Recently i have been having these popups with ips like.
http://89.188.16.43/go//?cmp=nm_firefox_rn&uid=00C2C7DAA3F911DDB0A9150044CFFFFF&rid=zdez&guid=18F0032549E7424087A87FF6D789E65C&affid=150044&lid=http&url=%7Bhttp:%2F%2F%5B0-9a-zA-Z%5C+%5C%%5C.%5C;%5C,%5C-%5C_%5C%3F%5C%23%26%5C=%5C%7B%5C%7D%5C%5B%5C%5D%5C%2F%5C%5C%5C$%5C:%5C@%5C%5E%5C~%5C%60%5D+%7D&v=1156&m=irq4
http://82.98.235.35/go//?cmp=nm_firefox_rn&uid=00C2C7DAA3F911DDB0A9150044CFFFFF&rid=zdez&guid=18F0032549E7424087A87FF6D789E65C&affid=150044&lid=http&url=http:%2F%2F192.168.100.1%2F&v=1156&m=irq4
after which they redirect to a antispyware website.
I have tried varies things but nothing seems to sort it out.
I have tried AVG, antispyware, combofix, smitfraud, antimalware etc...
they have found many things but not solve this issue.
Here is a copy of hijackthis log i do not see anything wrong there.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:33:46, on 11/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\WINDOWS\Explorer.EXE
D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
d:\program files\common files\mcafee\mna\mcnasvc.exe
d:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
D:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
D:\Program Files\McAfee\MPF\MPFSrv.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\McAfee.com\Agent\mcagent.exe
D:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Real\RealPlayer\realplay.exe
D:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
D:\WINDOWS\system32\wscntfy.exe
d:\PROGRA~1\mcafee\msc\mcuimgr.exe
D:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O8 - Extra context menu item: &Download all by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: &Download by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Download selected by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/204
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - d:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - d:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - D:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - D:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - D:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - D:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 3793 bytes
Also the computer has become slow to start and the browsers are taking a lot of mem usage like firefox 70000k and explorer 40000k.
here is a list of process
Process list saved on 13:47:16, on 11/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
[pid] [full path to filename] [file version] [company name]
564 D:\WINDOWS\System32\smss.exe 5.1.2600.2180 Microsoft Corporation
660 D:\WINDOWS\system32\winlogon.exe 5.1.2600.2180 Microsoft Corporation
704 D:\WINDOWS\system32\services.exe 5.1.2600.2180 Microsoft Corporation
716 D:\WINDOWS\system32\lsass.exe 5.1.2600.2180 Microsoft Corporation
900 D:\WINDOWS\system32\svchost.exe 5.1.2600.2180 Microsoft Corporation
1092 D:\WINDOWS\System32\svchost.exe 5.1.2600.2180 Microsoft Corporation
1320 D:\WINDOWS\system32\spoolsv.exe 5.1.2600.2180 Microsoft Corporation
1604 D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe 7.5.1.36 GRISOFT s.r.o.
1612 D:\WINDOWS\Explorer.EXE 6.0.2900.2180 Microsoft Corporation
1792 D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe 8.1.159.0 McAfee, Inc.
1812 d:\program files\common files\mcafee\mna\mcnasvc.exe 2.1.143.0 McAfee, Inc.
1872 d:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe 2.0.150.0 McAfee, Inc.
1928 D:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe 14.0.0.349 McAfee, Inc.
220 D:\Program Files\McAfee\MPF\MPFSrv.exe 9.0.136.0 McAfee, Inc.
408 D:\WINDOWS\system32\nvsvc32.exe 6.14.10.6693 NVIDIA Corporation
428 D:\Program Files\Common Files\Real\Update_OB\realsched.exe 0.1.1.45 RealNetworks, Inc.
916 D:\WINDOWS\system32\svchost.exe 5.1.2600.2180 Microsoft Corporation
1424 D:\PROGRA~1\McAfee.com\Agent\mcagent.exe 8.0.237.0 McAfee, Inc.
1772 D:\Program Files\Viewpoint\Common\ViewpointService.exe 2.0.0.54 Viewpoint Corporation
2728 D:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe 12.1.111.0 McAfee, Inc.
2824 D:\WINDOWS\system32\wscntfy.exe 5.1.2600.2180 Microsoft Corporation
3440 d:\PROGRA~1\mcafee\msc\mcuimgr.exe 8.0.226.0 McAfee, Inc.
3748 D:\WINDOWS\system32\rundll32.exe 5.1.2600.2180 Microsoft Corporation
2356 C:\PROGRA~1\MOZILL~1\FIREFOX.EXE 1.8.20080.17373 Mozilla Corporation
2700 D:\Program Files\Trend Micro\HijackThis\HijackThis.exe 2.0.0.2 Trend Micro Inc.