Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all articles
Browse latest Browse all 2798

need help to remove japan pop up mshta

$
0
0
Hi all,
I have difficulties to remove pop up porn Japanese,for almost a week
at first I have use MABM & Hijack This,the program can identify the sources in current user > run & run once ...I just deleted it,and before that I just regedit to trace the source when the pop up appears,...

But this pop up keep coming again, and I saw in others forum who has the same problem, the pop up appears when laptop connect with the power cord only,(sometimes when PUP coming, I just unplug and its gone)...but this is not the solutions i'm looking for..

I have tried Avira,Sality killer and TFS but its wont remove the mshta permanently,

can anyone guide me to clean this PUP...
Really appreciate for your time and effort ....:)

I attaché the current DSS and GMER log

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Enterprise
Boot Device: \Device\HarddiskVolume1
Install Date: 6/8/2013 3:49:06 AM
System Uptime: 6/24/2014 7:44:28 AM (0 hours ago)
.
Motherboard: LENOVO | | 2351A63
Processor: Intel(R) Core(TM) i5-3320M CPU @ 2.60GHz | CPU Socket - U3E1 | 1794/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 168 GiB total, 47.274 GiB free.
D: is CDROM ()
E: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows
Device ID: ROOT\NET\0001
Manufacturer: Cisco Systems
Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows
PNP Device ID: ROOT\NET\0001
Service: vpnva
.
==== System Restore Points ===================
.
RP75: 6/2/2014 1:03:57 PM - Scheduled Checkpoint
RP76: 6/9/2014 1:05:29 PM - Scheduled Checkpoint
RP77: 6/16/2014 11:21:08 AM - Installed HiJackThis
RP78: 6/17/2014 10:17:20 PM - Windows Update
RP79: 6/18/2014 9:48:35 AM - Installed SpyHunter
RP80: 6/18/2014 11:22:20 AM - Removed SpyHunter
RP81: 6/23/2014 4:17:55 PM - Removed SpyHunter
RP82: 6/24/2014 7:56:03 AM - Removed HiJackThis
RP83: 6/24/2014 7:56:32 AM - Removed HiJackThis
.
==== Installed Programs ======================
.
ABB ScreenSaver
ABB Sophie 1.2.0.0
ABB Summit 2014
Adobe Flash Player 13 ActiveX
Adobe Flash Player 13 Plugin
Adobe Reader X (10.1.9)
Adobe Shockwave Player 12.1
Burn.Now 4.5
Cisco AnyConnect Secure Mobility Client
Cisco AnyConnect Secure Mobility Client
Cisco AnyConnect Web Security Module
Cisco IP Communicator
Cisco Systems VPN Client 5.0.05.0290
Citrix Online Launcher
Configuration Manager Client
Corel Burn.Now Lenovo Edition
Corel DVD MovieFactory 7
Corel DVD MovieFactory Lenovo Edition
Corel WinDVD
Cuusamo Configurator 6.3
DHTML Editing Component
Direct DiscRecorder
Dolby Advanced Audio v2
DriveSize 3.7.1
Engineering Client Viewer 7.0
GIA
GoToMeeting 5.7.0.1172
HP Deskjet 1050 J410 series Basic Device Software
Integrated Camera Driver Installer Package Ver.1.2.1.18
Intel(R) Control Center
Intel(R) Network Connections 16.8.46.0
Intel(R) OpenCL CPU Runtime
Intel(R) Processor Graphics
Intel(R) USB 3.0 eXtensible Host Controller Driver
Internet Explorer
iPassConnect
Java 7 Update 51
Java Auto Updater
Lenovo Auto Scroll Utility
Lenovo Patch Utility
Lotus Notes 8.5.3
Malwarebytes Anti-Malware version 2.0.2.1012
McAfee Agent
McAfee Host Intrusion Prevention
McAfee VirusScan Enterprise
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Junk E-mail Reporting Add-in
Microsoft Office 365 ProPlus - en-us
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mobile Partner
Mozilla Firefox 23.0.1 (x86 en-US)
Mozilla Maintenance Service
MS Junk Reporting Tool
MSXML 4.0 SP2 (KB973688)
MSXML4.0 redistributable
Office 15 Click-to-Run Extensibility Component
Office 15 Click-to-Run Licensing Component
Office 15 Click-to-Run Localization Component
On Screen Display
PDF-XChange 2012 Pro
Power Manager
Quest Secure Password Extension x86
RapidBoot Shield
Realtek High Definition Audio Driver
RICOH_Media_Driver_v2.14.18.01
SAP Business Explorer
SAP GUI for Windows 7.30
SAP JNet
SAPSetup Automatic Workstation Update Service
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2898855v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2901110v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2931365)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft .NET Framework 4 Extended (KB2858302v2)
Security Update for Microsoft .NET Framework 4 Extended (KB2901110v2)
swMSM
ThinkPad Bluetooth with Enhanced Data Rate Software
ThinkPad Power Management Driver
ThinkPad UltraNav Driver
ThinkPad WiFi Radio Control
ThinkVantage Communications Utility
U3Launcher
VNC Enterprise Edition E4.5.1
VNC Mirror Driver 1.8.0
VNC Printer Driver 1.6.0
VsdSize 3.7.1
Windows XP Mode
WinZip 16.0
.
==== Event Viewer Messages From Past Week ========
.
6/24/2014 7:48:56 AM, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file.
6/24/2014 7:48:28 AM, Error: Microsoft-Windows-GroupPolicy [1129] - The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has succesfully processed. If you do not see a success message for several hours, then contact your administrator.
6/24/2014 7:46:50 AM, Error: Microsoft-Windows-TerminalServices-RemoteConnectionManager [1067] - The terminal server cannot register 'TERMSRV' Service Principal Name to be used for server authentication. The following error occured: The specified domain either does not exist or could not be contacted. .
6/24/2014 7:44:41 AM, Error: NETLOGON [5719] - This computer was not able to set up a secure session with a domain controller in domain ASIAPACIFIC due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain.
6/23/2014 7:58:50 AM, Error: Service Control Manager [7031] - The McAfee McShield service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
6/23/2014 7:52:32 AM, Error: Service Control Manager [7000] - The KernelMemory service failed to start due to the following error: The system cannot find the file specified.
6/23/2014 7:14:17 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
6/23/2014 7:14:16 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
6/23/2014 7:14:16 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
6/23/2014 7:14:07 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
6/23/2014 7:13:49 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: avipbb avkmgr discache spldr ssmdrv TPPWRIF vpcvmm Wanarpv6
6/23/2014 7:13:49 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service TermService with arguments "" in order to run the server: {F9A874B6-F8A8-4D73-B5A8-AB610816828B}
6/23/2014 5:22:14 PM, Error: Service Control Manager [7043] - The McAfee Framework Service service did not shut down properly after receiving a preshutdown control.
6/23/2014 4:49:08 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR30.
6/23/2014 10:20:35 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk3\DR3.
6/23/2014 10:10:09 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AntiVirSchedulerService service.
6/23/2014 1:51:19 AM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
6/23/2014 1:01:26 PM, Error: Microsoft-Windows-GroupPolicy [1055] - The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: a) Name Resolution failure on the current domain controller. b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).
6/22/2014 6:31:01 PM, Error: Service Control Manager [7034] - The ThinkPad PM Service service terminated unexpectedly. It has done this 1 time(s).
6/22/2014 6:29:25 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the btwdins service.
6/19/2014 6:10:11 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
6/19/2014 5:03:24 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
6/19/2014 5:01:41 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
6/18/2014 1:12:03 PM, Error: Microsoft-Windows-GroupPolicy [1058] - The processing of Group Policy failed. Windows attempted to read the file \\asiapacific.abb.com\SysVol\asiapacific.abb.com\Policies\{6A53A7AA-6351-4B10-9E3A-327A9EDE4639}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following: a) Name Resolution/Network Connectivity to the current domain controller. b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller). c) The Distributed File System (DFS) client has been disabled.
6/17/2014 5:14:10 PM, Error: Schannel [36888] - The following fatal alert was generated: 43. The internal error state is 552.
6/17/2014 5:14:10 PM, Error: Schannel [36884] - The certificate received from the remote server does not contain the expected name. It is therefore not possible to determine whether we are connecting to the correct server. The server name we were expecting is sip.id.abb.com. The SSL connection request has failed. The attached data contains the server certificate.
6/17/2014 10:15:37 PM, Error: Service Control Manager [7031] - The Cisco AnyConnect Secure Mobility Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
.
==== End Of File ===========================

Viewing all articles
Browse latest Browse all 2798

Trending Articles