• Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
    Dedicated community for Japanese speakers
  • 한국 커뮤니티
    Dedicated community for Korean speakers
Exit
Locked
0

Flash crashes in Firefox, runs in IE

New Here ,
Oct 05, 2014 Oct 05, 2014

Copy link to clipboard

Copied

Aloha! I sure hope someone can help me.

Here's my info:  PC, Windows 8.1 64bit, running up to date Firefox. All plugins are enabled/always activate. Never, ever had a problem before with Flash.

Problem:   A week ago, Flash started crashing. There is a yellow banner at the top saying Flash has crashed with the option to send a report.  There are 2 new add-ons in my Firefox manager- Intel Identity Protection Technology- not sure what they are for. Disabling them makes no difference. I also picked up a virus this past week, after Flash started crashing. I managed to get rid of that using Malwarebytes and Adware Cleaner.

At present, when I click to play a video, the screen's box becomes a blank gray color and I get a message that I need to upgrade to the newest Flash player. When I do (again) everything seems to go OK and install, but I still get the same thing when I try to play a video...gray box and the notice to upgrade.

What I've done:  Uninstalled Adobe Flash and reinstalled Shockwave Flash 15.0.0.152. Result is the same when using Firefox- it crashes. Shockwave Flash is set at "always activate" on the add-ons manager. I also reset Firefox when getting rid of the popup virus.

However, I did get it to work on IExplorer, so it makes me wonder if there is a problem with Firefox.

Can anyone help, please?

Views

1.5K

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines

correct answers 1 Correct answer

Adobe Employee , Oct 07, 2014 Oct 07, 2014

No, not really.  I'm just looking at it pragmatically:

  • There was some kind of malware infection
  • Your AntiVirus/AntiMalware packages caught at least some portion of it and attempted to remove it
  • Now the browser doesn't work right

For Firefox, one of the things we did when implementing Protected Mode was to make sure that other software couldn't insert itself between Flash and the Firefox process to intercept communication.  When something does try to do this, we just bail out, and you end up with a

...

Votes

Translate

Translate
Adobe Employee ,
Oct 06, 2014 Oct 06, 2014

Copy link to clipboard

Copied

It's really hard to say that your machine is in a pristine state at this point.  The anti-virus software cleaned up what it was able to detect, but hundreds of new malware variants appear daily, and it's common practice to establish a foothold with an older payload, then auto-update the malware with something more resilient once an attacker has control of the system.

My first recommendation would be to uninstall both Flash and Firefox, then reinstall Firefox, download Flash and re-install.

If you continue to experience problems, you could try running the Windows 8 System File Checker, to see if any of the Windows binaries might not be the expected ones:  https://support2.microsoft.com/kb/929833?wa=wsignin1.0

At that point, since the symptoms appeared after you had a malware issue, you have two choices.  If it was my personal machine, I would back up any critical data and then restore the machine to the factory state.  The other option is that we can troubleshoot the issue like it was any other Firefox issue, but I'm not sure how effective that will be.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Oct 06, 2014 Oct 06, 2014

Copy link to clipboard

Copied

Thanks, Jeromie. I've gone through all the Firefox and Adobe 'help thyself' suggestions (at least the ones I knew how to do or got the courage to try) and nothing has worked, so your suggestion of starting afresh might be the best. I'll uninstall Firefox and Flash and reinstall first, though, and let you know if it worked.

Thanks again. I appreciate your taking the time to respond.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Oct 06, 2014 Oct 06, 2014

Copy link to clipboard

Copied

No problem.  I've seen this thread a few times over the last week.  I'll mention it to the IE team when I talk to them this week.

Do you have any logs or anything from your antivirus system that might indicate what malware was detected?  They might be able to reproduce the infection and figure out what is getting left in the bad state.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Oct 06, 2014 Oct 06, 2014

Copy link to clipboard

Copied

Well, I've removed and installed Firefox and Adobe Flash player plugin 15 twice- still the same result. When I go to a video in Firefox, it says I need to download the plugin, and the link takes me back to where I was before to download the same thing. When I try it in IE, it now says I need an update...which takes me to the same download page I used.

This is a real puzzlement. I've never had problems with Flash before. And, it started before the virus. As for logs, here is the Adware Cleaner log that got the last bit of junk from Ask.

C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-SPE\Updater\Response\Response.31.10.2.0-0.xml->C:\AdwCleaner\Quarantine\C\ProgramData\AskPartnerNetwork\Toolbar\ORJ-SPE\Updater\Response\Response.31.10.2.0-0.xml.vir

C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-SPE\Updater\Config\Config.31.10.2.0-3.xml->C:\AdwCleaner\Quarantine\C\ProgramData\AskPartnerNetwork\Toolbar\ORJ-SPE\Updater\Config\Config.31.10.2.0-3.xml.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\APNSetup.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\APNSetup.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\UpdateManager.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\UpdateManager.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\ask-search.xml->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\ask-search.xml.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\ORJ-SPE\config.xml->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\ORJ-SPE\config.xml.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr_x64.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr_x64.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub_x64.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub_x64.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv_x64.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv_x64.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1031.mst->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1031.mst.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1033.mst->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1033.mst.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1034.mst->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1034.mst.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1036.mst->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1036.mst.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1040.mst->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1040.mst.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1041.mst->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1041.mst.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1043.mst->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1043.mst.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1045.mst->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1045.mst.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1049.mst->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\1049.mst.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\2070.mst->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\2070.mst.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\AskToolbarInstaller-12.17.1_ORJ-SPE.msi->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\AskToolbarInstaller-12.17.1_ORJ-SPE.msi.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\VNT\content.zip->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\VNT\content.zip.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\VNT\vntldr.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\VNT\vntldr.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\VNT\vntsrv.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\VNT\vntsrv.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\apnmcp.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\apnmcp.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\searchhook.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\searchhook.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\ServiceLocator.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\ServiceLocator.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\SO.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\SO.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\toolbar.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\toolbar.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Toolbar.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Toolbar.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\ToolbarPS.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\ToolbarPS.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\toolbar_x64.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\toolbar_x64.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\UpdateManager.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\UpdateManager.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\{PartnerID}\Passport.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\{PartnerID}\Passport.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\{PartnerID}\Passport_x64.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\{PartnerID}\Passport_x64.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\ask-search.xml->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\ask-search.xml.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\{PartnerID}\config.xml->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\{PartnerID}\config.xml.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr_x64.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr_x64.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub_x64.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub_x64.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv_x64.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv_x64.dll.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\ChromeUtils\APNNativeMsgHost.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\ChromeUtils\APNNativeMsgHost.exe.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\ChromeUtils\com.apn.native_messaging_host_aaaaaiabcopkplhgaedhbloeejhhankf.json->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\program files\AskPartnerNetwork\ChromeUtils\com.apn.native_messaging_host_aaaaaiabcopkplhgaedhbloeejhhankf.json.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\common appdata\AskPartnerNetwork\Toolbar\{PartnerID}\CRX\Update.xml->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\common appdata\AskPartnerNetwork\Toolbar\{PartnerID}\CRX\Update.xml.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\common appdata\AskPartnerNetwork\Toolbar\{PartnerID}\CRX\{Crx_Version}\Toolbar.crx->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\common appdata\AskPartnerNetwork\Toolbar\{PartnerID}\CRX\{Crx_Version}\Toolbar.crx.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\common appdata\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaaiabcopkplhgaedhbloeejhhankf.crx->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\common appdata\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaaiabcopkplhgaedhbloeejhhankf.crx.vir

C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\appdata\Mozilla\Firefox\Profiles\{DefaultProfilesFolder}\extensions\toolbar_ORJ-SPE@apn.ask.com.xpi->C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Source\appdata\Mozilla\Firefox\Profiles\{DefaultProfilesFolder}\extensions\toolbar_ORJ-SPE@apn.ask.com.xpi.vir

C:\Users\Patricia\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr.exe->C:\AdwCleaner\Quarantine\C\Users\Patricia\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr.exe.vir

C:\Users\Patricia\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr_x64.exe->C:\AdwCleaner\Quarantine\C\Users\Patricia\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr_x64.exe.vir

C:\Users\Patricia\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv.dll->C:\AdwCleaner\Quarantine\C\Users\Patricia\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv.dll.vir

C:\Users\Patricia\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub.dll->C:\AdwCleaner\Quarantine\C\Users\Patricia\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub.dll.vir

C:\Users\Patricia\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub_x64.dll->C:\AdwCleaner\Quarantine\C\Users\Patricia\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub_x64.dll.vir

C:\Users\Patricia\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv_x64.dll->C:\AdwCleaner\Quarantine\C\Users\Patricia\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv_x64.dll.vir

C:\Users\Patricia\Documents\Optimizer Pro\CookiesException.txt->C:\AdwCleaner\Quarantine\C\Users\Patricia\Documents\Optimizer Pro\CookiesException.txt.vir

C:\Windows\System32\roboot64.exe->C:\AdwCleaner\Quarantine\C\Windows\System32\roboot64.exe.vir

Here's the logs I tried to copy from Malwarebytes:

Malwarebytes Anti-Malware

www.malwarebytes.org

Scan Date: 10/2/2014

Scan Time: 4:36:49 PM

Logfile: 1.txt

Administrator: Yes

Version: 2.00.2.1012

Malware Database: v2014.10.02.10

Rootkit Database: v2014.09.19.01

License: Premium

Malware Protection: Enabled

Malicious Website Protection: Enabled

Self-protection: Disabled

OS: Windows 8.1

CPU: x64

File System: NTFS

User: Patricia

Scan Type: Threat Scan

Result: Completed

Objects Scanned: 344136

Time Elapsed: 8 min, 10 sec

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled

Processes: 0

(No malicious items detected)

Modules: 0

(No malicious items detected)

Registry Keys: 2

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [bc36b55ad2aad75f1fa72c15a85bf907],

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [18dafa151c600135160c65f3bc48e61a],

Registry Values: 1

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, zr2X2X1G1S1F2V1S2Q0V, Quarantined, [18dafa151c600135160c65f3bc48e61a]

Registry Data: 0

(No malicious items detected)

Folders: 0

(No malicious items detected)

Files: 3

PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSchedule.exe, Quarantined, [b042898665173bfbd78a2713ca371ae6],

PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe, Quarantined, [c13137d8334905318dd51c1e9170dd23],

PUP.Optional.BPlug, C:\Users\Patricia\AppData\Local\Temp\is1219359723\7759337A_stp.EXE, Quarantined, [14deb45bdca0280eaddaedcffd0457a9],

Physical Sectors: 0

(No malicious items detected)

(end)

Malwarebytes Anti-Malware

www.malwarebytes.org

Scan Date: 10/2/2014

Scan Time: 4:36:49 PM

Logfile: 2.txt

Administrator: Yes

Version: 2.00.2.1012

Malware Database: v2014.10.02.10

Rootkit Database: v2014.09.19.01

License: Premium

Malware Protection: Enabled

Malicious Website Protection: Enabled

Self-protection: Disabled

OS: Windows 8.1

CPU: x64

File System: NTFS

User: Patricia

Scan Type: Threat Scan

Result: Completed

Objects Scanned: 344136

Time Elapsed: 8 min, 10 sec

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled

Processes: 0

(No malicious items detected)

Modules: 0

(No malicious items detected)

Registry Keys: 2

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [bc36b55ad2aad75f1fa72c15a85bf907],

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [18dafa151c600135160c65f3bc48e61a],

Registry Values: 1

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, zr2X2X1G1S1F2V1S2Q0V, Quarantined, [18dafa151c600135160c65f3bc48e61a]

Registry Data: 0

(No malicious items detected)

Folders: 0

(No malicious items detected)

Files: 3

PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSchedule.exe, Quarantined, [b042898665173bfbd78a2713ca371ae6],

PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe, Quarantined, [c13137d8334905318dd51c1e9170dd23],

PUP.Optional.BPlug, C:\Users\Patricia\AppData\Local\Temp\is1219359723\7759337A_stp.EXE, Quarantined, [14deb45bdca0280eaddaedcffd0457a9],

Physical Sectors: 0

(No malicious items detected)

(end)

Malwarebytes Anti-Malware

www.malwarebytes.org

Scan Date: 10/2/2014

Scan Time: 4:36:49 PM

Logfile: 3.txt

Administrator: Yes

Version: 2.00.2.1012

Malware Database: v2014.10.02.10

Rootkit Database: v2014.09.19.01

License: Premium

Malware Protection: Enabled

Malicious Website Protection: Enabled

Self-protection: Disabled

OS: Windows 8.1

CPU: x64

File System: NTFS

User: Patricia

Scan Type: Threat Scan

Result: Completed

Objects Scanned: 344136

Time Elapsed: 8 min, 10 sec

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled

Processes: 0

(No malicious items detected)

Modules: 0

(No malicious items detected)

Registry Keys: 2

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [bc36b55ad2aad75f1fa72c15a85bf907],

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [18dafa151c600135160c65f3bc48e61a],

Registry Values: 1

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, zr2X2X1G1S1F2V1S2Q0V, Quarantined, [18dafa151c600135160c65f3bc48e61a]

Registry Data: 0

(No malicious items detected)

Folders: 0

(No malicious items detected)

Files: 3

PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSchedule.exe, Quarantined, [b042898665173bfbd78a2713ca371ae6],

PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe, Quarantined, [c13137d8334905318dd51c1e9170dd23],

PUP.Optional.BPlug, C:\Users\Patricia\AppData\Local\Temp\is1219359723\7759337A_stp.EXE, Quarantined, [14deb45bdca0280eaddaedcffd0457a9],

Physical Sectors: 0

(No malicious items detected)

(end)

Malwarebytes Anti-Malware

www.malwarebytes.org

Scan Date: 10/2/2014

Scan Time: 4:36:49 PM

Logfile: 3.txt

Administrator: Yes

Version: 2.00.2.1012

Malware Database: v2014.10.02.10

Rootkit Database: v2014.09.19.01

License: Premium

Malware Protection: Enabled

Malicious Website Protection: Enabled

Self-protection: Disabled

OS: Windows 8.1

CPU: x64

File System: NTFS

User: Patricia

Scan Type: Threat Scan

Result: Completed

Objects Scanned: 344136

Time Elapsed: 8 min, 10 sec

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled

Processes: 0

(No malicious items detected)

Modules: 0

(No malicious items detected)

Registry Keys: 2

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [bc36b55ad2aad75f1fa72c15a85bf907],

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [18dafa151c600135160c65f3bc48e61a],

Registry Values: 1

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, zr2X2X1G1S1F2V1S2Q0V, Quarantined, [18dafa151c600135160c65f3bc48e61a]

Registry Data: 0

(No malicious items detected)

Folders: 0

(No malicious items detected)

Files: 3

PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSchedule.exe, Quarantined, [b042898665173bfbd78a2713ca371ae6],

PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe, Quarantined, [c13137d8334905318dd51c1e9170dd23],

PUP.Optional.BPlug, C:\Users\Patricia\AppData\Local\Temp\is1219359723\7759337A_stp.EXE, Quarantined, [14deb45bdca0280eaddaedcffd0457a9],

Physical Sectors: 0

(No malicious items detected)

(end)

Malwarebytes Anti-Malware

www.malwarebytes.org

Scan Date: 10/2/2014

Scan Time: 4:36:49 PM

Logfile: 5.txt

Administrator: Yes

Version: 2.00.2.1012

Malware Database: v2014.10.02.10

Rootkit Database: v2014.09.19.01

License: Premium

Malware Protection: Enabled

Malicious Website Protection: Enabled

Self-protection: Disabled

OS: Windows 8.1

CPU: x64

File System: NTFS

User: Patricia

Scan Type: Threat Scan

Result: Completed

Objects Scanned: 344136

Time Elapsed: 8 min, 10 sec

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled

Processes: 0

(No malicious items detected)

Modules: 0

(No malicious items detected)

Registry Keys: 2

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [bc36b55ad2aad75f1fa72c15a85bf907],

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [18dafa151c600135160c65f3bc48e61a],

Registry Values: 1

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, zr2X2X1G1S1F2V1S2Q0V, Quarantined, [18dafa151c600135160c65f3bc48e61a]

Registry Data: 0

(No malicious items detected)

Folders: 0

(No malicious items detected)

Files: 3

PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSchedule.exe, Quarantined, [b042898665173bfbd78a2713ca371ae6],

PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe, Quarantined, [c13137d8334905318dd51c1e9170dd23],

PUP.Optional.BPlug, C:\Users\Patricia\AppData\Local\Temp\is1219359723\7759337A_stp.EXE, Quarantined, [14deb45bdca0280eaddaedcffd0457a9],

Physical Sectors: 0

(No malicious items detected)

(end)

Malwarebytes Anti-Malware

www.malwarebytes.org

Scan Date: 10/2/2014

Scan Time: 4:36:49 PM

Logfile: 6.txt

Administrator: Yes

Version: 2.00.2.1012

Malware Database: v2014.10.02.10

Rootkit Database: v2014.09.19.01

License: Premium

Malware Protection: Enabled

Malicious Website Protection: Enabled

Self-protection: Disabled

OS: Windows 8.1

CPU: x64

File System: NTFS

User: Patricia

Scan Type: Threat Scan

Result: Completed

Objects Scanned: 344136

Time Elapsed: 8 min, 10 sec

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled

Processes: 0

(No malicious items detected)

Modules: 0

(No malicious items detected)

Registry Keys: 2

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [bc36b55ad2aad75f1fa72c15a85bf907],

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [18dafa151c600135160c65f3bc48e61a],

Registry Values: 1

PUP.Optional.InstallCore.A, HKU\S-1-5-21-206369984-856847450-376174140-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, zr2X2X1G1S1F2V1S2Q0V, Quarantined, [18dafa151c600135160c65f3bc48e61a]

Registry Data: 0

(No malicious items detected)

Folders: 0

(No malicious items detected)

Files: 3

PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSchedule.exe, Quarantined, [b042898665173bfbd78a2713ca371ae6],

PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe, Quarantined, [c13137d8334905318dd51c1e9170dd23],

PUP.Optional.BPlug, C:\Users\Patricia\AppData\Local\Temp\is1219359723\7759337A_stp.EXE, Quarantined, [14deb45bdca0280eaddaedcffd0457a9],

Physical Sectors: 0

(No malicious items detected)

(end)

Malwarebytes Anti-Malware

www.malwarebytes.org

Scan Date: 10/3/2014

Scan Time: 8:25:37 AM

Logfile: 7.txt

Administrator: Yes

Version: 2.00.2.1012

Malware Database: v2014.10.03.05

Rootkit Database: v2014.09.19.01

License: Premium

Malware Protection: Enabled

Malicious Website Protection: Enabled

Self-protection: Disabled

OS: Windows 8.1

CPU: x64

File System: NTFS

User: Patricia

Scan Type: Threat Scan

Result: Completed

Objects Scanned: 345469

Time Elapsed: 8 min, 58 sec

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled

Processes: 0

(No malicious items detected)

Modules: 0

(No malicious items detected)

Registry Keys: 0

(No malicious items detected)

Registry Values: 0

(No malicious items detected)

Registry Data: 0

(No malicious items detected)

Folders: 1

Rogue.Multiple, C:\ProgramData\374311380, Quarantined, [312056ba2b516cca2a8b6b664fb38f71],

Files: 1

Rogue.Multiple, C:\ProgramData\374311380\BITC9D7.tmp, Quarantined, [312056ba2b516cca2a8b6b664fb38f71],

Physical Sectors: 0

(No malicious items detected)

(end)

Malwarebytes Anti-Malware

www.malwarebytes.org

Scan Date: 10/3/2014

Scan Time: 8:25:37 AM

Logfile: 8.txt

Administrator: Yes

Version: 2.00.2.1012

Malware Database: v2014.10.03.05

Rootkit Database: v2014.09.19.01

License: Premium

Malware Protection: Enabled

Malicious Website Protection: Enabled

Self-protection: Disabled

OS: Windows 8.1

CPU: x64

File System: NTFS

User: Patricia

Scan Type: Threat Scan

Result: Completed

Objects Scanned: 345469

Time Elapsed: 8 min, 58 sec

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled

Processes: 0

(No malicious items detected)

Modules: 0

(No malicious items detected)

Registry Keys: 0

(No malicious items detected)

Registry Values: 0

(No malicious items detected)

Registry Data: 0

(No malicious items detected)

Folders: 1

Rogue.Multiple, C:\ProgramData\374311380, Quarantined, [312056ba2b516cca2a8b6b664fb38f71],

Files: 1

Rogue.Multiple, C:\ProgramData\374311380\BITC9D7.tmp, Quarantined, [312056ba2b516cca2a8b6b664fb38f71],

Physical Sectors: 0

(No malicious items detected)

(end)

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Oct 07, 2014 Oct 07, 2014

Copy link to clipboard

Copied

Yeah, I have no good suggestions at this point.  I don't see any registry keys in the list that would be related to us.  Google Chrome comes with a built-in Flash Player that might work, but if it was my machine, I'd be skeptical of using it for online banking or anything sensitive until you restore it to factory settings.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Oct 07, 2014 Oct 07, 2014

Copy link to clipboard

Copied

Will refreshing the machine help, security-wise? I'm unfamiliar with this, but came across it while reading about the problem my laptop is having.

BTW, I really appreciate your help.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Oct 07, 2014 Oct 07, 2014

Copy link to clipboard

Copied

For the most confidence in knowing that you got rid of the virus, I would recommend backing up the files that you care about and starting over from scratch.  Windows 8 calls this Reset, as opposed to Refresh.  Refresh leaves all of your stuff in place and attempts to replace the operating system underneath, but I'm not familiar enough with the nuts and bolts of what it's actually doing under the hood to be confident that it would eliminate a nasty malware infection. 

Backing your data up to another location and starting from scratch (i.e. installing all your software from pristine sources), will give you a pretty high degree of confidence that your machine is no longer compromised.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Oct 07, 2014 Oct 07, 2014

Copy link to clipboard

Copied

OK, will tackle that this week.

So, no idea why Flash is not working, despite being installed?

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Oct 07, 2014 Oct 07, 2014

Copy link to clipboard

Copied

No, not really.  I'm just looking at it pragmatically:

  • There was some kind of malware infection
  • Your AntiVirus/AntiMalware packages caught at least some portion of it and attempted to remove it
  • Now the browser doesn't work right

For Firefox, one of the things we did when implementing Protected Mode was to make sure that other software couldn't insert itself between Flash and the Firefox process to intercept communication.  When something does try to do this, we just bail out, and you end up with a dead Flash Player.  There could be other possible root-causes, but what you're experiencing isn't a common or widespread issue.  At Flash Player's distribution scale, something with a 0.01% failure rate affects 100k people, anything that happens consistently like that sets off all the alarms.  I'm pretty confident that this is a unique problem created by something outside of the normal expected operation of the plug-in, browser and OS.

Short of an extensive forensic investigation into the current state of your machine, it's hard to say what's going on beyond "it doesn't look right".  Given the data points that I have, I'm thinking that you would be well served by taking a cautious approach, and that getting back to a known-good state will most likely fix it, or at the very least, make the troubleshooting far more straightforward.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Oct 07, 2014 Oct 07, 2014

Copy link to clipboard

Copied

LATEST

Makes sense! OK, will go that route. Thanks so very much for your help, Jeromie. I appreciate your taking time to answer my questions in a way I can understand.

You're awesome!

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines