1. Did you get all of the Windows updates as I suggested? If you did, I would have expected to see some change in the Windows/IE version information in your log's header.
2. The problem with your Favorites may or may not have been caused by the infections; I can't honestly say, as I've never seen that exact symptom before. I don't know if it will do the trick, but you can try running the
IEFix tool.
Just to be clear about it though- you
are saying that when you click on the Favorites menu item, it displays the contents of your C:\Windows folder instead of your Favorites folder, right? If that's not exactly what's happening, please give us better description of what
is happening.
3. Your latest log shows no signs of infections, but that doesn't mean that your system is clean yet. If you're still getting porn popups, you've obviously still got problems. Let's do some general clean-up to see if we can get rid of anything that's lingering:
A) Run a full anti-virus scan, making sure that your anti-virus program is using the most current virus definition updates. Also do the free online virus scans at these sites:
http://housecall.trendmicro.com/
http://www.kaspersky.com/scanforvirus.html
http://www.ravantivirus.com/scan/
http://www.pandasoftware.com/actives..._principal.htm
B) Download and run Ad Aware (download link are in my sig below).
Follow these directions for configuring Ad Aware (directions courtesy of our member "crunchie"):
1. When you first run Ad Aware, some of the settings will need to be changed before you scan
2.Close ALL windows except Ad-Aware SE
3. Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.
4. Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window
1) In the ‘General’ window make sure the following are selected in green:
*Automatically save log-file
*Automatically quarantine objects prior to removal
*Safe Mode (always request confirmation)
Under Definitions:
*Prompt to udate outdated definitions - set the number of days
2) Click on the ‘Scanning’ button on the left and select in green :
Under Driver, Folders & Files:
*Scan Within Archives
Under Select drives & folders to scan -
*choose all hard drives
Under Memory & Registry: all green
*Scan Active Processes
*Scan Registry
*Deep Scan Registry
*Scan my IE favorites for banned URL’s
*Scan my Hosts file
3) Click on the ‘Advanced’ button on the left and select in green:
Under Shell Integration:
*Move deleted files to recycle bin
Under Logfile Detail Level: (all green)
*include addtional object information
*DESELECT - include negligible objects information
*include environment information
Under Alternate Data Streams:
*Don't log streams smaller than 0 bytes
*Don't log ADS with the following names: CA_INOCULATEIT
4) Click the ‘Tweak’ button and select in green:
Under the ‘Scanning Engine’:
*Unload recognized processes during scanning
*Scan registry for all users instead of current user only
Under the ‘Cleaning Engine’:
*Let Windows remove files in use at next reboot
Under the Log Files:
*Include basic Ad-aware SE settings in logfile
*Include additional Ad-aware SE settings in logfile
*Please do not check or make green: Include Module list in logfile
5. Click on ‘Proceed’ to save the settings.
6. Click ‘Start’
*Choose:'Perform Full System Scan'
*DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
7. Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
8. If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window. Select all of the items in the list.
9. Save the log file when it asks and then click ‘finish’
10. REBOOT to complete the removal of what Ad-Aware SE found
* Run SpyBot.
1. Get the most current updates for the program.
2. Run the program. Once it completes, have it fix everything it finds.
3. Reboot.
C) Boot into Safe Mode (do this by hitting the F8 key as the computer is booting) and:
- Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files".
- For every user account listed under C:\Documents and Settings, delete everything inside the following folders (don't delete the folders themselves though):
1. Local Settings\Temp
2. Cookies
3. History
4. Local Settings\Temporary Internet Files\Content.IE5
- Delete the entire content of your C:\Windows\Temp folder.
(If you get any messages concerning the deletion of system files such as desktop.ini or index.dat, just choose to delete those files; they'll be automatically regenerated by Windows if needed.)
- Empty your Recycle Bin.
- Reboot normally.
C) Download and run SpywareBlaster (link in my sig). Download the latest updates for the program and click "Enable all protection". Once it applies the protections you can close the program.
D) Let us know the results of doing the above and tell us if you're still getting the popups.