Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

reCaptcha (including this website's) does not display on my PC


  • This topic is locked This topic is locked
9 replies to this topic

#1 JimBobWay

JimBobWay

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:03:14 AM

Posted 14 May 2013 - 11:11 PM

reCaptcha does not work on my computer. That includes the verification process you use for registration. In the case of the Bleeping Computer registration form, the box with the question, was displayed, but the registration form kept saying the answer I gave was wrong. I have also had this situation on other web sights, where I answer correctly, but the form says I answered wrong. A few web pages have a verification mechanism that works for me, but they are pages using their own "in house" verification, or some other type that is seldom seen elsewhere. My usual problem is that the trade mark "reCaptcha" box will not be displayed at all. The "Brand Name reCaptcha" never appears. I will only see this :

Captcha*      (and nothing else displayed next to, or directly under this).

 

or nothing at all.

 

The other worrysome symptom, is some web registrations ask what password to use. I enter a password and the form throws an error with something like "The Password must contain a minimum of eight characters". No matter what I enter, letters, numbers, or combination, all eight or more characters, the error repeats, and no password is ever approved.

I am using "Genuine" (legal, registered) Windows 8 (32bit) with all recent updates. Mozilla Firefox 19.02 with add-ons, Ghostery 2.9.3 - Google Disconnect 2.4.2 - Redirect Cleaner 2.1.1.

Java RTE and Java script are enabled.

 

DDS.txt:

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 10.0.9200.16537  BrowserJavaVersion: 10.21.2
Run by jim at 21:47:50 on 2013-05-14
Microsoft Windows 8 Pro with Media Center  6.2.9200.0.1252.1.1033.18.3002.2039 [GMT -6:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: COMODO Antivirus *Enabled/Updated* {B74CC7D2-B407-E1DC-1033-DD315BCDC8C8}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: COMODO Antivirus *Enabled/Updated* {0C2D2636-923D-EE52-2A83-E643204A8275}
.
============== Running Processes ================
.
C:\WINDOWS\system32\wininit.exe
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\System32\spoolsv.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Program Files\Comodo\Dragon\dragon_updater.exe
C:\WINDOWS\system32\dashost.exe
C:\WINDOWS\system32\taskhostex.exe
C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x86__8wekyb3d8bbwe\LiveComm.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Browny02\BrYNSvc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\COMODO\COMODO Internet Security\cis.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\system32\conhost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [Shotty] c:\program files\shotty\Shotty.exe
mRun: [Logitech Download Assistant] c:\windows\system32\rundll32.exe c:\windows\system32\LogiLDA.dll,LogiFetch
mRun: [BrStsMon00] c:\program files\browny02\brother\BrStMonW.exe /AUTORUN
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Everything] "c:\program files\everything\Everything.exe" -startup
TCP: NameServer = 192.168.0.5
TCP: Interfaces\{7E55D283-6EA4-4411-B57D-EA8322E426D4} : DHCPNameServer = 192.168.0.5
TCP: Interfaces\{7E55D283-6EA4-4411-B57D-EA8322E426D4}\E6566756273757D6D6562723 : DHCPNameServer = 192.168.0.1
SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jim\appdata\roaming\mozilla\firefox\profiles\07faiqyz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.solarham.net/planetk.htm
FF - plugin: c:\program files\emusic download manager 6\npEMusic603.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_6_602_180.dll
.
============= SERVICES / DRIVERS ===============
.
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2012-12-14 20072]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2012-12-14 591200]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=c:\windows\system32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2013-05-06 00:56:12    --------    d-----w-    c:\program files\LinuxLive USB Creator
2013-05-05 03:14:40    --------    d-----w-    c:\users\jim\appdata\roaming\TeraCopy
2013-05-01 16:15:07    --------    d-----w-    c:\users\jim\appdata\local\ElevatedDiagnostics
2013-04-28 18:40:42    --------    d-----w-    c:\program files\TeraCopy
2013-04-28 18:40:33    --------    d-----w-    c:\program files\Everything
2013-04-19 19:24:57    --------    d-----w-    c:\users\jim\appdata\local\eMusic
2013-04-19 19:24:41    --------    d-----w-    c:\program files\eMusic Download Manager 6
2013-04-19 15:05:57    94112    ----a-w-    c:\windows\system32\WindowsAccessBridge.dll
2013-04-18 16:43:59    550912    ----a-w-    c:\windows\system32\drvstore.dll
.
==================== Find3M  ====================
.
2013-04-23 14:04:10    348048    ----a-w-    c:\windows\system32\guard32.dll
2013-04-19 19:04:26    47368    ----a-w-    c:\windows\system32\certsentry.dll
2013-04-15 17:38:54    32896    ----a-w-    c:\windows\system32\drivers\cmdhlp.sys
2013-04-15 17:38:53    591200    ----a-w-    c:\windows\system32\drivers\cmdguard.sys
2013-04-15 17:38:53    20072    ----a-w-    c:\windows\system32\drivers\cmderd.sys
2013-04-15 17:38:37    35488    ----a-w-    c:\windows\system32\cmdcsr.dll
2013-04-15 17:38:25    276688    ----a-w-    c:\windows\system32\cmdvrt32.dll
2013-04-15 17:38:24    40656    ----a-w-    c:\windows\system32\cmdkbd32.dll
2013-04-02 22:08:01    78176    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
2013-04-02 22:08:01    692576    ----a-w-    c:\windows\system32\FlashPlayerApp.exe
2013-03-19 22:20:35    3393536    ----a-w-    c:\windows\system32\win32k.sys
2013-03-07 17:04:02    861088    ----a-w-    c:\windows\system32\npDeployJava1.dll
2013-03-07 17:04:02    782240    ----a-w-    c:\windows\system32\deployJava1.dll
2013-03-07 04:47:06    5575400    ----a-w-    c:\windows\system32\ntoskrnl.exe
2013-03-02 09:54:25    158952    ----a-w-    c:\windows\system32\drivers\sdbus.sys
2013-03-02 09:54:25    121576    ----a-w-    c:\windows\system32\drivers\tpm.sys
2013-03-02 09:54:20    104168    ----a-w-    c:\windows\system32\drivers\dumpsd.sys
2013-03-02 09:51:33    368360    ----a-w-    c:\windows\system32\drivers\vhdmp.sys
2013-03-02 09:21:20    271080    ----a-w-    c:\windows\system32\drivers\FWPKCLNT.SYS
2013-03-02 09:21:20    1802472    ----a-w-    c:\windows\system32\drivers\tcpip.sys
2013-03-02 09:06:16    57576    ----a-w-    c:\windows\system32\drivers\pdc.sys
2013-03-02 09:06:12    298728    ----a-w-    c:\windows\system32\drivers\Classpnp.sys
2013-03-02 08:52:49    268008    ----a-w-    c:\windows\system32\drivers\USBXHCI.SYS
2013-03-02 08:52:47    66280    ----a-w-    c:\windows\system32\drivers\storahci.sys
2013-03-02 08:52:47    302824    ----a-w-    c:\windows\system32\drivers\storport.sys
2013-03-02 08:52:47    237800    ----a-w-    c:\windows\system32\drivers\spaceport.sys
2013-03-02 08:24:08    34304    ----a-w-    c:\windows\system32\wuapp.exe
2013-03-02 08:24:03    53760    ----a-w-    c:\windows\system32\taskhostex.exe
2013-03-02 08:22:36    94208    ----a-w-    c:\windows\system32\NdisImPlatform.dll
2013-03-02 08:22:36    357888    ----a-w-    c:\windows\system32\netcfgx.dll
2013-03-02 08:22:32    5091840    ----a-w-    c:\windows\system32\mstscax.dll
2013-03-02 08:22:18    361984    ----a-w-    c:\windows\system32\MFMediaEngine.dll
2013-03-02 08:22:17    898048    ----a-w-    c:\windows\system32\mcmde.dll
2013-03-02 08:22:17    850944    ----a-w-    c:\windows\system32\mfasfsrcsnk.dll
2013-03-02 08:21:54    120832    ----a-w-    c:\windows\system32\discan.dll
2013-03-02 08:21:52    36352    ----a-w-    c:\windows\system32\DevDispItemProvider.dll
2013-03-02 08:21:43    1502720    ----a-w-    c:\windows\system32\wbem\cimwin32.dll
2013-03-02 08:21:40    309760    ----a-w-    c:\windows\system32\BCP47Langs.dll
2013-03-02 08:21:39    2033664    ----a-w-    c:\windows\system32\authui.dll
2013-03-02 08:21:32    145408    ----a-w-    c:\windows\system32\powercfg.cpl
2013-03-02 07:18:13    20992    ----a-w-    c:\windows\system32\drivers\mouhid.sys
2013-03-02 07:15:13    24064    ----a-w-    c:\windows\system32\drivers\monitor.sys
2013-02-21 10:30:16    1766912    ----a-w-    c:\windows\system32\wininet.dll
2013-02-21 10:30:12    661504    ----a-w-    c:\windows\system32\uxtheme.dll
2013-02-21 10:29:39    2877440    ----a-w-    c:\windows\system32\jscript9.dll
2013-02-21 10:29:37    61440    ----a-w-    c:\windows\system32\iesetup.dll
2013-02-21 10:29:37    109056    ----a-w-    c:\windows\system32\iesysprep.dll
2013-02-15 06:35:40    444416    ----a-w-    c:\windows\apppatch\AcSpecfc.dll
.
============= FINISH: 21:49:55.93 ===============
 

 

 

Attached Files



BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 40,510 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:14 AM

Posted 18 May 2013 - 09:59 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.
===

--RogueKiller--
  • Download & SAVE to your Desktop RogueKiller for 32bit or Roguekiller for 64bit
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7, right-click and select "Run as Administrator to start"
  • For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • click on "delete"
  • Wait until the Status box shows "Deleting Finished"
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Exit/Close RogueKiller+
  • ===

    Third party programs if not up to date can be the cause of infiltration an infection.

    Please run this security check for my review.

    Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
  • ===

    Search and delete the AdWare, PUP (Potentially Unwanted Program) installed on your computer.

    Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete tab follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Rn].txt (n is a number).

  • Please paste the logs in your next reply, DO NOT ATTACH THEM
    Let me know what problem persists.


#3 JimBobWay

JimBobWay
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:03:14 AM

Posted 19 May 2013 - 03:03 PM

Thank you,

I downloaded the three utilities and ran them as directed in the above instructions. The only glitch was that in Windows 8, AdwCleaner was not able to record a log file even though it did reboot at the end of it's scan.I searched for AdwCleaner[1].txt but it was not on C:\ drive and file search could not find it. I believe it has something to do with changes made in Windows 8. The results of the other scans are posted below this line:

___________________________________________________________

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 8 (6.2.9200 ) 32 bits version
Started in : Normal mode
User : jim [Admin rights]
Mode : Scan -- Date : 05/18/2013 14:31:20
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 2 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\WINDOWS\system32\drivers\etc\hosts



¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD3200BEVT-22ZCT0 +++++
--- User ---
[MBR] a0b42b1556cb3c3485a0837d0a69728c
[BSP] 957131575498f865f72b7828164b54b5 : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 10000 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 20482048 | Size: 295243 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[1]_S_05182013_02d1431.txt >>
RKreport[1]_S_05182013_02d1431.txt

_______________________________________________________
 Results of screen317's Security Check version 0.99.63  
   x86 (UAC is enabled)  
 Internet Explorer 9  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
Windows Defender   
COMODO Antivirus   
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:`````````
 CCleaner     
 Java 7 Update 21  
 Adobe Flash Player     11.6.602.180  
 Mozilla Firefox (20.0.1)
 Mozilla Thunderbird (17.0.5)
````````Process Check: objlist.exe by Laurent````````  
 Comodo Firewall cmdagent.exe
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C::  
````````````````````End of Log``````````````````````
 

I just tested to see if the Captcha of Bleeping Computer would display by trying to create a new account in my wife's name. There were the words "Security Check * " but nothing under them. When I tried to created the account the page said I entered the wrong security code.
 


Edited by JimBobWay, 19 May 2013 - 03:12 PM.


#4 nasdaq

nasdaq

  • Malware Response Team
  • 40,510 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:14 AM

Posted 20 May 2013 - 06:51 AM

Run the AdwCleaner Check tool as an Administrator.
See if you can get a log for my review.
===

You should remove Ghostery from your Firefox extentions.
http://www.systemlookup.com/FF_Extensions/375-firefox_ghostery_com.html

One more reason I would like to see a log from AdwCleaner.
===

Captcha is probably blocked by Internet Explorer.

Go to this Microsoft site:
http://support.microsoft.com/kb/923737#method1

Under this title
Let me reset Internet Explorer myself

Execute the manual instructions to reset IE.

Keep me posted.

#5 JimBobWay

JimBobWay
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:03:14 AM

Posted 25 May 2013 - 12:18 PM

OK, Internet Explorer is working now, after doing the reset as you said. I do not use IE very often, but use Firefox as my browser. I uninstalled Ghostery, which I liked because it caught the re-directs often used by websites. Firefox still does not show the Captcha boxes. I tried everything I could think of (all compatibility modes, as user, and as administrator) to get the AdwCleaner to generate a report, but after the reboot, Windows 8 comes up with the METRO desktop, and no report is shown or found. Can I use another program to do a similar report, maybe Lavasoft Ad-Aware, or Safer-Networking Spybot-S&D?


Edited by JimBobWay, 25 May 2013 - 12:35 PM.


#6 nasdaq

nasdaq

  • Malware Response Team
  • 40,510 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:14 AM

Posted 25 May 2013 - 12:42 PM

You should remove Firefox complete using the Add/Remove Programs applet and re-install it.

Keep me posted.

#7 JimBobWay

JimBobWay
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:03:14 AM

Posted 26 May 2013 - 11:23 PM

Fresh install of Firefox ver. 21.0, and I can now see the Captcha boxes used by Bleeping Computer. I still am not sure what caused the problem, but it is fixed. If I change anything in the future, I will test to make sure the Captcha is working.

Thank you for the help. Since I am no longer using Ghostery, what is your experience with alternatives like Abine's DoNotTrackMe?



#8 nasdaq

nasdaq

  • Malware Response Team
  • 40,510 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:14 AM

Posted 27 May 2013 - 07:11 AM

what is your experience with alternatives like Abine's DoNotTrackMe?

The reviews look good. I have no experience with it.

You can also look at AdBlock Plus which I have.
https://addons.mozilla.org/en-US/firefox/addon/adblock-plus/

#9 nasdaq

nasdaq

  • Malware Response Team
  • 40,510 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:14 AM

Posted 02 June 2013 - 08:56 AM

If all is well:

Time for some housekeeping
  • The following will implement some cleanup procedures as well as reset System Restore points:
  • Click Start > Run and copy/paste the following bold text into the Run box and click OK:
  • ComboFix /Uninstall
===

To remove AdwCleaner.

Please double click on AdwCleaner.exe to run the tool.
Click on Uninstall.
Confirm with Yes.

If you decide to keep the AdwCleaner tool make sure to delete your version and download the latest before running it.

Delete the other tools we used.
You can Keep the DDS tool as most forum will ask to see a log before suggesting a fix.

Surf Safely, and Think Prevention!
===

#10 nasdaq

nasdaq

  • Malware Response Team
  • 40,510 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:14 AM

Posted 08 June 2013 - 08:32 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users