Volume Panel
VPRINTOL
WexTech AnswerWorks
WinDirStat 1.1.2
Windows 7 Upgrade Advisor
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Media Player Firefox Plugin
WIRELESS
World of Padman
.
==== Event Viewer Messages From Past Week ========
.
9/26/2013 10:11:38 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TrkWks service.
9/26/2013 10:11:08 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SysMain service.
10/3/2013 7:18:49 AM, Error: bowser [8003]  - The master browser has received a server announcement from the computer DELL-BOX that believes that it is the master browser for the domain on transport NetBT_Tcpip_{386A2D13-A973-42B1-ADFE-A2BE67669. The master browser is stopping or an election is being forced.
10/3/2013 11:14:54 AM, Error: Service Control Manager [7038]  - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error:  Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
10/3/2013 11:14:54 AM, Error: Service Control Manager [7000]  - The NVIDIA Update Service Daemon service failed to start due to the following error:  The service did not start due to a logon failure.
10/3/2013 11:11:36 AM, Error: EventLog [6008]  - The previous system shutdown at 11:08:44 AM on 10/3/2013 was unexpected.
10/3/2013 1:44:43 PM, Error: volsnap [14]  - The shadow copies of volume C: were aborted because of an IO failure on volume C:.
.
==== End Of File ===========================

Thanks in advance for any help!
 

Link to post
Share on other sites

Welcome to the forum......try this:

Lets clean out any adware now: (this will require a reboot so save all your work)

Please download AdwCleaner by Xplode and save to your Desktop.

  • Double click on AdwCleaner.exe to run the tool.

    Vista/Windows 7/8 users right-click and select Run As Administrator

  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
  • Now click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Look over the log especially under Files/Folders for any program you want to save.
  • If there's a program you may want to save, just uncheck it from AdwCleaner.
  • If you're not sure, post the log for review. (all items found are adware/spyware/foistware)
  • If you're ready to clean it all up.....click the Clean button.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • Items that are deleted are moved to the Quarantine Folder: C:\AdwCleaner\Quarantine
  • To restore an item that has been deleted:
  • Go to Tools > Quarantine Manager > check what you want restored > now click on Restore.
Then..................

Open up Malwarebytes > Settings Tab > Scanner Settings > Under action for PUP > Select: Show in Results List and Check for removal.

Please Update and run a Quick Scan with Malwarebytes Anti-Malware, post the report.

Make sure that everything is checked, and click Remove Selected.

Please let me know how computer is running now, MrC

Link to post
Share on other sites

Hmmm... Well that was "interesting."

 

I had a bad feeling about AdwCleaner when it told me that it was ad supported and would try to load additional programs as part of the installation.  I went ahead anyway, declined the additional programs, (first one was some kind of game), but took comfort in the declaration that the programs could be removed in the usual fashion via Control Panel.  However, SpyBot flagged one item as malware, which I told it to block, and then let the install program run.  When that was done I immediately went to the control panel and deleted the 2 programs, but it was too late.  My browser had been hacked; home page was a new "search" site, default "search" has also been altered, and I was warned off any attempt to go to Google by the declaration the site was unsafe.  My PUP's had expanded from 4 to something like 55(!) and in attempting to remove them additional changes to the browser settings were made (proxy server, etc.).  After a lot of thrashing around here I've reduced the PUP's to 9 (original 4 plus additional "conduit" entries which came from AdwCleaner).

 

All in all that's quite disturbing.  Did I download the correct product?  Is any of what I described expected behavior?

Link to post
Share on other sites

Before running AdwCleaner I managed to reduce the PUP's to the original 4 that I started with:

 

PUP.Optional.OpenCandy  (Folder)
PUP.Optional.OpenCandy  (Folder)
PUP.Optional.OpenCandy  (Folder)
PUP.Optional.FileScout.A   (Folder)

 

AdwCleaner found the first and last folder, which I figured was OK as the middle two folders were located under the first folder and would go away with the first folder:  AdwCleaner also found 11 other Files/Folders which I elected to not delete - for the moment.

 

AdwCleaner[s0].txt

-------------------------------------------------------------------------------------------------------

 

# AdwCleaner v3.006 - Report created 07/10/2013 at 09:30:27
# Updated 01/10/2013 by Xplode
# Operating System : Windows Vista Home Premium Service Pack 2 (32 bits)
# Username : Tom Young - TOMYOUNGPC
# Running from : C:\Users\Tom Young\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

[x] Not Deleted : C:\ProgramData\Conduit
[x] Not Deleted : C:\Program Files\Conduit
[x] Not Deleted : C:\Users\Tom Young\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Tom Young\AppData\Roaming\file scout
Folder Deleted : C:\Users\Tom Young\AppData\Roaming\OpenCandy
[x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\PerformerSoft
[x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\CT3298566
[x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\CT3279411
[x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\Extensions\{1122b43d-30ee-403f-9bfa-3cc99b0caddd}
[x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\Extensions\{1122b43d-30ee-403f-9bfa-3cc99b0caddd}
[x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\Extensions\{465fcfbb-47a4-4866-a5d5-d12f9a77da00}
[x] Not Deleted : C:\Program Files\Mozilla Firefox\searchplugins\safesearch.xml
[x] Not Deleted : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\user.js

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\smartbar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\Tarma Installer
Key Deleted : HKLM\Software\TENCENT
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16506


-\\ Mozilla Firefox v24.0 (en-US)

[ File : C:\Users\Tom Young\AppData\Roaming\Mozilla\Firefox\Profiles\k0kb9aew.default\prefs.js ]

Line Deleted : user_pref("CT3279411.FF19Solved", "true");
Line Deleted : user_pref("CT3279411.UserID", "UN31874844020442146");
Line Deleted : user_pref("CT3279411.browser.search.defaultthis.engineName", "true");
Line Deleted : user_pref("CT3279411.fullUserID", "UN31874844020442146.IN.20130831082551");
Line Deleted : user_pref("CT3279411.installDate", "31/08/2013 08:26:27");
Line Deleted : user_pref("CT3279411.installSessionId", "{EAE31452-568B-4F4A-AB2B-FC0E8237587E}");
Line Deleted : user_pref("CT3279411.installSp", "TRUE");
Line Deleted : user_pref("CT3279411.installerVersion", "1.6.1.2");
Line Deleted : user_pref("CT3279411.keyword", "true");

Line Deleted : user_pref("CT3279411.originalSearchAddressUrl", "");
Line Deleted : user_pref("CT3279411.originalSearchEngine", "");
Line Deleted : user_pref("CT3279411.originalSearchEngineName", "");
Line Deleted : user_pref("CT3279411.searchRevert", "false");
Line Deleted : user_pref("CT3279411.searchUserMode", "2");
Line Deleted : user_pref("CT3279411.smartbar.homepage", "true");
Line Deleted : user_pref("CT3279411.versionFromInstaller", "10.19.2.5");
Line Deleted : user_pref("CT3279411.xpeMode", "0");
Line Deleted : user_pref("CT3298566.FF19Solved", "true");
Line Deleted : user_pref("CT3298566.UserID", "UN28866691762694183");
Line Deleted : user_pref("CT3298566.browser.search.defaultthis.engineName", "true");
Line Deleted : user_pref("CT3298566.fullUserID", "UN28866691762694183.IN.20131004055648");
Line Deleted : user_pref("CT3298566.installDate", "04/10/2013 05:56:53");
Line Deleted : user_pref("CT3298566.installSessionId", "{526C4219-A26C-4226-A5CC-AFEF01A4A1A9}");
Line Deleted : user_pref("CT3298566.installSp", "TRUE");
Line Deleted : user_pref("CT3298566.installerVersion", "1.7.1.7");
Line Deleted : user_pref("CT3298566.keyword", "true");


Line Deleted : user_pref("CT3298566.originalSearchEngine", "appbario12 Customized Web Search");
Line Deleted : user_pref("CT3298566.originalSearchEngineName", "appbario12 Customized Web Search");
Line Deleted : user_pref("CT3298566.searchRevert", "false");
Line Deleted : user_pref("CT3298566.searchUserMode", "2");
Line Deleted : user_pref("CT3298566.smartbar.homepage", "true");
Line Deleted : user_pref("CT3298566.versionFromInstaller", "10.20.1.8");
Line Deleted : user_pref("CT3298566.xpeMode", "0");


Line Deleted : user_pref("browser.search.defaultthis.engineName", "MixiDJ V30 Customized Web Search");


Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3298566");


Line Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3298566");
Line Deleted : user_pref("smartbar.homePageOwnerCTID", "CT3298566");
Line Deleted : user_pref("smartbar.machineId", "TQGAELERG/ZFC61CIRJIY0OB6GU88TK8U+Y3HFFROFHLGVVY5DEVZZYWPSGNUOELHL2O5/N2ZSYXLQK4TO2H5G");


*************************

AdwCleaner[R0].txt - [7997 octets] - [07/10/2013 09:18:39]
AdwCleaner[s0].txt - [8115 octets] - [07/10/2013 09:30:27]

########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [8175 octets] ##########

-------------------------------------------------------------------------------------------------------

 

Running Malwarebytes resulted in no items found.

-------------------------------------------------------------------------------------------------------

mbam-log-2013-10-07 (10-16-03)

 

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.10.07.08

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Tom Young :: TOMYOUNGPC [administrator]

10/7/2013 10:16:03 AM
mbam-log-2013-10-07 (10-16-03).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 281060
Time elapsed: 14 minute(s), 16 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
-------------------------------------------------------------------------------------------------------

 

Things seem to be working OK in the few minutes I've been using the computer.

 

Thank you for your help.

 

Link to post
Share on other sites

Well, things seem a little slow, but it's always difficult to asses that.  I didn't really focus on Registry entries like I should have so things are not working normally - I assume - because of deletions there, so I'll be working on reversing some of those deletions.  But the 4 PUPS are gone, and that's what I was really gunning for.

 

Thanks again.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.