Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Malware/Adware Infection


  • Please log in to reply
12 replies to this topic

#1 JinKazama23

JinKazama23

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:03:03 PM

Posted 25 November 2013 - 09:16 PM

Hi,

 

This check is long over due, but my laptop running Win8 seems to be infected with adware/malware (hopefully nothing more than that). Generally, there are ads showing (even on google homepage), pop-ups and accidental freezes. I would appreciate your help with this! 

 

 



BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,072 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:03 PM

Posted 25 November 2013 - 10:02 PM

Hello JK, How is it after doing these?
 
Please download MiniToolBox, save it to your desktop and run it.
Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.
  • Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.
    Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
     
    Download TDSSKiller and save it to your desktop.
  • Extract (unzip) its contents to your desktop.
  • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
  • .
    .
    .
    ADW Cleaner
    Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished...
    <-insert any special instructions here for what to uncheck OR remove this line if there are none->
  • This time click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • .
    .
    .
    thisisujrt.gif Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
  • .
    .
    .
    .
  • Last run ESET.
  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
  • Scan potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
  • NOTE:Sometimes if ESET finds no infections it will not create a log.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 JinKazama23

JinKazama23
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:03:03 PM

Posted 25 November 2013 - 10:24 PM

MiniToolBox by Farbar  Version: 13-07-2013
Ran by Anna (administrator) on 25-11-2013 at 21:12:50
Running from "C:\Users\Anna\Desktop"
Microsoft Windows 8  (X64)
Boot Mode: Normal
***************************************************************************
 
========================= Flush DNS: ===================================
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========================= IE Proxy Settings: ============================== 
 
Proxy is not enabled.
No Proxy Server is set.
 
"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================
 
 
 
========================= IP Configuration: ================================
 
Dell Wireless 1703 802.11b/g/n (2.4GHz) = Wi-Fi (Connected)
Realtek PCIe FE Family Controller = Ethernet (Media disconnected)
Bluetooth Device (Personal Area Network) = Bluetooth Network Connection (Media disconnected)
 
 
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
 
reset
set global icmpredirects=enabled
set interface interface="Local Area Connection* 9" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Wi-Fi" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 12" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Bluetooth Network Connection" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
 
 
popd
# End of IPv4 configuration
 
 
 
Windows IP Configuration
 
   Host Name . . . . . . . . . . . . : Anna
   Primary Dns Suffix  . . . . . . . : 
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : hsd1.il.comcast.net.
 
Ethernet adapter Bluetooth Network Connection:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Bluetooth Device (Personal Area Network)
   Physical Address. . . . . . . . . : B8-76-3F-76-DF-B0
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Wireless LAN adapter Local Area Connection* 12:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
   Physical Address. . . . . . . . . : 1A-76-3F-76-DF-AF
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Wireless LAN adapter Wi-Fi:
 
   Connection-specific DNS Suffix  . : hsd1.il.comcast.net.
   Description . . . . . . . . . . . : Dell Wireless 1703 802.11b/g/n (2.4GHz)
   Physical Address. . . . . . . . . : B8-76-3F-76-DF-AF
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::a46f:b149:d3fe:b21d%13(Preferred) 
   IPv4 Address. . . . . . . . . . . : 192.168.1.107(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : 25 listopada 2013 20:37:37
   Lease Expires . . . . . . . . . . : 26 listopada 2013 20:37:37
   Default Gateway . . . . . . . . . : 192.168.1.1
   DHCP Server . . . . . . . . . . . : 192.168.1.1
   DHCPv6 IAID . . . . . . . . . . . : 330855999
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-18-E6-8D-CD-B8-CA-3A-E0-F8-4F
   DNS Servers . . . . . . . . . . . : 75.75.75.75
                                       75.75.76.76
   NetBIOS over Tcpip. . . . . . . . : Enabled
 
Ethernet adapter Ethernet:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Realtek PCIe FE Family Controller
   Physical Address. . . . . . . . . : B8-CA-3A-E0-F8-4F
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter isatap.hsd1.il.comcast.net.:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : hsd1.il.comcast.net.
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter Local Area Connection* 14:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft 6to4 Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter Teredo Tunneling Pseudo-Interface:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2001:0:9d38:6ab8:3cf0:250e:bc47:ef4(Preferred) 
   Link-local IPv6 Address . . . . . : fe80::3cf0:250e:bc47:ef4%19(Preferred) 
   Default Gateway . . . . . . . . . : ::
   NetBIOS over Tcpip. . . . . . . . : Disabled
Server:  cdns01.comcast.net
Address:  75.75.75.75
 
Name:    google.com
Addresses:  2607:f8b0:4009:803::1008
 74.125.225.71
 74.125.225.72
 74.125.225.64
 74.125.225.65
 74.125.225.67
 74.125.225.78
 74.125.225.73
 74.125.225.69
 74.125.225.66
 74.125.225.70
 74.125.225.68
 
 
Pinging google.com [173.194.46.78] with 32 bytes of data:
Reply from 173.194.46.78: bytes=32 time=298ms TTL=55
Reply from 173.194.46.78: bytes=32 time=15ms TTL=55
 
Ping statistics for 173.194.46.78:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 15ms, Maximum = 298ms, Average = 156ms
Server:  cdns01.comcast.net
Address:  75.75.75.75
 
Name:    yahoo.com
Addresses:  206.190.36.45
 98.139.183.24
 98.138.253.109
 
 
Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=291ms TTL=49
Reply from 98.139.183.24: bytes=32 time=53ms TTL=51
 
Ping statistics for 98.139.183.24:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 53ms, Maximum = 291ms, Average = 172ms
 
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
 
Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 17...b8 76 3f 76 df b0 ......Bluetooth Device (Personal Area Network)
 14...1a 76 3f 76 df af ......Microsoft Wi-Fi Direct Virtual Adapter
 13...b8 76 3f 76 df af ......Dell Wireless 1703 802.11b/g/n (2.4GHz)
 12...b8 ca 3a e0 f8 4f ......Realtek PCIe FE Family Controller
  1...........................Software Loopback Interface 1
 15...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
 16...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
 19...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================
 
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1    192.168.1.107     25
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.1.0    255.255.255.0         On-link     192.168.1.107    281
    192.168.1.107  255.255.255.255         On-link     192.168.1.107    281
    192.168.1.255  255.255.255.255         On-link     192.168.1.107    281
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link     192.168.1.107    281
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link     192.168.1.107    281
===========================================================================
Persistent Routes:
  None
 
IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
 19    306 ::/0                     On-link
  1    306 ::1/128                  On-link
 19    306 2001::/32                On-link
 19    306 2001:0:9d38:6ab8:3cf0:250e:bc47:ef4/128
                                    On-link
 13    281 fe80::/64                On-link
 19    306 fe80::/64                On-link
 19    306 fe80::3cf0:250e:bc47:ef4/128
                                    On-link
 13    281 fe80::a46f:b149:d3fe:b21d/128
                                    On-link
  1    306 ff00::/8                 On-link
 19    306 ff00::/8                 On-link
 13    281 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================
 
Catalog5 01 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\pnrpnsp.dll [67584] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [67584] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\NLAapi.dll [55296] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [21504] (Microsoft Corporation)
Catalog5 07 C:\Windows\SysWOW64\wshbth.dll [50688] (Microsoft Corporation)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\napinsp.dll [66560] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\pnrpnsp.dll [85504] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [85504] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\NLAapi.dll [72192] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [53760] (Microsoft Corporation)
x64-Catalog5 07 C:\Windows\System32\wshbth.dll [64000] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
 
========================= Event log errors: ===============================
 
Application errors:
==================
Error: (11/25/2013 08:07:20 PM) (Source: CltMngSvc) (User: )
Description: CltMngSvcServiceInstall: Fail to Start serviceSearch Protect by Conduit Updater (Error: 1056)
 
Error: (11/24/2013 04:43:33 PM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: The I/O writes cannot be held during the shadow copy creation period on volume \\?\Volume{4ee90f4d-17f2-4b74-9969-608b3d9a25e0}\.
The volume index in the shadow copy set is 0. Error details: Open[0x00000000, The operation completed successfully.
], Flush[0x00000000, The operation completed successfully.
], Release[0x80042314, The shadow copy provider timed out while holding writes to the volume being shadow copied. This is probably due to excessive activity on the volume by an application or a system service. Try again later when activity on the volume is reduced.
], OnRun[0x00000000, The operation completed successfully.
].
 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (11/24/2013 04:43:31 PM) (Source: System Restore) (User: )
Description: Failed to create restore point (Process = C:\Windows\system32\svchost.exe -k netsvcs; Description = Windows Update; Error = 0x81000101).
 
Error: (10/14/2013 00:43:15 PM) (Source: System Restore) (User: )
Description: Failed to create restore point (Process = C:\Windows\system32\svchost.exe -k netsvcs; Description = Windows Update; Error = 0x81000101).
 
Error: (10/12/2013 08:45:10 AM) (Source: Customer Experience Improvement Program) (User: )
Description: 80070005
 
Error: (10/11/2013 03:02:34 PM) (Source: Application Error) (User: )
Description: Faulting application name: pcdrsysinfocsmi.p5x, version: 6.0.6032.39, time stamp: 0x4ffe56d2
Faulting module name: MSVCR90.dll, version: 9.0.30729.6871, time stamp: 0x4fee5fd5
Exception code: 0x40000015
Fault offset: 0x000000000004267f
Faulting process id: 0x24ac
Faulting application start time: 0xpcdrsysinfocsmi.p5x0
Faulting application path: pcdrsysinfocsmi.p5x1
Faulting module path: pcdrsysinfocsmi.p5x2
Report Id: pcdrsysinfocsmi.p5x3
Faulting package full name: pcdrsysinfocsmi.p5x4
Faulting package-relative application ID: pcdrsysinfocsmi.p5x5
 
Error: (10/11/2013 08:26:04 AM) (Source: Application Error) (User: )
Description: Faulting application name: pcdrsysinfocsmi.p5x, version: 6.0.6032.39, time stamp: 0x4ffe56d2
Faulting module name: MSVCR90.dll, version: 9.0.30729.6871, time stamp: 0x4fee5fd5
Exception code: 0x40000015
Fault offset: 0x000000000004267f
Faulting process id: 0x288c
Faulting application start time: 0xpcdrsysinfocsmi.p5x0
Faulting application path: pcdrsysinfocsmi.p5x1
Faulting module path: pcdrsysinfocsmi.p5x2
Report Id: pcdrsysinfocsmi.p5x3
Faulting package full name: pcdrsysinfocsmi.p5x4
Faulting package-relative application ID: pcdrsysinfocsmi.p5x5
 
Error: (10/11/2013 07:41:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (User: ANNA)
Description: Activation of app Allrecipes.Allrecipes_f8zhmzza100am!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (09/29/2013 08:16:45 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80070005
 
Error: (09/27/2013 10:42:35 AM) (Source: Customer Experience Improvement Program) (User: )
Description: 80070005
 
 
System errors:
=============
Error: (11/25/2013 08:41:07 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: {3A185DDE-E020-4985-A8F2-E27CDC4A0F3A}
 
Error: (11/25/2013 08:34:54 PM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error: 
%%5
 
Error: (11/25/2013 08:30:07 PM) (Source: Service Control Manager) (User: )
Description: The Windows Update service did not shut down properly after receiving a preshutdown control.
 
Error: (11/25/2013 08:25:56 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070103: Intel Corporation - Storage Controller - Intel® 7 Series Chipset Family SATA AHCI Controller.
 
Error: (11/24/2013 04:43:33 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Intel Corporation - Storage Controller - Intel® 7 Series Chipset Family SATA AHCI Controller.
 
Error: (11/24/2013 04:43:30 PM) (Source: volsnap) (User: )
Description: The flush and hold writes operation on volume C: timed out while waiting for a release writes command.
 
Error: (10/14/2013 00:53:44 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070103: Intel Corporation - Storage Controller - Intel® 7 Series Chipset Family SATA AHCI Controller.
 
Error: (10/12/2013 00:18:47 PM) (Source: NetBT) (User: )
Description: The name "WORKGROUP      :1d" could not be registered on the interface with IP address 192.168.1.100.
The computer with the IP address 192.168.1.102 did not allow the name to be claimed by
this computer.
 
Error: (10/11/2013 07:01:00 PM) (Source: DCOM) (User: ANNA)
Description: {3A185DDE-E020-4985-A8F2-E27CDC4A0F3A}
 
Error: (10/11/2013 07:44:25 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070103: Intel Corporation - Storage Controller - Intel® 7 Series Chipset Family SATA AHCI Controller.
 
 
Microsoft Office Sessions:
=========================
Error: (11/25/2013 08:07:20 PM) (Source: CltMngSvc)(User: )
Description: CltMngSvcServiceInstall: Fail to Start serviceSearch Protect by Conduit Updater (Error: 1056)
 
Error: (11/24/2013 04:43:33 PM) (Source: VSS)(User: )
Description: \\?\Volume{4ee90f4d-17f2-4b74-9969-608b3d9a25e0}\00x00000000, The operation completed successfully.
0x00000000, The operation completed successfully.
0x80042314, The shadow copy provider timed out while holding writes to the volume being shadow copied. This is probably due to excessive activity on the volume by an application or a system service. Try again later when activity on the volume is reduced.
0x00000000, The operation completed successfully.
 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (11/24/2013 04:43:31 PM) (Source: System Restore)(User: )
Description: C:\Windows\system32\svchost.exe -k netsvcsWindows Update0x81000101
 
Error: (10/14/2013 00:43:15 PM) (Source: System Restore)(User: )
Description: C:\Windows\system32\svchost.exe -k netsvcsWindows Update0x81000101
 
Error: (10/12/2013 08:45:10 AM) (Source: Customer Experience Improvement Program)(User: )
Description: 80070005
 
Error: (10/11/2013 03:02:34 PM) (Source: Application Error)(User: )
Description: pcdrsysinfocsmi.p5x6.0.6032.394ffe56d2MSVCR90.dll9.0.30729.68714fee5fd540000015000000000004267f24ac01cec6c532ed6f6eC:\Program Files\Dell Support Center\pcdrsysinfocsmi.p5xC:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_08e717a5a83adddf\MSVCR90.dll72e7065a-32b8-11e3-be83-b8763f76dfb0
 
Error: (10/11/2013 08:26:04 AM) (Source: Application Error)(User: )
Description: pcdrsysinfocsmi.p5x6.0.6032.394ffe56d2MSVCR90.dll9.0.30729.68714fee5fd540000015000000000004267f288c01cec68dcab46a67C:\Program Files\Dell Support Center\pcdrsysinfocsmi.p5xC:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_08e717a5a83adddf\MSVCR90.dll0edfd35d-3281-11e3-be83-b8763f76dfb0
 
Error: (10/11/2013 07:41:05 AM) (Source: Microsoft-Windows-Immersive-Shell)(User: ANNA)
Description: Allrecipes.Allrecipes_f8zhmzza100am!App-2144927142
 
Error: (09/29/2013 08:16:45 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80070005
 
Error: (09/27/2013 10:42:35 AM) (Source: Customer Experience Improvement Program)(User: )
Description: 80070005
 
 
=========================== Installed Programs ============================
 
µTorrent (Version: 3.3.1.30003)
Amazon Browser App (Version: 1.0.0.0)
AVG 2013 (Version: 13.0.3426)
AVG 2013 (Version: 13.0.3629)
AVG 2013 (Version: 2013.0.3426)
Bundled software uninstaller
Cisco WebEx Meetings
Coupon Server (Version: 1.27.153.10)
CyberLink LabelPrint 2.5 (Version: 2.5.5415a)
CyberLink Media Suite 10 (Version: 10.0.1.1913)
CyberLink Media Suite Essentials (Version: 10.0)
CyberLink Power2Go 8 (Version: 8.0.0.1904)
CyberLink PowerDirector 10 (Version: 10.0.1.1904)
CyberLink PowerDVD 10 (Version: 10.0.4318.52)
D3DX10 (Version: 15.4.2368.0902)
DAEMON Tools Lite (Version: 4.47.1.0335)
Dealply
DealPly (remove only) (Version: 4.8.7.2)
Dell Backup and Recovery - Support Software (Version: 1.0.0.2)
Dell Backup and Recovery (Version: 1.0.0.2)
Dell Product Registration (Version: 1.16.1)
Dell Support Center (Version: 3.2.6032.39)
Dell Touchpad (Version: 16.3.7.0)
Dell WLAN and Bluetooth Client Installation (Version: 10.0)
DSC/AA Factory Installer (Version: 3.2.6032.39)
Fast Free Converter (Version: 4.1)
Google Chrome (Version: 30.0.1599.69)
Google Update Helper (Version: 1.3.21.165)
Intel® Management Engine Components (Version: 8.1.0.1252)
Intel® Processor Graphics (Version: 9.17.10.2867)
Intel® Rapid Storage Technology (Version: 11.7.0.1013)
Intel® Trusted Connect Service Client (Version: 1.24.388.1)
Java 7 Update 45 (Version: 7.0.450)
Java Auto Updater (Version: 2.1.9.8)
McAfee SecurityCenter (Version: 11.6.511)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office (Version: 14.0.6120.5004)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Movie Maker (Version: 16.4.3505.0912)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT110 (Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
Photo Gallery (Version: 16.4.3505.0912)
Plants vs. Zombies
Qualcomm Atheros Bluetooth Suite (64) (Version: 8.0.0.218)
Quickset64 (Version: 10.15.012)
Realtek High Definition Audio Driver (Version: 6.0.1.6788)
Realtek USB 2.0 Card Reader (Version: 6.1.8400.39030)
Search Protect by conduit (Version: 1.7.0.72)
Search Protection (Version: 7.5.0.1)
Shared C Run-time for x64 (Version: 10.0.0)
Total Commander 64-bit (Remove or Repair) (Version: 8.01)
Vafmusic8 Toolbar (Version: 6.14.0.28)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1)
Windows Live Communications Platform (Version: 16.4.3505.0912)
Windows Live Essentials (Version: 16.4.3505.0912)
Windows Live Installer (Version: 16.4.3505.0912)
Windows Live Photo Common (Version: 16.4.3505.0912)
Windows Live PIMT Platform (Version: 16.4.3505.0912)
Windows Live SOXE (Version: 16.4.3505.0912)
Windows Live SOXE Definitions (Version: 16.4.3505.0912)
Windows Live UX Platform (Version: 16.4.3505.0912)
Windows Live UX Platform Language Pack (Version: 16.4.3505.0912)
WinRAR 4.20 (32-bit) (Version: 4.20.0)
 
========================= Memory info: ===================================
 
Percentage of memory in use: 42%
Total physical RAM: 3965.27 MB
Available physical RAM: 2280.25 MB
Total Pagefile: 4797.27 MB
Available Pagefile: 2233.02 MB
Total Virtual: 4095.88 MB
Available Virtual: 3969 MB
 
========================= Partitions: =====================================
 
1 Drive c: (OS) (Fixed) (Total:283.12 GB) (Free:218.14 GB) NTFS
3 Drive e: (PVZPC-AU) (CDROM) (Total:0.27 GB) (Free:0 GB) CDFS
4 Drive x: (PBR Image) (Fixed) (Total:13.83 GB) (Free:0.26 GB) NTFS
5 Drive y: (WINRETOOLS) (Fixed) (Total:0.49 GB) (Free:0.21 GB) NTFS
 
========================= Users: ========================================
 
User accounts for \\ANNA
 
Administrator            Anna                     Guest                    
zbyni_000                
 
 
**** End of log ****
 
the rest coming soon...
# AdwCleaner v3.013 - Report created 25/11/2013 at 21:19:34
# Updated 24/11/2013 by Xplode
# Operating System : Windows 8  (64 bits)
# Username : Anna - ANNA
# Running from : C:\Users\Anna\Desktop\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
Service Deleted : CltMngSvc
[#] Service Deleted : dealplylive
[#] Service Deleted : dealplylivem
Service Deleted : FastFreeConverterUpdt
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\Searchprotect
[!] Folder Deleted : C:\ProgramData\DealPlyLive
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\DealPly
[!] Folder Deleted : C:\Program Files (x86)\DealPlyLive
Folder Deleted : C:\Program Files (x86)\Fast Free Converter
Folder Deleted : C:\Program Files (x86)\File Type Helper
Folder Deleted : C:\Program Files (x86)\Searchprotect
Folder Deleted : C:\Program Files (x86)\Coupon Server
Folder Deleted : C:\Program Files (x86)\Vafmusic8
Folder Deleted : C:\Users\Anna\AppData\Local\Bundled software uninstaller
Folder Deleted : C:\Users\Anna\AppData\Local\Conduit
Folder Deleted : C:\Users\Anna\AppData\Local\DealPlyLive
Folder Deleted : C:\Users\Anna\AppData\Local\Coupon Server
Folder Deleted : C:\Users\Anna\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Anna\AppData\LocalLow\Fast Free Converter
Folder Deleted : C:\Users\Anna\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Anna\AppData\LocalLow\Vafmusic8
Folder Deleted : C:\Users\Anna\AppData\Roaming\DealPly
Folder Deleted : C:\Users\Anna\AppData\Roaming\Search Protection
Folder Deleted : C:\Users\Anna\AppData\Roaming\Searchprotect
Folder Deleted : C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
Folder Deleted : C:\Users\zbyni_000\AppData\Roaming\Searchprotect
Folder Deleted : C:\Users\Administrator\AppData\LocalLow\Fast Free Converter
Folder Deleted : C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\mphpbdjcljebbcnfopfngmfdackbbdgf
Folder Deleted : C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\mogmppbjfkngfoaecoialclfiabnpndg
File Deleted : C:\END
File Deleted : C:\Windows\Tasks\Dealply.job
File Deleted : C:\Windows\System32\Tasks\Dealply
File Deleted : C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job
File Deleted : C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineCore
File Deleted : C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job
File Deleted : C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineUA
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKCU\Software\Google\Chrome\Extensions\mogmppbjfkngfoaecoialclfiabnpndg
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mogmppbjfkngfoaecoialclfiabnpndg
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SearchProtect]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dealplylive.exe
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLive.OneClickCtrl.9
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLive.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLive.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLive.Update3WebControl.3
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.coreclass
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.credentialdialogmachine
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.credentialdialogmachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.ondemandcomclassmachine
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.ondemandcomclassmachinefallback
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.ondemandcomclassmachinefallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.ondemandcomclasssvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3webmachine
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3webmachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3webmachinefallback
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3webmachinefallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3websvc
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3websvc.1.0
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dealplylive.exe
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchProtectAll]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=3
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=9
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0035852.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0035852.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0035852.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0035852.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3303001
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{80FABB17-63AF-4655-9F07-B6509EE37AF2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{F48FC5B2-094A-44C7-B48C-289738C9582D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0D89DE71-3D99-4288-84DC-F18F1047A7D8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1E0C9B2A-6447-452C-B012-2314A0C29412}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{34A8CEB6-89BB-49F1-B5E4-0D0D6C21F3B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3A4DBD3A-98CC-41CE-AD21-352D42B6F754}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4F8A50F6-69DE-4BE3-A33A-A1079B9AC0DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{501CB57A-D4E2-4855-96AD-EDB0A9083395}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6FF2C4DD-77A4-4BB5-BA4C-B42DEFBF9137}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80FABB17-63AF-4655-9F07-B6509EE37AF2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{83ABA270-8390-4CA6-AE48-FC089F55629E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8B218A5F-1A3D-4347-94EF-A79575EB8094}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9BDB5E09-4BBA-4422-8C2B-529B281C32B8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE48ED75-5A56-4C5F-BBCE-6F1AC3875F66}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C536F080-57B7-46D6-8894-C647553F2889}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA5D945F-E738-4D0B-A0B5-25AC51C64659}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F48FC5B2-094A-44C7-B48C-289738C9582D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F7698761-4ABA-45C2-A5BB-D2163922C725}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FFCC53E6-2655-47FC-A89B-54E8D7F305D1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2088F46C-E352-46DD-9434-BB81014359DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E7007A9-D556-4668-957D-A95836C91F8B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110311581152}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220322582252}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355585552}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366586652}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440344584452}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE48ED75-5A56-4C5F-BBCE-6F1AC3875F66}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2088F46C-E352-46DD-9434-BB81014359DB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311581152}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE48ED75-5A56-4C5F-BBCE-6F1AC3875F66}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311581152}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE48ED75-5A56-4C5F-BBCE-6F1AC3875F66}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110311581152}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6E7007A9-D556-4668-957D-A95836C91F8B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C536F080-57B7-46D6-8894-C647553F2889}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0fe56ab1-9530-4a1d-9059-a3ddc689e603}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{284020b9-6a9a-448c-912a-c994b2cd861a}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3d15aa1d-6658-4952-bb59-e6dc38305c7b}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4bd0a216-2c79-410f-a172-ed91cbbd3741}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8c6fb671-4b9c-434c-bb4c-6cb785bd4805}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00D0308C-B523-4066-A59F-29D62E0198BF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C9430634-D4F9-4B6E-A9C6-2B90DEB32B95}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2088F46C-E352-46DD-9434-BB81014359DB}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2088F46C-E352-46DD-9434-BB81014359DB}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{2088F46C-E352-46DD-9434-BB81014359DB}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{2088F46C-E352-46DD-9434-BB81014359DB}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355585552}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366586652}
Value Deleted : HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist [1]
Key Deleted : HKCU\Software\BI
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\DealPly
Key Deleted : HKCU\Software\DealPlyLive
Key Deleted : HKCU\Software\installedbrowserextensions
Key Deleted : HKCU\Software\SearchProtect
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\Coupon Server
Key Deleted : HKCU\Software\AppDataLow\Software\Vafmusic8
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DealPly
Key Deleted : HKLM\Software\DealPlyLive
Key Deleted : HKLM\Software\Fast Free Converter
Key Deleted : HKLM\Software\SearchProtect
Key Deleted : HKLM\Software\Coupon Server
Key Deleted : HKLM\Software\Vafmusic8
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DealPly
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fast Free Converter
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Coupon Server
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Vafmusic8 Toolbar
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v10.0.9200.16537
 
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
 
-\\ Google Chrome v30.0.1599.69
 
[ File : C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
[ File : C:\Users\zbyni_000\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [13716 octets] - [25/11/2013 21:18:01]
AdwCleaner[S0].txt - [13610 octets] - [25/11/2013 21:19:34]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13671 octets] ##########


#4 JinKazama23

JinKazama23
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:03:03 PM

Posted 25 November 2013 - 10:51 PM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 8 x64
Ran by Anna on 2013-11-25 at 21:25:56,96
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\searchprotection
 
 
 
~~~ Registry Keys
 
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\dealplylive
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BB2CBDE2-9EF6-4A83-87F7-6B15467FFA1C}
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] "C:\Users\Anna\appdata\local\cre"
 
 
 
~~~ Chrome
 
Successfully deleted: [Folder] C:\Users\Anna\appdata\local\Google\Chrome\User Data\Default\Extensions\mphpbdjcljebbcnfopfngmfdackbbdgf
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 2013-11-25 at 21:34:13,66
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


#5 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,072 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:03 PM

Posted 25 November 2013 - 10:52 PM

Good your getting it out..
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#6 JinKazama23

JinKazama23
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:03:03 PM

Posted 26 November 2013 - 01:57 AM

Here's ESET, doesn't look too pretty.

 

C:\AdwCleaner\Quarantine\C\Program Files (x86)\Coupon Server\Coupon Server-bg.exe.vir a variant of Win32/Toolbar.CrossRider.H application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Coupon Server\Coupon Server-bho.dll.vir a variant of Win32/Toolbar.CrossRider.H application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Coupon Server\Coupon Server-buttonutil.dll.vir probably a variant of Win32/Toolbar.CrossRider.H application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Coupon Server\Coupon Server-buttonutil.exe.vir a variant of Win32/Toolbar.CrossRider.I application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Coupon Server\Coupon Server-buttonutil64.dll.vir a variant of Win64/Toolbar.Crossrider.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Coupon Server\Coupon Server-buttonutil64.exe.vir a variant of Win64/Toolbar.Crossrider.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Coupon Server\Coupon Server-codedownloader.exe.vir a variant of Win32/Toolbar.CrossRider.J application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Coupon Server\Coupon Server-helper.exe.vir a variant of Win32/Toolbar.CrossRider.I application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\DealPly\DealPly.crx.vir Win32/DealPly.J application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\DealPly\DealPly.xpi.vir Win32/DealPly.J application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\DealPly\DealPlyIE.dll.vir a variant of Win32/DealPly.G application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\DealPly\DealPlyUpdateVer.exe.vir a variant of Win32/DealPly.F application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\bin\ChromeModule.dll.vir probably a variant of Win32/Conduit.SearchProtect.C application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\bin\cltmng.exe.vir a variant of Win32/Conduit.SearchProtect.B application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\bin\CltMngSvc.exe.vir Win32/Conduit.SearchProtect.E application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\bin\FirefoxModule.dll.vir probably a variant of Win32/Conduit.SearchProtect.C application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\bin\InternetExplorerModule.dll.vir probably a variant of Win32/Conduit.SearchProtect.C application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\bin\SPRunner.exe.vir a variant of Win32/Conduit.SearchProtect.D application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\ffprotect\application.js.vir Win32/Conduit.SearchProtect.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\ffprotect\nsprotector.js.vir Win32/Conduit.SearchProtect.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Vafmusic8\ldrtbVafm.dll.vir a variant of Win32/Toolbar.Conduit.P application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Vafmusic8\tbVafm.dll.vir a variant of Win32/Toolbar.Conduit.B application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\Local\Bundled software uninstaller\bi_client.exe.vir Win32/Somoto.A application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\Local\Conduit\CT3303001\Vafmusic8AutoUpdateHelper.exe.vir multiple threats
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\mphpbdjcljebbcnfopfngmfdackbbdgf\3.5.0.0_0\background.js.vir Win32/DealPly.J application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\LocalLow\Vafmusic8\ldrtbVaf0.dll.vir a variant of Win32/Toolbar.Conduit.P application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\LocalLow\Vafmusic8\ldrtbVafm.dll.vir a variant of Win32/Toolbar.Conduit.P application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\LocalLow\Vafmusic8\tbVaf0.dll.vir a variant of Win32/Toolbar.Conduit.B application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\LocalLow\Vafmusic8\tbVafm.dll.vir a variant of Win32/Toolbar.Conduit.B application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe.vir a variant of Win32/DealPly.F application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\Roaming\Search Protection\SearchProtection.exe.vir a variant of Win32/Toolbar.Widgi application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\Roaming\Searchprotect\bin\ChromeModule.dll.vir probably a variant of Win32/Conduit.SearchProtect.C application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\Roaming\Searchprotect\bin\cltmng.exe.vir a variant of Win32/Conduit.SearchProtect.B application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\Roaming\Searchprotect\bin\CltMngSvc.exe.vir Win32/Conduit.SearchProtect.E application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\Roaming\Searchprotect\bin\FirefoxModule.dll.vir probably a variant of Win32/Conduit.SearchProtect.C application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\Roaming\Searchprotect\bin\InternetExplorerModule.dll.vir probably a variant of Win32/Conduit.SearchProtect.C application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\Roaming\Searchprotect\bin\SPRunner.exe.vir a variant of Win32/Conduit.SearchProtect.D application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\Roaming\Searchprotect\ffprotect\application.js.vir Win32/Conduit.SearchProtect.A application
C:\AdwCleaner\Quarantine\C\Users\Anna\AppData\Roaming\Searchprotect\ffprotect\nsprotector.js.vir Win32/Conduit.SearchProtect.A application
C:\AdwCleaner\Quarantine\C\Users\zbyni_000\AppData\Roaming\Searchprotect\bin\ChromeModule.dll.vir a variant of Win32/Conduit.SearchProtect.C application
C:\AdwCleaner\Quarantine\C\Users\zbyni_000\AppData\Roaming\Searchprotect\bin\cltmng.exe.vir a variant of Win32/Conduit.SearchProtect.B application
C:\AdwCleaner\Quarantine\C\Users\zbyni_000\AppData\Roaming\Searchprotect\bin\CltMngSvc.exe.vir Win32/Conduit.SearchProtect.E application
C:\AdwCleaner\Quarantine\C\Users\zbyni_000\AppData\Roaming\Searchprotect\bin\FirefoxModule.dll.vir a variant of Win32/Conduit.SearchProtect.C application
C:\AdwCleaner\Quarantine\C\Users\zbyni_000\AppData\Roaming\Searchprotect\bin\InternetExplorerModule.dll.vir a variant of Win32/Conduit.SearchProtect.C application
C:\AdwCleaner\Quarantine\C\Users\zbyni_000\AppData\Roaming\Searchprotect\bin\SPHook32.dll.vir probably a variant of Win32/Conduit.SearchProtect.C application
C:\AdwCleaner\Quarantine\C\Users\zbyni_000\AppData\Roaming\Searchprotect\bin\SPRunner.exe.vir Win32/Conduit.SearchProtect.D application
C:\AdwCleaner\Quarantine\C\Users\zbyni_000\AppData\Roaming\Searchprotect\ffprotect\application.js.vir Win32/Conduit.SearchProtect.A application
C:\AdwCleaner\Quarantine\C\Users\zbyni_000\AppData\Roaming\Searchprotect\ffprotect\nsprotector.js.vir Win32/Conduit.SearchProtect.A application
C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\hstart.exe a variant of Win32/HiddenStart.A application
C:\Users\Anna\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\63ZHVWMN\SPSetup[1].exe multiple threats
C:\Users\Anna\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HBDFR1KG\bi_downloader[1].exe Win32/Somoto.A application
C:\Users\Anna\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KUZV2011\BiTool[1].dll Win32/Somoto.C application
C:\Users\Anna\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KUZV2011\Vafmusic8[1].exe multiple threats
C:\Users\Anna\AppData\Local\Temp\bitool.dll Win32/Somoto.C application
C:\Users\Anna\AppData\Local\Temp\dp.exe a variant of Win32/DealPly.I application
C:\Users\Anna\AppData\Local\Temp\nsz7678.tmp Win32/Somoto.A application
C:\Users\Anna\AppData\Local\Temp\SearchProtectionSetup.exe probably a variant of Win32/Toolbar.Widgi application
C:\Users\Anna\AppData\Local\Temp\SecondStepInstaller.exe multiple threats
C:\Users\Anna\AppData\Local\Temp\ct3303001\ieLogic.exe multiple threats
C:\Users\Anna\AppData\Local\Temp\DIQM\daemon-tools-lite_036\daemon-tools-lite_V.179628875c.exe probably a variant of Win32/DomaIQ.L application
C:\Users\Anna\AppData\Local\Temp\DIQM\daemon-tools-lite_036\setup__120.exe a variant of Win32/Amonetize.H application
C:\Users\Anna\AppData\Local\Temp\DIQM\daemon-tools-lite_036\software\CouponServer.exe Win32/Packed.ScrambleWrapper.C application
C:\Users\Anna\Downloads\daemon-tools-lite_V.179628875c.exe multiple threats
C:\Users\Anna\Downloads\DTLite4471-0335.exe multiple threats
C:\Users\Anna\Downloads\iLividSetup-r352-n-bc.exe Win32/Toolbar.SearchSuite application
C:\Users\Anna\Downloads\Setup.exe a variant of Win32/Adware.iBryte.G application


#7 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,072 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:03 PM

Posted 26 November 2013 - 11:46 AM

Yes but the bright side is it now gone. Your AV is outdated, AVG 2013 and that don't help.


Empty your temp folders using TFC (Temporary File Cleaner)
  • Please download TFC by Old Timer and save it to your desktop.
    alternate download link
  • Save any unsaved work. (TFC will close ALL open programs including your browser!)
  • Double-click on TFC.exe to run it. (If you are using Vista, right-click on the file and choose "Run As Administrator".)
  • Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
  • Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway allowing Windows to load normally (not into Safe Mode) to ensure a complete clean.
Run one more tool...

Please download aswMBR ( 4.5MB ) to your desktop.
  • Double click the aswMBR.exe icon, and click Run.
  • When asked if you'd like to "download the latest Avast! virus definitions", click Yes.
  • Click the Scan button to start the scan.
  • On completion of the scan, click the save log button, save it to your desktop, then copy and paste it in your next reply.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#8 JinKazama23

JinKazama23
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:03:03 PM

Posted 26 November 2013 - 06:37 PM

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-11-26 17:34:48
-----------------------------
17:34:48.354    OS Version: Windows x64 6.2.9200 
17:34:48.355    Number of processors: 2 586 0x3A09
17:34:48.357    ComputerName: ANNA  UserName: Anna
17:34:48.570    Initialze error 1 
17:36:48.386    AVAST engine defs: 13112600
17:37:13.935    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000034
17:37:13.938    Disk 0 Vendor: Hitachi_HTS545032A7E380 GGBOA950 Size: 305245MB BusType: 11
17:37:13.947    Disk 0 MBR read successfully
17:37:13.950    Disk 0 MBR scan
17:37:13.956    Disk 0 unknown MBR code
17:37:13.961    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
17:37:13.969    Disk 0 scanning C:\Windows\system32\drivers
17:37:13.972    Service scanning
17:37:14.671    Modules scanning
17:37:14.678    Disk 0 trace - called modules:
17:37:14.712    ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll iaStorA.sys 
17:37:14.717    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800600f740]
17:37:14.721    3 CLASSPNP.SYS[fffff88000aece0a] -> nt!IofCallDriver -> \Device\00000034[0xfffffa8004cad720]
17:37:14.903    AVAST engine scan C:\Windows
17:37:14.918    AVAST engine scan C:\Windows\system32
17:37:14.934    AVAST engine scan C:\Windows\system32\drivers
17:37:14.946    AVAST engine scan C:\Users\Anna
17:37:14.957    AVAST engine scan C:\ProgramData
17:37:14.964    Scan finished successfully
17:37:26.034    Disk 0 MBR has been saved successfully to "C:\Users\Anna\Desktop\MBR.dat"
17:37:26.043    The log file has been saved successfully to "C:\Users\Anna\Desktop\aswMBR.txt"
 
 
I was concerned about ESET scan, because at the end it said 66 threats were found and 0 items were cleaned. 


#9 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,072 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:03 PM

Posted 26 November 2013 - 08:52 PM

Run ESET again..

◾Under scan settings, check "Scan Archives" and "Remove found threats"
Click Advanced settings and select the following:
◾Scan potentially unwanted applications
◾Scan for potentially unsafe applications
◾Enable Anti-Stealth technology


How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#10 JinKazama23

JinKazama23
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:03:03 PM

Posted 27 November 2013 - 01:24 AM

Done.This time 53 infections have been found and removed.



#11 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,072 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:03 PM

Posted 27 November 2013 - 01:29 PM

Ok, then this should be running well now.


How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#12 JinKazama23

JinKazama23
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:03:03 PM

Posted 27 November 2013 - 02:15 PM

Yup everything looks good. 

Thanks!



#13 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,072 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:03 PM

Posted 27 November 2013 - 02:39 PM

You're welcome... Happy Thanksgiving!!
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users