Malware - popup videos and random hyperlinks in text

I frequently see strange hyperlinks in text on various webpages (including Avast!). If I hover over them, small adverts appear.
This will be followed by a new Chrome window opening with a link such as
http://www.gfdcv.com/sc?p=OTQ0MzY0NTAzMtHto01xOBa7bttbA3T8Q57sjeUaV3PMiFCgXEDFcBbwc%2FP9ZymccckXpc2iP3GIUZo6xj8iuA9UWRjinl%2BwON6n7jY4YRZ7hC3446rntLyUpVe5uqQJjRpENyvFZAGIiqFrclL0hb42XI0cJTLOxXFJYCqQ9Ceb83n0HkzFq6Yx0WdQeB%2F7%2FeQSlPUFyeqQGeqRcKS1EvajWfGygDJHGdst%2Fole7UlYtfvEC7K1wtrsfM6ZoOrlH6e0wpOK8TVRgdRR2V35bwIG8%2BGkw1VcrSluQmgBFHmmC6Jo%2FCiqZZehp4gzkzsD5cLlp5Y6aFwgzA%3D%3D&ia=0&t=1

Also, short video windows will open and play adverts for ski resorts and other such things.

I am working thru the instructions on the post “Logs to assist in cleaning malware”
Rob

Malware Scan History Log
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 10/08/2014
Scan Time: 12:30:50 PM
Logfile: MalwareScanHistLog.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.08.08.01
Rootkit Database: v2014.08.04.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Sparrow

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 306944
Time Elapsed: 3 min, 11 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 2
PUP.Optional.Superfish.A, C:\Users\Sparrow\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, Delete-on-Reboot, [80184082413ad462018562886999e11f],
PUP.Optional.Superfish.A, C:\Users\Sparrow\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, Quarantined, [f4a4566cc5b673c3563033b7c939a759],

Physical Sectors: 0
(No malicious items detected)

(end)

FRST.txt

Addition (from FARBAR)

MBR files
.dat renamed to .log

Hm does this happen on all sites or just some specific sites

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.

Essexboy,

I suspect that Bigfoot software since it altered winsock.
Remove it and restore winsock.
Let’s see what happens.

essexboy and Eddy
thanks for replying
I’ll get onto that now
Rob

essexboy
it happens to all sites
after running Adwcleaner, my PC rebooted (as you forewarned). On restarting, there was a window for Qualcomm Atheros Killer Network Manager, with a popup warning “LSP not mapped correctly”. I clicked “yes” to enable.
I hope I have attached the right file.

I’ll go kill Bigfoot now (per Eddy’s post) but I’m not so sure about restoring winsock

Rob

No sign of Bigfoot (from Ctrl Panel/uninstall software). Are you referring to the Qualcomm Atheros Killer Network Manager?
apol’s if I’m being dense
Rob

Yes it will be called Qualcomm Atheros Killer Network Manager