#21  
Old 02-02-2013, 02:09 PM
jholland1964's Avatar
jholland1964 jholland1964 is offline
Almost Really Old Member
 
Join Date: Feb 2004
Location: The Middle
Posts: 30,998
Ok good. Now do this:

Download DDS by sUBs and save it to your Desktop.

http://www.bleepingcomputer.com/download/anti-virus/dds

Be sure follow the instructions below carefully
If your AV has a script blocker, please disable it
DoubleClick on dds.scr to run the tool
* A command box will open, displaying added information for your reading pleasure while DDS completes its scan.

* Upon completion, a Dialog Box should open instructing you to save and post the TWO resulting logs (DDS.txt & Attach.txt).
Copy&Paste both the DDS.txt and the DDS Attach.txt into your post for assistance.
Notice I say copy/paste BOTH logs. The Attach.txt log says at the top to attach it, please do not attach it but copy/paste it also

Both of these logs are very long and because of that will take multiple replies in order to post them here. Please split the logs carefully as each and every line must be seen.
__________________

1. Dell Inspiron N5040;
Windows 7 64bit SP1
Firefox v.33.0.2, IE11;WLM2012; Avira Free, Windows Firewall, MBAM, SpywareBlaster, SUPERAntispyware

2.Dell Inspiron N7010; Windows 7 64bit SP1
*same programs as computer 1 above*


Help Us To Help You

System Restore

Stick with the Clean up
Reply With Quote
  #22  
Old 02-02-2013, 02:30 PM
over easy's Avatar
over easy over easy is offline
sailor
 
Join Date: Apr 2009
Location: Rio Grande valley
Posts: 775
.
==== Installed Programs ======================
.
7-Zip 9.20 (x64 edition)
Adobe Digital Editions
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader XI
avast! Free Antivirus
Bejeweled 2 Deluxe 1.0
calibre
CCleaner
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Classic Shell
EnGenius 11n USB Wireless LAN Driver and Utility
Google Earth Plug-in
Google Update Helper
GPS Information
GPSinfo version S-0PC-07-1109022
Intel(R) Turbo Boost Technology Driver
K-Lite Codec Pack 7.0.0 (Standard)
Lexmark Printable Web
Lexmark S300-S400 Series
Lexmark Toolbar
Malwarebytes Anti-Malware version 1.70.0.1100
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Monster Mobile Media Manager
Mozilla Firefox 18.0.1 (x86 en-US)
Mozilla Maintenance Service
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MWSnap 3
Nitro Reader 2
NVIDIA Control Panel 304.79
NVIDIA Graphics Driver 304.79
NVIDIA HD Audio Driver 1.3.17.0
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.12.0604
O2Micro Flash Memory Card Windows Driver
OpenOffice.org 3.4.1
Picasa 3
PlayReady PC Runtime x86
Realtek WLAN Driver
Risk II
SeaClear II
SeaCOM
Secunia PSI (3.0.0.6001)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
SpeedFan (remove only)
Spybot - Search & Destroy
SumatraPDF
SUPERAntiSpyware
TOSHIBA Hardware Setup
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
VLC media player 2.0.5
WinPatrol
WinRAR 4.11 (32-bit)
.
==== End Of File ===========================
__________________
toshiba Qosmio x505, w7home premium, intel core i5, m450@240GHZ, 4gb ram, 64bit OS, avast free, spywareblaster free, spybot, and antimalware free, cclnr, FF .
Reply With Quote
  #23  
Old 02-02-2013, 02:31 PM
over easy's Avatar
over easy over easy is offline
sailor
 
Join Date: Apr 2009
Location: Rio Grande valley
Posts: 775
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16457
Run by Ron at 15:27:44 on 2013-02-02
.
============== Running Processes ================
.
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Windows\system32\DRIVERS\o2flash.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\PROGRAM FILES (X86)\SPYBOT - SEARCH & DESTROY 2\SDTRAY.EXE
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit = userinit.exe,
BHO: Lexmark Toolbar: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Lexmark Printable Web: {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
BHO: ClassicIE9BHO Class: {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll
TB: Lexmark Toolbar: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
mRun: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
IE: {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{35DA4339-7FEC-4227-8248-DA4EA236793D} : DHCPNameServer = 10.20.7.1
TCP: Interfaces\{35DA4339-7FEC-4227-8248-DA4EA236793D}\2656C6B696E6E2630383 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{35DA4339-7FEC-4227-8248-DA4EA236793D}\4335561637256543 : DHCPNameServer = 10.20.7.1
TCP: Interfaces\{35DA4339-7FEC-4227-8248-DA4EA236793D}\4516B656D29447D2541637970223 : DHCPNameServer = 192.168.254.254 192.168.254.254
TCP: Interfaces\{35DA4339-7FEC-4227-8248-DA4EA236793D}\45271696C656276596C6C616765613 : DHCPNameServer = 174.137.64.2 174.137.64.3
TCP: Interfaces\{35DA4339-7FEC-4227-8248-DA4EA236793D}\45271696C656276596C6C616765623 : DHCPNameServer = 174.137.64.2 174.137.64.3
TCP: Interfaces\{35DA4339-7FEC-4227-8248-DA4EA236793D}\65562796A7F6E602D494649443531303C402 6454833402355636572756 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{35DA4339-7FEC-4227-8248-DA4EA236793D}\D49646771697 : DHCPNameServer = 66.211.112.5 12.231.80.5
TCP: Interfaces\{4864F689-6BCF-4863-AE5D-00375F527DD2} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{4864F689-6BCF-4863-AE5D-00375F527DD2}\2656C6B696E6E2630383 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{4864F689-6BCF-4863-AE5D-00375F527DD2}\3464D4D4162796E616 : DHCPNameServer = 71.3.0.116 76.2.127.122
TCP: Interfaces\{4864F689-6BCF-4863-AE5D-00375F527DD2}\4516B656D29447D2541637970223 : DHCPNameServer = 192.168.254.254 192.168.254.254
TCP: Interfaces\{4864F689-6BCF-4863-AE5D-00375F527DD2}\54E656277656479636 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{4864F689-6BCF-4863-AE5D-00375F527DD2}\6496378696E676 : DHCPNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\13.2.0\ViProtocol.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
x64-mWinlogon: Userinit = C:\Windows\System32\userinit.exe
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll
x64-BHO: ClassicIE9BHO Class: {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll
x64-Run: [Classic Start Menu] C:\Program Files\Classic Shell\ClassicStartMenu.exe
x64-IE: {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
x64-IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Ron\AppData\Roaming\Mozilla\Firefox\Profi les\n65akm5f.default-1350721630696\
FF - prefs.js: browser.startup.homepage - about:home
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0\npsitesafety.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Nitro PDF\Reader 2\npdf.dll
FF - plugin: C:\Program Files (x86)\Nitro PDF\Reader 2\npnitroie.dll
FF - plugin: C:\Program Files (x86)\Nitro PDF\Reader 2\npnitromozilla.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_50 2_146.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2012-12-18 07:27; {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}; C:\Users\Ron\AppData\Roaming\Mozilla\Firefox\Profi les\n65akm5f.default-1350721630696\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - ExtSQL: 2012-12-31 14:04; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\Ron\AppData\Roaming\Mozilla\Firefox\Profi les\n65akm5f.default-1350721630696\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2012-12-31 14:04; elemhidehelper@adblockplus.org; C:\Users\Ron\AppData\Roaming\Mozilla\Firefox\Profi les\n65akm5f.default-1350721630696\extensions\elemhidehelper@adblockplu s.org.xpi
FF - ExtSQL: 2012-12-31 14:19; adblockpopups@jessehakanen.net; C:\Users\Ron\AppData\Roaming\Mozilla\Firefox\Profi les\n65akm5f.default-1350721630696\extensions\adblockpopups@jessehakane n.net.xpi
FF - ExtSQL: 2012-12-31 14:33; wrc@avast.com; C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2013-01-04 14:07; {b9db16a4-6edc-47ec-a1f4-b86292ed211d}; C:\Users\Ron\AppData\Roaming\Mozilla\Firefox\Profi les\n65akm5f.default-1350721630696\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
.
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
__________________
toshiba Qosmio x505, w7home premium, intel core i5, m450@240GHZ, 4gb ram, 64bit OS, avast free, spywareblaster free, spybot, and antimalware free, cclnr, FF .
Reply With Quote
  #24  
Old 02-02-2013, 02:32 PM
over easy's Avatar
over easy over easy is offline
sailor
 
Join Date: Apr 2009
Location: Rio Grande valley
Posts: 775
========== SERVICES / DRIVERS ===============
.
R? !SASCORE;SAS Core Service
R? androidusb;SAMSUNG Android Composite ADB Interface Driver
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64
R? cpuz135;cpuz135
R? cpuz136;cpuz136
R? EnGenius11nSU;EnGenius11nSU
R? lxeaCATSCustConnectService;lxeaCATSCustConnectServ ice
R? massfilter;Mass Storage Filter Driver
R? MBAMProtector;MBAMProtector
R? MBAMScheduler;MBAMScheduler
R? MBAMService;MBAMService
R? NitroReaderDriverReadSpool2;NitroPDFReaderDriverCr eatorReadSpool2
R? PSI;PSI
R? RdpVideoMiniport;Remote Desktop Video Miniport Driver
R? RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter
R? Secunia PSI Agent;Secunia PSI Agent
R? ssadbus;SAMSUNG Android USB Composite Device driver (WDM)
R? ssadmdfl;SAMSUNG Android USB Modem (Filter)
R? ssadmdm;SAMSUNG Android USB Modem Drivers
R? TsUsbFlt;TsUsbFlt
R? vToolbarUpdater13.2.0;vToolbarUpdater13.2.0
R? WatAdminSvc;Windows Activation Technologies Service
R? WDC_SAM;WD SCSI Pass Thru driver
R? ZTEusbMB;ZTE NMEAExt2 Port
R? ZTEusbwwan;ZTE MBN Miniport
S? aswFsBlk;aswFsBlk
S? aswMonFlt;aswMonFlt
S? aswSnx;aswSnx
S? aswSP;aswSP
S? avast! Antivirus;avast! Antivirus
S? avgtp;avgtp
S? Impcd;Impcd
S? L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20)
S? lxea_device;lxea_device
S? O2MDGRDR;O2MDGRDR
S? O2SDGRDR;O2SDGRDR
S? QIOMem;Generic IO & Memory Access
S? rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver
S? SASDIFSV;SASDIFSV
S? SASKUTIL;SASKUTIL
S? SDScannerService;Spybot-S&D 2 Scanner Service
S? SDUpdateService;Spybot-S&D 2 Updating Service
S? SDWSCService;Spybot-S&D 2 Security Center Service
S? Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver
.
=============== Created Last 30 ================
.
2013-01-28 22:49:16 -------- d-----w- C:\Users\Ron\AppData\Local\Secunia PSI
2013-01-28 22:41:37 -------- d-----w- C:\Program Files (x86)\Secunia
2013-01-23 02:41:18 17272 ----a-w- C:\Windows\System32\sdnclean64.exe
2013-01-23 02:41:12 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-01-22 10:26:35 9161176 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FB834771-358E-401A-AE02-4C8C0B60E1D7}\mpengine.dll
2013-01-13 02:24:43 -------- d-----w- C:\Users\Ron\morgen and linda
2013-01-09 12:11:44 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2013-01-09 02:53:55 -------- d-----w- C:\Program Files\Classic Shell
2013-01-08 17:41:17 -------- d-----w- C:\Users\Ron\AppData\Roaming\NVIDIA
2013-01-05 13:36:35 -------- d-----r- C:\cmap4OLD
2013-01-04 19:37:19 -------- d-----w- C:\tempGEKAP
2013-01-04 19:08:44 -------- d-----w- C:\Users\Ron\dwhelper
.
==================== Find3M ====================
.
2013-01-15 16:42:39 697864 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-01-15 16:42:38 74248 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-16 17:11:22 46080 ----a-w- C:\Windows\System32\atmlib.dll
2012-12-16 14:45:03 367616 ----a-w- C:\Windows\System32\atmfd.dll
2012-12-16 14:13:28 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2012-12-16 14:13:20 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2012-12-14 21:49:28 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-12-07 13:20:16 441856 ----a-w- C:\Windows\System32\Wpc.dll
2012-12-07 13:15:31 2746368 ----a-w- C:\Windows\System32\gameux.dll
2012-12-07 12:26:17 308736 ----a-w- C:\Windows\SysWow64\Wpc.dll
2012-12-07 12:20:43 2576384 ----a-w- C:\Windows\SysWow64\gameux.dll
2012-12-07 11:20:04 30720 ----a-w- C:\Windows\System32\usk.rs
2012-12-07 11:20:03 43520 ----a-w- C:\Windows\System32\csrr.rs
2012-12-07 11:20:03 23552 ----a-w- C:\Windows\System32\oflc.rs
2012-12-07 11:20:01 45568 ----a-w- C:\Windows\System32\oflc-nz.rs
2012-12-07 11:20:01 44544 ----a-w- C:\Windows\System32\pegibbfc.rs
2012-12-07 11:20:01 20480 ----a-w- C:\Windows\System32\pegi-fi.rs
2012-12-07 11:20:00 20480 ----a-w- C:\Windows\System32\pegi-pt.rs
2012-12-07 11:19:59 20480 ----a-w- C:\Windows\System32\pegi.rs
2012-12-07 11:19:58 46592 ----a-w- C:\Windows\System32\fpb.rs
2012-12-07 11:19:57 40960 ----a-w- C:\Windows\System32\cob-au.rs
2012-12-07 11:19:57 21504 ----a-w- C:\Windows\System32\grb.rs
2012-12-07 11:19:57 15360 ----a-w- C:\Windows\System32\djctq.rs
2012-12-07 11:19:56 55296 ----a-w- C:\Windows\System32\cero.rs
2012-12-07 11:19:55 51712 ----a-w- C:\Windows\System32\esrb.rs
2012-12-03 12:12:12 159232 ----a-w- C:\Windows\System32\drivers\ser2pl64.sys
2012-11-30 05:45:35 362496 ----a-w- C:\Windows\System32\wow64win.dll
2012-11-30 05:45:35 243200 ----a-w- C:\Windows\System32\wow64.dll
2012-11-30 05:45:35 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2012-11-30 05:45:14 215040 ----a-w- C:\Windows\System32\winsrv.dll
2012-11-30 05:43:12 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2012-11-30 04:54:00 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2012-11-30 04:53:59 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2012-11-30 03:23:48 338432 ----a-w- C:\Windows\System32\conhost.exe
2012-11-30 02:44:06 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2012-11-30 02:44:04 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2012-11-30 02:44:04 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-11-30 02:44:03 2048 ----a-w- C:\Windows\SysWow64\user.exe
2012-11-30 02:38:59 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38:59 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38:59 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38:59 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-11-23 03:26:31 3149824 ----a-w- C:\Windows\System32\win32k.sys
2012-11-23 03:13:57 68608 ----a-w- C:\Windows\System32\taskhost.exe
2012-11-22 05:44:23 800768 ----a-w- C:\Windows\System32\usp10.dll
2012-11-22 04:45:03 626688 ----a-w- C:\Windows\SysWow64\usp10.dll
2012-11-20 05:48:49 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-11-20 04:51:09 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-11-14 06:11:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2012-11-14 06:04:11 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-11-14 06:02:49 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-11-14 05:57:46 599040 ----a-w- C:\Windows\System32\vbscript.dll
2012-11-14 05:57:35 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-11-14 05:52:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-11-14 02:09:22 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-11-14 01:57:37 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-11-14 01:49:25 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-11-14 01:48:27 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2012-11-14 01:44:42 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-11-10 20:48:34 30568 ----a-w- C:\Windows\System32\drivers\avgtpx64.sys
2012-11-09 05:45:32 750592 ----a-w- C:\Windows\System32\win32spl.dll
2012-11-09 05:45:09 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-11-09 04:43:04 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll
2012-11-09 04:42:49 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
.
============= FINISH: 15:28:06.48 ===============
__________________
toshiba Qosmio x505, w7home premium, intel core i5, m450@240GHZ, 4gb ram, 64bit OS, avast free, spywareblaster free, spybot, and antimalware free, cclnr, FF .
Reply With Quote
  #25  
Old 02-02-2013, 02:59 PM
MikeN.
Guest
 
Posts: n/a
I dont see anything in that log. Try clearing your FF cache. Tools/Options/Advanced/Network Clear now
Reply With Quote
  #26  
Old 02-02-2013, 03:14 PM
jholland1964's Avatar
jholland1964 jholland1964 is offline
Almost Really Old Member
 
Join Date: Feb 2004
Location: The Middle
Posts: 30,998
Quote:
Originally Posted by over easy View Post
sorry folks. i did go to tools and restore to default but it didnt work so i came here. i just went back to tools options and restore to default and it worked.
1. When you say you restored to default...what exactly did you restore to default? The only thing giving the option to restore to default is the Home Page, which takes it back to the original Firefox start page. It doesn't restore any other defaults.

Quote:
Originally Posted by over easy View Post
thought it worked. i have a normal size home page with out the tool bar that shows maps and other stuff and i dont know how to get it back. also the web site i went to where this all changed is still too small to read. i have a picture in mwsnap but cant seem to paste it.
2. I still am not sure what this toolbar truly is. Is it a toolbar you have installed as an addon or one you have created or what?

I am sorry and glad of course your log showed nothing unusual or strange that was installed. That is good of course but doesn't help with this. I do have a few questions, other than the two above I would like you to answer:

3. Are you running the PAID version of SpyBot? It is obviously running all the time and has five files associated with it running.

4. Have you disabled Windows Defender? If not you absolutely MUST. It will interfere with most other security programs, especially when attempting to do fixes with them and very often just when they try to do the job they were designed to do.
It appears the only programs running when the scan was done AND at start up are security programs. While this can be good, there are times when this also can be too much, especially when trying to correct some sort of problem such as yours.

5. Does the same problem happen with Internet Explorer? If you don't know please try and report back.

6. Have you tried using Firefox in Firefox Safe Mode? This runs the browser without any addons enabled. When you have a problem like this one that really is the first step you should try, very often an addon can be the cause.
To do this do the following:
Go up to Help and click on Restart with Add-ons Disabled. You will get a box asking if you are sure, click yes. Firefox will close and restart in its safe mode. See if the problem still exists. If it does not then the problem lies with one of the Disabled Add-ons. So you will have to re-enable them one at a time until you find which one is causing the problem.

So there are SIX questions here you need to answer.
__________________

1. Dell Inspiron N5040;
Windows 7 64bit SP1
Firefox v.33.0.2, IE11;WLM2012; Avira Free, Windows Firewall, MBAM, SpywareBlaster, SUPERAntispyware

2.Dell Inspiron N7010; Windows 7 64bit SP1
*same programs as computer 1 above*


Help Us To Help You

System Restore

Stick with the Clean up
Reply With Quote
  #27  
Old 02-02-2013, 03:14 PM
over easy's Avatar
over easy over easy is offline
sailor
 
Join Date: Apr 2009
Location: Rio Grande valley
Posts: 775
i have been trying different things and i have found out, if i use the space in the middle on google's page it goes to the dinghy page no matter what i type in. if i go to the top where the address is posted after you arrive at a site i can go any where i want and it is regular size. how weird is that.
__________________
toshiba Qosmio x505, w7home premium, intel core i5, m450@240GHZ, 4gb ram, 64bit OS, avast free, spywareblaster free, spybot, and antimalware free, cclnr, FF .
Reply With Quote
  #28  
Old 02-02-2013, 03:25 PM
jholland1964's Avatar
jholland1964 jholland1964 is offline
Almost Really Old Member
 
Join Date: Feb 2004
Location: The Middle
Posts: 30,998
Quote:
Originally Posted by over easy View Post
i have been trying different things and i have found out, if i use the space in the middle on google's page it goes to the dinghy page no matter what i type in. if i go to the top where the address is posted after you arrive at a site i can go any where i want and it is regular size. how weird is that.
What is the EXACT Address of the dinghy page showing in the address bar after you are taken there? Place your cursor in the address bar and it should turn blue, right click and choose Copy. Come back here and paste it into a reply. This is very important.


Does your google page look like my attached? Are you certain it actually says Google?

Right-click on the input field of the Search bar, and select Clear Search History. Your Search bar history is cleared. Then try again.
Attached Images
File Type: jpg google.jpg (17.7 KB, 10 views)
__________________

1. Dell Inspiron N5040;
Windows 7 64bit SP1
Firefox v.33.0.2, IE11;WLM2012; Avira Free, Windows Firewall, MBAM, SpywareBlaster, SUPERAntispyware

2.Dell Inspiron N7010; Windows 7 64bit SP1
*same programs as computer 1 above*


Help Us To Help You

System Restore

Stick with the Clean up

Last edited by jholland1964; 02-02-2013 at 03:29 PM. Reason: forgot attachment
Reply With Quote
  #29  
Old 02-02-2013, 03:42 PM
over easy's Avatar
over easy over easy is offline
sailor
 
Join Date: Apr 2009
Location: Rio Grande valley
Posts: 775
https://www.google.com/search?q=fibe...ient=firefox-a the google page looks like the original. just like yours. now that i look close i see that what ever i type in goes to the site i type in. it is so small that i thought it went to the dinghy page.
__________________
toshiba Qosmio x505, w7home premium, intel core i5, m450@240GHZ, 4gb ram, 64bit OS, avast free, spywareblaster free, spybot, and antimalware free, cclnr, FF .
Reply With Quote
  #30  
Old 02-02-2013, 03:45 PM
jholland1964's Avatar
jholland1964 jholland1964 is offline
Almost Really Old Member
 
Join Date: Feb 2004
Location: The Middle
Posts: 30,998
Quote:
Originally Posted by over easy View Post
https://www.google.com/search?q=fibe...ient=firefox-a the google page looks like the original. just like yours. now that i look close i see that what ever i type in goes to the site i type in. it is so small that i thought it went to the dinghy page.
Can't you give us a print screen of this? Honestly I am not sure of what you are seeing or not seeing.
__________________

1. Dell Inspiron N5040;
Windows 7 64bit SP1
Firefox v.33.0.2, IE11;WLM2012; Avira Free, Windows Firewall, MBAM, SpywareBlaster, SUPERAntispyware

2.Dell Inspiron N7010; Windows 7 64bit SP1
*same programs as computer 1 above*


Help Us To Help You

System Restore

Stick with the Clean up
Reply With Quote
  #31  
Old 02-02-2013, 03:48 PM
jholland1964's Avatar
jholland1964 jholland1964 is offline
Almost Really Old Member
 
Join Date: Feb 2004
Location: The Middle
Posts: 30,998
Look at my attachment, is this what you are seeing?
Attached Images
File Type: jpg small print.jpg (74.9 KB, 17 views)
__________________

1. Dell Inspiron N5040;
Windows 7 64bit SP1
Firefox v.33.0.2, IE11;WLM2012; Avira Free, Windows Firewall, MBAM, SpywareBlaster, SUPERAntispyware

2.Dell Inspiron N7010; Windows 7 64bit SP1
*same programs as computer 1 above*


Help Us To Help You

System Restore

Stick with the Clean up
Reply With Quote
  #32  
Old 02-02-2013, 03:53 PM
MikeN.
Guest
 
Posts: n/a
Quote:
Originally Posted by over easy View Post
https://www.google.com/search?q=fibe...ient=firefox-a the google page looks like the original. just like yours. now that i look close i see that what ever i type in goes to the site i type in. it is so small that i thought it went to the dinghy page.
Maybe I am reading this wrong. When you type in Google search box fiberglass dinghy you are getting a page with links regarding fiberglass dinghy's as you are supposed to be
Reply With Quote
  #33  
Old 02-02-2013, 03:58 PM
over easy's Avatar
over easy over easy is offline
sailor
 
Join Date: Apr 2009
Location: Rio Grande valley
Posts: 775
Quote:
Originally Posted by jholland1964 View Post
Look at my attachment, is this what you are seeing?
no. it is in the upper left hand corner of the page and all of the page is there, even the google tool bar that has maps and other stuff on it. the black tool bar goes all the way across but the google address is small as are the different sites of dinghies i could go to if i clk'd one. i tried clking one and it went there but it stayed tiny and unreadable.
__________________
toshiba Qosmio x505, w7home premium, intel core i5, m450@240GHZ, 4gb ram, 64bit OS, avast free, spywareblaster free, spybot, and antimalware free, cclnr, FF .
Reply With Quote
  #34  
Old 02-02-2013, 03:59 PM
jholland1964's Avatar
jholland1964 jholland1964 is offline
Almost Really Old Member
 
Join Date: Feb 2004
Location: The Middle
Posts: 30,998
Quote:
Originally Posted by over easy View Post
no. it is in the upper left hand corner of the page and all of the page is there, even the google tool bar that has maps and other stuff on it. the black tool bar goes all the way across but the google address is small as are the different sites of dinghies i could go to if i clk'd one. i tried clking one and it went there but it stayed tiny and unreadable.
This happens on ONLY this one page? Look at this attachment.
Attached Images
File Type: jpg fibre glass dinghies page.jpg (27.2 KB, 10 views)
__________________

1. Dell Inspiron N5040;
Windows 7 64bit SP1
Firefox v.33.0.2, IE11;WLM2012; Avira Free, Windows Firewall, MBAM, SpywareBlaster, SUPERAntispyware

2.Dell Inspiron N7010; Windows 7 64bit SP1
*same programs as computer 1 above*


Help Us To Help You

System Restore

Stick with the Clean up
Reply With Quote
  #35  
Old 02-02-2013, 04:00 PM
over easy's Avatar
over easy over easy is offline
sailor
 
Join Date: Apr 2009
Location: Rio Grande valley
Posts: 775
i have a picture with mwsnap but i cant get it to paste. even if it did it is not readable.
__________________
toshiba Qosmio x505, w7home premium, intel core i5, m450@240GHZ, 4gb ram, 64bit OS, avast free, spywareblaster free, spybot, and antimalware free, cclnr, FF .
Reply With Quote
  #36  
Old 02-02-2013, 04:02 PM
jholland1964's Avatar
jholland1964 jholland1964 is offline
Almost Really Old Member
 
Join Date: Feb 2004
Location: The Middle
Posts: 30,998
Quote:
Originally Posted by over easy View Post
i have a picture with mwsnap but i cant get it to paste. even if it did it is not readable.
Ok, try this one...is this what you see?
Attached Images
File Type: jpg google search.jpg (20.0 KB, 21 views)
__________________

1. Dell Inspiron N5040;
Windows 7 64bit SP1
Firefox v.33.0.2, IE11;WLM2012; Avira Free, Windows Firewall, MBAM, SpywareBlaster, SUPERAntispyware

2.Dell Inspiron N7010; Windows 7 64bit SP1
*same programs as computer 1 above*


Help Us To Help You

System Restore

Stick with the Clean up
Reply With Quote
  #37  
Old 02-02-2013, 04:06 PM
over easy's Avatar
over easy over easy is offline
sailor
 
Join Date: Apr 2009
Location: Rio Grande valley
Posts: 775
Quote:
Originally Posted by jholland1964 View Post
Ok, try this one...is this what you see?
yes maam it is exactly.
__________________
toshiba Qosmio x505, w7home premium, intel core i5, m450@240GHZ, 4gb ram, 64bit OS, avast free, spywareblaster free, spybot, and antimalware free, cclnr, FF .
Reply With Quote
  #38  
Old 02-02-2013, 04:06 PM
MikeN.
Guest
 
Posts: n/a
Did you try this by any chance?

http://forum.worldstart.com/showpost...1&postcount=25
Reply With Quote
  #39  
Old 02-02-2013, 04:08 PM
jholland1964's Avatar
jholland1964 jholland1964 is offline
Almost Really Old Member
 
Join Date: Feb 2004
Location: The Middle
Posts: 30,998
Quote:
Originally Posted by over easy View Post
yes maam it is exactly.
Go back to that page and hit Ctrl key and 0.....that is a zero not an o...this will reset the page back to what it is supposed to be.
__________________

1. Dell Inspiron N5040;
Windows 7 64bit SP1
Firefox v.33.0.2, IE11;WLM2012; Avira Free, Windows Firewall, MBAM, SpywareBlaster, SUPERAntispyware

2.Dell Inspiron N7010; Windows 7 64bit SP1
*same programs as computer 1 above*


Help Us To Help You

System Restore

Stick with the Clean up
Reply With Quote
  #40  
Old 02-02-2013, 04:15 PM
over easy's Avatar
over easy over easy is offline
sailor
 
Join Date: Apr 2009
Location: Rio Grande valley
Posts: 775
Quote:
Originally Posted by jholland1964 View Post
Go back to that page and hit Ctrl key and 0.....that is a zero not an o...this will reset the page back to what it is supposed to be.
that did it. how did it happen? i know i screwed up but have no idea how. now how do i get my home page to show the tool bar with maps and stuff?
__________________
toshiba Qosmio x505, w7home premium, intel core i5, m450@240GHZ, 4gb ram, 64bit OS, avast free, spywareblaster free, spybot, and antimalware free, cclnr, FF .
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 01:28 PM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Copyright 2000-2011 WorldStart, Inc