C:\ProgramData\boost_interprocess

Hi I have just done a Malwarebytes Scan and picked up 3 things, C:\ProgramData\boost_interprocess, C:\ProgramData\boost_interprocess\Nobu64AgentService and C:\ProgramData\boost_interprocess\Nobu64TrayIcon. My avast however hasn’t detected anything, Any help would be appreciated. Logs attached below.

Hi,

Please download zoek.zip or zoek.rar by smeenk (
http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png
) from here or here and save it to your Desktop.
Unpack the archive…

[*]Close any open browsers
[*]Temporarily disable your AntiVirus program. (If necessary)
If you are unsure how to do this please read this or this Instruction.

[*]Double click on zoek.exe to run the tool .
Please wait for the tool to start…

[*]Copy the text present inside the code box below and paste it into the large window in the zoek tool:

StandardSearch;

[*]Click on
http://www.mcshield.net/personal/magna86/Images/Run%20Script%20by%20zoek.png
button.
Please wait until a logreport will open (this can be after reboot)

[*]Save notepad to your Desktop and attach here zoek-results.log
Note: It will also create a log in the C:\ directory named “zoek-results.log

Those logs links do not load up my firefox says server not found

I download them and Avast blocked them as a malware gen

It is False Positive. Disable Avast, until we finish here…

How am I supposed to trust you I have had 3 blocks from that site

You can trust him, he’s a certified expert.

Well ok, sorry, i’m just very paranoid, can you please send a link again

Which link are you talking about…?? All links are in reply #1.

http://hijackthis.nl/smeenk/ is this the site?

Please follow THEagle’s advice, he’ll lead you.

Sorry for doubting you Sir but every time I tried to download it Avast would say it was a Malwaregen32. Any way I have attached the log

Run Zoek with this script

autoclean;
emptyalltemp;

Uploaded zoek to Avast as an FP … :slight_smile:

Oh so it was a false positive, thank you for confirming that Essexboy. Ok I have run that scan, Twinheaded Eagle and attached the log below. What is next?

Adware should be gone now, do you agree? Any other problem?

There was never any adware. Malwarebytes just deteted it as a threat and Avast didnt so I posted here.

Ok, you’re clean…

The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
[i]
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Remove disinfection tools

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Create registry backup

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Purge System Restore [/i]
Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:[b]DelFix.txt[/b])

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.

The folders still there.

Zoek deleted this folder. Remove it manually…