Buy Malwarebytes antimalware











This site is hosted at Hostgator.com




Sponsored Adverts

Sponsored Ads

These adverts come direct from Google adsense



Welcome to The Spykiller

You need to register to  get help with malware cleaning on your computer or take part in the general discussion forums and to upload files that have been requested from other forums. Unfortunately we are getting massive spam attacks from allowing guest postings to uploads
It takes a very long time and a lot of hard work on our part to read all the logs posted here and research and prepare the fixes for you. In many cases each part of the fix takes about 30 minutes to prepare so a large part of our time is spent helping you

 INSTRUCTIONS - Read This Before Posting For Malware Removal Help

Author Topic: Random Popups  (Read 729 times)

Offline ironfistmonk

  • *
  • Posts: 4
Random Popups
« on: April 15, 2012, 10:52:05 »
Lately I've been receiving random pop ups while using Firefox. They open in a new tab with address from click.eyk.net or click.***.net (*** random alphabets) and are redirected to http://accessorybrandnames.com. ESET has blocked the website for being potentially harmful. The DDS log is as shown below. I do not have access to a Windows Install disc, or a Boot CD. Thanks in advance for aiding in resolving the problem.

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421  BrowserJavaVersion: 1.6.0_31
Run by -MElviN at 16:50:30 on 2012-04-15
Microsoft Windows 7 Professional   6.1.7601.1.1252.65.1033.18.4087.2303 [GMT 8:00]
.
AV: ESET Smart Security 4.2 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET Smart Security 4.2 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Users\-MElviN\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files (x86)\D-Link\D-Link Wireless 108G DWA-120\AirPlusCFG.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k iissvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.sg/
uInternet Settings,ProxyServer = proxy.singnet.com.sg:8080
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [ANIWZCS2Service] C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe
mRun: [D-Link D-Link Wireless 108G DWA-120] C:\Program Files (x86)\D-Link\D-Link Wireless 108G DWA-120\AirPlusCFG.exe
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\-MElviN\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\-MElviN\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{07F88955-F927-4A64-AF44-EDEE5ECA4645} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{2494D826-3731-40D0-86F3-29D0AD9881AF} : DhcpNameServer = 192.168.1.254
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: IDMIEHlprObj Class: {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO-X64:     IDM Helper - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64:     AcroIEHelperStub - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64:     SkypeIEPluginBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [ANIWZCS2Service] C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe
mRun-x64: [D-Link D-Link Wireless 108G DWA-120] C:\Program Files (x86)\D-Link\D-Link Wireless 108G DWA-120\AirPlusCFG.exe
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\-MElviN\AppData\Roaming\Mozilla\Firefox\Profiles\o4bbzw2t.default\
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
FF - component: C:\Users\-MElviN\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\AhnLab\ASP\Components\aosmgr\conflict_221\npaosmgr.dll
FF - plugin: C:\Program Files (x86)\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 ArcSec;archlp;C:\Windows\system32\drivers\ArcSec.sys --> C:\Windows\system32\drivers\ArcSec.sys [?]
R1 JSWPSLWF;JumpStart Wireless Filter Driver;C:\Windows\system32\DRIVERS\jswpslwfx.sys --> C:\Windows\system32\DRIVERS\jswpslwfx.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-23 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-13 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-12 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 eamonm;eamonm;C:\Windows\system32\DRIVERS\eamonm.sys --> C:\Windows\system32\DRIVERS\eamonm.sys [?]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2010-3-24 810120]
R2 epfwwfp;epfwwfp;C:\Windows\system32\DRIVERS\epfwwfp.sys --> C:\Windows\system32\DRIVERS\epfwwfp.sys [?]
R2 IDMWFP;IDMWFP;C:\Windows\system32\DRIVERS\idmwfp.sys --> C:\Windows\system32\DRIVERS\idmwfp.sys [?]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-11-17 2253120]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-2-16 136176]
S2 MBAMService;MBAMService;C:\Users\-MElviN\Desktop\Malwarebytes Anti-Malware v1.61.0.1400 Portable\Portable\App\Malwarebytes\mbamservice.exe [2012-4-14 654408]
S3 A5AGU;D-Link Wireless LAN 802.11 USB device driver;C:\Windows\system32\DRIVERS\AGUx64.sys --> C:\Windows\system32\DRIVERS\AGUx64.sys [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-2-16 136176]
S3 ivusb;Initio Driver for USB Default Controller;C:\Windows\system32\DRIVERS\ivusb.sys --> C:\Windows\system32\DRIVERS\ivusb.sys [?]
S3 jswpsapi;Jumpstart Wifi Protected Setup;C:\Program Files (x86)\D-Link\D-Link Wireless 108G DWA-120\JSWUtilVst\jswpsapi.exe [2010-9-26 942080]
S3 Mkd2Nadr;Mkd2Nadr;C:\Windows\System32\drivers\Mkd2Nadr.sys [2011-6-16 106040]
S3 Mkd3kfNt;Mkd3kfNt;C:\Windows\system32\drivers\Mkd3kfNt.sys --> C:\Windows\system32\drivers\Mkd3kfNt.sys [?]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2012-04-15 08:46:00   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{26150AF1-BDA7-4F51-B06D-528240DCF754}
2012-04-15 08:45:49   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{D6A6E70D-0F98-4D0D-8581-AB64ACC10B65}
2012-04-15 08:35:32   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{CBA200F4-56FC-41A0-8DF1-E69BB6BA5474}
2012-04-15 06:03:55   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{1C30868C-0DC3-443E-B243-3BA5F9D5522C}
2012-04-15 06:03:43   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{ADD66414-56B6-47D1-A062-FC4C6B6FD189}
2012-04-14 09:20:44   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{8EBC952D-758B-4D4F-B65D-F455E574E71E}
2012-04-14 09:20:32   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{E3B4FCCE-CAC2-44A7-8C7C-9FF2125A7BEB}
2012-04-14 07:26:47   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{6D9FF6AA-9F0E-4266-ACDD-9ADD9B17275E}
2012-04-14 07:26:34   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{3649179D-DF8E-4988-8408-AC722EC04E18}
2012-04-14 04:56:58   --------   d-----w-   C:\Users\-MElviN\AppData\Roaming\SUPERAntiSpyware.com
2012-04-14 04:56:26   --------   d-----w-   C:\ProgramData\SUPERAntiSpyware.com
2012-04-14 04:56:26   --------   d-----w-   C:\Program Files\SUPERAntiSpyware
2012-04-14 04:41:39   --------   d-----w-   C:\Users\-MElviN\AppData\Roaming\Malwarebytes
2012-04-14 04:41:37   --------   d-----w-   C:\ProgramData\Malwarebytes
2012-04-14 04:37:37   69000   ----a-w-   C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{440A7200-B7E4-4818-B571-CD7B1A8A8FBA}\offreg.dll
2012-04-14 04:22:10   8669240   ----a-w-   C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{440A7200-B7E4-4818-B571-CD7B1A8A8FBA}\mpengine.dll
2012-04-14 04:21:03   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{E374CEAB-18AD-479A-AED7-D5446A6B19CD}
2012-04-14 04:20:51   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{38C06E68-9DB0-479A-B339-BDA75C85EB9D}
2012-04-13 16:30:53   --------   d-----r-   C:\Users\-MElviN\Dropbox
2012-04-13 16:29:05   --------   d-----w-   C:\Users\-MElviN\AppData\Roaming\Dropbox
2012-04-13 06:58:14   --------   d-----w-   C:\Program Files (x86)\Common Files\Steam
2012-04-13 06:58:13   --------   d-----w-   C:\Program Files (x86)\Steam
2012-04-12 19:22:42   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{B4038B35-FA80-453D-BF32-963FCE0AEE42}
2012-04-12 19:00:43   23408   ----a-w-   C:\Windows\System32\drivers\fs_rec.sys
2012-04-12 19:00:42   81408   ----a-w-   C:\Windows\System32\imagehlp.dll
2012-04-12 19:00:42   159232   ----a-w-   C:\Windows\SysWow64\imagehlp.dll
2012-04-12 19:00:41   5120   ----a-w-   C:\Windows\SysWow64\wmi.dll
2012-04-12 19:00:41   5120   ----a-w-   C:\Windows\System32\wmi.dll
2012-04-12 19:00:41   220672   ----a-w-   C:\Windows\System32\wintrust.dll
2012-04-12 19:00:41   172544   ----a-w-   C:\Windows\SysWow64\wintrust.dll
2012-04-12 05:14:01   14032   ----a-w-   C:\Windows\System32\drivers\se64a.sys
2012-04-12 05:09:15   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{59721FFD-12D1-45A1-8C5C-55F39C2547B0}
2012-04-11 04:05:48   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{706A2864-6447-40E7-9C27-FC404944CA48}
2012-04-10 02:52:36   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{70CA6DF1-78CF-4357-B068-3BF5BA8DF2C2}
2012-04-09 02:31:59   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{E4C7F6F8-C873-4705-B90E-60121675F52D}
2012-04-08 14:31:35   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{659EFC59-97E1-4ADF-8AA1-BDA867F245DC}
2012-04-08 02:31:12   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{21055632-CC1E-40EA-9E2B-BE0C13C26317}
2012-04-07 02:30:32   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{CB52EE68-6E6F-4149-8280-9BAFEFE45E29}
2012-04-06 14:30:07   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{C47C239E-384F-4C62-85D1-56A022E50CCE}
2012-04-06 02:29:43   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{9142065F-56A9-4725-873C-C1D1735CD7EA}
2012-04-05 14:29:19   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{CDC16AD3-3CF6-49FD-BEDA-3C73B5F750DD}
2012-04-05 00:20:36   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{4A50359C-97F1-47A6-9329-8E9E4E296613}
2012-04-04 05:53:56   182160   ----a-w-   C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2012-04-04 05:53:56   182160   ----a-w-   C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
2012-04-04 03:12:41   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{9C8861E9-08E0-48B7-8E7E-215800253D51}
2012-04-03 03:45:03   --------   d-----w-   C:\Program Files (x86)\Comical
2012-04-03 03:12:07   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{82D6D456-C844-45EF-981B-E5C2781BD9BE}
2012-04-02 01:37:10   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{27F1C708-C0B8-42B6-BD5B-A8DB734418B3}
2012-04-01 01:36:36   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{1D10FF5D-0CB2-4E4F-9495-ECD3F4265A9D}
2012-03-31 01:27:49   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{B98B77F5-039F-4A41-B23C-83A1CC80359D}
2012-03-30 00:53:23   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{CD94181F-A94F-4006-9B68-FC9BE84288FE}
2012-03-29 12:41:30   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{1C18F4B9-C508-4096-BF98-F8735472D542}
2012-03-28 11:56:17   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{BFBC3BFF-CAE2-4E42-B805-174D1C1E16DC}
2012-03-28 11:56:06   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{6AED1E9F-83C9-4934-A72F-509F37879716}
2012-03-27 23:55:41   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{427DDA21-BC34-4145-B9C4-2617270A486F}
2012-03-27 23:55:31   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{1F084585-4D48-4E21-AEAE-997C1C78C1E4}
2012-03-27 11:55:06   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{B02D63ED-7163-4C20-8EAF-8D6A2F35F738}
2012-03-26 23:54:44   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{90B80DA9-83FB-4567-A6B0-6442A7790D43}
2012-03-26 23:54:33   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{99ECE993-C1FB-4559-82AC-9A7C043CF09D}
2012-03-26 11:42:04   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{6985444E-7FE8-47EA-BC85-BF956D7DD0FF}
2012-03-26 11:41:49   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{E027FA0D-9C97-4937-97EA-8CA6766EA098}
2012-03-25 07:13:25   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{758080C1-FDA8-4DC2-84A0-DFBECFEF930E}
2012-03-25 07:13:11   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{3C6555D1-CF7F-45A0-8D48-012DA9D0C917}
2012-03-24 09:22:21   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{B43C7D29-1A22-45D8-BC62-090B8F163464}
2012-03-24 09:22:11   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{D666EF14-B001-4D0D-8B9E-BF8BFAD616F8}
2012-03-23 09:05:35   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{D41FD5B3-F78E-4438-BF24-790A8B9B05F3}
2012-03-23 09:05:23   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{19DCEFD5-EB4B-439C-B35C-8D157B5DE374}
2012-03-22 13:44:56   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{02EFC11F-A7E9-45E8-BE90-D01ADB569460}
2012-03-22 01:44:34   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{F12C2418-70D2-4984-B824-15F95C121337}
2012-03-22 01:44:23   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{9951ECB0-6B84-4EFC-A30D-84C84F63C6E0}
2012-03-21 08:36:33   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{AECBAE18-7EB5-4492-936C-BF6626EDFA26}
2012-03-21 08:36:22   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{77B41E58-390D-44E8-A0A9-9186D0B2E749}
2012-03-20 13:32:26   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{EDBE4561-B0B9-48C7-9748-849FD9D2E4BC}
2012-03-20 01:32:02   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{E21E0D07-7B20-4A6A-93C4-A8F7EAF59F1B}
2012-03-20 01:31:48   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{44BF9BF7-CCB3-44BE-BEC9-0EC01CFA3FDD}
2012-03-19 09:51:28   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{15C7DA6E-0D8A-42E3-8289-0903CCFD3987}
2012-03-19 09:51:17   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{8E8B6300-39AE-40B3-8544-F7CA0218BB5E}
2012-03-18 16:00:47   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{3568334A-0C55-456A-A874-FAB7A58AFE38}
2012-03-18 04:00:24   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{30CD3181-F6C8-4C94-8CE1-3729EF17F584}
2012-03-18 04:00:11   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{15A0AC0D-D9E5-49CA-91F6-631D8D1F54F3}
2012-03-17 08:25:26   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{FD0E183D-1CC9-4920-A192-CC863DB79FEB}
2012-03-17 08:25:13   --------   d-----w-   C:\Users\-MElviN\AppData\Local\{6E1262D0-F792-49F4-B2AD-0F0AE03B1A5A}
.
==================== Find3M  ====================
.
2012-03-09 16:51:26   1174979   ----a-w-   C:\Windows\apppatch\unins000.exe
2012-03-06 06:53:37   5559152   ----a-w-   C:\Windows\System32\ntoskrnl.exe
2012-03-06 05:59:47   3968368   ----a-w-   C:\Windows\SysWow64\ntkrnlpa.exe
2012-03-06 05:59:41   3913072   ----a-w-   C:\Windows\SysWow64\ntoskrnl.exe
2012-03-05 13:00:21   472808   ----a-w-   C:\Windows\SysWow64\deployJava1.dll
2012-02-28 06:56:48   2311168   ----a-w-   C:\Windows\System32\jscript9.dll
2012-02-28 06:49:56   1390080   ----a-w-   C:\Windows\System32\wininet.dll
2012-02-28 06:48:57   1493504   ----a-w-   C:\Windows\System32\inetcpl.cpl
2012-02-28 06:42:55   2382848   ----a-w-   C:\Windows\System32\mshtml.tlb
2012-02-28 01:18:55   1799168   ----a-w-   C:\Windows\SysWow64\jscript9.dll
2012-02-28 01:11:21   1427456   ----a-w-   C:\Windows\SysWow64\inetcpl.cpl
2012-02-28 01:11:07   1127424   ----a-w-   C:\Windows\SysWow64\wininet.dll
2012-02-28 01:03:16   2382848   ----a-w-   C:\Windows\SysWow64\mshtml.tlb
2012-02-27 08:28:17   1391104   ----a-w-   C:\apploc.msi
2012-02-23 01:18:36   279656   ------w-   C:\Windows\System32\MpSigStub.exe
2012-02-17 06:38:26   1031680   ----a-w-   C:\Windows\System32\rdpcore.dll
2012-02-17 05:34:22   826880   ----a-w-   C:\Windows\SysWow64\rdpcore.dll
2012-02-17 04:58:24   210944   ----a-w-   C:\Windows\System32\drivers\rdpwd.sys
2012-02-17 04:57:32   23552   ----a-w-   C:\Windows\System32\drivers\tdtcp.sys
2012-02-17 00:49:09   414368   ----a-w-   C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-10 06:36:07   1544192   ----a-w-   C:\Windows\System32\DWrite.dll
2012-02-10 05:38:43   1077248   ----a-w-   C:\Windows\SysWow64\DWrite.dll
2012-02-07 03:02:40   1070352   ----a-w-   C:\Windows\SysWow64\MSCOMCTL.OCX
2012-02-03 04:34:34   3145728   ----a-w-   C:\Windows\System32\win32k.sys
2012-01-25 06:38:39   77312   ----a-w-   C:\Windows\System32\rdpwsx.dll
2012-01-25 06:38:38   149504   ----a-w-   C:\Windows\System32\rdpcorekmts.dll
2012-01-25 06:33:30   9216   ----a-w-   C:\Windows\System32\rdrmemptylst.exe
.
============= FINISH: 16:50:46.03 ===============

< moderator edit to remove link to suspicious site >
« Last Edit: April 15, 2012, 11:21:11 by Derek »


Offline Derek

  • Administrator
  • *****
  • Posts: 11929
Re: Random Popups
« Reply #1 on: April 15, 2012, 11:12:25 »
step1
Run tdss killer from http://support.kaspersky.com/viruses/solutions?qid=208280684
let it cure anything it fnds ( except SPTD.SYS, which should be ignored) & then reboot
post back with its log
By default, the utility outputs the log into system disk (it is usually the disk with installed operating system, C:\) root folder.
Logs have names like: UtilityName.Version_Date_Time_log.txt.
E.g. C:\TDSSKiller.2.4.7_23.07.2010_15.31.43_log.txt
 
if it doesn't ask to reboot, please reboot
then
Delete any existing version of ComboFix you have sitting on your desktop
Please read and follow all these instructions very carefully
Do not edit or remove any information or user names etc, otherwise we cannot fix the problem. If you insist on editing out anything then I will close the topic & refuse to offer any help.
Download ComboFix from Here or Hereto your Desktop.
As you download it rename it to username123.exe

**Note:  It is important that it is saved directly to your desktop  and run from the desktop and not any other folder on your computer**
--------------------------------------------------------------------
1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Very Important! Temporarily disable your anti-virus and  anti-malware real-time protection and any script blocking components of them or your firewall before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results" or stop combofix running at all
  • Click on THIS LINK to see instructions on how to temporarily disable many security programs while running combofix. The list does not cover every program. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again after combofix has finished
--------------------------------------------------------------------
2. Close any open browsers and any other programs you might have running
Double click on renamed combofix.exe & follow the prompts.
If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?"
Please select yes & let it download the files it needs to do this. Once the recovery console is installed Combofix will then offer to scan for malware. Select continue or yes.
When finished, it will produce a report for you. 
Please post the "C:\ComboFix.txt" for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell us when you reply. Read HERE why we disable autoruns
Please do not install any new programs or update anything (always allow your antivirus/antispyware to update) unless told to do so while we are fixing your problem. If combofix alerts to a new version and offers to update, please let it. It is essential we always use the latest version. 
Please tell us if it has cured the problems or if there are any outstanding issues
 
Derek
Microsoft MVP  Windows - Security
Modern Malware is so involved and difficult to fix that it takes a very long time and a lot of hard work and research to prepare the fixes for you. A large part of my time is spent helping you
Would you do all this for nothing?
 I run this site to raise funds for Hedgehog Rescue
Please donate if I have helped you or you have found this site useful.

Offline ironfistmonk

  • *
  • Posts: 4
Re: Random Popups
« Reply #2 on: April 15, 2012, 13:32:31 »
I've done the scans here are the logs. Once again thanks for the help =).

Offline Derek

  • Administrator
  • *****
  • Posts: 11929
Re: Random Popups
« Reply #3 on: April 15, 2012, 16:21:33 »
how is it now
it looks like internet download manager might have been the culprit
Derek
Microsoft MVP  Windows - Security
Modern Malware is so involved and difficult to fix that it takes a very long time and a lot of hard work and research to prepare the fixes for you. A large part of my time is spent helping you
Would you do all this for nothing?
 I run this site to raise funds for Hedgehog Rescue
Please donate if I have helped you or you have found this site useful.

Offline ironfistmonk

  • *
  • Posts: 4
Re: Random Popups
« Reply #4 on: April 15, 2012, 17:18:16 »
Everything seems fine now. No more pop ups thanks alot! How did internet download manager actually caused the problem if you don't mind explaining thanks!

Offline Derek

  • Administrator
  • *****
  • Posts: 11929
Re: Random Popups
« Reply #5 on: April 16, 2012, 12:41:08 »
cf deleted a couple of things and some FF addons for IDM
from what I can find out those addons are tracking or advert related
Do you have the full paid for version of IDM or an expired trial version. I understand that the trial version has adverts ( after the trial runs out) but the full paid for version doesn't contain advertising
Derek
Microsoft MVP  Windows - Security
Modern Malware is so involved and difficult to fix that it takes a very long time and a lot of hard work and research to prepare the fixes for you. A large part of my time is spent helping you
Would you do all this for nothing?
 I run this site to raise funds for Hedgehog Rescue
Please donate if I have helped you or you have found this site useful.

Offline ironfistmonk

  • *
  • Posts: 4
Re: Random Popups
« Reply #6 on: April 17, 2012, 15:50:45 »
I have the full version. I never had any problems with it until recently I wonder why.. Anyway thanks for helping me sort the problem. I would gladly donate to help the Hedgehog Rescue in few days time.

Offline Derek

  • Administrator
  • *****
  • Posts: 11929
Re: Random Popups
« Reply #7 on: April 17, 2012, 15:59:25 »
in that case I think we should restore the IDM files and assume that the other files combofix deleted were responsible
 
please go to C:\qoobox & find ComboFix-quarantined-files.txt
upload that here so I can prepare a script to restore the files
Derek
Microsoft MVP  Windows - Security
Modern Malware is so involved and difficult to fix that it takes a very long time and a lot of hard work and research to prepare the fixes for you. A large part of my time is spent helping you
Would you do all this for nothing?
 I run this site to raise funds for Hedgehog Rescue
Please donate if I have helped you or you have found this site useful.

 

Donations

You have come to The Spykiller for help because your Antivirus or Antispyware hasn't been able to fix your problem.

Modern Malware has become so involved and difficult to fix that it takes a very long time and a lot of hard work to read all the logs posted here and research and prepare the fixes for you. In many cases each part of the fix takes about 30 minutes to prepare, so a large part of my time is spent helping you

Would you do all this for nothing?

The reason I run this site is to raise funds for Hedgehog Rescue

Please donate if I have helped you or you have found this site useful.

You can donate safely and securely by using the paypal service, just click on one of the buttons below.

To donate in UK £

To donate in US$

To donate in Euro €

Any amount no matter how small is gratefully accepted and needed to ensure we keep the Rescue Centre running

To donate via paypal when the button doesn't appear or the link doesn't work: just go to www.paypal.com or your country's paypal log in page and chose send money and use help@thehedgehog.co.uk as recipient email address and select other service as the option. then follow prompts


Useful Advice and Programs

Stop killing hedgehogs with strimmers
Welcome, Guest. Please login or register.
Did you miss your activation email?
June 19, 2013, 06:55:59

Login with username, password and session length

secunia Software inspector


RoboForm: Learn more...

You have come to The Spykiller for help because your Antivirus or Antispyware hasn't been able to fix your problem.

Modern Malware is so involved and difficult to fix that it takes a very long time and a lot of hard work to read all the logs posted here and research and prepare the fixes for you.
In many cases each part of the fix takes about 30 minutes to prepare, so a large part of my time is spent helping you

Would you do all this for nothing?

I run this site to help raise funds for Hedgehog Rescue

Please donate if I have helped you or you have found this site useful.

You can donate safely and securely by using the PayPal service, just click on one of the buttons below.

To donate in UK £

To donate in US$

To donate in Euro €

Any amount no matter how small is gratefully accepted and needed to ensure we keep the Rescue Centre running