PUP.Optional.HDVidCodec.A

View previous topic View next topic Go down

PUP.Optional.HDVidCodec.A

Post by pierluigi on Thu 30 Jan 2014, 10:39 am

Hello! I post here even though MBam apparently removed the malware in the object.The problem is that I still think there is a problem and it is probably this malware that left my system unstable. But please, let me know if I need to post somewhere else.

I was trying to create a backup image of my computer with Macrium Reflect and got this message:
MFT corrupt - Error code = 6. Please run 'chkdsk C: /f'

I was unable to run the chkdsk, and even now, when I schedule it at the next restart (I have one drive, C:), it won't run. I also noticed that I am unable to run a defrag on my C drive. It is at that point that I ran MBam and found the malware. Once removed, though, I was still unable to run chkdsk and still cannot make an image backup on Reflect. In the meantime, I did a manual backup and used the windows utility for an image backup.

Please, excuse me if I posted in the wrong spot and thank you in advance for your time and help!

Below, there are the logs of MBam (the one with the malware found and one I did now); ADWCleaner; SecurityCheck; and command prompt>scannow:

MBAM 1:

Malwarebytes Anti-Malware 1.75.0.1300
[You must be registered and logged in to see this link.]

Database version: v2014.01.29.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Pierliugi :: PIERLUIGI-PC [administrator]

1/28/2014 10:24:30 PM
mbam-log-2014-01-28 (22-24-30).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 229569
Time elapsed: 5 minute(s), 51 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 16
HKCR\CLSID\{11111111-1111-1111-1111-110311431162} (PUP.Optional.HDvidCodec.A) -> Quarantined and deleted successfully.
HKCR\TypeLib\{44444444-4444-4444-4444-440344434462} (PUP.Optional.HDvidCodec.A) -> Quarantined and deleted successfully.
HKCR\Interface\{55555555-5555-5555-5555-550355435562} (PUP.Optional.HDvidCodec.A) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0034362.BHO.1 (PUP.Optional.HDvidCodec.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311431162} (PUP.Optional.HDvidCodec.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311431162} (PUP.Optional.HDvidCodec.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311431162} (PUP.Optional.HDvidCodec.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HDvid Codec V1 (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0034362.BHO (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0034362.Sandbox (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0034362.Sandbox.1 (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
HKCU\Software\1ClickDownload (PUP.Optional.1ClickDownload.A) -> Quarantined and deleted successfully.
HKCU\Software\AppDataLow\Software\Crossrider (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
HKCU\Software\InstalledBrowserExtensions\installdaddy (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\dnllcmllkjofnojidnaknldfehfhehoo (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 2
C:\Program Files (x86)\HDvid Codec V1 (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\hdvidcodec.com (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.

Files Detected: 26
C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-bho.dll (PUP.Optional.HDvidCodec.A) -> Quarantined and deleted successfully.
C:\Windows\Tasks\HDvid Codec V1-codedownloader.job (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Windows\Tasks\HDvid Codec V1-enabler.job (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Windows\Tasks\HDvid Codec V1-updater.job (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\background.html (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-bg.exe (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-buttonutil.dll (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-buttonutil.exe (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-buttonutil64.dll (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-buttonutil64.exe (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-codedownloader.exe (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-enabler.exe (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-helper.exe (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-updater.exe (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1.ico (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\Installer.log (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\Uninstall.exe (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\HDvid Codec V1\utils.exe (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\hdvidcodec.com\b.bmp (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\hdvidcodec.com\finish.bmp (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\hdvidcodec.com\FinishHDVID.exe (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\hdvidcodec.com\HDvidCodec10.crx (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\hdvidcodec.com\HDvidCodecIE.exe (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\hdvidcodec.com\hdvidextsetup.exe (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\hdvidcodec.com\hdvid_temp.bmp (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\hdvidcodec.com\uninst.exe (PUP.Optional.HDVidCodec.A) -> Quarantined and deleted successfully.

(end)

MBAM 2

Malwarebytes Anti-Malware 1.75.0.1300
[You must be registered and logged in to see this link.]

Database version: v2014.01.29.11

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Pierliugi :: PIERLUIGI-PC [administrator]

1/29/2014 6:04:06 PM
mbam-log-2014-01-29 (18-04-06).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 228941
Time elapsed: 5 minute(s), 46 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

ADW Cleaner

# AdwCleaner v3.018 - Report created 29/01/2014 at 14:16:30
# Updated 28/01/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Pierliugi - PIERLUIGI-PC
# Running from : C:\Users\Pierliugi\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files (x86)\orbitdownloader
Folder Deleted : C:\Users\Pierliugi\AppData\Local\DefineExt
Folder Deleted : C:\Users\Pierliugi\AppData\Roaming\cacaoweb
Folder Deleted : C:\Users\Pierliugi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HDvidCodec.com
Folder Deleted : C:\Users\Pierliugi\AppData\Roaming\Mozilla\Firefox\Profiles\mj61596u.default\Extensions\cacaoweb@cacaoweb.org
Folder Deleted : C:\Users\Pierliugi\AppData\Local\Google\Chrome\User Data\Default\Extensions\leahdjjpjmnamomgpojikeapflgbmjab
File Deleted : C:\Users\Pierliugi\AppData\Roaming\Mozilla\Firefox\Profiles\mj61596u.default\user.js

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Google\Chrome\Extensions\leahdjjpjmnamomgpojikeapflgbmjab
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Download by Orbit
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Grab video by Orbit
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Do&wnload selected by Orbit
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Down&load all by Orbit
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [cacaoweb]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Users\Pierliugi\AppData\Roaming\cacaoweb\cacaoweb.exe]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{000123B4-9B42-4900-B3F7-F4B073EFC214}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3F1D494B-0CEF-4468-96C9-386E2E4DEC90}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7854F00C-DC77-477E-A10E-603F48442D3B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366436662}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0880527-DC28-4EBB-BA27-D22102F22A9F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{BCDDE143-FAE3-4C57-B22B-C4E8678CFDC0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{000123B4-9B42-4900-B3F7-F4B073EFC214}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{000123B4-9B42-4900-B3F7-F4B073EFC214}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4250488A-CB24-0893-C066-B1AEA57BCFF2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366436662}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files (x86)\Orbitdownloader\orbitdm.exe]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files (x86)\Orbitdownloader\orbitnet.exe]
Key Deleted : HKCU\Software\anchorfree
Key Deleted : HKCU\Software\cacaoweb
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\installedbrowserextensions
Key Deleted : HKCU\Software\Orbit
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\Orbit
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Orbit_is1

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Mozilla Firefox v24.0 (en-US)

[ File : C:\Users\Pierliugi\AppData\Roaming\Mozilla\Firefox\Profiles\mj61596u.default\prefs.js ]


-\\ Google Chrome v

[ File : C:\Users\Pierliugi\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [5080 octets] - [29/01/2014 13:02:07]
AdwCleaner[S0].txt - [4613 octets] - [29/01/2014 14:16:30]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4673 octets] ##########

SECURITYCHECK

Results of screen317's Security Check version 0.99.79
Windows 7 Service Pack 1 x64 (UAC is disabled!)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
Java 7 Update 51
Adobe Flash Player 12.0.0.43 Flash Player out of Date!
Adobe Reader XI
Mozilla Firefox 24.0 Firefox out of Date!
Mozilla Thunderbird (24.2.0)
Google Chrome 32.0.1700.102
Google Chrome 32.0.1700.76
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````

SCANNOW

2014-01-29 17:33:49, Info CBS Starting TrustedInstaller initialization.
2014-01-29 17:33:49, Info CBS Loaded Servicing Stack v6.1.7601.17592 with Core: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_672ce6c3de2cb17f\cbscore.dll
2014-01-29 17:33:49, Info CSI 00000001@2014/1/29:22:33:49.970 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7fef981f0ad @0x7fef9ad9849 @0x7fef9aa34e3 @0xffe7e97c @0xffe7d799 @0xffe7db2f)
2014-01-29 17:33:49, Info CSI 00000002@2014/1/29:22:33:49.985 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7fef981f0ad @0x7fef9b26816 @0x7fef9af2aac @0x7fef9aa35b9 @0xffe7e97c @0xffe7d799)
2014-01-29 17:33:49, Info CSI 00000003@2014/1/29:22:33:49.985 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7fef981f0ad @0x7fefb548738 @0x7fefb548866 @0xffe7e474 @0xffe7d7de @0xffe7db2f)
2014-01-29 17:33:49, Info CBS Ending TrustedInstaller initialization.
2014-01-29 17:33:49, Info CBS Starting the TrustedInstaller main loop.
2014-01-29 17:33:49, Info CBS TrustedInstaller service starts successfully.
2014-01-29 17:33:49, Info CBS SQM: Initializing online with Windows opt-in: False
2014-01-29 17:33:49, Info CBS SQM: Cleaning up report files older than 10 days.
2014-01-29 17:33:49, Info CBS SQM: Requesting upload of all unsent reports.
2014-01-29 17:33:49, Info CBS SQM: Failed to start upload with file pattern: C:\Windows\servicing\sqm\*_std.sqm, flags: 0x2 [HRESULT = 0x80004005 - E_FAIL]
2014-01-29 17:33:49, Info CBS SQM: Failed to start standard sample upload. [HRESULT = 0x80004005 - E_FAIL]
2014-01-29 17:33:49, Info CBS SQM: Queued 0 file(s) for upload with pattern: C:\Windows\servicing\sqm\*_all.sqm, flags: 0x6
2014-01-29 17:33:49, Info CBS SQM: Warning: Failed to upload all unsent reports. [HRESULT = 0x80004005 - E_FAIL]
2014-01-29 17:33:49, Info CBS No startup processing required, TrustedInstaller service was not set as autostart, or else a reboot is still pending.
2014-01-29 17:33:49, Info CBS NonStart: Checking to ensure startup processing was not required.
2014-01-29 17:33:50, Info CSI 00000004 IAdvancedInstallerAwareStore_ResolvePendingTransactions (call 1) (flags = 00000004, progress = NULL, phase = 0, pdwDisposition = @0x10afd80
2014-01-29 17:33:50, Info CSI 00000005 Creating NT transaction (seq 1), objectname [6]"(null)"
2014-01-29 17:33:50, Info CSI 00000006 Created NT transaction (seq 1) result 0x00000000, handle @0x1e8
2014-01-29 17:33:50, Info CSI 00000007@2014/1/29:22:33:50.063 CSI perf trace:
CSIPERF:TXCOMMIT;308
2014-01-29 17:33:50, Info CBS NonStart: Success, startup processing not required as expected.
2014-01-29 17:33:50, Info CBS Startup processing thread terminated normally
2014-01-29 17:33:50, Info CSI 00000008 CSI Store 2320032 (0x00000000002366a0) initialized
2014-01-29 17:33:50, Info CBS Session: 30350658_778711329 initialized by client WindowsUpdateAgent.
2014-01-29 17:33:50, Info CBS Trusted Installer signaled for shutdown, going to exit.
2014-01-29 17:33:50, Info CBS Ending the TrustedInstaller main loop.
2014-01-29 17:33:50, Info CBS Starting TrustedInstaller finalization.
2014-01-29 17:33:52, Info CBS Ending TrustedInstaller finalization.
2014-01-29 17:52:40, Info CBS Starting TrustedInstaller initialization.
2014-01-29 17:52:40, Info CBS Loaded Servicing Stack v6.1.7601.17592 with Core: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_672ce6c3de2cb17f\cbscore.dll
2014-01-29 17:52:41, Info CSI 00000001@2014/1/29:22:52:41.256 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7fef950f0ad @0x7fef97c9849 @0x7fef97934e3 @0xffd0e97c @0xffd0d799 @0xffd0db2f)
2014-01-29 17:52:41, Info CSI 00000002@2014/1/29:22:52:41.256 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7fef950f0ad @0x7fef9816816 @0x7fef97e2aac @0x7fef97935b9 @0xffd0e97c @0xffd0d799)
2014-01-29 17:52:41, Info CSI 00000003@2014/1/29:22:52:41.256 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7fef950f0ad @0x7fefb508738 @0x7fefb508866 @0xffd0e474 @0xffd0d7de @0xffd0db2f)
2014-01-29 17:52:41, Info CBS Ending TrustedInstaller initialization.
2014-01-29 17:52:41, Info CBS Starting the TrustedInstaller main loop.
2014-01-29 17:52:41, Info CBS TrustedInstaller service starts successfully.
2014-01-29 17:52:41, Info CBS SQM: Initializing online with Windows opt-in: False
2014-01-29 17:52:41, Info CBS SQM: Cleaning up report files older than 10 days.
2014-01-29 17:52:41, Info CBS SQM: Requesting upload of all unsent reports.
2014-01-29 17:52:41, Info CBS SQM: Failed to start upload with file pattern: C:\Windows\servicing\sqm\*_std.sqm, flags: 0x2 [HRESULT = 0x80004005 - E_FAIL]
2014-01-29 17:52:41, Info CBS SQM: Failed to start standard sample upload. [HRESULT = 0x80004005 - E_FAIL]
2014-01-29 17:52:41, Info CBS SQM: Queued 0 file(s) for upload with pattern: C:\Windows\servicing\sqm\*_all.sqm, flags: 0x6
2014-01-29 17:52:41, Info CBS SQM: Warning: Failed to upload all unsent reports. [HRESULT = 0x80004005 - E_FAIL]
2014-01-29 17:52:41, Info CBS No startup processing required, TrustedInstaller service was not set as autostart, or else a reboot is still pending.
2014-01-29 17:52:41, Info CBS NonStart: Checking to ensure startup processing was not required.
2014-01-29 17:52:41, Info CSI 00000004 IAdvancedInstallerAwareStore_ResolvePendingTransactions (call 1) (flags = 00000004, progress = NULL, phase = 0, pdwDisposition = @0x190f900
2014-01-29 17:52:41, Info CSI 00000005 Creating NT transaction (seq 1), objectname [6]"(null)"
2014-01-29 17:52:41, Info CSI 00000006 Created NT transaction (seq 1) result 0x00000000, handle @0x1e8
2014-01-29 17:52:41, Info CSI 00000007@2014/1/29:22:52:41.427 CSI perf trace:
CSIPERF:TXCOMMIT;328
2014-01-29 17:52:41, Info CBS NonStart: Success, startup processing not required as expected.
2014-01-29 17:52:41, Info CBS Startup processing thread terminated normally
2014-01-29 17:52:41, Info CSI 00000008 CSI Store 4457760 (0x0000000000440520) initialized
2014-01-29 17:52:41, Info CBS Session: 30350660_3502420472 initialized by client WindowsUpdateAgent.
2014-01-29 17:52:42, Info CBS Trusted Installer signaled for shutdown, going to exit.
2014-01-29 17:52:42, Info CBS Ending the TrustedInstaller main loop.
2014-01-29 17:52:42, Info CBS Starting TrustedInstaller finalization.
2014-01-29 17:52:43, Info CBS Ending TrustedInstaller finalization.
2014-01-29 18:02:06, Info CBS Starting TrustedInstaller initialization.
2014-01-29 18:02:06, Info CBS Loaded Servicing Stack v6.1.7601.17592 with Core: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_672ce6c3de2cb17f\cbscore.dll
2014-01-29 18:02:07, Info CSI 00000001@2014/1/29:23:02:07.438 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7fef634f0ad @0x7fef97b9849 @0x7fef97834e3 @0xff57e97c @0xff57d799 @0xff57db2f)
2014-01-29 18:02:07, Info CSI 00000002@2014/1/29:23:02:07.438 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7fef634f0ad @0x7fef9806816 @0x7fef97d2aac @0x7fef97835b9 @0xff57e97c @0xff57d799)
2014-01-29 18:02:07, Info CSI 00000003@2014/1/29:23:02:07.438 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7fef634f0ad @0x7fefb3c8738 @0x7fefb3c8866 @0xff57e474 @0xff57d7de @0xff57db2f)
2014-01-29 18:02:07, Info CBS Ending TrustedInstaller initialization.
2014-01-29 18:02:07, Info CBS Starting the TrustedInstaller main loop.
2014-01-29 18:02:07, Info CBS TrustedInstaller service starts successfully.
2014-01-29 18:02:07, Info CBS SQM: Initializing online with Windows opt-in: False
2014-01-29 18:02:07, Info CBS SQM: Cleaning up report files older than 10 days.
2014-01-29 18:02:07, Info CBS SQM: Requesting upload of all unsent reports.
2014-01-29 18:02:07, Info CBS SQM: Failed to start upload with file pattern: C:\Windows\servicing\sqm\*_std.sqm, flags: 0x2 [HRESULT = 0x80004005 - E_FAIL]
2014-01-29 18:02:07, Info CBS SQM: Failed to start standard sample upload. [HRESULT = 0x80004005 - E_FAIL]
2014-01-29 18:02:07, Info CBS SQM: Queued 0 file(s) for upload with pattern: C:\Windows\servicing\sqm\*_all.sqm, flags: 0x6
2014-01-29 18:02:07, Info CBS SQM: Warning: Failed to upload all unsent reports. [HRESULT = 0x80004005 - E_FAIL]
2014-01-29 18:02:07, Info CBS No startup processing required, TrustedInstaller service was not set as autostart, or else a reboot is still pending.
2014-01-29 18:02:07, Info CBS NonStart: Checking to ensure startup processing was not required.
2014-01-29 18:02:07, Info CSI 00000004 IAdvancedInstallerAwareStore_ResolvePendingTransactions (call 1) (flags = 00000004, progress = NULL, phase = 0, pdwDisposition = @0x190fcc0
2014-01-29 18:02:07, Info CSI 00000005 Creating NT transaction (seq 1), objectname [6]"(null)"
2014-01-29 18:02:07, Info CSI 00000006 Created NT transaction (seq 1) result 0x00000000, handle @0x1e8
2014-01-29 18:02:07, Info CSI 00000007@2014/1/29:23:02:07.532 CSI perf trace:
CSIPERF:TXCOMMIT;9700
2014-01-29 18:02:07, Info CBS NonStart: Success, startup processing not required as expected.
2014-01-29 18:02:07, Info CBS Startup processing thread terminated normally
2014-01-29 18:02:07, Info CSI 00000008 CSI Store 3544048 (0x00000000003613f0) initialized
2014-01-29 18:02:07, Info CBS Session: 30350662_573526339 initialized by client WindowsUpdateAgent.
2014-01-29 18:02:08, Info CBS Trusted Installer signaled for shutdown, going to exit.
2014-01-29 18:02:08, Info CBS Ending the TrustedInstaller main loop.
2014-01-29 18:02:08, Info CBS Starting TrustedInstaller finalization.
2014-01-29 18:02:09, Info CBS Ending TrustedInstaller finalization.

END

pierluigi

Newbie Surfer
Newbie Surfer

Posts : 13
Joined : 2010-08-25
Operating System : Windows 7 64bit

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by Superdave on Thu 30 Jan 2014, 10:59 am

Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*************************************************************************
MFT corrupt - Error code = 6. Please run 'chkdsk C: /f'
This message usually means you have some bad sectors on your harddrive.
****************************************
Please download Junkware Removal Tool to your desktop.

Warning! Once the scan is complete JRT will shut down your browser with NO warning.

Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.
*****************************************
Malwarebytes' Anti-Rootkit

Please download Malwarebytes' Anti-Rootkit and save it to your desktop.

  • Be sure to print out and follow the instructions provided on that same page for performing a scan.
  • Caution: This is a beta version so also read the disclaimer and back up all your data before using.
  • When the scan completes, click on the Cleanup button to remove any threats found and reboot the computer if prompted to do so.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • If there are problems with Internet access, Windows Update, Windows Firewall or other system issues, run the fixdamage tool located in the folder Malwarebytes Anti-Rootkit was run from and reboot your computer.
  • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
  • Copy and paste the contents of these two log files in your next reply.


Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by pierluigi on Thu 30 Jan 2014, 11:53 am

Thank you Dave!

Everything went pretty smoothly. However, once I tried to start Malwarebytes, it prompted this messge with the title: Probable rootkit activity - Registry value "AppInit_Dlls" has been found, which may be caused by rootkit activity.

I did not delete this because I didn't know. Anyway, after the scan, Malwarebytes didn't find anything to clean.

Here are the logs:

JUNKWARE:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.0 (01.07.2014:1)
OS: Windows 7 Home Premium x64
Ran by Pierliugi on Wed 01/29/2014 at 19:09:29.32
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\hdvid codec v1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21D59046-8568-4E51-BD32-79BD751DCCE6}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{499B15AC-881F-4224-9373-E2AF2D95108B}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5C2A9ED0-361D-4678-BBB6-FA668315952D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{82FE22F6-6581-4ED3-B962-D0114CFC8F04}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A178FE10-2662-4286-93AB-0477A425A351}



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted: [File] C:\Users\Pierliugi\AppData\Roaming\mozilla\firefox\profiles\mj61596u.default\extensions\hdvc3@hdvidcodec.com.xpi
Emptied folder: C:\Users\Pierliugi\AppData\Roaming\mozilla\firefox\profiles\mj61596u.default\minidumps [19 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 01/29/2014 at 19:15:54.58
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

MALWAREBYTES ROOTKIT (I got just one log)

Malwarebytes Anti-Rootkit BETA 1.07.0.1009
[You must be registered and logged in to see this link.]

Database version: v2014.01.29.11

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Pierliugi :: PIERLUIGI-PC [administrator]

1/29/2014 7:22:01 PM
mbar-log-2014-01-29 (19-22-01).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 268199
Time elapsed: 18 minute(s), 30 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

Thank you!

pierluigi

Newbie Surfer
Newbie Surfer

Posts : 13
Joined : 2010-08-25
Operating System : Windows 7 64bit

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by Superdave on Thu 30 Jan 2014, 12:22 pm

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.

•Check
•Click the button.
•Accept any security warnings from your browser.

  • Leave the check mark next to Remove found threats.

•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by pierluigi on Thu 30 Jan 2014, 11:15 pm

Hello! ESET didn't find any threat.

Here is the log:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=52c10ad4671b82418f02bfc31604214f
# engine=16859
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-01-30 04:42:36
# local_time=2014-01-29 11:42:36 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 16564077 142600406 0 0
# scanned=188669
# found=0
# cleaned=0
# scan_time=9663

Thank you!

pierluigi

Newbie Surfer
Newbie Surfer

Posts : 13
Joined : 2010-08-25
Operating System : Windows 7 64bit

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by Superdave on Fri 31 Jan 2014, 5:36 am

Is there any change in your computer?

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by pierluigi on Fri 31 Jan 2014, 6:01 am

Hi Dave,

The computer is running fine, but I still get the same message when I attempt an image backup and can't run a scheduled chkdsk or a defragmentation. Should I ask for help in the "Operating Systems" or the "Hardware" sections of the forum?

Thank you for checking and for your help!

pierluigi

Newbie Surfer
Newbie Surfer

Posts : 13
Joined : 2010-08-25
Operating System : Windows 7 64bit

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by Superdave on Fri 31 Jan 2014, 10:09 am

Please try this even if you don't have the OS disk.

To Run the SFC /SCANNOW Command in Windows 7
1. Open an elevated command prompt.

2. To Scan and Repair System Files
NOTE: Scans the integrity of all protected system files and repairs the system files if needed.
A) In the elevated command prompt, type sfc /scannow and press Enter. (see screenshot below)
NOTE: This may take some time to finish.



B) Go to step 4.

3. To Only Verify if the System Files are Corrupted
NOTE: Scans and only verifies the integrity of all proteced system files only.
A) In the elevated command prompt, type sfc /verifyonly and press Enter.

4. When the scan is complete, hopefully you will see all is ok like the screenshot below.
NOTE: If not, then you can attempt to run a System Restore using a restore point dated before the bad file occured to fix it. You may need to repeat doing a System Restore until you find a older restore point that may work.



5. When done, close the elevated command prompt.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by pierluigi on Fri 31 Jan 2014, 11:25 am

Hi there!

I did run the scannow, but did not get the happy ending screen. So, I went and tried the System restore route, but when I started, it told me that "The Disc Local Disc (C:) has errors" and that I should run a check, the chkdsk that of course I am unable to run.
Also, the oldest restore point I see is from January 27, 2014. Is that normal? I have an "Image Backup" from September. Could I get my system back from there?

Let me know if you want to see the log from the scannow, it's long and it didn't let me post it.

Thank you!

pierluigi

Newbie Surfer
Newbie Surfer

Posts : 13
Joined : 2010-08-25
Operating System : Windows 7 64bit

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by Superdave on Fri 31 Jan 2014, 1:12 pm

Also, the oldest restore point I see is from January 27, 2014. Is that normal? I have an "Image Backup" from September. Could I get my system back from there?
Yes, that's quite normal. Windows does a Restore Point when it downloads updates. You may be able to get your system back with that image backup but it will still be unstable because of the harddrive. You can try a hard drive diagnostic below but it won't work if the harddrive is a Maxtor.

Run hard drive diagnostics: tacktech.com
Make sure, you select tool, which is appropriate for the brand of your hard drive.
Depending on the program, it'll create bootable floppy, or bootable CD.
If downloaded file is of .iso type, use ImgBurn: imgburn to burn .iso file to a CD (select "Write image file to disc" option), and make the CD bootable.
For Toshiba hard drives, see here:

Note : If you do not know how to set your computer to boot from CD follow the steps here

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by pierluigi on Fri 31 Jan 2014, 2:26 pm

Sorry to bother with this, but it seems like the links on the tacktech website are too old or broken, at least for Samsung. My HD is a SAMSUNG Spinpoint M8 ST640LM001/HN-M640MBB, what utility should I be looking for?

pierluigi

Newbie Surfer
Newbie Surfer

Posts : 13
Joined : 2010-08-25
Operating System : Windows 7 64bit

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by Superdave on Sat 01 Feb 2014, 5:52 am

A lot of HD manufacturers has discontinued their diagnostics. You may be able to find one here. Click on the downloads tab.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by pierluigi on Sat 01 Feb 2014, 9:31 am

Ok Dave, I have downloaded the utility from the website and run a number of test. All passed. I have avoided the "Fix All" test because I'm not sure if there is something to fix and because it threatened to procure a loss of data or a failure of the HD, I'm not sure I should aim for that if no other test has found bad sectors or errors on the disk. Do you agree? What else is left to do to repair this MFT corruption? Thank you!

pierluigi

Newbie Surfer
Newbie Surfer

Posts : 13
Joined : 2010-08-25
Operating System : Windows 7 64bit

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by Superdave on Sat 01 Feb 2014, 10:20 am

The only thing I can think of is to do a Repair from the Recovery Console. If you still have the same problem after that, it would indicate there is a problem with the hard drive. The Repair will not affect your files.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by pierluigi on Sat 01 Feb 2014, 10:53 am

Hi Dave! I got to the recovery console and ran a chkdsk in the command prompt and the memory diagnostic tool. They didn't find any problem. Is there anything else I could run from that interface? It didn't look like it, but I'm open to suggestions. This problem is having us run in circles!

pierluigi

Newbie Surfer
Newbie Surfer

Posts : 13
Joined : 2010-08-25
Operating System : Windows 7 64bit

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by Superdave on Sat 01 Feb 2014, 11:08 am

Please check this site from MS about that problem.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by pierluigi on Sat 01 Feb 2014, 11:35 am

Thank you! So, it looks like windows 7 needs a reinstall at this point. Thank you for your assistance, I'll be checking with the people who installed the new drive less than a year ago.

pierluigi

Newbie Surfer
Newbie Surfer

Posts : 13
Joined : 2010-08-25
Operating System : Windows 7 64bit

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by Superdave on Sat 01 Feb 2014, 11:44 am

I found these sites. They all point to some corruption with the file system.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by pierluigi on Sat 01 Feb 2014, 11:49 am

Hi Dave, I just remembered that I have an image backup (with a separated system and data backup) from September. Should I try to recuperate the system from there? Would that affect all the other data and programs I now have? Thank you!

pierluigi

Newbie Surfer
Newbie Surfer

Posts : 13
Joined : 2010-08-25
Operating System : Windows 7 64bit

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by Superdave on Sat 01 Feb 2014, 12:01 pm

I'm not really familiar with Image backups so I can't really comment on that.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by pierluigi on Sat 01 Feb 2014, 12:50 pm

Obviously, me neither! Well, thank you so much for your support!

pierluigi

Newbie Surfer
Newbie Surfer

Posts : 13
Joined : 2010-08-25
Operating System : Windows 7 64bit

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by Superdave on Sat 01 Feb 2014, 1:23 pm

pierluigi wrote:Obviously, me neither! Well, thank you so much for your support!
Good luck with that and please let me know how this turns out.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: PUP.Optional.HDVidCodec.A

Post by Sponsored content Today at 6:16 pm


Sponsored content


Back to top Go down

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum