Avast Web Shield constantly detects a threat that I cannot find


Avast Web Shield pops up every few minutes to let me know it has detected and blocked a threat. I have run several things in an effort to identify and remove any harmful files. So far, they all keep coming back clean. A lot of them say they are an Internet Explorer process yet I don’t even use IE.

Please help!

I ran the logs you all requested and attached the results.

Hi jenfont, :slight_smile:

My name is Valinorum and I will be the acolyte today. Before we proceed, please, acknowledge yourself the following(s):

[*]Please do not create any new threads on this while we are working on your system as it wastes another volunteer’s time. If you are being helped/have solved the issue/no longer wish to continue, notify me in your reply and I will quickly close this thread. Failing to comply will result in denial of future assistance.
[*]Please do not install any new software while we are working on this system as it may hinder our process.
[*]Malware removal is a complicated process so don’t stop following the steps even if the symptoms are not found. Keep up with me until I declare you clean.
[*]Please do not try to fix anything without being ask.
[*]Please do not attach your logs or put them inside code/quote tags. Do a Copy/Paste of the entire contents of the log file and submit it inside your post unless directed otherwise.
[*]Please print or save the instructions I give you for quick reference. We may be using Safe mode which will cut you off from internet and you will not always be able to access this thread.
[*]Back up your data. I will not knowingly suggest your any course that might damage your system but sometimes Malware infections are so severe that only option we have is to re-format and re-install the operating system.
[*]If you are confused about any instruction, stop and ask. Do not keep on going.
[*]Do not repeat the steps if you face any problems.
[*]I am not an omniscient. There are things even I cannot foresee. But what I know took years to learn and perfect the skill. This site is run by volunteers who help people in need in their own free time. I would ask you to respect their time and be patient as sometimes real life demands our time and replies to you can be delayed.
[*]Private Message(PM) if and only if I have not responded to your thread within three days or your query is offtopic and personal. Do not PM me under any other circumstances. Your thread is the only medium of communication.
[*]The fixes are for your system only. Please refrain from using these fixes on other system as it may do serious damage.

[*]Step #1 Fix with FRST
Make sure that you still have FRST.exe on your Desktop. If you do not have it, download the suitable version from here to your Desktop.
[*]Open Notepad.exe. Do not use any other text editor software;
[*]Copy and Paste the contents inside the code-box to your Notepad

HKLM\...\Run: [] => [X]
HKU\S-1-5-21-4026194587-2901221759-3025965959-1002\...\MountPoints2: F - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-4026194587-2901221759-3025965959-1002\...\MountPoints2: {a138c09e-6dc7-11e4-a581-54271ef4c362} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-4026194587-2901221759-3025965959-1002\...\MountPoints2: {b88b832e-5191-11e4-9051-54271ef4c362} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-4026194587-2901221759-3025965959-1002\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml.dll,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf> (the data entry has 243 more characters). <==== Poweliks!
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
CustomCLSID: HKU\S-1-5-21-4026194587-2901221759-3025965959-1002_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml.dll,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf> (the data entry has 251 more characters). <==== Poweliks?
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns

[*]Click on File > Save as…
[list][*]Inside the File Name box type fixlist.txt
[*]From the Save as type drop down list, choose All Files
[*]Save the file to your Desktop;
[*]Re-run FRST.exe and click Fix;
[*]Note: If FRST advises there is a new updated version to be downloaded, do so/allow this.[]After the completion, a log will be produced;
]Attach the log in your next reply.[/list]

[*]Required Log(s):
[*]FRST Fix Log


Enclosed is the results of the fix, thank you so much for your help.


Again, thank you so much for your help. Enclosed below is the delfix results.



DelFix v10.8 - Logfile created 27/12/2014 at 15:12:41

Updated 29/07/2014 by Xplode

Username : Mike - MIKE-PC

Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Activating UAC … OK

~ Removing disinfection tools …

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\TDSSKiller.
Deleted : C:\Users\Mike\Desktop\Addition.txt
Deleted : C:\Users\Mike\Desktop\aswMBR.txt
Deleted : C:\Users\Mike\Desktop\Fixlog.txt
Deleted : C:\Users\Mike\Desktop\FRST.txt
Deleted : C:\Users\Mike\Desktop\FRST64.exe
Deleted : C:\Users\Mike\Desktop\MBR.dat
Deleted : C:\Users\Mike\Desktop\Rkill.txt
Deleted : C:\Users\Mike\Downloads\adwcleaner_4.106.exe
Deleted : C:\Users\Mike\Downloads\aswmbr.exe
Deleted : C:\Users\Mike\Downloads\tdsskiller.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR

~ Creating registry backup … OK

~ Cleaning system restore …

Donation sent, thank you for your time.

You are most welcome. Surf safely. :slight_smile: