Avast WEBforum

Other => Viruses and worms => Topic started by: REDACTED on May 03, 2015, 12:37:43 AM

Title: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 03, 2015, 12:37:43 AM
Hello community,

I'm having this problem (as described in the title) others already posted about in previous messages, but as you need to know the info about my own machine, here it goes :

Using Windows 7 64-bits, Avast version : 2014.9.0.2021

I did the Farbar scan and I attached the FRST.txt file.


I hope you can help me, it's really getting extremely annoying.

Thank you !
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: Eddy on May 03, 2015, 01:01:59 AM
1]
Where are the other logs that we need ?
https://forum.avast.com/index.php?topic=53253.0

2]
You have used a old version of Farbar.
Use the latest one to create the log files.

3]
You are using a old version of avast.
Perform a clean installation of the latest one:
https://forum.avast.com/index.php?topic=169255.msg1203279#msg1203279
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 03, 2015, 06:05:33 AM
Please follow the instructions above and I will prepare a fix.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 03, 2015, 06:34:42 PM
Hello,

Thank you for your rapid response. I followed all the instructions, please find the log files in the attachment.

I also downloaded the latest Avast version, as well as Farbar.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 03, 2015, 07:02:48 PM
Hi elvazur, :)

My name is Valinorum and I will be the acolyte today. Before we proceed, please, acknowledge yourself the following(s):



Uninstall Bundled software uninstaller and YTD YouTube Downloader & Converter 3.7.





Code: [Select]
Start
CreateRestorePoint:
CloseProcesses:
EmptyTemp:
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-3319195597-3395872903-476012188-1000\...\MountPoints2: G - G:\PERMIS.EXE
HKU\S-1-5-21-3319195597-3395872903-476012188-1000\...\MountPoints2: {2824cda2-318e-11e3-9a9b-c86000c8af9e} - F:\setup.exe
HKU\S-1-5-21-3319195597-3395872903-476012188-1000\...\MountPoints2: {2824cda7-318e-11e3-9a9b-c86000c8af9e} - G:\Setup.exe
HKU\S-1-5-21-3319195597-3395872903-476012188-1000\...\MountPoints2: {9615f26c-35a4-11e3-93ef-c86000c8af9e} - I:\setup.exe
HKU\S-1-5-21-3319195597-3395872903-476012188-1000\...\MountPoints2: {ed20bc40-ea99-11e3-ab97-c86000c8af9e} - J:\Setup.exe
FF Extension: 1-Click YouTube Video Downloader - C:\Users\Nizar\AppData\Roaming\Mozilla\Firefox\Profiles\izuprjyf.default-1380744932825\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2014-05-16]
S2 FreemakeVideoCapture; "C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe" [X]
C:\Program Files (x86)\Freemake\
2015-05-03 16:20 - 2012-06-09 11:42 - 00000200 _____ () C:\Windows\Tasks\AutoKMS.job
2015-05-03 15:20 - 2012-06-09 11:42 - 00000202 _____ () C:\Windows\Tasks\AutoKMSDaily.job
Task: {7A486422-45C6-4D79-8B93-2F2F468954CF} - System32\Tasks\AutoKMSDaily => C:\Windows\AutoKMS.exe
Task: {841B3CA9-69D5-486E-AA00-4D1D05554C72} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe
Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS.exe
Task: C:\Windows\Tasks\AutoKMSDaily.job => C:\Windows\AutoKMS.exe
C:\Windows\AutoKMS.exe
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
AlternateDataStreams: C:\Users\Nizar\AppData\Local\Temp:AedC5fBdFMAybTED72U
AlternateDataStreams: C:\Users\Nizar\AppData\Local\Temporary Internet Files:iKmMPWxVLk36LAD3gmO
FirewallRules: [TCP Query User{AA928441-9BCD-48EC-BA41-3E241969D571}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [UDP Query User{B245E5E2-1E8B-443D-8440-A50E1713A860}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
C:\windows\kmsemulator.exe
Hosts:
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state on
RemoveProxy:
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns
End



Regards,
Valinorum
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 03, 2015, 07:20:41 PM
Hello Valinorum :)

Here is the fix log as requested.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 03, 2015, 07:28:59 PM
How is your PC?
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 03, 2015, 07:35:07 PM
Still the same, getting popups about the same issue.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 03, 2015, 08:03:05 PM
Reset (http://www.howtogeek.com/171924/how-to-reset-your-web-browser-to-its-default-settings/) your browser after completing Step 2.






Regards,
Valinorum
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 03, 2015, 08:21:42 PM
Hi again,

Here's the AdwCleaner log.

(still getting the pop-ups)
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 03, 2015, 08:27:43 PM
Reset (http://www.howtogeek.com/171924/how-to-reset-your-web-browser-to-its-default-settings/) your browser.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 03, 2015, 08:35:28 PM
I followed the instructions, but I only have a "Refresh" button (see attachment). I don't know if it's the same, but I did it.

The pop-ups are still popping, they are totally independent from my internet browser I think.

What I have been doing before to be able to work without interruption, is I go to the task manager and kill the "explorer.exe" process. Then it stops.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 04, 2015, 06:01:26 PM
Yes, click on the 'Refresh Firefox' button.

Quote
What I have been doing before to be able to work without interruption, is I go to the task manager and kill the "explorer.exe" process. Then it stops.
Let us eliminate the general possibilities first. Since you mentioned that killing "explorer.exe" process is stopping the pop-up, I would ask you to re-run FRST.exe and type explorer.exe in the search box. Click on "Search Files" and attach the log when done.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 04, 2015, 08:08:59 PM
Here's the Search log.

PS : I had already hit the refresh button :)
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 06, 2015, 07:13:13 PM


Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 07, 2015, 11:00:52 AM
I did the scan and cleaning, but I'm still getting the pop-ups.
Here are the logs.

mbar-log :

Malwarebytes Anti-Rootkit BETA 1.09.1.1004
www.malwarebytes.org

Database version:
  main:    v2015.05.06.04
  rootkit: v2015.04.21.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.17728
Nizar :: NIZAR-PC [administrator]

5/6/2015 10:29:01 PM
mbar-log-2015-05-06 (22-29-01).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 450202
Time elapsed: 10 minute(s), 31 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 3
C:\ProgramData\Microsoft\Secure\Icons\temp\tmp120C.exe (Trojan.Krypt) -> Delete on reboot. [d894bed258324de958154dbe18eab44c]
C:\ProgramData\Microsoft\Secure\Icons\temp\tmp4A67.exe (Trojan.Agent.FSAVXGen) -> Delete on reboot. [c2aa8e021f6b77bf80656446ec1507f9]
C:\ProgramData\Microsoft\Secure\Icons\temp\tmp53E9.exe (Trojan.Agent.DED) -> Delete on reboot. [98d45b3593f7c76f187fa45715eced13]

Physical Sectors Detected: 0
(No malicious items detected)

(end)


-------------------------------------------
-------------------------------------------
-------------------------------------------

System-log :

Malwarebytes Anti-Rootkit BETA 1.09.1.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17728

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, X:\ DRIVE_FIXED
CPU speed: 3.202000 GHz
Memory total: 12823044096, free: 9158299648

Downloaded database version: v2015.05.06.04
Downloaded database version: v2015.04.21.01
Downloaded database version: v2015.05.06.01
=======================================
Initializing...
------------ Kernel report ------------
     05/06/2015 22:28:46
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\msahci.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\system32\DRIVERS\iaStorA.sys
\SystemRoot\system32\DRIVERS\storport.sys
\SystemRoot\system32\DRIVERS\asahci64.sys
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\vmstorfl.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\system32\DRIVERS\iaStorF.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\System32\Drivers\aswVmm.sys
\SystemRoot\System32\Drivers\aswRvrt.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\drivers\aswSnx.sys
\SystemRoot\system32\drivers\aswSP.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\drivers\aswRdr2.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\SysWow64\drivers\AsIO.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\nvlddmkm.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\drivers\ctaud2k.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\drivers\ctoss2k.sys
\SystemRoot\system32\drivers\ctprxy2k.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\DRIVERS\HECIx64.sys
\SystemRoot\system32\DRIVERS\e1c62x64.sys
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\system32\DRIVERS\asmtxhci.sys
\SystemRoot\system32\DRIVERS\1394ohci.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\DRIVERS\wmiacpi.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\rdpbus.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\dtscsibus.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\drivers\ha20x22k.sys
\SystemRoot\system32\drivers\emupia2k.sys
\SystemRoot\system32\drivers\ctsfm2k.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\System32\drivers\CTHWIUT.SYS
\SystemRoot\System32\drivers\CT20XUT.SYS
\SystemRoot\System32\drivers\CTEXFIFX.SYS
\SystemRoot\system32\drivers\nvhda64v.sys
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\system32\DRIVERS\asmthub3.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\Drivers\dump_iaStorA.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\drivers\aswMonFlt.sys
\??\C:\Windows\system32\drivers\mbam.sys
\SystemRoot\system32\DRIVERS\athurx.sys
\SystemRoot\System32\drivers\vwifibus.sys
\SystemRoot\system32\drivers\aswStm.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\??\C:\Windows\system32\drivers\acedrv11.sys
\SystemRoot\system32\drivers\aswHwid.sys
\SystemRoot\system32\drivers\npf.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\DRIVERS\WUDFRd.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\nsi.dll
\Windows\System32\iertutil.dll
\Windows\System32\user32.dll
\Windows\System32\comdlg32.dll
\Windows\System32\shell32.dll
\Windows\System32\difxapi.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\msvcrt.dll
\Windows\System32\sechost.dll
\Windows\System32\msctf.dll
\Windows\System32\shlwapi.dll
\Windows\System32\ole32.dll
\Windows\System32\normaliz.dll
\Windows\System32\usp10.dll
\Windows\System32\clbcatq.dll
\Windows\System32\gdi32.dll
\Windows\System32\psapi.dll
\Windows\System32\advapi32.dll
\Windows\System32\lpk.dll
\Windows\System32\ws2_32.dll
\Windows\System32\imagehlp.dll
\Windows\System32\oleaut32.dll
\Windows\System32\setupapi.dll
\Windows\System32\urlmon.dll
\Windows\System32\kernel32.dll
\Windows\System32\wininet.dll
\Windows\System32\Wldap32.dll
\Windows\System32\imm32.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\devobj.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\wintrust.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\crypt32.dll
\Windows\System32\comctl32.dll
\Windows\System32\userenv.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\KernelBase.dll
\Windows\System32\msasn1.dll
\Windows\System32\profapi.dll
\Windows\SysWOW64\normaliz.dll
----------- End -----------
Done!

Scan started
Database versions:
  main:    v2015.05.06.04
  rootkit: v2015.04.21.01

<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa800ac59790, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800ac592c0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800ac59790, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800ab8ac50, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa800a8fb040, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xfffffa800a8a26f0, DeviceName: \Device\00000077\, DriverName: \Driver\iaStorA\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 62C0FF3C

Partition information:

    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 2048  Numsec = 204800
    Partition file system is NTFS
    Partition is bootable

    Partition 1 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 206848  Numsec = 468652032

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

Disk Size: 240057409536 bytes
Sector size: 512 bytes

Done!
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xfffffa800ac5f790, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800ac5f2c0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800ac5f790, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800ab8bc50, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa800a8f8060, DeviceName: \Device\00000078\, DriverName: \Driver\iaStorA\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 13EDEF9C

Partition information:

    Partition 0 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 2048  Numsec = 1331200000

    Partition 1 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 1331202048  Numsec = 622317568

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

Disk Size: 1000204886016 bytes
Sector size: 512 bytes

Done!
Physical Sector Size: 0
Drive: 2, DevicePointer: 0xfffffa8012c2a060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8012c28b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8012c2a060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8012b6ab80, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa8012c24b60, DeviceName: \Device\0000009b\, DriverName: \Driver\USBSTOR\
------------ End ----------
Infected: C:\ProgramData\Microsoft\Secure\Icons\temp\tmp120C.exe --> [Trojan.Krypt]
Infected: C:\ProgramData\Microsoft\Secure\Icons\temp\tmp4A67.exe --> [Trojan.Agent.FSAVXGen]
Infected: C:\ProgramData\Microsoft\Secure\Icons\temp\tmp53E9.exe --> [Trojan.Agent.DED]
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-C0A52BF0372227CBDF49E2BBB5E658D1A0AFA169.bin.VE1" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-C0A52BF0372227CBDF49E2BBB5E658D1A0AFA169.bin.VF" is compressed (flags = 1)
File "C:\ProgramData\AVAST Software\Avast\log\AvastSvc.log" is compressed (flags = 1)
File "C:\ProgramData\AVAST Software\Avast\log\AvastUI.log" is compressed (flags = 1)
File "C:\ProgramData\AVAST Software\Avast\log\CommChannel.Protocol.log" is compressed (flags = 1)
File "C:\ProgramData\AVAST Software\Avast\log\Instup.log" is compressed (flags = 1)
File "C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log" is compressed (flags = 1)
Scan finished
Creating System Restore point...
Cleaning up...
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-r.mbam...
Removal finished

Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 08, 2015, 06:17:14 AM
Please post a fresh FRST scan log.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 08, 2015, 10:57:34 PM
I really wonder why it worked with other people already from steps before.
Do you think killing the explorer.exe process before running the scans and fixed could make a difference ?

The FRST Scan log as well as the Addition.txt are in the attachment (copy/paste doesn't go 'cause the message exceeds the characters limit).
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 11, 2015, 03:20:53 PM
Explorer.exe should not have caused this. Follow the step outlined below and we shall move on from there.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 12, 2015, 01:47:45 AM
Hello,
I just put my antiradioactive suit and ran Combofix, it went through some stages but I have this warning:

Unable to create a backup of the current registry file
C:\Windows\System32\config\SYSTEM !
Continue restoration of this file?


I have no idea whether to say Yes or No.

I'm writing from my mobile phone, I'm keeping the computer on standby until I hear from you.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 12, 2015, 01:51:59 AM
By the way, Combofix is just about to reboot. Screen says this:

Rebooting Windows
Please allow Combofix to reboot the machine.
Warning! Do not manually reboot the machine yourself
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: Michael (alan1998) on May 12, 2015, 12:19:38 PM
Last one is just saying let CF do it, don't touch anything. When CF reboots the machine, it will auto run and do more stuff. if you do the reboot using the power button, CF won't continue.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 12, 2015, 04:33:28 PM
FRST has already created a backup of the registry so continue with ComboFix.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 13, 2015, 12:22:25 AM
I continued but I got this error message :

Error restoring C:/Windows/erdnt/subs/system
To
C:/Windows /System32/config/System

Continue with the next file?
[RegReplaceKey: 5 - Access is denied]

I was going to click Yes, but I'd better be sure and wait for your response.

It will be the second day I sleep with the computer turned on right beside me...
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 13, 2015, 03:28:07 PM
Click 'Yes' and proceed.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 14, 2015, 02:28:39 AM
The log file is attached.

I have the impression that the pop-ups have stopped - hurray !
Not sure yet though because I'm not having access to my computer very often these days, but if I see something I will let you know.

Thank you very much for your pro help ! :)
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 14, 2015, 06:38:15 AM
Monitor it for the next 24 hours and report to me. Just a friendly reminder, if you ever encounter such problem in the future, do not run Combofix on your own as it one of the most powerful removal tools and if done incorrectly, it can make the PC un-bootable.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 15, 2015, 12:59:04 AM
Bad news ... I'm still getting pop-ups about the same thing.

Is this thing just extremely annoying, or is there some kind of danger related to it ? Like should I backup my stuff or it's inoffensive ?
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 16, 2015, 03:34:52 PM
Code: [Select]
Start
CreateRestorePoint:
CloseProcesses:
Emptytemp:
ShellIconOverlayIdentifiers: [1SecureIconsProvider] -> {FC9D8189-520A-4417-AED7-9EAC810C6FBA} => C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll [2014-11-17] ()
C:\ProgramData\Microsoft\Secure
End
[/list]
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 17, 2015, 04:08:35 PM
Here is the log file. So far no pop-ups ! :)

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-05-2015 02
Ran by Nizar at 2015-05-17 15:14:52 Run:2
Running from C:\Users\Nizar\Desktop
Loaded Profiles: Nizar (Available profiles: Nizar & UpdatusUser)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CreateRestorePoint:
CloseProcesses:
Emptytemp:
ShellIconOverlayIdentifiers: [1SecureIconsProvider] -> {FC9D8189-520A-4417-AED7-9EAC810C6FBA} => C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll [2014-11-17] ()
C:\ProgramData\Microsoft\Secure
End
*****************

Restore point was successfully created.
Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\1SecureIconsProvider" => Key deleted successfully.
"HKCR\CLSID\{FC9D8189-520A-4417-AED7-9EAC810C6FBA}" => Key deleted successfully.

"C:\ProgramData\Microsoft\Secure" directory move:

Could not move "C:\ProgramData\Microsoft\Secure" directory. => Scheduled to move on reboot.

EmptyTemp: => Removed 458.2 MB temporary data.

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-05-17 15:16:34)<=

C:\ProgramData\Microsoft\Secure => Is moved successfully.

==== End of Fixlog 15:16:34 ====
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 17, 2015, 06:40:24 PM
Please monitor the PC for next 24 hours and report to me if the pop-up re-appears. If everything is okay after the aforementioned time period, we shall move on to the next phase.
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 19, 2015, 02:02:38 AM
Hello,

Still nothing to declare, everything seems fine :)
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 19, 2015, 01:46:31 PM
Perusing your logs, I see no infection currently present in your system. Unless you are having any issue(s), the machine appears to be Malware-free as we speak.



♣ Removal of Tools and Quarantined Files ♣



Despite the tools we have used are clean, they are powerful removal tools and made in a way so that they carry out any commands given to them without (most cases) asking for a confirmation. In the hands of an inept person, they can make the machine un-bootable -- a scenario we do not wish to see. Also, we need to remove the quarantined files/folders from your system as a dormant malware can be as bad as an active one if given the proper environment. I shall now give you the guidelines to remove the tools and the quarantined files from your system.



♣ Prevention and Future Guidelines ♣



Prevention is better than cure -- goes the old saying. As much as we love to see you visit our site, we do not want to see you having your PC infected by malwares again.

My help is free but if you feel like making my day you may donate any amount you wish by clicking the 'donate' button. I really appreciate your kindness.
(https://www.paypalobjects.com/en_US/i/btn/btn_donate_SM.gif) (https://www.paypal.com/cgi-bin/webscr?cmd=_donations&business=valinorum%40gmail%2ecom&lc=US&item_name=Malware%20Removal%20Assistance&item_number=avast%21&currency_code=USD&bn=PP%2dDonationsBF%3abtn_donateCC_LG%2egif%3aNonHosted)

Regards,
Valinorum
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 21, 2015, 11:18:22 PM
Hello Valinorum,

Here is the log you asked for :

# DelFix v1.010 - Logfile created 21/05/2015 at 23:05:03
# Updated 26/04/2015 by Xplode
# Username : Nizar - NIZAR-PC
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\Qoobox
Deleted : C:\Combofix
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\Nizar\Desktop\FRST-OlderVersion
Deleted : C:\Users\Nizar\Desktop\mbar
Deleted : C:\ComboFix.txt
Deleted : C:\Users\Nizar\Desktop\Addition.txt
Deleted : C:\Users\Nizar\Desktop\AdwCleaner[S0].txt
Deleted : C:\Users\Nizar\Desktop\AdwCleaner[S1]_.txt
Deleted : C:\Users\Nizar\Desktop\adwcleaner_4.203.exe
Deleted : C:\Users\Nizar\Desktop\ComboFix.exe
Deleted : C:\Users\Nizar\Desktop\Fixlog.txt
Deleted : C:\Users\Nizar\Desktop\FRST.txt
Deleted : C:\Users\Nizar\Desktop\FRST64.exe
Deleted : C:\Users\Nizar\Desktop\log COMBOFIX.txt
Deleted : C:\Users\Nizar\Desktop\logs.txt
Deleted : C:\Users\Nizar\Desktop\Search.txt
Deleted : C:\Users\Nizar\Downloads\Addition.txt
Deleted : C:\Users\Nizar\Downloads\aswmbr.exe
Deleted : C:\Users\Nizar\Downloads\aswMBR.txt
Deleted : C:\Users\Nizar\Downloads\FRST.txt
Deleted : C:\Users\Nizar\Downloads\FRST64.exe
Deleted : C:\Users\Nizar\Downloads\MBR.dat
Deleted : C:\Windows\grep.exe
Deleted : C:\Windows\PEV.exe
Deleted : C:\Windows\NIRCMD.exe
Deleted : C:\Windows\MBR.exe
Deleted : C:\Windows\SED.exe
Deleted : C:\Windows\SWREG.exe
Deleted : C:\Windows\SWSC.exe
Deleted : C:\Windows\SWXCACLS.exe
Deleted : C:\Windows\Zip.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #406 [Restore Point Created by FRST | 05/17/2015 13:14:53]
Deleted : RP #407 [Windows Update | 05/18/2015 19:43:21]
Deleted : RP #408 [Windows Update | 05/19/2015 22:43:38]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########


Thank you so much for you patient help and advice ! You rock.
(It is actually me in the attached photo)
Title: Re: Harrassing pop-up : onlinesecuritymetere.in
Post by: REDACTED on May 22, 2015, 07:00:21 AM
You are welcome. Surf safely. :)