This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Stupid "CouponDropDown" Bug! Arrrrrgggghhhh!

125 min read

This thread's last reply is from March 11, 2015, 5:17 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

The second Fixlog you requested:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-03-2015
Ran by [removed] at 2015-03-08 03:18:23 Run:2
Running from C:\Users\[removed]\Desktop\Malware Removal.com\FRST64
[removed]
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Program Files\Codelobster Software
C:\Program Files\WinZip\Utils\WzSysScan
C:\Program Files (x86)\Pavtube\Pavtube Video Converter Ultimate\Pavtube Patch By Umer.exe
C:\ProgramData\{2002a3ab-b40a-e6f2-2002-2a3abb408eae}\superpc_soft_partner.exe
C:\Transfer\Data and Programs\Game-Cloner.2.10.588.rar
C:\Transfer\Data and Programs\codelobster.php.edition.pro.5.2\Codelobster Pro.zip
C:\Transfer\Data and Programs\codelobster.php.edition.pro.5.2\codelobster.php.edition.pro.5.2-patch.exe.5250.gzquar
C:\Transfer\Data and Programs\codelobster.php.edition.pro.5.2\Codelobster Pro\codelobster.php.edition.pro.5.2-patch.exe.5249.gzquar
C:\Transfer\Data and Programs\Pavtube\Pavtube Video Converter Ultimate 4.5 Included Patch.7z
C:\Transfer\Windows Dreamspark\Windows 7 product keys (100% wotked) by Zyonara001\Windows 7 Activator All Versions v4 DyNaCr3w.exe
C:\Users\All Users\{2002a3ab-b40a-e6f2-2002-2a3abb408eae}\superpc_soft_partner.exe
C:\Users\Tsunami Dream\AppData\Local\nsqF1B7.tmp
C:\Users\Tsunami Dream\AppData\Local\03000200-1425202547-0500-0006-000700080009\onsy8292.tmp
C:\Users\Tsunami Dream\AppData\Local\03000200-1425202547-0500-0006-000700080009\rnsy8291.exe
C:\Users\Tsunami Dream\AppData\Local\Temp\{28E2A9B7-67DF-4010-9C98-6543C84FB194}.exe
C:\Users\Tsunami Dream\AppData\Local\Temp\{C2162A1F-D5FC-4268-B6D9-265B16A6175E}.exe
C:\Users\Tsunami Dream\AppData\Roaming\DUWV
C:\Users\Tsunami Dream\AppData\Roaming\LJZLY
C:\Users\Tsunami Dream\AppData\Roaming\03000200-1425202495-0500-0006-000700080009\rnstF394.exe
C:\Users\Tsunami Dream\AppData\Roaming\03000200-1425202495-0500-0006-000700080009\Uninstall.exe
C:\Users\Tsunami Dream\AppData\Roaming\03000200-1425202495-0500-0006-000700080009\vnsyB811.tmp
C:\Windows\Installer\1f283b.msi
G:\RSL-PC\Backup Set 2015-02-23 170156\Backup Files 2015-02-23 170156\Backup files 2.zip
G:\RSL-PC\Backup Set 2015-02-23 170156\Backup Files 2015-02-23 170156\Backup files 5.zip
G:\RSL-PC\Backup Set 2015-02-23 170156\Backup Files 2015-02-23 170156\Backup files 59.zip
EmptyTemp:
RemoveProxy:
*****************

C:\Program Files\Codelobster Software => Moved successfully.
C:\Program Files\WinZip\Utils\WzSysScan => Moved successfully.
C:\Program Files (x86)\Pavtube\Pavtube Video Converter Ultimate\Pavtube Patch By Umer.exe => Moved successfully.
C:\ProgramData\{2002a3ab-b40a-e6f2-2002-2a3abb408eae}\superpc_soft_partner.exe => Moved successfully.
C:\Transfer\Data and Programs\Game-Cloner.2.10.588.rar => Moved successfully.
C:\Transfer\Data and Programs\codelobster.php.edition.pro.5.2\Codelobster Pro.zip => Moved successfully.
C:\Transfer\Data and Programs\codelobster.php.edition.pro.5.2\codelobster.php.edition.pro.5.2-patch.exe.5250.gzquar => Moved successfully.
C:\Transfer\Data and Programs\codelobster.php.edition.pro.5.2\Codelobster Pro\codelobster.php.edition.pro.5.2-patch.exe.5249.gzquar => Moved successfully.
C:\Transfer\Data and Programs\Pavtube\Pavtube Video Converter Ultimate 4.5 Included Patch.7z => Moved successfully.
"C:\Transfer\Windows Dreamspark\Windows 7 product keys (100% wotked) by Zyonara001\Windows 7 Activator All Versions v4 DyNaCr3w.exe" => File/Directory not found.
"C:\Users\All Users\{2002a3ab-b40a-e6f2-2002-2a3abb408eae}\superpc_soft_partner.exe" => File/Directory not found.
C:\Users\Tsunami Dream\AppData\Local\nsqF1B7.tmp => Moved successfully.
C:\Users\Tsunami Dream\AppData\Local\03000200-1425202547-0500-0006-000700080009\onsy8292.tmp => Moved successfully.
C:\Users\Tsunami Dream\AppData\Local\03000200-1425202547-0500-0006-000700080009\rnsy8291.exe => Moved successfully.
C:\Users\Tsunami Dream\AppData\Local\Temp\{28E2A9B7-67DF-4010-9C98-6543C84FB194}.exe => Moved successfully.
C:\Users\Tsunami Dream\AppData\Local\Temp\{C2162A1F-D5FC-4268-B6D9-265B16A6175E}.exe => Moved successfully.
C:\Users\Tsunami Dream\AppData\Roaming\DUWV => Moved successfully.
C:\Users\Tsunami Dream\AppData\Roaming\LJZLY => Moved successfully.
C:\Users\Tsunami Dream\AppData\Roaming\03000200-1425202495-0500-0006-000700080009\rnstF394.exe => Moved successfully.
C:\Users\Tsunami Dream\AppData\Roaming\03000200-1425202495-0500-0006-000700080009\Uninstall.exe => Moved successfully.
C:\Users\Tsunami Dream\AppData\Roaming\03000200-1425202495-0500-0006-000700080009\vnsyB811.tmp => Moved successfully.
C:\Windows\Installer\1f283b.msi => Moved successfully.
G:\RSL-PC\Backup Set 2015-02-23 170156\Backup Files 2015-02-23 170156\Backup files 2.zip => Moved successfully.
G:\RSL-PC\Backup Set 2015-02-23 170156\Backup Files 2015-02-23 170156\Backup files 5.zip => Moved successfully.
G:\RSL-PC\Backup Set 2015-02-23 170156\Backup Files 2015-02-23 170156\Backup files 59.zip => Moved successfully.

========= RemoveProxy: =========

"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value not found.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully.
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value not found.
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value not found.
HKU\S-1-5-21-2140818859-1863541225-2881176698-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value not found.
HKU\S-1-5-21-2140818859-1863541225-2881176698-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully.
HKU\S-1-5-21-2140818859-1863541225-2881176698-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully.


========= End of RemoveProxy: =========

EmptyTemp: => Removed 42.1 MB temporary data.


The system needed a reboot.

==== End of Fixlog 03:18:30 ====


My computer is running much better, I appreciate your continued efforts. I am still having an issue with the 3 minute shutdown, though. Do you have any idea what may be causing it?
A slow shut down can often occur because your computer is performing "housekeeping" duties, which need to be shut down before it can shut down your active processes.

Try doing the following, and see if it improves things at all.

  • Click Start and in the Search programs and files box type cmd.exe
  • Right click on the cmd.exe icon at the top of the list of found items, and select Run as Administrator
  • A Command Window will open.
  • Type chkdsk /r at the prompt and then hit Enter
  • A message will be displayed saying that the disk is busy and a check cannot be made, and asking if you want to schedule one, answer Y
  • Reboot your computer.


On reboot, Windows will check for any damaged sectors on your hard drive, and if it finds any will attempt to repair them. Any it can't repair it will mark, so that data is not written to the damaged sectors.

The check will take some time, so be patient and let it finish, when it has finished your computer will reboot into normal mode.

Let me know if this improves things for you.
lack of response,