Hi guys, I need help this following message keeps popping up on the bottom of my screen: g.js adadvisor.net, then asks me if I want to OPEN ,SAVE or CANCEL. I have been getting this massage for the last 2 weeks.
any help would be greatly appreciated. I am using VISTA IE9
Thank You
Sam
Hello
babbagene and welcome to the
WTT forum.
My name is
Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
please follow all instructions in the order posted please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear all logs/reports, etc. must be posted in Notepad . Please ensure that word wrap is un checked . In Notepad click Format , uncheck Word wrap if it is checked if you don't understand something, please don't hesitate to ask for clarification before proceeding the fixes are specific to your problem and should only be used for this issue on this machine. please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed! IMPORTANT :
Please
DO NOT install/uninstall any programs unless asked to.
Please
DO NOT run any scans other than those requested
===================================================
adadvisor.net is a domain used by Targus Info, an advertising company that is part of a network of sites et al used to track you, what you do and what you click on, as you go from site to site.
Over time, adadvisor.net and other sites that do the same, can help make an online profile of the sites you visit, your searches, purchases, and other behaviour. Your profile can then be exchanged and sold between other companies like adadvisor.net as well as being sold to other advertisers and marketers.
Let’s see what else is lurking.
===================================================
Download and run OTL
===================================================
Run aswMBR download aswMBR.exe to your desktop. double click the aswMBR.exe to run it if asked, accept the AVAST virus definition download click the "Scan" button to start scan on completion of the scan click Save log , save it to your desktop and post in your next reply Logs to include with next post :
OTL.txt
Extras.txt
aswMBR log
Thanks
Satchfan
Hi Satchfan, TY for your help. I tried to save the OTL to the desktop , but I keep getting this message: c:\user\sam\downloads\otl(3).exe is not a valid win32 application. I can never get it to the desktop or downloaded.
Hi babbagene
Try Running
aswMBR .
If this also won't run, try them both in Safe mode.
To Enter Safemode go to Start> Shut off your Computer> Restart as the computer starts to boot-up, tap the F8 KEY - this will bring up a menu use the Up and Down Arrow Keys to scroll up to Safemode with Networking then press Enter on your keyboard
Satchfan
Hi Satch , I was able to run it in regular mode , here is the log:
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-04-30 16:28:01
—————————–
16:28:01.860 OS Version: Windows 6.0.6002 Service Pack 2
16:28:01.860 Number of processors: 2 586 0x6B02
16:28:01.861 ComputerName: SAM-PC UserName: Sam
16:28:06.481 Initialize success
16:28:41.094 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000056
16:28:41.099 Disk 0 Vendor: ST500DM0 JC4B Size: 476940MB BusType: 6
16:28:41.113 Disk 0 MBR read successfully
16:28:41.119 Disk 0 MBR scan
16:28:41.127 Disk 0 unknown MBR code
16:28:41.136 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 466452 MB offset 63
16:28:41.170 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10485 MB offset 955295744
16:28:41.195 Disk 0 scanning sectors +976769024
16:28:41.263 Disk 0 scanning C:\Windows\system32\drivers
16:28:47.447 Service scanning
16:28:57.686 Modules scanning
16:29:02.608 Disk 0 trace - called modules:
16:29:02.623 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys
16:29:02.629 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85e61140]
16:29:02.992 3 CLASSPNP.SYS[8072e8b3] -> nt!IofCallDriver -> [0x85489700]
16:29:03.000 5 acpi.sys[8060b6bc] -> nt!IofCallDriver -> \Device\00000056[0x846a8b88]
16:29:03.007 Scan finished successfully
16:29:13.994 Disk 0 MBR has been saved successfully to "C:\Users\Sam\Documents\MBR.dat"
16:29:14.000 The log file has been saved successfully to "C:\Users\Sam\Documents\aswMBR.txt"
Let's try a different scan.
Run DDS
Please download DDS by sUBs from one of the following links and save it to your desktop.
DDS.scr
DDS.pif
disable any script blocking protection (How to Disable your Security Programs ) double click DDS icon to run the tool (may take up to 3 minutes to run) when done, DDS.txt will open. after a few moments, attach.txt will open in a second window. save both reports to your desktop. Post the contents of the DDS.txt and Attach.txt reports in your next reply
Satchfan
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by [removed] at 17:52:51 on 2012-04-30
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1464 [GMT -4:00]
.
AV: Norton Security Suite *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Security Suite *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Security Suite *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k hpdevmgmt
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton Security Suite\Engine\5.2.1.3\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Norton Security Suite\Engine\5.2.1.3\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\hp\support\hpsysdrv.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe
C:\WINDOWS\System32\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\hp\kbd\kbd.exe
c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_2_202_233_ActiveX.exe
C:\Users\Sam\AppData\Roaming\mjusbsp\st00000\mjsetup.exe
C:\Users\Sam\AppData\Roaming\mjusbsp\magicJack.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cndt
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cndt
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cndt
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton security suite\engine\5.2.1.3\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton security suite\engine\5.2.1.3\ips\IPSBHO.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton security suite\engine\5.2.1.3\coIEPlg.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN
uRun: [cdloader] "c:\users\sam\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [KBD] c:\hp\kbd\KbdStub.EXE
mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: []
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe"
mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\snapfi~1.lnk - c:\program files\snapfish picture mover\SnapfishMediaDetector.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{6CA0F23B-C7FC-430F-93B0-CB54DE0E3C35} : DhcpNameServer = 75.75.75.75 75.75.76.76
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0502010.003\symds.sys [2012-4-23 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0502010.003\symefa.sys [2012-4-23 744568]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\bashdefs\20120413.001\BHDrvx86.sys [2012-4-19 821880]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\ipsdefs\20120427.001\IDSvix86.sys [2012-4-27 368248]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0502010.003\ironx86.sys [2012-4-23 136312]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0502010.003\symtdiv.sys [2012-4-23 331384]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 N360;Norton Security Suite;c:\program files\norton security suite\engine\5.2.1.3\ccsvchst.exe [2012-4-23 130008]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-4-15 106104]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-14 253088]
.
=============== Created Last 30 ================
.
2012-04-30 07:26:46 ——– d—–w- c:\program files\Pure Networks
2012-04-30 07:26:10 ——– d—–w- c:\programdata\webex
2012-04-30 07:25:59 8673792 —-a-w- c:\programdata\atscie.msi
2012-04-30 07:23:51 24880 —-a-w- c:\windows\system32\drivers\pnarp.sys
2012-04-30 07:22:37 26416 —-a-w- c:\windows\system32\drivers\purendis.sys
2012-04-30 07:22:35 ——– d—–w- c:\program files\common files\Pure Networks Shared
2012-04-30 07:22:23 ——– d—–w- c:\programdata\Pure Networks
2012-04-30 07:22:23 ——– d—–w- c:\program files\Linksys
2012-04-28 21:48:13 ——– d—–w- c:\users\sam\appdata\local\Microsoft Games
2012-04-26 20:22:30 ——– d—–w- c:\users\sam\appdata\roaming\WildTangent
2012-04-24 03:59:36 331384 —-a-w- c:\windows\system32\drivers\n360\0502010.003\symtdiv.sys
2012-04-24 03:59:36 299640 —-a-w- c:\windows\system32\drivers\n360\0502010.003\symnets.sys
2012-04-24 03:59:35 744568 —-a-w- c:\windows\system32\drivers\n360\0502010.003\symefa.sys
2012-04-24 03:59:35 516216 —-a-w- c:\windows\system32\drivers\n360\0502010.003\srtsp.sys
2012-04-24 03:59:35 50168 —-a-w- c:\windows\system32\drivers\n360\0502010.003\srtspx.sys
2012-04-24 03:59:35 340088 —-a-w- c:\windows\system32\drivers\n360\0502010.003\symds.sys
2012-04-24 03:59:35 136312 —-a-r- c:\windows\system32\drivers\n360\0502010.003\ironx86.sys
2012-04-24 03:59:13 ——– d—–w- c:\windows\system32\drivers\n360\0502010.003
2012-04-23 22:05:39 ——– d—–w- c:\users\sam\appdata\roaming\Malwarebytes
2012-04-23 22:05:28 ——– d—–w- c:\programdata\Malwarebytes
2012-04-23 22:05:27 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-04-23 22:05:27 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-04-18 22:13:49 ——– d—–w- c:\program files\common files\xing shared
2012-04-18 01:59:11 ——– d—–w- c:\users\sam\appdata\local\Google
2012-04-17 22:34:03 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-04-17 22:34:03 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-04-17 22:34:03 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-04-17 22:34:03 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-04-17 22:34:03 1068544 —-a-w- c:\windows\system32\DWrite.dll
2012-04-17 14:54:28 ——– d—–w- c:\program files\Gamers Unite! Snag Bar
2012-04-17 07:11:18 5120 —-a-w- c:\windows\system32\wmi.dll
2012-04-17 07:11:18 172032 —-a-w- c:\windows\system32\wintrust.dll
2012-04-17 07:11:18 157696 —-a-w- c:\windows\system32\imagehlp.dll
2012-04-17 07:11:18 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-17 07:07:59 586240 —-a-w- c:\windows\system32\stobject.dll
2012-04-17 07:06:47 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2012-04-17 07:06:47 519680 —-a-w- c:\windows\system32\d3d11.dll
2012-04-17 07:06:47 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2012-04-17 07:06:47 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-04-17 07:06:47 252928 —-a-w- c:\windows\system32\dxdiag.exe
2012-04-17 07:06:47 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2012-04-17 07:06:47 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-04-17 01:55:59 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-04-17 01:51:40 613376 —-a-w- c:\windows\system32\rdpencom.dll
2012-04-17 01:51:40 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-16 20:49:35 ——– d—–w- c:\windows\system32\eu-ES
2012-04-16 20:49:35 ——– d—–w- c:\windows\system32\ca-ES
2012-04-16 20:49:33 ——– d—–w- c:\windows\system32\vi-VN
2012-04-16 17:50:48 ——– d—–w- c:\windows\system32\EventProviders
2012-04-16 11:38:59 97792 —-a-w- c:\windows\system32\mprapi.dll
2012-04-16 07:01:38 99176 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2012-04-16 07:01:38 49472 —-a-w- c:\windows\system32\netfxperf.dll
2012-04-16 07:01:38 297808 —-a-w- c:\windows\system32\mscoree.dll
2012-04-16 07:01:38 295264 —-a-w- c:\windows\system32\PresentationHost.exe
2012-04-16 07:01:38 1130824 —-a-w- c:\windows\system32\dfshim.dll
2012-04-16 07:00:58 ——– d—–w- c:\program files\MSXML 4.0
2012-04-15 14:09:11 17920 —-a-w- c:\windows\system32\netevent.dll
2012-04-15 14:09:11 125952 —-a-w- c:\windows\system32\srvsvc.dll
2012-04-15 04:12:17 995383 —-a-w- c:\windows\system32\temp.001
2012-04-15 04:12:17 295000 —-a-w- c:\windows\system32\temp.000
2012-04-15 04:12:15 ——– d—–w- c:\program files\ClubWPT
2012-04-15 04:02:16 ——– d—–w- c:\programdata\WEBREG
2012-04-15 04:00:25 ——– d—–w- c:\users\sam\appdata\local\HP
2012-04-15 03:54:56 274944 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\hpzpp5ha.dll
2012-04-15 03:51:23 ——– d—–w- c:\program files\common files\Hewlett-Packard
2012-04-15 03:50:55 ——– d—–w- c:\program files\common files\HP
2012-04-15 03:49:43 118272 —-a-w- c:\windows\system32\hpz3l5ha.dll
2012-04-15 03:47:33 970752 —-a-w- c:\windows\system32\hpotiop5.dll
2012-04-15 03:47:33 729088 —-a-w- c:\windows\system32\hpowiax5.dll
2012-04-15 03:47:33 364544 —-a-w- c:\windows\system32\hppldcoi.dll
2012-04-15 03:47:33 309760 —-a-w- c:\windows\system32\difxapi.dll
2012-04-15 03:47:33 303104 —-a-w- c:\windows\system32\hpovst12.dll
2012-04-15 03:47:33 271704 —-a-w- c:\windows\system32\hpzids01.dll
2012-04-14 20:07:56 411648 —-a-w- c:\windows\system32\drivers\http.sys
2012-04-14 20:07:56 24064 —-a-w- c:\windows\system32\nshhttp.dll
2012-04-14 20:07:55 30720 —-a-w- c:\windows\system32\httpapi.dll
2012-04-14 20:06:04 708608 —-a-w- c:\program files\common files\system\ado\msado15.dll
2012-04-14 20:06:04 57344 —-a-w- c:\program files\common files\system\msadc\msadcs.dll
2012-04-14 20:06:04 413696 —-a-w- c:\windows\system32\odbc32.dll
2012-04-14 20:06:04 253952 —-a-w- c:\program files\common files\system\ado\msadox.dll
2012-04-14 20:06:04 241664 —-a-w- c:\program files\common files\system\ado\msadomd.dll
2012-04-14 20:06:04 180224 —-a-w- c:\program files\common files\system\msadc\msadco.dll
2012-04-14 20:06:00 66048 —-a-w- c:\program files\windows mail\wabmig.exe
2012-04-14 20:06:00 515584 —-a-w- c:\program files\windows mail\wab.exe
2012-04-14 20:06:00 33280 —-a-w- c:\program files\windows mail\wabfind.dll
2012-04-14 20:04:59 218624 —-a-w- c:\windows\system32\msv1_0.dll
2012-04-14 19:56:27 91136 —-a-w- c:\windows\system32\avifil32.dll
2012-04-14 19:56:27 82944 —-a-w- c:\windows\system32\mciavi32.dll
2012-04-14 19:56:27 50176 —-a-w- c:\windows\system32\iyuv_32.dll
2012-04-14 19:56:27 31744 —-a-w- c:\windows\system32\msvidc32.dll
2012-04-14 19:56:27 22528 —-a-w- c:\windows\system32\msyuv.dll
2012-04-14 19:56:27 13312 —-a-w- c:\windows\system32\msrle32.dll
2012-04-14 19:56:27 123904 —-a-w- c:\windows\system32\msvfw32.dll
2012-04-14 19:56:27 12288 —-a-w- c:\windows\system32\tsbyuv.dll
2012-04-14 18:52:15 2048 —-a-w- c:\program files\internet explorer\iecompat.dll
2012-04-14 18:52:10 265720 —-a-w- c:\program files\internet explorer\msdbg2.dll
2012-04-14 18:52:09 355832 —-a-w- c:\program files\internet explorer\pdm.dll
2012-04-14 18:18:58 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-04-14 18:18:57 126584 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-04-14 18:18:48 106928 —-a-w- c:\windows\system32\GEARAspi.dll
2012-04-14 18:18:44 ——– d—–w- c:\windows\system32\drivers\N360
2012-04-14 18:18:42 ——– d—–w- c:\program files\Norton Security Suite
2012-04-14 18:18:35 ——– d—–w- c:\programdata\NortonInstaller
2012-04-14 18:18:35 ——– d—–w- c:\program files\NortonInstaller
2012-04-14 18:16:37 ——– d—–w- c:\programdata\Norton
2012-04-14 18:13:25 472808 —-a-w- c:\windows\system32\deployJava1.dll
2012-04-14 18:02:12 ——– d—–w- c:\users\sam\appdata\local\ID Vault
2012-04-14 18:02:12 ——– d—–w- c:\programdata\IsolatedStorage
2012-04-14 18:02:00 ——– d—–w- c:\users\sam\appdata\roaming\ID Vault
2012-04-14 18:01:45 ——– d—–w- c:\program files\Constant Guard Protection Suite
2012-04-14 18:01:23 ——– d—–w- c:\programdata\White Sky, Inc
2012-04-14 17:54:47 ——– d—–w- c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP
2012-04-14 17:39:37 ——– d—–w- c:\users\sam\appdata\local\tjnet
2012-04-14 17:36:44 ——– d—–w- c:\users\sam\appdata\local\magicJack
2012-04-14 17:36:39 ——– d—–w- c:\programdata\magicJack
2012-04-14 17:36:07 ——– d—–w- c:\users\sam\appdata\roaming\mjusbsp
2012-04-14 14:13:22 ——– d—–w- c:\users\sam\appdata\roaming\Symantec
2012-04-14 14:12:53 ——– d—–w- c:\users\sam\appdata\local\VirtualStore
2012-04-14 14:10:20 98304 —-a-w- c:\windows\system32\cabview.dll
2012-04-14 14:09:25 ——– d—–w- c:\users\sam\appdata\roaming\HP TCS
2012-04-14 14:08:59 ——– d—–w- c:\users\sam\appdata\local\Adobe
2012-04-14 14:04:13 2421760 —-a-w- c:\windows\system32\wucltux.dll
2012-04-14 14:04:04 87552 —-a-w- c:\windows\system32\wudriver.dll
2012-04-14 14:04:01 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-04-14 14:04:01 171608 —-a-w- c:\windows\system32\wuwebv.dll
2012-04-14 14:03:24 ——– d-sh–we C:\Documents and Settings
.
==================== Find3M ====================
.
2012-04-18 22:13:35 348160 —-a-w- c:\windows\system32\msvcr71.dll
2012-04-17 07:07:59 209920 —-a-w- c:\windows\system32\mfplat.dll
2012-04-17 07:06:49 4096 —-a-w- c:\windows\system32\drivers\en-us\dxgkrnl.sys.mui
2012-04-14 20:05:45 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-14 20:05:45 418464 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-02-28 01:18:55 1799168 —-a-w- c:\windows\system32\jscript9.dll
2012-02-28 01:11:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2012-02-28 01:11:07 1127424 —-a-w- c:\windows\system32\wininet.dll
2012-02-28 01:03:16 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-02-02 15:16:25 2044416 —-a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 17:53:14.01 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 4/14/2012 12:59:21 PM
System Uptime: 4/30/2012 8:25:03 AM (9 hours ago)
.
Motherboard: OEM_MB | | NARRA3
Processor: AMD Athlon™ 64 X2 Dual Core Processor 5000+ | Socket AM2 | 2200/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 456 GiB total, 362.022 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 1.343 GiB free.
E: is CDROM (CDFS)
G: is Removable
H: is Removable
I: is Removable
J: is Removable
K: is CDROM ()
L: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: PS/2 Compatible Mouse
Device ID: ACPI\PNP0F13\4&37EFC377&0
Manufacturer: Microsoft
Name: PS/2 Compatible Mouse
PNP Device ID: ACPI\PNP0F13\4&37EFC377&0
Service: i8042prt
.
==== System Restore Points ===================
.
RP10: 4/14/2012 2:51:51 PM - Windows Update
RP11: 4/14/2012 2:53:00 PM - Windows Update
RP12: 4/14/2012 4:06:16 PM - Windows Update
RP14: 4/14/2012 11:49:13 PM - HP Installation Restore Point
RP15: 4/15/2012 3:00:11 AM - Windows Update
RP16: 4/16/2012 3:00:15 AM - Windows Update
RP17: 4/16/2012 4:31:28 AM - Windows Update
RP18: 4/16/2012 1:49:01 PM - Windows Update
RP19: 4/16/2012 1:50:10 PM - Windows Update
RP20: 4/16/2012 4:41:15 PM - Windows Update
RP21: 4/16/2012 8:02:48 PM - Norton Security Suite Registry
RP22: 4/17/2012 3:00:21 AM - Windows Update
RP23: 4/18/2012 1:06:52 AM - Scheduled Checkpoint
RP24: 4/18/2012 3:00:12 AM - Windows Update
RP25: 4/24/2012 12:15:18 PM - Scheduled Checkpoint
RP26: 4/25/2012 3:34:10 AM - Scheduled Checkpoint
RP27: 4/26/2012 1:12:43 AM - Removed Google Earth.
RP28: 4/26/2012 2:45:28 AM - Norton Security Suite Registry
RP29: 4/27/2012 1:52:53 AM - Scheduled Checkpoint
RP30: 4/28/2012 12:30:52 AM - Scheduled Checkpoint
RP32: 4/29/2012 2:17:50 AM - Scheduled Checkpoint
RP33: 4/30/2012 3:22:43 AM - Device Driver Package Install: Cisco Systems, Inc. Network Protocol
RP34: 4/30/2012 3:23:51 AM - Device Driver Package Install: Cisco Systems, Inc. Network Protocol
RP35: 4/30/2012 4:24:42 AM - Norton Security Suite Registry
.
==== Installed Programs ======================
.
32 Bit HP CIO Components Installer
Adobe Flash Player 11 ActiveX
Adobe Reader 8.1.2
AIO_Scan
BufferChm
C5200
C5200_Help
Cards_Calendar_OrderGift_DoMorePlugout
Cisco Network Magic
ClubWPT
Compatibility Pack for the 2007 Office system
Copy
CustomerResearchQFolder
CyberLink DVD Suite Deluxe
CyberLink PowerDirector
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DocProc
DocProcQFolder
Enhanced Multimedia Keyboard Solution
eSupportQFolder
Fax
GPBaseService
Hardware Diagnostic Tools
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Customer Feedback
HP Customer Participation Program 10.0
HP Demo
HP Imaging Device Functions 10.0
HP Photosmart All-In-One Driver Software 10.0 Rel .2
HP Photosmart Essential 2.5
HP Picasso Media Center Add-In
HP Solution Center 10.0
HP Total Care Advisor
HP Update
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotoSmartPhotobookWebPack1
HPProductAssistant
HPSSupply
HPTCSSetup
Java Auto Updater
Java™ 6 Update 31
Java™ SE Runtime Environment 6 Update 1
LabelPrint
LightScribe System Software 1.12.37.1
LightScribeTemplateLabeler
LiveUpdate (Symantec Corporation)
magicJack
Malwarebytes Anti-Malware version 1.61.0.1400
MarketResearch
Microsoft .NET Framework 3.5 SP1
Microsoft Office Home and Student 60 day trial
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 6.1
My HP Games
Network Magic
Norton Security Suite
NVIDIA Drivers
OCR Software by I.R.I.S. 10.0
PanoStandAlone
Power2Go
PS_AIO_02_ProductContext
PS_AIO_02_Software
PS_AIO_02_Software_Min
PSSWCORE
Pure Networks Platform
Python 2.5
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
Scan
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Shop for HP Supplies
Snapfish Picture Mover
Soft Data Fax Modem with SmartCP
SolutionCenter
Status
Toolbox
TrayApp
UnloadSupport
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VideoToolkit01
WebEx Support Manager for Internet Explorer
WebReg
.
==== Event Viewer Messages From Past Week ========
.
4/30/2012 8:27:17 AM, Error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting.
4/30/2012 8:26:21 AM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
4/30/2012 8:25:33 AM, Error: EventLog [6008] - The previous system shutdown at 7:48:19 AM on 4/30/2012 was unexpected.
4/30/2012 8:18:26 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Audiosrv service.
4/30/2012 8:16:55 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Eventlog service.
4/30/2012 3:48:32 AM, Error: cdrom [11] - The driver detected a controller error on \Device\CdRom3.
4/30/2012 3:29:28 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.103 for the Network Card with network address 002215259706 has been denied by the DHCP server [removed] (The DHCP Server sent a DHCPNACK message).
4/30/2012 10:38:13 AM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk5\DR6.
4/30/2012 1:47:05 AM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk1\DR26.
4/25/2012 8:09:04 PM, Error: bowser [8003] - The master browser has received a server announcement from the computer SAMANTHA that believes that it is the master browser for the domain on transport NetBT_Tcpip_{6CA0F23B-C7FC-430F-93B0-CB54DE0E3. The master browser is stopping or an election is being forced.
4/24/2012 12:03:32 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TrkWks service.
.
==== End Of File ===========================
Hi Sam
Nothing bad in that log so that's a good sign.
Uninstall the following program: 1. Click
Start ,
Control Panel ,
Programs , and then
Programs and Features .
2. Click on
Java™ SE Runtime Environment 6 Update 1 and then
Uninstall .
If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
===============================================
Clear all your temporary files
Download
ATF Cleaner double-click ATF-Cleaner.exe (on your desktop) to run the program. under Main choose: Select All click the Empty Selected button.
If you use Firefox browser click Firefox at the top and choose: Select All click the Empty Selected button.
NOTE : If you would like to keep your saved passwords, please click
No at the prompt.
If you use Opera browser click Opera at the top and choose: Select All click the Empty Selected button.
NOTE : If you would like to keep your saved passwords, please click
No at the prompt.
Click
Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu
===============================================
Run Malwarebytes’ Anti-Malware
I noticed that you had MBAM on your system: if you no longer have it, you can download it from
here :
start Malwarebytes-Anti-Malware and update it, (“Update” tab} once it is updated, click on “Scanner” tab, select Perform quick scan , then click Scan . when the scan is complete, click OK , then Show Results to view the results. be sure that everything is checked, and click Remove Selected . when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below) the log is automatically saved and can be viewed by clicking the Logs tab in MBAM. copy and paste the contents of that report in your next reply and exit MBAM.
NOTE : If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
Please let me know if there is any change
Satchfan
Good Morning Satchfan here is the log:
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.01.05
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Sam :: SAM-PC [administrator]
5/1/2012 6:18:34 AM
mbam-log-2012-05-01 (06-18-34).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 183497
Time elapsed: 3 minute(s), 36 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
Is the popup still happening now?
Hi Satchfan , so far so good , no pop-up any longer . I will let you know for sure tomorrow.
Thank You
Regards
Sam
Hi Sam
so far so good , no pop-up any longer . I will let you know for sure tomorrow
OK.
Can you meanwhile run this scan to make sure there is nothing else left behind.
Run ESET Online Scan
Note : You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read
here .
Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan 1. Click the
Eset online Scanner button.
2.
For alternate browsers only : (Microsoft Internet Explorer users can skip these steps)
• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.
3. Check
Yes, I accept the Terms of Use
4. Click the
Start button.
5. Accept any security warnings from your browser.
6. Check
Scan archives
7. Push the
Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push
List of found threats
10. Push
Export to Text file and save the file to your desktop using a unique name, such as
ESETScan . Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the
back button.
12. Push
Finish
If a log has been produced post it in your next reply.
Thanks
Satchfan
Hello babbagene
It has been several days since I posted instructions to help with your computer problem.
Please let me know if you are having problems and still need help.
Thanks
Satchfan
Im sorry Satch fan , I thought I wrote back to you . The problem has been resolved by youn . Thank You so much!
Regards
Sam
Hi Sam
I assume that the
Eset can came back clear.
Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:
Create a Restore Point click Start , right-click Computer , and then Properties . in the left pane, click System protection . If you're prompted for an administrator password or confirmation, type the password or provide confirmation. click the System Protection tab, and then click Create . in the System Protection dialog box, type a description, and then click Create .
Remove old restore points click the Start button and in the search box, type Disk Cleanup , and then, in the list of results, click Disk Cleanup . if prompted, select the drive that you want to clean up, and then click OK . in the Disk Cleanup for (drive letter) dialog box, click Clean up system files . If you're prompted for an administrator password or confirmation, type the password or provide confirmation. if prompted, select the drive that you want to clean up, and then click OK . click the More Options tab, under System Restore and Shadow Copies , click Clean up . in the Disk Cleanup dialog box, click Delete . click Delete Files , and then click OK .
===================================================
Update Reader
Visit
ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.
===================================================
Update and run Malwarebytes . This really is an excellent program that you should update and run on a regular basis, probably weekly.
===================================================
I also recommend that you read the following:
How to prevent malware by miekiemoes
Safe computing
Satchfan