This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

g.js adadvisor.netkeeps popping up on bottomof screen [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys, I need help this following message keeps popping up on the bottom of my screen: g.js adadvisor.net, then asks me if I want to OPEN ,SAVE or CANCEL. I have been getting this massage for the last 2 weeks. any help would be greatly appreciated. I am using VISTA IE9 Thank You Sam
Hello babbagene and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

adadvisor.net is a domain used by Targus Info, an advertising company that is part of a network of sites et al used to track you, what you do and what you click on, as you go from site to site.

Over time, adadvisor.net and other sites that do the same, can help make an online profile of the sites you visit, your searches, purchases, and other behaviour. Your profile can then be exchanged and sold between other companies like adadvisor.net as well as being sold to other advertisers and marketers.

Let’s see what else is lurking.

===================================================

Download and run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
Hi Satchfan, TY for your help. I tried to save the OTL to the desktop , but I keep getting this message: c:\user\sam\downloads\otl(3).exe is not a valid win32 application. I can never get it to the desktop or downloaded.
Hi babbagene

Try Running aswMBR.

If this also won't run, try them both in Safe mode.

To Enter Safemode
  • go to Start> Shut off your Computer> Restart
  • as the computer starts to boot-up, tap the F8 KEY - this will bring up a menu
  • use the Up and Down Arrow Keys to scroll up to Safemode with Networking
  • then press Enter on your keyboard
Satchfan
Hi Satch , I was able to run it in regular mode , here is the log: aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-04-30 16:28:01 —————————– 16:28:01.860 OS Version: Windows 6.0.6002 Service Pack 2 16:28:01.860 Number of processors: 2 586 0x6B02 16:28:01.861 ComputerName: SAM-PC UserName: Sam 16:28:06.481 Initialize success 16:28:41.094 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000056 16:28:41.099 Disk 0 Vendor: ST500DM0 JC4B Size: 476940MB BusType: 6 16:28:41.113 Disk 0 MBR read successfully 16:28:41.119 Disk 0 MBR scan 16:28:41.127 Disk 0 unknown MBR code 16:28:41.136 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 466452 MB offset 63 16:28:41.170 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10485 MB offset 955295744 16:28:41.195 Disk 0 scanning sectors +976769024 16:28:41.263 Disk 0 scanning C:\Windows\system32\drivers 16:28:47.447 Service scanning 16:28:57.686 Modules scanning 16:29:02.608 Disk 0 trace - called modules: 16:29:02.623 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys 16:29:02.629 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85e61140] 16:29:02.992 3 CLASSPNP.SYS[8072e8b3] -> nt!IofCallDriver -> [0x85489700] 16:29:03.000 5 acpi.sys[8060b6bc] -> nt!IofCallDriver -> \Device\00000056[0x846a8b88] 16:29:03.007 Scan finished successfully 16:29:13.994 Disk 0 MBR has been saved successfully to "C:\Users\Sam\Documents\MBR.dat" 16:29:14.000 The log file has been saved successfully to "C:\Users\Sam\Documents\aswMBR.txt"
Let's try a different scan.

Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.pif

  • disable any script blocking protection (How to Disable your Security Programs)
  • double click DDS icon to run the tool (may take up to 3 minutes to run)
  • when done, DDS.txt will open.
  • after a few moments, attach.txt will open in a second window.
  • save both reports to your desktop.
  • Post the contents of the DDS.txt and Attach.txt reports in your next reply
Satchfan
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by [removed] at 17:52:51 on 2012-04-30 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1464 [GMT -4:00] . AV: Norton Security Suite *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton Security Suite *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Security Suite *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k hpdevmgmt c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Norton Security Suite\Engine\5.2.1.3\ccSvcHst.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe C:\Windows\system32\taskeng.exe C:\Program Files\Norton Security Suite\Engine\5.2.1.3\ccSvcHst.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\hp\support\hpsysdrv.exe C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\RtHDVCpl.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Real\RealPlayer\Update\realsched.exe C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe C:\Program Files\Pure Networks\Network Magic\nmapp.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe C:\WINDOWS\System32\rundll32.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\DllHost.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\hp\kbd\kbd.exe c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Windows\system32\taskeng.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Windows Mail\WinMail.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil32_11_2_202_233_ActiveX.exe C:\Users\Sam\AppData\Roaming\mjusbsp\st00000\mjsetup.exe C:\Users\Sam\AppData\Roaming\mjusbsp\magicJack.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://google.com/ uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cndt mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cndt mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cndt BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton security suite\engine\5.2.1.3\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton security suite\engine\5.2.1.3\ips\IPSBHO.DLL BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton security suite\engine\5.2.1.3\coIEPlg.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN uRun: [cdloader] "c:\users\sam\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe mRun: [KBD] c:\hp\kbd\KbdStub.EXE mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [] mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe" mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\snapfi~1.lnk - c:\program files\snapfish picture mover\SnapfishMediaDetector.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 TCP: Interfaces\{6CA0F23B-C7FC-430F-93B0-CB54DE0E3C35} : DhcpNameServer = 75.75.75.75 75.75.76.76 Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0502010.003\symds.sys [2012-4-23 340088] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0502010.003\symefa.sys [2012-4-23 744568] R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\bashdefs\20120413.001\BHDrvx86.sys [2012-4-19 821880] R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\ipsdefs\20120427.001\IDSvix86.sys [2012-4-27 368248] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0502010.003\ironx86.sys [2012-4-23 136312] R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0502010.003\symtdiv.sys [2012-4-23 331384] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 N360;Norton Security Suite;c:\program files\norton security suite\engine\5.2.1.3\ccsvchst.exe [2012-4-23 130008] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-4-15 106104] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-14 253088] . =============== Created Last 30 ================ . 2012-04-30 07:26:46 ——– d—–w- c:\program files\Pure Networks 2012-04-30 07:26:10 ——– d—–w- c:\programdata\webex 2012-04-30 07:25:59 8673792 —-a-w- c:\programdata\atscie.msi 2012-04-30 07:23:51 24880 —-a-w- c:\windows\system32\drivers\pnarp.sys 2012-04-30 07:22:37 26416 —-a-w- c:\windows\system32\drivers\purendis.sys 2012-04-30 07:22:35 ——– d—–w- c:\program files\common files\Pure Networks Shared 2012-04-30 07:22:23 ——– d—–w- c:\programdata\Pure Networks 2012-04-30 07:22:23 ——– d—–w- c:\program files\Linksys 2012-04-28 21:48:13 ——– d—–w- c:\users\sam\appdata\local\Microsoft Games 2012-04-26 20:22:30 ——– d—–w- c:\users\sam\appdata\roaming\WildTangent 2012-04-24 03:59:36 331384 —-a-w- c:\windows\system32\drivers\n360\0502010.003\symtdiv.sys 2012-04-24 03:59:36 299640 —-a-w- c:\windows\system32\drivers\n360\0502010.003\symnets.sys 2012-04-24 03:59:35 744568 —-a-w- c:\windows\system32\drivers\n360\0502010.003\symefa.sys 2012-04-24 03:59:35 516216 —-a-w- c:\windows\system32\drivers\n360\0502010.003\srtsp.sys 2012-04-24 03:59:35 50168 —-a-w- c:\windows\system32\drivers\n360\0502010.003\srtspx.sys 2012-04-24 03:59:35 340088 —-a-w- c:\windows\system32\drivers\n360\0502010.003\symds.sys 2012-04-24 03:59:35 136312 —-a-r- c:\windows\system32\drivers\n360\0502010.003\ironx86.sys 2012-04-24 03:59:13 ——– d—–w- c:\windows\system32\drivers\n360\0502010.003 2012-04-23 22:05:39 ——– d—–w- c:\users\sam\appdata\roaming\Malwarebytes 2012-04-23 22:05:28 ——– d—–w- c:\programdata\Malwarebytes 2012-04-23 22:05:27 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-04-23 22:05:27 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-04-18 22:13:49 ——– d—–w- c:\program files\common files\xing shared 2012-04-18 01:59:11 ——– d—–w- c:\users\sam\appdata\local\Google 2012-04-17 22:34:03 683008 —-a-w- c:\windows\system32\d2d1.dll 2012-04-17 22:34:03 219648 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-04-17 22:34:03 160768 —-a-w- c:\windows\system32\d3d10_1.dll 2012-04-17 22:34:03 1172480 —-a-w- c:\windows\system32\d3d10warp.dll 2012-04-17 22:34:03 1068544 —-a-w- c:\windows\system32\DWrite.dll 2012-04-17 14:54:28 ——– d—–w- c:\program files\Gamers Unite! Snag Bar 2012-04-17 07:11:18 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-17 07:11:18 172032 —-a-w- c:\windows\system32\wintrust.dll 2012-04-17 07:11:18 157696 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-17 07:11:18 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-17 07:07:59 586240 —-a-w- c:\windows\system32\stobject.dll 2012-04-17 07:06:47 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll 2012-04-17 07:06:47 519680 —-a-w- c:\windows\system32\d3d11.dll 2012-04-17 07:06:47 369664 —-a-w- c:\windows\system32\WMPhoto.dll 2012-04-17 07:06:47 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll 2012-04-17 07:06:47 252928 —-a-w- c:\windows\system32\dxdiag.exe 2012-04-17 07:06:47 195584 —-a-w- c:\windows\system32\dxdiagn.dll 2012-04-17 07:06:47 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll 2012-04-17 01:55:59 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-04-17 01:51:40 613376 —-a-w- c:\windows\system32\rdpencom.dll 2012-04-17 01:51:40 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-16 20:49:35 ——– d—–w- c:\windows\system32\eu-ES 2012-04-16 20:49:35 ——– d—–w- c:\windows\system32\ca-ES 2012-04-16 20:49:33 ——– d—–w- c:\windows\system32\vi-VN 2012-04-16 17:50:48 ——– d—–w- c:\windows\system32\EventProviders 2012-04-16 11:38:59 97792 —-a-w- c:\windows\system32\mprapi.dll 2012-04-16 07:01:38 99176 —-a-w- c:\windows\system32\PresentationHostProxy.dll 2012-04-16 07:01:38 49472 —-a-w- c:\windows\system32\netfxperf.dll 2012-04-16 07:01:38 297808 —-a-w- c:\windows\system32\mscoree.dll 2012-04-16 07:01:38 295264 —-a-w- c:\windows\system32\PresentationHost.exe 2012-04-16 07:01:38 1130824 —-a-w- c:\windows\system32\dfshim.dll 2012-04-16 07:00:58 ——– d—–w- c:\program files\MSXML 4.0 2012-04-15 14:09:11 17920 —-a-w- c:\windows\system32\netevent.dll 2012-04-15 14:09:11 125952 —-a-w- c:\windows\system32\srvsvc.dll 2012-04-15 04:12:17 995383 —-a-w- c:\windows\system32\temp.001 2012-04-15 04:12:17 295000 —-a-w- c:\windows\system32\temp.000 2012-04-15 04:12:15 ——– d—–w- c:\program files\ClubWPT 2012-04-15 04:02:16 ——– d—–w- c:\programdata\WEBREG 2012-04-15 04:00:25 ——– d—–w- c:\users\sam\appdata\local\HP 2012-04-15 03:54:56 274944 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\hpzpp5ha.dll 2012-04-15 03:51:23 ——– d—–w- c:\program files\common files\Hewlett-Packard 2012-04-15 03:50:55 ——– d—–w- c:\program files\common files\HP 2012-04-15 03:49:43 118272 —-a-w- c:\windows\system32\hpz3l5ha.dll 2012-04-15 03:47:33 970752 —-a-w- c:\windows\system32\hpotiop5.dll 2012-04-15 03:47:33 729088 —-a-w- c:\windows\system32\hpowiax5.dll 2012-04-15 03:47:33 364544 —-a-w- c:\windows\system32\hppldcoi.dll 2012-04-15 03:47:33 309760 —-a-w- c:\windows\system32\difxapi.dll 2012-04-15 03:47:33 303104 —-a-w- c:\windows\system32\hpovst12.dll 2012-04-15 03:47:33 271704 —-a-w- c:\windows\system32\hpzids01.dll 2012-04-14 20:07:56 411648 —-a-w- c:\windows\system32\drivers\http.sys 2012-04-14 20:07:56 24064 —-a-w- c:\windows\system32\nshhttp.dll 2012-04-14 20:07:55 30720 —-a-w- c:\windows\system32\httpapi.dll 2012-04-14 20:06:04 708608 —-a-w- c:\program files\common files\system\ado\msado15.dll 2012-04-14 20:06:04 57344 —-a-w- c:\program files\common files\system\msadc\msadcs.dll 2012-04-14 20:06:04 413696 —-a-w- c:\windows\system32\odbc32.dll 2012-04-14 20:06:04 253952 —-a-w- c:\program files\common files\system\ado\msadox.dll 2012-04-14 20:06:04 241664 —-a-w- c:\program files\common files\system\ado\msadomd.dll 2012-04-14 20:06:04 180224 —-a-w- c:\program files\common files\system\msadc\msadco.dll 2012-04-14 20:06:00 66048 —-a-w- c:\program files\windows mail\wabmig.exe 2012-04-14 20:06:00 515584 —-a-w- c:\program files\windows mail\wab.exe 2012-04-14 20:06:00 33280 —-a-w- c:\program files\windows mail\wabfind.dll 2012-04-14 20:04:59 218624 —-a-w- c:\windows\system32\msv1_0.dll 2012-04-14 19:56:27 91136 —-a-w- c:\windows\system32\avifil32.dll 2012-04-14 19:56:27 82944 —-a-w- c:\windows\system32\mciavi32.dll 2012-04-14 19:56:27 50176 —-a-w- c:\windows\system32\iyuv_32.dll 2012-04-14 19:56:27 31744 —-a-w- c:\windows\system32\msvidc32.dll 2012-04-14 19:56:27 22528 —-a-w- c:\windows\system32\msyuv.dll 2012-04-14 19:56:27 13312 —-a-w- c:\windows\system32\msrle32.dll 2012-04-14 19:56:27 123904 —-a-w- c:\windows\system32\msvfw32.dll 2012-04-14 19:56:27 12288 —-a-w- c:\windows\system32\tsbyuv.dll 2012-04-14 18:52:15 2048 —-a-w- c:\program files\internet explorer\iecompat.dll 2012-04-14 18:52:10 265720 —-a-w- c:\program files\internet explorer\msdbg2.dll 2012-04-14 18:52:09 355832 —-a-w- c:\program files\internet explorer\pdm.dll 2012-04-14 18:18:58 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-04-14 18:18:57 126584 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2012-04-14 18:18:48 106928 —-a-w- c:\windows\system32\GEARAspi.dll 2012-04-14 18:18:44 ——– d—–w- c:\windows\system32\drivers\N360 2012-04-14 18:18:42 ——– d—–w- c:\program files\Norton Security Suite 2012-04-14 18:18:35 ——– d—–w- c:\programdata\NortonInstaller 2012-04-14 18:18:35 ——– d—–w- c:\program files\NortonInstaller 2012-04-14 18:16:37 ——– d—–w- c:\programdata\Norton 2012-04-14 18:13:25 472808 —-a-w- c:\windows\system32\deployJava1.dll 2012-04-14 18:02:12 ——– d—–w- c:\users\sam\appdata\local\ID Vault 2012-04-14 18:02:12 ——– d—–w- c:\programdata\IsolatedStorage 2012-04-14 18:02:00 ——– d—–w- c:\users\sam\appdata\roaming\ID Vault 2012-04-14 18:01:45 ——– d—–w- c:\program files\Constant Guard Protection Suite 2012-04-14 18:01:23 ——– d—–w- c:\programdata\White Sky, Inc 2012-04-14 17:54:47 ——– d—–w- c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP 2012-04-14 17:39:37 ——– d—–w- c:\users\sam\appdata\local\tjnet 2012-04-14 17:36:44 ——– d—–w- c:\users\sam\appdata\local\magicJack 2012-04-14 17:36:39 ——– d—–w- c:\programdata\magicJack 2012-04-14 17:36:07 ——– d—–w- c:\users\sam\appdata\roaming\mjusbsp 2012-04-14 14:13:22 ——– d—–w- c:\users\sam\appdata\roaming\Symantec 2012-04-14 14:12:53 ——– d—–w- c:\users\sam\appdata\local\VirtualStore 2012-04-14 14:10:20 98304 —-a-w- c:\windows\system32\cabview.dll 2012-04-14 14:09:25 ——– d—–w- c:\users\sam\appdata\roaming\HP TCS 2012-04-14 14:08:59 ——– d—–w- c:\users\sam\appdata\local\Adobe 2012-04-14 14:04:13 2421760 —-a-w- c:\windows\system32\wucltux.dll 2012-04-14 14:04:04 87552 —-a-w- c:\windows\system32\wudriver.dll 2012-04-14 14:04:01 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-04-14 14:04:01 171608 —-a-w- c:\windows\system32\wuwebv.dll 2012-04-14 14:03:24 ——– d-sh–we C:\Documents and Settings . ==================== Find3M ==================== . 2012-04-18 22:13:35 348160 —-a-w- c:\windows\system32\msvcr71.dll 2012-04-17 07:07:59 209920 —-a-w- c:\windows\system32\mfplat.dll 2012-04-17 07:06:49 4096 —-a-w- c:\windows\system32\drivers\en-us\dxgkrnl.sys.mui 2012-04-14 20:05:45 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-04-14 20:05:45 418464 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-02-28 01:18:55 1799168 —-a-w- c:\windows\system32\jscript9.dll 2012-02-28 01:11:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl 2012-02-28 01:11:07 1127424 —-a-w- c:\windows\system32\wininet.dll 2012-02-28 01:03:16 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-02-02 15:16:25 2044416 —-a-w- c:\windows\system32\win32k.sys . ============= FINISH: 17:53:14.01 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 4/14/2012 12:59:21 PM System Uptime: 4/30/2012 8:25:03 AM (9 hours ago) . Motherboard: OEM_MB | | NARRA3 Processor: AMD Athlon™ 64 X2 Dual Core Processor 5000+ | Socket AM2 | 2200/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 456 GiB total, 362.022 GiB free. D: is FIXED (NTFS) - 10 GiB total, 1.343 GiB free. E: is CDROM (CDFS) G: is Removable H: is Removable I: is Removable J: is Removable K: is CDROM () L: is Removable . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318} Description: PS/2 Compatible Mouse Device ID: ACPI\PNP0F13\4&37EFC377&0 Manufacturer: Microsoft Name: PS/2 Compatible Mouse PNP Device ID: ACPI\PNP0F13\4&37EFC377&0 Service: i8042prt . ==== System Restore Points =================== . RP10: 4/14/2012 2:51:51 PM - Windows Update RP11: 4/14/2012 2:53:00 PM - Windows Update RP12: 4/14/2012 4:06:16 PM - Windows Update RP14: 4/14/2012 11:49:13 PM - HP Installation Restore Point RP15: 4/15/2012 3:00:11 AM - Windows Update RP16: 4/16/2012 3:00:15 AM - Windows Update RP17: 4/16/2012 4:31:28 AM - Windows Update RP18: 4/16/2012 1:49:01 PM - Windows Update RP19: 4/16/2012 1:50:10 PM - Windows Update RP20: 4/16/2012 4:41:15 PM - Windows Update RP21: 4/16/2012 8:02:48 PM - Norton Security Suite Registry RP22: 4/17/2012 3:00:21 AM - Windows Update RP23: 4/18/2012 1:06:52 AM - Scheduled Checkpoint RP24: 4/18/2012 3:00:12 AM - Windows Update RP25: 4/24/2012 12:15:18 PM - Scheduled Checkpoint RP26: 4/25/2012 3:34:10 AM - Scheduled Checkpoint RP27: 4/26/2012 1:12:43 AM - Removed Google Earth. RP28: 4/26/2012 2:45:28 AM - Norton Security Suite Registry RP29: 4/27/2012 1:52:53 AM - Scheduled Checkpoint RP30: 4/28/2012 12:30:52 AM - Scheduled Checkpoint RP32: 4/29/2012 2:17:50 AM - Scheduled Checkpoint RP33: 4/30/2012 3:22:43 AM - Device Driver Package Install: Cisco Systems, Inc. Network Protocol RP34: 4/30/2012 3:23:51 AM - Device Driver Package Install: Cisco Systems, Inc. Network Protocol RP35: 4/30/2012 4:24:42 AM - Norton Security Suite Registry . ==== Installed Programs ====================== . 32 Bit HP CIO Components Installer Adobe Flash Player 11 ActiveX Adobe Reader 8.1.2 AIO_Scan BufferChm C5200 C5200_Help Cards_Calendar_OrderGift_DoMorePlugout Cisco Network Magic ClubWPT Compatibility Pack for the 2007 Office system Copy CustomerResearchQFolder CyberLink DVD Suite Deluxe CyberLink PowerDirector Destination Component DeviceDiscovery DeviceManagementQFolder DocProc DocProcQFolder Enhanced Multimedia Keyboard Solution eSupportQFolder Fax GPBaseService Hardware Diagnostic Tools Hewlett-Packard Active Check for Health Check Hewlett-Packard Asset Agent for Health Check Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Active Support Library HP Customer Experience Enhancements HP Customer Feedback HP Customer Participation Program 10.0 HP Demo HP Imaging Device Functions 10.0 HP Photosmart All-In-One Driver Software 10.0 Rel .2 HP Photosmart Essential 2.5 HP Picasso Media Center Add-In HP Solution Center 10.0 HP Total Care Advisor HP Update HPPhotoSmartDiscLabel_PaperLabel HPPhotoSmartDiscLabel_PrintOnDisc HPPhotoSmartDiscLabelContent1 hpphotosmartdisclabelplugin HPPhotoSmartPhotobookWebPack1 HPProductAssistant HPSSupply HPTCSSetup Java Auto Updater Java™ 6 Update 31 Java™ SE Runtime Environment 6 Update 1 LabelPrint LightScribe System Software 1.12.37.1 LightScribeTemplateLabeler LiveUpdate (Symantec Corporation) magicJack Malwarebytes Anti-Malware version 1.61.0.1400 MarketResearch Microsoft .NET Framework 3.5 SP1 Microsoft Office Home and Student 60 day trial Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Visual C++ 2005 Redistributable Microsoft Works MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) muvee autoProducer 6.1 My HP Games Network Magic Norton Security Suite NVIDIA Drivers OCR Software by I.R.I.S. 10.0 PanoStandAlone Power2Go PS_AIO_02_ProductContext PS_AIO_02_Software PS_AIO_02_Software_Min PSSWCORE Pure Networks Platform Python 2.5 RealNetworks - Microsoft Visual C++ 2008 Runtime RealPlayer Realtek High Definition Audio Driver RealUpgrade 1.1 Scan Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Shop for HP Supplies Snapfish Picture Mover Soft Data Fax Modem with SmartCP SolutionCenter Status Toolbox TrayApp UnloadSupport Update for Microsoft .NET Framework 3.5 SP1 (KB963707) VideoToolkit01 WebEx Support Manager for Internet Explorer WebReg . ==== Event Viewer Messages From Past Week ======== . 4/30/2012 8:27:17 AM, Error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting. 4/30/2012 8:26:21 AM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 4/30/2012 8:25:33 AM, Error: EventLog [6008] - The previous system shutdown at 7:48:19 AM on 4/30/2012 was unexpected. 4/30/2012 8:18:26 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Audiosrv service. 4/30/2012 8:16:55 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Eventlog service. 4/30/2012 3:48:32 AM, Error: cdrom [11] - The driver detected a controller error on \Device\CdRom3. 4/30/2012 3:29:28 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.103 for the Network Card with network address 002215259706 has been denied by the DHCP server [removed] (The DHCP Server sent a DHCPNACK message). 4/30/2012 10:38:13 AM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk5\DR6. 4/30/2012 1:47:05 AM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk1\DR26. 4/25/2012 8:09:04 PM, Error: bowser [8003] - The master browser has received a server announcement from the computer SAMANTHA that believes that it is the master browser for the domain on transport NetBT_Tcpip_{6CA0F23B-C7FC-430F-93B0-CB54DE0E3. The master browser is stopping or an election is being forced. 4/24/2012 12:03:32 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TrkWks service. . ==== End Of File ===========================
Hi Sam

Nothing bad in that log so that's a good sign.

Uninstall the following program:1. Click Start, Control Panel, Programs, and then Programs and Features.
2. Click on Java™ SE Runtime Environment 6 Update 1 and then Uninstall.
If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

===============================================

Clear all your temporary files

Download ATF Cleaner
  • double-click ATF-Cleaner.exe (on your desktop) to run the program.
  • under Main choose: Select All
  • click the Empty Selected button.
If you use Firefox browser
  • click Firefox at the top and choose: Select All
  • click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • click Opera at the top and choose: Select All
  • click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

For Technical Support, double-click the e-mail address located at the bottom of each menu

===============================================

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Please let me know if there is any change

Satchfan
Good Morning Satchfan here is the log: Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.05.01.05 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Sam :: SAM-PC [administrator] 5/1/2012 6:18:34 AM mbam-log-2012-05-01 (06-18-34).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 183497 Time elapsed: 3 minute(s), 36 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Hi Sam

so far so good , no pop-up any longer . I will let you know for sure tomorrow

OK.

Can you meanwhile run this scan to make sure there is nothing else left behind.

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

Thanks

Satchfan
Hello babbagene It has been several days since I posted instructions to help with your computer problem. Please let me know if you are having problems and still need help. Thanks Satchfan
Im sorry Satch fan , I thought I wrote back to you . The problem has been resolved by youn . Thank You so much! Regards Sam
Hi Sam

I assume that the Eset can came back clear.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

Create a Restore Point
  • click Start, right-click Computer, and then Properties.
  • in the left pane, click System protection. If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
  • click the System Protection tab, and then click Create.
  • in the System Protection dialog box, type a description, and then click Create.
Remove old restore points
  • click the Start button and in the search box, type Disk Cleanup, and then, in the list of results, click Disk Cleanup.
  • if prompted, select the drive that you want to clean up, and then click OK.
  • in the Disk Cleanup for (drive letter) dialog box, click Clean up system files. If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
  • if prompted, select the drive that you want to clean up, and then click OK.
  • click the More Options tab, under System Restore and Shadow Copies, click Clean up.
  • in the Disk Cleanup dialog box, click Delete.
  • click Delete Files, and then click OK.
===================================================

Update Reader

Visit ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

===================================================

Update and run Malwarebytes. This really is an excellent program that you should update and run on a regular basis, probably weekly.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes


Safe computing

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI