need some help getting a lot of pop up notifications from avast saying i have malware the process is C:\Windows\System32\svchost.exe
i used farbar recovery here are the log files
Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!
need some help getting a lot of pop up notifications from avast saying i have malware the process is C:\Windows\System32\svchost.exe
i used farbar recovery here are the log files
CreateRestorePoint:
HKU\S-1-5-21-183760795-2501133323-4075679530-1001\...\Command Processor: CD /d C:\ <===== ATTENTION!
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: WSAMVCUchrome - No CLSID Value
FF Plugin HKU\S-1-5-21-183760795-2501133323-4075679530-1001: tdameritrade.com/tossc -> C:\Program Files\thinkorswim\nptossc.dll No File
CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - No Path Or update_url value
2015-06-02 23:54 - 2015-06-23 00:32 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-06-29 18:30 - 2014-09-10 17:46 - 00001338 _____ C:\Windows\Tasks\NSKPLG.job
2015-06-29 18:30 - 2014-09-10 17:45 - 00001684 _____ C:\Windows\Tasks\BVRGMFU.job
2015-06-29 18:30 - 2014-09-10 17:43 - 00001334 _____ C:\Windows\Tasks\TSRH.job
2015-04-14 12:28 - 2015-04-14 12:28 - 0004387 _____ () C:\Users\lucky\AppData\Roaming\8JLETVeFEoboy1Kjqn
2014-09-01 04:18 - 2015-04-09 02:56 - 0000365 _____ () C:\Users\lucky\AppData\Roaming\BVRGMFU
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\lucky\AppData\Roaming\Cu8L0W44hBX
2014-09-01 04:18 - 2015-04-09 02:57 - 0000365 _____ () C:\Users\lucky\AppData\Roaming\EPWBHYDT
2013-06-17 16:57 - 2013-06-17 16:57 - 0000037 ___SH () C:\Users\lucky\AppData\Local\1517305038504592ead82131.36681408
2014-04-13 01:18 - 2013-11-11 10:58 - 4900568 _____ (COMODO) C:\ProgramData\cis22FA.exe
2014-04-13 00:51 - 2013-11-11 10:58 - 4900568 _____ (COMODO) C:\ProgramData\cis3D39.exe
2014-04-13 00:57 - 2013-11-11 10:58 - 4900568 _____ (COMODO) C:\ProgramData\cis44C.exe
2014-04-13 01:02 - 2013-11-11 10:58 - 4900568 _____ (COMODO) C:\ProgramData\cis7C87.exe
2014-04-13 01:22 - 2013-11-11 10:58 - 4900568 _____ (COMODO) C:\ProgramData\cis9E31.exe
014-06-12 16:53 - 2014-06-12 16:53 - 0004919 _____ () C:\ProgramData\uxxadbmu.rlu
Task: {13C8284D-B66A-43CC-BFBE-814C9DADA8BC} - System32\Tasks\SolutoTask_29eebd75-6160-4b99-9c5f-a2d0ab2d0623 => C:\ProgramData\Soluto\Temp\ninite.evernote_5_1_0_2217.setup-22f94a22-b488-aa1a-a4ef-69269eb40e0f.exe <==== ATTENTION
Task: {2608F0F2-0361-4B52-97C9-2F5D95C74414} - \FTdownloader V7.0-codedownloader No Task File <==== ATTENTION
Task: {30ED8319-22AF-4EAB-A3EE-092B8E64C1BE} - System32\Tasks\NSKPLG => C:\Users\lucky\AppData\Roaming\NSKPLG.exe <==== ATTENTION
Task: {577A7E22-044C-4215-BBFE-948F982FC721} - System32\Tasks\BVRGMFU => C:\Users\lucky\AppData\Roaming\BVRGMFU.exe <==== ATTENTION
Task: {5C86F962-C9BC-4E4E-8B01-C04CB4DD5FF5} - \FTdownloader V7.0-chromeinstaller-dev No Task File <==== ATTENTION
Task: {62515543-DE4A-49C5-B003-47147643D1BE} - System32\Tasks\SolutoTask_af222ae4-0d86-47e7-b84a-7a4e93f7935c => C:\ProgramData\Soluto\Temp\ninite.openoffice_4_00_9714.setup-22f94a22-b502-3fb6-a49b-dc44f1752a53.exe <==== ATTENTION
Task: {94BBDC4C-5736-4A79-BDF6-62A62981738F} - System32\Tasks\SolutoTask_16dc203a-2f17-45dc-a68b-b0e0ae2cf749 => C:\ProgramData\Soluto\Temp\ninite.irfanview_4_37.setup-22f94a22-b4cb-6aaf-8ed8-4e1a60ee9de6.exe <==== ATTENTION
Task: {9E187248-B33C-4675-912D-7FD973F94EA0} - \FTdownloader V7.0-firefoxinstaller No Task File <==== ATTENTION
Task: {D656DDAB-FB67-414B-B17E-EA7B968EB087} - System32\Tasks\TSRH => C:\Users\lucky\AppData\Roaming\TSRH.exe <==== ATTENTION
Task: {EBDF55DF-35D5-4F30-8684-4E6E4CF146E2} - System32\Tasks\SolutoTask_bf15e3bf-7186-4dde-9382-19ab6fcee96e => C:\ProgramData\Soluto\Temp\ninite.openoffice_4_00_9714.setup-22f94a22-b502-3fb6-a49b-dc44f1752a53.exe <==== ATTENTION
Task: C:\Windows\Tasks\BVRGMFU.job => C:\Users\lucky\AppData\Roaming\BVRGMFU.exe <==== ATTENTION
Task: C:\Windows\Tasks\NSKPLG.job => C:\Users\lucky\AppData\Roaming\NSKPLG.exe <==== ATTENTION
Task: C:\Windows\Tasks\TSRH.job => C:\Users\lucky\AppData\Roaming\TSRH.exe <==== ATTENTION
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
0 members, 0 guests, 0 anonymous users
Community Forum Software by IP.Board
Licensed to: Geeks to Go, Inc.