This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help with pop ups. Programs listed with "" publisher [Solved]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am attaching another Fixlog, it will make outtube and coinsave and Renrun visible so you can uninstall them via Programs and Features in the Control Panel, it looks like Active mail is visible so you should be able to uninstall that one

Ok, I ran your new fixlist and was able to delete the items from the control panel. Here's a copy of the log that was created after the fix: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by [removed] at 2015-03-26 22:47:17 Run:3 Running from C:\Users\[removed]\Desktop [removed] Boot Mode: Normal ============================================== Content of fixlist: ***************** Start CreateRestorePoint: CloseProcesses: coinsaove (HKLM-x32\…\{C8AAF59A-6BAA-F68B-9470-A856460A8093}) (Version: - "") <==== ATTENTION Youtube Preview Is it worth watching (HKLM-x32\…\{CDFBAC3A-2FE1-0B77-34C9-065BBCC8B77C}) (Version: - "") <==== ATTENTION Renren Album Downloader (HKLM-x32\…\{AF992111-52BE-832B-5882-8477E4A3C99A}) (Version: - "") <==== ATTENTION EmptyTemp: End ***************** Restore point was successfully created. Processes closed successfully. coinsaove (HKLM-x32\…\{C8AAF59A-6BAA-F68B-9470-A856460A8093}) (Version: - "") <==== ATTENTION => Error: No automatic fix found for this entry. Youtube Preview Is it worth watching (HKLM-x32\…\{CDFBAC3A-2FE1-0B77-34C9-065BBCC8B77C}) (Version: - "") <==== ATTENTION => Error: No automatic fix found for this entry. Renren Album Downloader (HKLM-x32\…\{AF992111-52BE-832B-5882-8477E4A3C99A}) (Version: - "") <==== ATTENTION => Error: No automatic fix found for this entry. EmptyTemp: => Removed 628 MB temporary data. The system needed a reboot. ==== End of Fixlog 22:48:35 ====

Yes, lets run a free online Virus scanner, I have seen this run in 45 minutes on some systems and for a few hours on others so do it when you have time

 

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan
 
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
 
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
  2. ESET OnlineScan
  3. Click the [external image: esetOnline.png] button.
  4. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on [external image: esetSmartInstall.png] to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the [external image: esetSmartInstallDesktopIcon.png] icon on your desktop.
    3. Check [external image: esetAcceptTerms.png]
    4. Click the [external image: esetStart.png] button.
    5. Accept any security warnings from your browser.
    6. Check [external image: esetScanArchives.png]
    7. Make sure that the option "Remove found threats" is Unchecked
    8. Push the Start button.
    9. ESET will then download updates for itself, install itself, and begin
    10. scanning your computer. Please be patient as this can take some time.
    11. When the scan completes, push [external image: esetListThreats.png]
    12. Push [external image: esetExport.png], and save the file to your desktop using a unique name, such as
    13. ESETScan. Include the contents of this report in your next reply.
    14. Push the [external image: esetBack.png] button.
    15. Push [external image: esetFinish.png]
    16. Please make sure you include the following items in your next post:
      The log that was produced after running ESET Online Scanner.
      Hey Ken, just to check in with you - I had to switch apartments won't have the internet for a moment, so I might be slow to respond just this weekend. I should be all set by Monday.

      Hey Ken, sorry for the delay. I had a scheduling problem with my ISP and getting a Korean friend to help me. Would be it all right for me to run the scan tonight, and then put the log on a USB? I'd be able to post the log tomorrow morning from work. 

       

      I should have thought of that earlier. 

      When you download ESET, before the scan begins it needs internet access to update the virus definitions so that the database is up to date, I dont mind waiting a few more days until you get settled

      Hey Ken, thanks again for your patience. I'm up and running. I know you mentioned the scan would take a while but I left for work and came back and it was still going - somewhere around 47 percent. The odd thing was it was still counting files, but it had been going for 8 hours. I figure I should uninstall, restart, and then try again - but I'm wondering if there's some misstep I took.

      Sometimes it takes awhile, make sure your anti virus is disabled as it may hinder if from running.

       

      If no joy than try this one

      Trendmicro Housecall

      Ah, so I tried again and it took a more reasonable 90ish minutes. Here's the scan log: C:\AdwCleaner\Quarantine\C\Program Files (x86)\DeealExpress\DeealExpress.exe.vir a variant of Win32/AdWare.MultiPlug.BN application C:\AdwCleaner\Quarantine\C\Program Files (x86)\FuindBeSTDeal\TJPxbrqOuvJFX7.exe.vir a variant of Win32/AdWare.MultiPlug.BN application C:\AdwCleaner\Quarantine\C\Program Files (x86)\MIniimumPricue\MIniimumPricue.exe.vir a variant of Win32/AdWare.MultiPlug.BN application C:\AdwCleaner\Quarantine\C\Program Files (x86)\taKesaavve\taKesaavve.exe.vir a variant of Win32/AdWare.MultiPlug.BN application C:\AdwCleaner\Quarantine\C\Program Files (x86)\Vuze_Remote\ldrtbVuze.dll.vir a variant of Win32/Toolbar.Conduit.P potentially unwanted application C:\AdwCleaner\Quarantine\C\Program Files (x86)\Vuze_Remote\prxtbVuze.dll.vir Win32/Toolbar.Conduit.O potentially unwanted application C:\AdwCleaner\Quarantine\C\Program Files (x86)\Vuze_Remote\tbVuze.dll.vir a variant of Win32/Toolbar.Conduit.B potentially unwanted application C:\AdwCleaner\Quarantine\C\Program Files (x86)\Vuze_Remote\Vuze_RemoteToolbarHelper.exe.vir Win32/Toolbar.Conduit.Q potentially unwanted application C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir a variant of Win32/ELEX.AV potentially unwanted application C:\AdwCleaner\Quarantine\C\ProgramData\MiINImmumPrice\FOZTfd6IXkgQZt.dll.vir Win32/Adware.MultiPlug.EG application C:\AdwCleaner\Quarantine\C\ProgramData\MiINImmumPrice\FOZTfd6IXkgQZt.exe.vir a variant of Win32/AdWare.MultiPlug.BN application C:\AdwCleaner\Quarantine\C\ProgramData\null\content.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\ProgramData\null\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\ProgramData\null\NukBt8Tzro.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\torch\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\torch\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\torch\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\torch\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\torch\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\Guest\AppData\Local\torch\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\SS\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\SS\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\SS\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\SS\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\SS\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\SS\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\SS\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\SS\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\SS\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\SS\AppData\Local\torch\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\SS\AppData\Local\torch\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\SS\AppData\Local\torch\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\SS\AppData\LocalLow\Vuze_Remote\ldrtbVuze.dll.vir a variant of Win32/Toolbar.Conduit.P potentially unwanted application C:\AdwCleaner\Quarantine\C\Users\SS\AppData\LocalLow\Vuze_Remote\tbVuze.dll.vir a variant of Win32/Toolbar.Conduit.B potentially unwanted application C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Chromatic Browser\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\torch\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\BYwwAqC.js.vir JS/Kryptik.ATB trojan C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\torch\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\content.js.vir JS/Chromex.Agent.L trojan C:\AdwCleaner\Quarantine\C\Users\UpdatusUser\AppData\Local\torch\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm\5.2\lsdb.js.vir JS/Adware.MultiPlug.B application C:\Users\SS\Downloads\dfdownloader_MsQ8rk_.exe a variant of Win32/DepoDownloader.A potentially unwanted application C:\Users\SS\Downloads\HSS-2.25-install-anchorfree-232-expatshield.exe a variant of Win32/Toolbar.Conduit.AI potentially unwanted application

      It looks like most of it is in AdwCleaner Quarantine

       

      Double click on AdwCleaner.exe to run the tool again.
      • Click on the Uninstall button.
      • Click Yes when asked are you sure you want to uninstall.
      • Both AdwCleaner.exe, its folder and all logs will be removed.
      •  
        C:\Users\SS\Downloads\dfdownloader_MsQ8rk_.exe  <–Delete this file

        Looks like your good to go   :clap:

         

         

         
        Please download DelFix and save the file to your Desktop.
         
        [external image: DelFix_zps139e2ea1.jpg]
         
        • Windows XP Double Click DelFix.exe to run the program. 
        • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
        • Checkmark " Remove Disinfection Tools"
        • Click the Run button
        •  
          This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
           
           
           
          ==========================================================
           
           
           
            How did I get infected in the first place ?    
            Read these links and find out how to prevent getting infected again.
          • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
          • WhattheTech
          • Grinler BleepingComputer 
          • GeeksTo Go
          • Dslreports
          •  
             
            Safe Surfn
            Ken

            Ask AI

            AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

            Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI