Hi,
Please run a new HJT! Scan, and check to fix the following entries, being sure to double check that you haven't missed any. Next, close
all browser windows and click the
Fix checked button…
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O4 - HKCU\..\Run: [WNSC] C:\WINDOWS\System32\wnsintcc.exe
Next, please double click on the
My Computer icon on the desktop. Go to
Tools | Folder Options, click on the
View tab and make sure that
Show hidden files and folders is checked. Also uncheck
Hide protected operating system files. Now click
Apply to all folders, then click
Apply then
OK.
Then boot into safe mode, (see
here for info if needed) and delete the entire contents of the C:\Windows\
Temp folder, but
not the folder itself. Next please find and delete the following
bolded file...
C:\WINDOWS\System32\
wnsintcc.exe
Then please boot back into normal mode and post a new log, just to make sure. That should be you sorted out regards popups. This seems to be a new strain of executables causing multiple popups, and although the filename is ultimately random, they usually look like this..
wnxxxxxx.exe (random string length)
..to make them look as though they are genuine Windows files at first glance.
I do however urge anyone who wants to suddenly delete any files that look like this to proceed with caution..!!!!!!!!!
Cheers
Liam