Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

url mal alerts with avast [Closed]

malware avast

  • This topic is locked This topic is locked

#1
lucky43113

lucky43113

    New Member

  • Member
  • Pip
  • 1 posts

need some help getting a lot of pop up notifications from avast saying  i have malware the process is C:\Windows\System32\svchost.exe

 

i used farbar recovery here are the log files 

Attached Files


  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Could you let me know if this stops the alerts

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint:
HKU\S-1-5-21-183760795-2501133323-4075679530-1001\...\Command Processor: CD /d C:\ <===== ATTENTION!
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: WSAMVCUchrome - No CLSID Value
FF Plugin HKU\S-1-5-21-183760795-2501133323-4075679530-1001: tdameritrade.com/tossc -> C:\Program Files\thinkorswim\nptossc.dll No File
CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - No Path Or update_url value
2015-06-02 23:54 - 2015-06-23 00:32 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-06-29 18:30 - 2014-09-10 17:46 - 00001338 _____ C:\Windows\Tasks\NSKPLG.job
2015-06-29 18:30 - 2014-09-10 17:45 - 00001684 _____ C:\Windows\Tasks\BVRGMFU.job
2015-06-29 18:30 - 2014-09-10 17:43 - 00001334 _____ C:\Windows\Tasks\TSRH.job
2015-04-14 12:28 - 2015-04-14 12:28 - 0004387 _____ () C:\Users\lucky\AppData\Roaming\8JLETVeFEoboy1Kjqn
2014-09-01 04:18 - 2015-04-09 02:56 - 0000365 _____ () C:\Users\lucky\AppData\Roaming\BVRGMFU
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\lucky\AppData\Roaming\Cu8L0W44hBX
2014-09-01 04:18 - 2015-04-09 02:57 - 0000365 _____ () C:\Users\lucky\AppData\Roaming\EPWBHYDT
2013-06-17 16:57 - 2013-06-17 16:57 - 0000037 ___SH () C:\Users\lucky\AppData\Local\1517305038504592ead82131.36681408
2014-04-13 01:18 - 2013-11-11 10:58 - 4900568 _____ (COMODO) C:\ProgramData\cis22FA.exe
2014-04-13 00:51 - 2013-11-11 10:58 - 4900568 _____ (COMODO) C:\ProgramData\cis3D39.exe
2014-04-13 00:57 - 2013-11-11 10:58 - 4900568 _____ (COMODO) C:\ProgramData\cis44C.exe
2014-04-13 01:02 - 2013-11-11 10:58 - 4900568 _____ (COMODO) C:\ProgramData\cis7C87.exe
2014-04-13 01:22 - 2013-11-11 10:58 - 4900568 _____ (COMODO) C:\ProgramData\cis9E31.exe
014-06-12 16:53 - 2014-06-12 16:53 - 0004919 _____ () C:\ProgramData\uxxadbmu.rlu
Task: {13C8284D-B66A-43CC-BFBE-814C9DADA8BC} - System32\Tasks\SolutoTask_29eebd75-6160-4b99-9c5f-a2d0ab2d0623 => C:\ProgramData\Soluto\Temp\ninite.evernote_5_1_0_2217.setup-22f94a22-b488-aa1a-a4ef-69269eb40e0f.exe <==== ATTENTION
Task: {2608F0F2-0361-4B52-97C9-2F5D95C74414} - \FTdownloader V7.0-codedownloader No Task File <==== ATTENTION
Task: {30ED8319-22AF-4EAB-A3EE-092B8E64C1BE} - System32\Tasks\NSKPLG => C:\Users\lucky\AppData\Roaming\NSKPLG.exe <==== ATTENTION
Task: {577A7E22-044C-4215-BBFE-948F982FC721} - System32\Tasks\BVRGMFU => C:\Users\lucky\AppData\Roaming\BVRGMFU.exe <==== ATTENTION
Task: {5C86F962-C9BC-4E4E-8B01-C04CB4DD5FF5} - \FTdownloader V7.0-chromeinstaller-dev No Task File <==== ATTENTION
Task: {62515543-DE4A-49C5-B003-47147643D1BE} - System32\Tasks\SolutoTask_af222ae4-0d86-47e7-b84a-7a4e93f7935c => C:\ProgramData\Soluto\Temp\ninite.openoffice_4_00_9714.setup-22f94a22-b502-3fb6-a49b-dc44f1752a53.exe <==== ATTENTION
Task: {94BBDC4C-5736-4A79-BDF6-62A62981738F} - System32\Tasks\SolutoTask_16dc203a-2f17-45dc-a68b-b0e0ae2cf749 => C:\ProgramData\Soluto\Temp\ninite.irfanview_4_37.setup-22f94a22-b4cb-6aaf-8ed8-4e1a60ee9de6.exe <==== ATTENTION
Task: {9E187248-B33C-4675-912D-7FD973F94EA0} - \FTdownloader V7.0-firefoxinstaller No Task File <==== ATTENTION
Task: {D656DDAB-FB67-414B-B17E-EA7B968EB087} - System32\Tasks\TSRH => C:\Users\lucky\AppData\Roaming\TSRH.exe <==== ATTENTION
Task: {EBDF55DF-35D5-4F30-8684-4E6E4CF146E2} - System32\Tasks\SolutoTask_bf15e3bf-7186-4dde-9382-19ab6fcee96e => C:\ProgramData\Soluto\Temp\ninite.openoffice_4_00_9714.setup-22f94a22-b502-3fb6-a49b-dc44f1752a53.exe <==== ATTENTION
Task: C:\Windows\Tasks\BVRGMFU.job => C:\Users\lucky\AppData\Roaming\BVRGMFU.exe <==== ATTENTION
Task: C:\Windows\Tasks\NSKPLG.job => C:\Users\lucky\AppData\Roaming\NSKPLG.exe <==== ATTENTION
Task: C:\Windows\Tasks\TSRH.job => C:\Users\lucky\AppData\Roaming\TSRH.exe <==== ATTENTION
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.

  • 0

#3
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP