Solved: Error message

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

astough

Thread Starter
Joined
Aug 19, 2013
Messages
26
The computer is supposed to run a virus scan every night and then restart. In the morning the attached message is displayed. I was wondering if anyone knew what this was about and how to fix it. Any help would be greatly appreciated.

Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
Processor: Intel(R) Core(TM) i3-2100 CPU @ 3.10GHz, Intel64 Family 6 Model 42 Stepping 7
Processor Count: 4
RAM: 8040 Mb
Graphics Card: Intel(R) HD Graphics, -1924 Mb
Hard Drives: C: Total - 928092 MB, Free - 781823 MB;
Motherboard: LENOVO, To be filled by O.E.M.
Antivirus: McAfee Anti-Virus and Anti-Spyware, Updated and Enabled
 

Attachments

Phantom010

Retired Trusted Advisor
Joined
Mar 9, 2009
Messages
34,801
Please run Autoruns. No installation required. Simply run the executable file.

Run the program.

Select File in the upper left corner.

Click Save...

Change the File Type to: Text (*.txt)

Save the file to your desktop.

Attach it to your next reply.
 

flavallee

Frank
Trusted Advisor
Joined
May 12, 2002
Messages
83,256
That error message appears to be associated with Playtopus-related adware.

You have a LOT of running processes in your computer.

I've never used the Autoruns utility, so I'll leave you with Phantom010.

---------------------------------------------------------
 

Phantom010

Retired Trusted Advisor
Joined
Mar 9, 2009
Messages
34,801
Run Autoruns again.

Select the Scheduled Tasks tab.

Right-click and delete the following entry:

Playtopus Updater File not found: C:\Users\Judy\AppData\Local\PLAYTO~1\Updater.dll

Restart the computer and the RunDLL message should be gone.
 

astough

Thread Starter
Joined
Aug 19, 2013
Messages
26
I deleted that file, and restarted the computer. The message did not appear after the reboot. I am leaving this thread open just in case the error comes back over night. I will close it tomorrow if it does not. For now it looks like the resolution is PERFECT! Thank you so much for your time and your assistance.
 

astough

Thread Starter
Joined
Aug 19, 2013
Messages
26
Sadly, the error has come back. We were away from the computer for awhile and when we returned it was there. I reran "Autoruns" and have attached it. I saw where the file I had deleted was back. I also got an error during autoruns. I have attached that as well.
 

Attachments

Phantom010

Retired Trusted Advisor
Joined
Mar 9, 2009
Messages
34,801
Please download AdwCleaner.

  • Double-click the adwcleaner.exe to run the tool.
  • Click Scan.
  • When the scan is finished, click Clean.
  • When the cleaning process is over, click Report and a Notepad window will be opened.
  • Please post the contents into your next reply.
-----------------------------------------------------------------------

Please download and run the free Malwarebytes Anti-Malware.
  • Select the language and click OK.
  • Accept the agreement.
  • Make sure the Enable the Free Trial box is deselected and the Launch Malwarebytes Anti-Malware box is selected, and then click on Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Scan Now.
  • The scan may take some time to complete, so please be patient.
  • When the scan is completed, click on Quarantine All.
  • Click on Copy to Clipboard.
  • Paste the contents into your next reply.
  • You may be prompted to restart the computer instead, to complete the removal process.
  • If indeed prompted, upon restart, launch Malwarebytes Anti-Malware again and select History.
  • Double-click on the last scan done, then on Copy to Clipboard.
  • Paste the contents into your next reply.
 

astough

Thread Starter
Joined
Aug 19, 2013
Messages
26
I can't get malwarebytes to run. I will try it again in the morning and send the info
 

Phantom010

Retired Trusted Advisor
Joined
Mar 9, 2009
Messages
34,801
If you can't get Malwarebytes Anti-Malware to run, for now, please just run AdwCleaner.
 

astough

Thread Starter
Joined
Aug 19, 2013
Messages
26
# AdwCleaner v4.109 - Report created 28/01/2015 at 17:56:50
# Updated 24/01/2015 by Xplode
# Database : 2015-01-26.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Judy - JUDY-PC
# Running from : C:\Users\Judy\Downloads\adwcleaner_4.109.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : YahooAUService
[#] Service Deleted : Skype C2C Service

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\Yahoo! Companion
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wiseconvert
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\MyPC Backup
Folder Deleted : C:\Program Files (x86)\Quiknowledge
Folder Deleted : C:\Program Files (x86)\VideoConverter
Folder Deleted : C:\Program Files (x86)\Wajam
Folder Deleted : C:\Program Files (x86)\wiseconvert
Folder Deleted : C:\Users\Judy\AppData\Local\PackageAware
Folder Deleted : C:\Users\Judy\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Judy\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Judy\AppData\LocalLow\Yahoo! Companion
Folder Deleted : C:\Users\Judy\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Judy\AppData\Roaming\Mysearchdial
Folder Deleted : C:\Users\Judy\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Judy\AppData\Roaming\UpdaterEX
Folder Deleted : C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
File Deleted : C:\END
File Deleted : C:\windows\System32\roboot64.exe
File Deleted : C:\windows\System32\sasnative64.exe
File Deleted : C:\Users\Judy\AppData\Local\speedial.crx

***** [ Scheduled Tasks ] *****

Task Deleted : LaunchApp
Task Deleted : Playtopus Updater

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3201318
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3209604
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C1ECF1CF-11E2-45D1-BCAB-8E4CB079BA2B}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\Freecause
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\{F2E9660B-98AF-42c0-8258-9CDDF07BF95D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\craftcrawlers.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\shugarysweets.com
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local;192.168.*.*

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17496


-\\ Mozilla Firefox v34.0 (x86 en-GB)


-\\ Google Chrome v

[C:\Users\Judy\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Judy\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}

*************************

AdwCleaner[R0].txt - [5132 octets] - [28/01/2015 17:54:22]
AdwCleaner[S0].txt - [5023 octets] - [28/01/2015 17:56:50]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5083 octets] ##########


Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 1/29/2015
Scan Time: 3:28:15 PM
Logfile:
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.01.29.11
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Judy

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 358063
Time Elapsed: 34 min, 55 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)
 

Phantom010

Retired Trusted Advisor
Joined
Mar 9, 2009
Messages
34,801
Task Deleted : Playtopus Updater

That should have taken care of your RunDLL pop-up?
 

astough

Thread Starter
Joined
Aug 19, 2013
Messages
26
Just like yesterday, it didn't come up when I rebooted. I will see if it comes back before morning. *fingers crossed*
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Members online

Top