This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

win32.pornpopup

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So, I had win32.pornpopup on my computer, so I decided not to fight and just reinstall windows 7.

All I had installed is zone alarm, avast, google chrome, and spybot.

I ran spybot - 5 entries of win32.pornpopup.

I had also reset my router before I connected my computer to the internet.

new HiJackThis log -


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:30:28 PM, on 6/25/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Travis\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files (x86)\ZoneAlarm\tbZone.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files (x86)\ZoneAlarm\tbZone.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O3 - Toolbar: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files (x86)\ZoneAlarm\tbZone.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 7073 bytes
Hello and :welcome:

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 48 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________


I am checking over your logs and will post the next instructions shortly.
Hi,

You will need to right click and choose "Run as Administrator" to run the tools we will use.


You have µTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/d/security-centra…-p-id-theft-103

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.

I would recommend that you uninstall µTorrent, via Control Panel -> Add or Remove Programs.

However, if you do not wish to remove this program please be advised not to use the said program during the course of cleaning your machine.

References for the risk of these programs can be found in these links:
http://www.esecurityguy.com/p2p_file_sharing
http://www.microsoft.com/protect/data/down…ilesharing.aspx

–Next–

Please read here and here regarding Ask and HotSpot toolbars. You can uninstall them if you want to.

–Next–

Please go to VirSCAN
  • Click on Browse.
  • On the File Upload window, copy/paste the text below into the File name box:
    Q:\140062.enu\Office14\ONENOTEM.EXE
  • Click Upload. Allow the file to be scanned. If it says already scanned – click Reanalyze Now
Please post the results in your next reply.

–Next–

Please post the Spybot logs created when you run the scan.
Open Spybot -> Mode -> Advanced mode -> Tools -> View Reports -> View Pervious reports.
The files are named Checks.yymmdd-hhmm and Fixes.yymmdd-hhmm. "yymmdd-hhmm" denotes the date and time when you run the scan.

–Next–

[external image: Posted Image]
Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
  • Right click GMER.exe then choose "Run as Administrator" to run the tool.
    [external image: Posted Image]
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      [external image: Posted Image]
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Please copy and paste the report into your Post.

To post in your next reply (don't attach):
1. VirSCAN log.
2. Spybot logs.
3. GMER log.
the ONENOTEM.EXE was from the Microsoft Office 2010 Beta, which I downloaded from Microsoft.

As I said, I reinstalled windows, but I still have the win32.pornpopup problem (I only have Avast! Free Antivirus, Google Chrome, Zone Alarm Free Firewall, and Spybot S&D installed) – here's my spybot log:


— Report generated: 2010-06-25 17:12 —

WebTrends live: Tracking cookie (Chrome: Chrome) (Cookie, nothing done)


DoubleClick: Tracking cookie (Chrome: Chrome) (Cookie, nothing done)


MediaPlex: Tracking cookie (Chrome: Chrome) (Cookie, nothing done)


MediaPlex: Tracking cookie (Chrome: Chrome) (Cookie, nothing done)


Win32.PornPopUp: Tracking cookie (Chrome: Chrome) (Cookie, nothing done)


Win32.PornPopUp: Tracking cookie (Chrome: Chrome) (Cookie, nothing done)


Win32.PornPopUp: Tracking cookie (Chrome: Chrome) (Cookie, nothing done)


Win32.PornPopUp: Tracking cookie (Chrome: Chrome) (Cookie, nothing done)


Win32.PornPopUp: Tracking cookie (Chrome: Chrome) (Cookie, nothing done)



MediaPlex: Tracking cookie (Chrome: Chrome) (Cookie, nothing done)


Statcounter: Tracking cookie (Chrome: Chrome) (Cookie, nothing done)



— Spybot - Search & Destroy version: 1.6.2 (build: 20090126) —

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-01-26 TeaTimer.exe ([removed])
2010-06-25 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-01-26 advcheck.dll ([removed])
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll ([removed])
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2010-06-16 Includes\Adware.sbi (*)
2010-06-22 Includes\AdwareC.sbi (*)
2010-01-25 Includes\Cookies.sbi (*)
2009-11-03 Includes\Dialer.sbi (*)
2010-06-22 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2010-06-22 Includes\HijackersC.sbi (*)
2010-06-02 Includes\iPhone.sbi (*)
2010-01-20 Includes\Keyloggers.sbi (*)
2010-06-22 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2010-06-01 Includes\Malware.sbi (*)
2010-06-22 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-06-23 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-06-22 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-06-16 Includes\Spyware.sbi (*)
2010-06-22 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-06-01 Includes\Trojans.sbi (*)
2010-06-22 Includes\TrojansC-02.sbi (*)
2010-06-22 Includes\TrojansC-03.sbi (*)
2010-06-22 Includes\TrojansC-04.sbi (*)
2010-06-22 Includes\TrojansC-05.sbi (*)
2010-06-22 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

I'll add my gmer log in a moment.

edit: GMER doesn't seem to be working properly for my computer… Here's what shows up when I run it as an administrator:

[external image: Posted Image]
Hi,

Let's try this instead:

Download Rooter.exe to your desktop
  • Then right click Rooter.exe then choose "Run as Administrator" to run the tool.
  • Click on the Scan button. Wait for the scan to finish.
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here.
Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully … . Windows 7 Home Edition (6.1.7600) [32_bits] - Intel64 Family 6 Model 23 Stepping 10, GenuineIntel . [wscsvc] (Security Center) RUNNING (state:4) [MpsSvc] RUNNING (state:4) Windows Firewall -> Disabled ! Windows Defender -> Enabled User Account Control (UAC) -> Enabled . Internet Explorer 8.0.7600.16385 . C:\ [Fixed-NTFS] .. ( Total:297 Go - Free:281 Go ) D:\ [CD_Rom] . Scan : 22:56.05 Path : C:\Users\Travis\Desktop\Rooter.exe User : Travis ( Administrator -> YES ) . ———————-\\ Processes . Locked [System Process] (0) Locked System (4) ______ ?????????? (280) ______ ?????????? (372) ______ ?????????? (420) ______ ?????????? (448) ______ ?????????? (488) ______ ?????????? (536) ______ ?????????? (544) ______ ?????????? (552) ______ ?????????? (648) ______ ?????????? (744) ______ ?????????? (808) ______ ?????????? (872) ______ ?????????? (896) ______ ?????????? (328) ______ ?????????? (892) ______ ?????????? (1040) ______ C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (1356) ______ ?????????? (1396) ______ ?????????? (1592) ______ ?????????? (1636) ______ ?????????? (2088) ______ ?????????? (2172) ______ ?????????? (2460) ______ ?????????? (2580) ______ ?????????? (2660) ______ ?????????? (2932) ______ C:\Program Files\Alwil Software\Avast5\AvastUI.exe (3048) ______ ?????????? (1680) ______ ?????????? (2920) ______ ?????????? (604) ______ ?????????? (3040) ______ ?????????? (3140) ______ ?????????? (3376) ______ ?????????? (3636) ______ ?????????? (4140) ______ C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (3216) ______ C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (3832) ______ ?????????? (3116) ______ ?????????? (4620) Locked ???? (3252) ______ C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (4916) ______ C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (4112) ______ C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (2036) ______ C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (3280) ______ ?????????? (2608) ______ ?????????? (2900) ______ ?????????? (2968) ______ ?????????? (4464) ______ ?????????? (2944) ______ ?????????? (3792) ______ C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (3628) ______ ?????????? (4120) ______ ?????????? (3524) ______ C:\Users\Travis\Desktop\Rooter.exe (4572) ______ ?????????? (5032) . ———————-\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 –[ MBR ]– (Start_Offset:1048576 | Length:104857600) \Device\Harddisk0\Partition2 (Start_Offset:105906176 | Length:319965626368) . ———————-\\ Scheduled Tasks . C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job C:\Windows\Tasks\SA.DAT C:\Windows\Tasks\SCHEDLGU.TXT . ———————-\\ Registry . . ———————-\\ Files & Folders . ———————-\\ Scan completed at 22:56.06 . C:\Rooter$\Rooter_1.txt - (26/06/2010 | 22:56.06)
Hi,

Do the following:
  • Open Chrome.
  • Click Tools.
  • Select Options.
  • Click the Under the Hood tab.
  • Click Clear browsing data…
  • Put a check mark beside the following:
    • Clear browsing history
    • Clear download history
    • Empty the cache
    • Delete cookies
  • Click Clear Browsing Data.
  • Exit Chrome.
–Next–

Please read through these instructions to familiarize yourself with what to expect when this tool runs

Download Combofix from either of the links below. Save it to your desktop.

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

———————————————————–


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Right click and choose Run as Administrator ComboFix.exe & follow the prompts. When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

———————————————————–

Hi,

Let's do this instead:

Right click OTL.exe then choose "Run as Administrator" to run the tool.
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    c:\windows\syswow64\PerfStringBackup.TMP
    c:\windows\EXPLORERDE.exe
    c:\windows\system32\explorerframetrash.dll
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • Then post the result and a new OTL log in your next reply. ( don't check the boxes beside LOP Check or Purity this time )
–Next–

MBAM:
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

To post in your next reply:
1. OTL logs.
2. Malwarebytes log.
3. How is you computer?
I'm on a fresh install of windows (just reinstalled a few days ago, but I'm still having the win32.pornpopup problem.) I think the explorerde.exe and those files were left over from a theme I installed and didn't want to use anymore, so I just changed the file names. Here's the MBAM log though - Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4248 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 6/27/2010 9:37:35 PM mbam-log-2010-06-27 (21-37-35).txt Scan type: Quick scan Objects scanned: 130461 Time elapsed: 4 minute(s), 14 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi,

Hi,

Why not uninstall it if you don't want to use it? The pop up may have been coming from that theme.

Do this then:

Right click OTL.exe then choose "Run as Administrator" to run the tool.
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    c:\windows\syswow64\PerfStringBackup.TMP
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • Then post the result and a new OTL log in your next reply. ( don't check the boxes beside LOP Check or Purity this time )
–Next–

Can you post a screen shot of the pop up? Chrome right?

To post in your next reply:
1. OTL logs.
2. Screen shot.
OTL log - All processes killed ========== FILES ========== File\Folder c:\windows\syswow64\PerfStringBackup.TMP not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: AppData User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Guest ->Temp folder emptied: 1145518 bytes ->Temporary Internet Files folder emptied: 10276530 bytes User: Public User: Travis ->Temp folder emptied: 226007402 bytes ->Temporary Internet Files folder emptied: 4875283 bytes ->Java cache emptied: 857857 bytes ->Google Chrome cache emptied: 449554034 bytes ->Flash cache emptied: 13423 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 14476186 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 674.00 mb [EMPTYFLASH] User: All Users User: AppData User: Default User: Default User User: Guest User: Public User: Travis ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.7.0 log created on 06272010_215921 Files\Folders moved on Reboot… C:\Users\Guest\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Travis\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Travis\AppData\Local\Temp\~DF3F622873E563514C.TMP moved successfully. File\Folder C:\Users\Travis\AppData\Local\Temp\~PI11CF.tmp not found! File\Folder C:\Users\Travis\AppData\Local\Temp\~PIAD8.tmp not found! File\Folder C:\Users\Travis\AppData\Local\Temp\~PIDB8.tmp not found! File move failed. C:\Windows\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot. File\Folder C:\Windows\temp\ZLT05e77.TMP not found! Registry entries deleted on Reboot… The popup is only found in spybot. Nothing actually pops up when I'm on the internet, it's just a cookie or something in spybot that ALWAYS comes back no matter what I do.
Hi,

Those found by Spybot are tracking cookies. They are basically text files.

More on cookies: http://en.wikipedia.org/wiki/HTTP_cookie

I've included instructions on post #7 to clear your chrome's cookies and browsing/download history.

You are only using Google Chrome?

Please do the following, this scan can take a while:

Run an on-line scan with Kaspersky

Right click Internet Explorer or Firefox then choose "Run as Administrator" to run the program.

NOTE: After scanning with Kaspersky, close your browser then run it without administrator privileges for your browsing.

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
–Next–

  • Open OTL.exe.
  • Right click on the icon then choose "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • There will only be a single log produced. OTL.Txt.
    Note:This log can be located in the OTL. folder on your C:\ drive if it fails to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it with your next reply.
To post in your next reply:
1. Kaspersky log.
2. OTL log.
Hi,

Try the following:

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

The latest update is Java 6 update 20.

Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are two options in the window to clear the cache - Leave both Checked
    Applications and Applets
    Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

Try running the kaspersky online scan again please.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI