Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Malwarebytes found pup.optional.conduit.a


  • This topic is locked This topic is locked
38 replies to this topic

#1 dolphin6476

dolphin6476

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:32 AM

Posted 13 November 2013 - 12:01 AM

I had a dozen attempts at a change of firefox home page during install of JetAudio basic from download.com (ie browser hijack popups warnings from Superantispyware) . I dont think it had got as far as install jetaudio, there was a cnet installer which asked if I wanted a bunch of other stuff, which I believe I rejected, but as I hadnt seen a cnet installer before (always seemed to just download a file in the past when I used this site, without pushing other downloads), I suppose I may have clicked on accept the first time foolishly thinking because they say clear of spyware I should trust the installer.

I have since read some cautionary discussion on using the cnet installer, suggesting people have had problems even when rejecting any bundled downloads, seeming some junk can be bundled anyway? see here http://forums.cnet.com/7723-6132_102-591945-0/search-conduit-malware/
 
I also note that a few days before I started having problems with the shockwave flash plugin crashing - this may indicate separate issue, or maybe just be instability of the current version of firefox / flash perhaps
 
Anyway, I ran Malwarebytes in full scan, found a lot of files associated with pup.optional.conduit.a I cleared those (log attached), and then ran malywarebytes again in quick, which came up clean. Always suspicious things are not always that simple, I searched for what I was up against, whether any other action required. I found this page: https://forums.malwarebytes.org/index.php?showtopic=131221 and followed the instructions, ie I downloaded and ran DDS (dds.txt and attact.txt attached) I downloaded and ran Junkware Removal Tool (JRT.txt attached) I downloaded and ran AdwCleaner by Xplode (log attached) I then updated and ran Malwarebytes again in quick mode which came up clean (log attached) although, as this came up clean before running the last three tools which found more issues, I am not sure what this latter step proves.

Do you think I am clear now, or is there anything else I should do? Thanks ! :-)
 
Update: Also, even after doing all this, I still found conduit listed as the default search engine in Google Chrome (default search engine now changed and I deleted the Conduit entry), so I ran AdwCleaner again, and have attached the log file from the second run.
 
I then searched windows explorer for conduit, and found some entries in a folder in which I backed up my firefox profile a few days before - when I had problems with flash plugin crashes. I deleted this folder.
 
I subsequently ran combofix (I know I should wait for support, but have been talked through this before a few years ago on a separate issue), and here is the log. I would be grateful to know whether all is now clear, or if there is more work to do. I will not uninstall combofix until I get the all clear (log attached)
 
I have had to add the latest log files using google chrome, as the shockwave flash plugin is still crashing when using firefox.

Edited by gringo_pr, 03 December 2013 - 09:37 PM.


BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,600 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:32 AM

Posted 18 November 2013 - 12:05 AM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/513893 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 dolphin6476

dolphin6476
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:32 AM

Posted 18 November 2013 - 09:36 AM

I have also since run microsoft system file checker, which also found some files it replaced for whatever reason, and resolved them (no issues found by sfc which it could not resolve automatically). I can send add these logs if requested, but am not sure whether it is appropriate to post sfc logs or whether I would need to anonymise any data before posting
 
New DDS log attached
 
I have my original Windows CD/DVD available (may take a few minutes finding it, but around somewhere)
 
I still have problems with shockwave flash plugin hanging when using firefox, but this may be a shockwave / firefox issue?
 
I dont know if conduit is fully gone, I havent cleaned up after runninng the tools in my previous message, as I am waiting for a response with the all clear, or with further actions I need to undertake.

Edited by gringo_pr, 03 December 2013 - 09:38 PM.


#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:07:32 AM

Posted 20 November 2013 - 09:58 PM





Hello dolphin6476

I would like to welcome you to the Malware Removal section of the forum.

Around here they call me Gringo and I will be glad to help you with your malware problems.

Very Important --> Please read this post completely, I have spent my time to put together somethings for you to keep in mind while I am helping you to make things go easier, faster and smoother for both of us!

  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the "Follow This Topic" Button, make sure that the "Receive notification" box is checked and that it is set to "Instantly" - This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.

I would like you to run this program for me.

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#5 dolphin6476

dolphin6476
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:32 AM

Posted 21 November 2013 - 09:16 AM

Hi thanks Gringo, Before I proceed I just wanted to check a couple of things, as I do not know if your post to me was automated, or has considered my previous message.

1) Can you please confirm that you have read my post above, and also this post (http://www.bleepingcomputer.com/forums/t/514790/hi-any-reason-my-post-has-received-no-help/) - important section copied below:
 

I think the problem with the firefox shockwave plugin crashing I have solved, so I do not think it is a symptom of some residual malware issue:
 

"Warning:  Unresponsive Plugin

Shockwave Flash may be busy, or it may have stopped responding.  You can stop the plug now, or you can continue to see if the plugin will complete."

I noticed plugin-hang-ui.exe running under processes list on Task Manager. I did not disable this, which is what some chat on the forums suggests. I identified that the space on the c drive was low. It still had gigabtyes free, but not many. Disk space free was between four and five GB, but I have RAM of 8GB.

 

I noticed the event viewer showed this: "Error: volmgr [49]  - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory." and wondered whether the lack of C drive space had anything to do with the flash plugin hitting problems also. Having ensured that space on the C drive is now around 12GB, the problem with the shockwave plugin stopping responding has gone away. When videos are maximised and minimised there still can be a brief pause, but there is no crash.

I noticed after solving the plugin issue myself, others have noted the problem: https://support.mozilla.org/en-US/questions/955286

However despite this issue being solved, I would still appreciate someone looking over the logs I previously posted to see if conduit has been successfully removed, and whether any other issues are present, and suggest what clean up actions to take to remove the tools I have run in my previous post.

 

2) Please can you confirm that you have reviewed the attached logs on my message above, including the second run of DDS following my post being picked up as forgotten by a helpbot.

 

3) Please can you let me know if there is anything in the attached logs that I should be concerned about, and whether any issues have been resolved.

 

4) Please can you let me know if there are cleanup actions which I need to do to remove previously run tools before I run any further tools that you suggest such as Farbar

 

5) Since running the tools above and resolving the plugin problem I have had no alerts from security software, or any other symptoms of malware, so I am cautious about running any tools that are overly invasive, unless you feel it is absolutely necessary. I am really after some comfort that what I have done so far is OK and that there is nothing else I need to do, and if I need to do anything else, what and why.

 

Thanks very much.

Rick



#6 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:07:32 AM

Posted 21 November 2013 - 12:24 PM

Hello Rick

I have looked over some of the reports but you have run so many tools I would like to see a new clean report just to see where we stand


Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#7 dolphin6476

dolphin6476
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:32 AM

Posted 22 November 2013 - 02:51 AM

I ran the same tools that another or the response team advised another party to run, in the same order in response to the same issue (conduit)

 

I find it troubling that you will not answer the five questions I asked above, and just want me to run yet another tool. The new tool you refer to, will it simply scan, or will it attempt to fix any issues it finds. I saw a youtube video on this tool which suggested it should be run from the recovery console, which makes me concerned it may cause problems when presently I may have none, which may be able to be established by properly reviewing the logs I have posted. Is it necessary to run Farbar from a recovery console?

 

I really would like one of the team to review what I have posted before I run any more tools please.



#8 dolphin6476

dolphin6476
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:32 AM

Posted 22 November 2013 - 01:37 PM

Hi Gringo,

I have researcher farbar, and can see it has a scan option only. I have run the tool, and will go through the log files and anonymise them before submitting



#9 dolphin6476

dolphin6476
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:32 AM

Posted 22 November 2013 - 11:03 PM

FRST log included

Attached Files

  • Attached File  FRST.zip   11.51KB   6 downloads


#10 dolphin6476

dolphin6476
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:32 AM

Posted 22 November 2013 - 11:12 PM

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-11-2013 01
Ran by Test at 2013-11-22 18:08:22
Running from C:\Users\Test\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

==================== Installed Programs ======================

7-Zip 9.22 (x64 edition) (Version: 9.22.00.0)
Adobe AIR (x32 Version: 3.9.0.1210)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.152)
Adobe Photoshop 6.0 (x32 Version: 6.0)
Adobe Photoshop 7.0 (x32 Version: 7.0)
Adobe Reader X (10.1.8) (x32 Version: 10.1.8)
Adobe Shockwave Player 12.0 (x32 Version: 12.0.5.146)
Adobe SVG Viewer (x32 Version: 1.0)
Amazon MP3 Downloader 1.0.17 (x32 Version: 1.0.17)
AMD APP SDK Runtime (Version: 10.0.937.2)
AMD Catalyst Install Manager (Version: 8.0.877.0)
AMD Fuel (Version: 2013.0429.2313.39747)
AMD VISION Engine Control Center (x32 Version: 2013.0429.2313.39747)
Apple Application Support (x32 Version: 2.3)
Apple Software Update (x32 Version: 2.1.3.127)
Application Verifier x64 External Package (Version: 8.59.29722)
BBC iPlayer Downloads (x32 Version: 1.0.2)
Canon Easy-PhotoPrint EX (x32)
Canon Easy-WebPrint EX (x32 Version: 1.3.5.0)
CANON iMAGE GATEWAY Task for ZoomBrowser EX (x32 Version: 1.7.2.11)
Canon Inkjet Printer Driver Add-On Module
Canon Internet Library for ZoomBrowser EX (x32 Version: 1.6.3.9)
Canon MOV Decoder (x32 Version: 1.5.0.7)
Canon MOV Encoder (x32 Version: 1.3.1.3)
Canon MovieEdit Task for ZoomBrowser EX (x32 Version: 3.4.1.9)
Canon MP Navigator EX 1.0 (x32)
Canon MP220 series
Canon My Image Garden (x32 Version: 1.0.3)
Canon My Image Garden Design Files (x32 Version: 1.0.1)
Canon My Printer (x32 Version: 3.0.0)
Canon RAW Image Task for ZoomBrowser EX (x32 Version: 2.4.0.7)
Canon Utilities CameraWindow (x32 Version: 7.4.0.7)
Canon Utilities CameraWindow DC (x32 Version: 7.4.1.10)
Canon Utilities CameraWindow DC 8 (x32 Version: 8.1.0.11)
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX (x32 Version: 6.5.0.3)
Canon Utilities Digital Photo Professional 3.8 (x32 Version: 3.8.1.0)
Canon Utilities EOS Utility (x32 Version: 1.1.0.8)
Canon Utilities MyCamera (x32 Version: 7.3.0.5)
Canon Utilities MyCamera DC (x32 Version: 7.2.1.6)
Canon Utilities PhotoStitch (x32 Version: 3.1.22.46)
Canon Utilities Picture Style Editor (x32 Version: 1.3.0.0)
Canon Utilities RemoteCapture DC (x32 Version: 3.1.0.5)
Canon Utilities RemoteCapture Task for ZoomBrowser EX (x32 Version: 1.8.0.1)
Canon Utilities Solution Menu (x32)
Canon Utilities ZoomBrowser EX (x32 Version: 6.5.1.15)
Canon ZoomBrowser EX Memory Card Utility (x32 Version: 1.3.0.4)
CanoScan Toolbox Ver4.9 (x32)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0429.2313.39747)
Catalyst Control Center Localization All (x32 Version: 2013.0429.2313.39747)
CCC Help Chinese Standard (x32 Version: 2013.0429.2312.39747)
CCC Help Chinese Traditional (x32 Version: 2013.0429.2312.39747)
CCC Help Czech (x32 Version: 2013.0429.2312.39747)
CCC Help Danish (x32 Version: 2013.0429.2312.39747)
CCC Help Dutch (x32 Version: 2013.0429.2312.39747)
CCC Help English (x32 Version: 2013.0429.2312.39747)
CCC Help Finnish (x32 Version: 2013.0429.2312.39747)
CCC Help French (x32 Version: 2013.0429.2312.39747)
CCC Help German (x32 Version: 2013.0429.2312.39747)
CCC Help Greek (x32 Version: 2013.0429.2312.39747)
CCC Help Hungarian (x32 Version: 2013.0429.2312.39747)
CCC Help Italian (x32 Version: 2013.0429.2312.39747)
CCC Help Japanese (x32 Version: 2013.0429.2312.39747)
CCC Help Korean (x32 Version: 2013.0429.2312.39747)
CCC Help Norwegian (x32 Version: 2013.0429.2312.39747)
CCC Help Polish (x32 Version: 2013.0429.2312.39747)
CCC Help Portuguese (x32 Version: 2013.0429.2312.39747)
CCC Help Russian (x32 Version: 2013.0429.2312.39747)
CCC Help Spanish (x32 Version: 2013.0429.2312.39747)
CCC Help Swedish (x32 Version: 2013.0429.2312.39747)
CCC Help Thai (x32 Version: 2013.0429.2312.39747)
CCC Help Turkish (x32 Version: 2013.0429.2312.39747)
ccc-utility64 (Version: 2013.0429.2313.39747)
CCleaner (Version: 4.07)
CDDRV_Installer (Version: 4.60)
CD-LabelPrint (x32)
CyberLink PowerDirector (x32 Version: 7.0.3017)
D3DX10 (x32 Version: 15.4.2368.0902)
Dropbox (HKCU Version: 2.0.22)
EasyTune5 (x32)
Elevated Installer (x32 Version: 2.1.13)
FileZilla Client 3.5.3 (x32 Version: 3.5.3)
Futuremark SystemInfo (x32 Version: 3.21.2.1)
GameShadow (x32 Version: 1.91.0000)
Garmin City Navigator Europe NT 2011.10 (x32 Version: 14.10.0.0)
Garmin City Navigator Europe NT 2012.10 Update (x32 Version: 15.10.0.0)
Garmin City Navigator Europe NT 2013.40 Update (x32 Version: 16.40.0.0)
Garmin Communicator Plugin x64 (Version: 4.0.3)
Garmin Express (x32 Version: 2.1.13)
Garmin Express Tray (x32 Version: 2.1.13)
Garmin POI Loader (x32 Version: 2.5.4.0)
Garmin Update Service (x32 Version: 2.1.13)
Garmin USB Drivers (x32 Version: 2.3.1.0)
Garmin VoiceStudio v2.10 (x32 Version: 2.10.0.0)
Garmin WebUpdater (x32 Version: 2.5.6)
Google Chrome (x32 Version: 31.0.1650.57)
Google Earth (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.165)
HydraVision (x32 Version: 4.2.234.0)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
JPEG Camera v1.10.7 (x32 Version: 1.10.7)
KhalInstallWrapper (Version: 2.00.0000)
Kits Configuration Installer (x32 Version: 8.59.25584)
Logitech SetPoint (x32 Version: 4.80)
Malwarebytes Anti-Malware version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Silverlight (x32 Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Moo0 Audio Converter 1.32 (x32)
Moo0 Voice Recorder 1.43 (x32)
Moo0 YouTube Downloader 1.06 (x32)
Mozilla Firefox 25.0.1 (x86 en-GB) (x32 Version: 25.0.1)
Mozilla Maintenance Service (x32 Version: 25.0.1)
MSVCRT (x32 Version: 15.4.2862.0708)
Nero Audio Pack 1 (x32 Version: 11.0.11500.110.0)
Nero Blu-ray Player (x32 Version: 12.0.14300)
Nero Blu-ray Player Help (CHM) (x32 Version: 12.0.4000)
Nero Core Components (x32 Version: 11.0.18100)
Nero Kwik Media (x32 Version: 1.18.18500)
Nero Kwik Media (x32 Version: 12.0.01300)
Nero Kwik Media Help (CHM) (x32 Version: 12.0.4000)
Nero Kwik Themes Basic (x32 Version: 12.0.11500)
Nero SharedVideoCodecs (x32 Version: 1.0.12100.2.0)
Nero Update (x32 Version: 11.0.11800.31.0)
Norton Identity Safe (x32 Version: 2013.4.0.10)
Norton Internet Security (x32 Version: 21.1.0.18)
NVIDIA Drivers (Version: 1.10.62.40)
OpenOffice 4.0.1 (x32 Version: 4.01.9714)
PowerDirector (x32 Version: 7.00.0000)
Prerequisite installer (x32 Version: 12.0.0002)
QuickTime (x32 Version: 7.74.80.86)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6077)
R-Studio 4.5 (x32 Version: 4.5.127472)
SanDisk ImageMate (x32 Version: 1.2.0.2)
SDK Debuggers (x32 Version: 8.59.29746)
Seagate DiscWizard (x32 Version: 13.0.14387)
SeaTools for Windows (x32 Version: 1.2.0.6)
Secunia PSI (3.0.0.8013) (x32 Version: 3.0.0.8013)
Segoe UI (x32 Version: 15.4.2271.0615)
Silent Hunter III (x32 Version: 1.4.0000)
Skype Click to Call (x32 Version: 6.13.13771)
Skype™ 6.10 (x32 Version: 6.10.104)
SmartSound Quicktracks Plugin (x32 Version: 3.0.3.0)
Speedshifter (x32 Version: 2.0.3)
Spybot - Search & Destroy (x32 Version: 1.6.2)
SpywareBlaster 5.0 (x32 Version: 5.0.0)
SUPERAntiSpyware (Version: 5.0.1108)
swMSM (x32 Version: 12.0.0.1)
Ultimate Extras sounds from Microsoft® Tinker™
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3)
Visual C++ 8.0 Runtime Setup Package (x64) (x32 Version: 9.0.0.623)
Visual Studio 2008 x64 Redistributables (x32 Version: 10.0.0.2)
Winamp (x32 Version: 5.65 )
Winamp Detector Plug-in (HKCU Version: 1.0.0.1)
Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (04/19/2012 2.3.1.0) (Version: 04/19/2012 2.3.1.0)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3555.0308)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live Sync (x32 Version: 14.0.8117.416)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
Windows Software Development Kit (x32 Version: 8.59.29750)
Windows Software Development Kit EULA (x32 Version: 8.59.25584)
Windows Sound Schemes

==================== Restore Points  =========================

19-11-2013 13:53:12 Scheduled Checkpoint
20-11-2013 23:55:21 Scheduled Checkpoint
22-11-2013 00:00:00 Scheduled Checkpoint

==================== Hosts content: ==========================

2006-11-02 12:34 - 2013-11-13 13:29 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {35C18BED-7309-4773-BF54-A202CBD45104} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\WSCStub.exe [2013-10-08] (Symantec Corporation)
Task: {363BF00C-BF72-47C7-B800-DAFD1EFBA83C} - System32\Tasks\Norton Identity Safe\Norton Error Processor => C:\Program Files (x86)\Norton Identity Safe\Engine\2013.4.0.10\symerr.exe [2013-05-29] (Symantec Corporation)
Task: {4DEB789E-B165-46BC-A260-19B45B57FEEC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-05-19] (Google Inc.)
Task: {514FE56E-C43D-458C-A3DD-3455E4199626} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-05-19] (Google Inc.)
Task: {530B8BBB-ADD5-4BAC-A7BA-582A5C328047} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\symerr.exe [2013-08-01] (Symantec Corporation)
Task: {54945676-3D43-4C49-8F5B-3C6BAFF4546E} - System32\Tasks\RunAsStdUser Task => C:\Program Files (x86)\Moo0\VoiceRecorder 1.43\VoiceRecorder.exe [2013-10-19] (Moo0)
Task: {76589EC5-BA8F-47D2-9F87-41095C8A058C} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\symerr.exe [2013-08-01] (Symantec Corporation)
Task: {9475DD97-BB54-4FD8-A31A-032B4833F6AA} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {AA105019-BFFB-4713-B627-81B47F4419F0} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {AC226F3D-CC4E-423B-9245-0D5975A33B7C} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-05-10] (Microsoft Corporation)
Task: {B5214EC0-8822-4A10-92DD-15354514CE5E} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {C28278BF-1ABF-4595-BB2A-15201DDF25E3} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2010-05-10] ()
Task: {C3CD720D-8932-44AB-A0E7-C1CFEB3BC1BE} - System32\Tasks\Norton Identity Safe\Norton Error Analyzer => C:\Program Files (x86)\Norton Identity Safe\Engine\2013.4.0.10\symerr.exe [2013-05-29] (Symantec Corporation)
Task: {C41E9FD5-A5DB-4DEF-9715-E4F7BAFEE730} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-18] (Microsoft Corporation)
Task: {D65491AF-C6B6-465F-A556-190C32F288BF} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2008-01-18] (Microsoft Corporation)
Task: {DA3A3E7E-A7E8-441D-BC96-F62898619860} - System32\Tasks\CCleanerSkipUAC => C:\Program Files (x86)\CCleaner\CCleaner.exe [2013-10-22] (Piriform Ltd)
Task: {E25B57CA-0BFA-4E4D-9FEC-CA7BF0B26B8C} - System32\Tasks\{EA9A2468-5176-49B6-866B-14211FB0C0A7} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-10-21] (Skype Technologies S.A.)
Task: {E7780D61-A38E-4CEC-BDE6-8DE57EA44663} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2010-04-07 01:22 - 2012-11-16 19:37 - 00045056 _____ () C:\Windows\system32\atitmp64.dll
2010-01-02 14:42 - 2010-01-02 14:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2010-05-18 22:37 - 2009-07-20 11:35 - 00018960 _____ () C:\Program Files\Logitech\SetPoint\khalwrapper.dll
2013-04-29 23:25 - 2013-04-29 23:25 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2013-06-18 15:49 - 2013-06-18 15:49 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2013-04-29 23:08 - 2013-04-29 23:08 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2013-06-19 16:19 - 2012-05-30 14:51 - 00699280 ____R () C:\PROGRAM FILES (X86)\NORTON IDENTITY SAFE\ENGINE\2013.4.0.10\wincfi39.dll
2011-03-27 03:40 - 2008-10-18 17:08 - 00180224 _____ () C:\Windows\SysWOW64\ustor.dll
2013-03-13 20:48 - 2013-03-13 20:48 - 24978944 _____ () C:\Users\Test\AppData\Roaming\Dropbox\bin\libcef.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:5C321E34

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/21/2013 01:32:49 PM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\TEST\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\CACHE\ZZZZZZZZ> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (11/21/2013 01:32:46 PM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\TEST\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\CACHE\ZZZZZZZZ> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (11/21/2013 01:32:44 PM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\TEST\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\CACHE\ZZZZZZZZ> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (11/18/2013 00:41:41 PM) (Source: Application Hang) (User: )
Description: The program winamp.exe version 5.6.5.3438 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 19a8
Start Time: 01cee45b794d39db
Termination Time: 22

Error: (11/18/2013 00:41:14 PM) (Source: Application Hang) (User: )
Description: The program winamp.exe version 5.6.5.3438 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 4cc
Start Time: 01cee45b55e5815b
Termination Time: 16

Error: (11/18/2013 11:10:47 AM) (Source: System Restore) (User: )
Description: Failed to create restore point on volume (Process = C:\Users\Test\AppData\Local\Temp\nsoCC84.tmp\d3dx9_31_42_x86\dxsetup.exe /silent; Descripton = äx×v; Hr = 0x80070057).

Error: (11/15/2013 05:50:26 PM) (Source: Application Hang) (User: )
Description: The program firefox.exe version 25.0.0.5046 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: a50
Start Time: 01cee22adba0ee9e
Termination Time: 30

Error: (11/15/2013 05:26:35 PM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\TEST\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\CACHE\ZZZZZZZZ> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (11/15/2013 05:26:25 PM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\TEST\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\CACHE\ZZZZZZZZ> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (11/14/2013 05:22:26 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\TEST\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\QHMM4RI8.TEST PROFILE 14 NOV\THUMBNAILS\ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ.ZZZ> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)


System errors:
=============
Error: (11/20/2013 10:20:23 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT AUTHORITY)
Description: 0x80070032

Error: (11/20/2013 10:18:58 PM) (Source: Service Control Manager) (User: )
Description: Beep

Error: (11/20/2013 10:18:33 PM) (Source: volmgr) (User: )
Description: Configuring the Page file for crash dump failed. Make sure there is a page
file on the boot partition and that is large enough to contain all physical
memory.

Error: (11/20/2013 10:18:16 PM) (Source: volmgr) (User: )
Description: Configuring the Page file for crash dump failed. Make sure there is a page
file on the boot partition and that is large enough to contain all physical
memory.

Error: (11/19/2013 01:13:48 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT AUTHORITY)
Description: 0x80070032

Error: (11/19/2013 01:11:20 PM) (Source: Service Control Manager) (User: )
Description: Beep

Error: (11/19/2013 01:10:54 PM) (Source: volmgr) (User: )
Description: Configuring the Page file for crash dump failed. Make sure there is a page
file on the boot partition and that is large enough to contain all physical
memory.

Error: (11/19/2013 01:10:38 PM) (Source: volmgr) (User: )
Description: Configuring the Page file for crash dump failed. Make sure there is a page
file on the boot partition and that is large enough to contain all physical
memory.

Error: (11/18/2013 05:40:54 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT AUTHORITY)
Description: 0x80070032

Error: (11/18/2013 05:39:31 PM) (Source: Service Control Manager) (User: )
Description: Beep


Microsoft Office Sessions:
=========================
Error: (11/21/2013 01:32:49 PM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\TEST\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\CACHE\ZZZZZZZZ

Error: (11/21/2013 01:32:46 PM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\TEST\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\CACHE\ZZZZZZZZ

Error: (11/21/2013 01:32:44 PM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\TEST\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\CACHE\ZZZZZZZZ

Error: (11/18/2013 00:41:41 PM) (Source: Application Hang)(User: )
Description: winamp.exe5.6.5.343819a801cee45b794d39db22

Error: (11/18/2013 00:41:14 PM) (Source: Application Hang)(User: )
Description: winamp.exe5.6.5.34384cc01cee45b55e5815b16

Error: (11/18/2013 11:10:47 AM) (Source: System Restore)(User: )
Description: C:\Users\Test\AppData\Local\Temp\nsoCC84.tmp\d3dx9_31_42_x86\dxsetup.exe /silentäx×v0x80070057

Error: (11/15/2013 05:50:26 PM) (Source: Application Hang)(User: )
Description: firefox.exe25.0.0.5046a5001cee22adba0ee9e30

Error: (11/15/2013 05:26:35 PM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\TEST\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\CACHE\ZZZZZZZZ

Error: (11/15/2013 05:26:25 PM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\TEST\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\CACHE\ZZZZZZZZ

Error: (11/14/2013 05:22:26 AM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\TEST\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\QHMM4RI8.TEST PROFILE 14 NOV\THUMBNAILS\ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ.ZZZ


CodeIntegrity Errors:
===================================
  Date: 2013-11-22 18:08:05.262
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\SYMEVENT64x86.SYS because the set of per-page image hashes could not be found on the system.

  Date: 2013-11-22 18:08:04.508
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\SYMEVENT64x86.SYS because the set of per-page image hashes could not be found on the system.

  Date: 2013-11-22 18:08:03.750
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\SYMEVENT64x86.SYS because the set of per-page image hashes could not be found on the system.

  Date: 2013-11-22 18:08:02.969
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\SYMEVENT64x86.SYS because the set of per-page image hashes could not be found on the system.

  Date: 2013-11-22 18:07:43.066
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\SYMEVENT64x86.SYS because the set of per-page image hashes could not be found on the system.

  Date: 2013-11-22 18:07:42.318
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\SYMEVENT64x86.SYS because the set of per-page image hashes could not be found on the system.

  Date: 2013-11-22 18:07:41.565
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\SYMEVENT64x86.SYS because the set of per-page image hashes could not be found on the system.

  Date: 2013-11-22 18:07:40.807
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\SYMEVENT64x86.SYS because the set of per-page image hashes could not be found on the system.

  Date: 2013-11-22 18:07:35.702
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20131114.001\BHDrvx64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-11-22 18:07:34.941
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20131114.001\BHDrvx64.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 35%
Total physical RAM: 8190.64 MB
Available physical RAM: 5292.7 MB
Total Pagefile: 8861.15 MB
Available Pagefile: 5730.06 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:97.66 GB) (Free:12.42 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:45.81 GB) (Free:15.76 GB) NTFS
Drive h: () (Removable) (Total:3.76 GB) (Free:0.79 GB) FAT32
Drive m: (Data) (Fixed) (Total:1863.01 GB) (Free:1660.76 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149 GB) (Disk ID: F0DB73DC)
Partition 1: (Active) - (Size=98 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=46 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=6 GB) - (Type=05)

========================================================
Disk: 1 (Size: 1863 GB) (Disk ID: C5D05F54)
Partition 1: (Not Active) - (Size=-198626508800) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows XP) (Size: 4 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=4 GB) - (Type=0C)

==================== End Of Log ============================



#11 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:07:32 AM

Posted 23 November 2013 - 02:43 PM

Hello dolphin6476


Sorry for not responding sooner, I had read your concerns and wanted to respond to them,

You stated why if you had sent ten reports why I needed another report and was upset that I did not go thru the reports.

I did glance at them and I find it very alarming that even tho we have everywhere in this forum saying not to run these tools on your own that that is the very thing you did do, Then you expect someone on their free time to dissect each report trying to figure out which one was run in which order (that is more important than anything else) then you remove so much stuff that I feel that the report is worthless

From what I was allowed to see of the report I do not see anything of note to worry about except you should uninstall chrome and reinstall it


All of our tools only needs to be deleted as they do not install


Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#12 dolphin6476

dolphin6476
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:32 AM

Posted 24 November 2013 - 12:49 PM

Gringo, I do appreciate the help that is provided by this forum.

 

I found another topic where another expert said to run those tools for the same problem, ie conduit, I ran the same tools in the same order. They were generic tools, I did not run any custom fix scripts designed for other users.

 

I state the order of the tools used in my report, there is no mystery about this.

 

Assuming the advice given by the previous expert was valid, there was absolutely no reason why I should not have taken the same steps. Those steps should have resolved my issue, but I wanted to run it past someone.

 

 

The tool you asked me to use has a section which includes a great many file names of recently changed documents. The report is not worthless, I have only removed details of files changes where these have file names which I feel I need to remove for privacy reasons, they have absolutely no bearing on the questions I am asking on this forum. Indeed, these forums state that people shouldnt post logs into the posts but should attach them, but you asked me to do the opposite. You must have enough awareness of computer security that sharing the last month of changed file names on their PC could give users some privacy concerns.

 

Please, if you would like to help, help, and please provide some feedback on the logs, and perhaps explain why I should uninstall and reinstall Chrome.

 

If your nose is put out of joint by the fact that I had need to take some action myself beforehand, then please can you allocate this topic to someone else who is not offended by the fact that I had to get some confidence the system was secure while waiting for assistance. I should also point out last post that three of the files I attached were malwarebytes logs, two related to forum instructions to include on first post, ie dds and attach.txt, and another was a second run of dds following instructions to do so from the helpbot when the post had been forgotten.

 

I know full well there are proper cleanup instructions for combofix, and can find them on other posts, and run them myself, but I wanted to ensure before cleaning up that there was nothing I had missed.

 

I know you guys are volunteers and I respect that, but you also need to respect that there are some of us who need help that are reasonably competent and can do some of the work themselves, and just need a bit of assurance there is nothing they havent missed.

 

Please dont forget that my topic was forgotten, and others were getting answers a lot quicker - without being able to bump, or repost, or ask for help on another forum I had to take some action myself. In the end it still took days to get a response even after the topic was flagged up as forgotten by a bot. I sympathise that it can take time, and posts can get missed, but you have to understand that I could not sit there and do nothing.

I have removed and reinstalled Chrome


Edited by dolphin6476, 24 November 2013 - 01:30 PM.


#13 dolphin6476

dolphin6476
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:32 AM

Posted 25 November 2013 - 08:40 AM

HI Gringo, please can you refer this topic to someone else who is prepared to look through the logs, thank you. I posted here to try and get some reassurance that the problems have been resolved, and with you just saying you have "glanced" at the logs, I dont really feel I am getting that reassurance. I appreciate you are busy, and a volunteer. Perhaps there is another member of the team who is a little less busy.


Edited by dolphin6476, 25 November 2013 - 09:01 AM.


#14 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:07:32 AM

Posted 25 November 2013 - 10:14 PM


Hello dolphin6476

There were allot of reports to go thru - remember normally we do one at a time not 10 of them - I have gone thru the reports and there is nothing major in them. the MBAM reports and the adware and junk cleaners did just that remove allot of junk but not serious

At this time I would like you to run this script for me and it is a good time to check out the computer to see if there is anything else that needs to be addressed.

:Run CFScript:

Please start by opening Notepad and copy/paste the text in the box into the window:

ClearJavaCache::


 
Save it to your desktop as CFScript.txt

Referring to the picture above, drag CFScript.txt into ComboFix.exe
CFScriptB-4.gif
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"
  • In your next post I need the following
    • report from Combofix
    • let me know of any problems you may have had
    • How is the computer doing now after running the script?
Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#15 dolphin6476

dolphin6476
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:32 AM

Posted 27 November 2013 - 09:50 AM

Thanks Gringo, I will perform this this afternoon and report back






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users