Infection URL:MAL also maybe a SVCHOST.EXE problem need help

I don’t know where I caught this thing, but it is invading my browsers, if I do not use the browsers than there are no problems. But the message keeps popping up no matter what I do and no matter which site I visit.

I am attaching a couple of logs.

Two from Malware, one addition and one from FRST. There are two Malware attachments because I did a clean in between before I found this forum.
And I cannot get aswMBR.exe to complete, it errors before it is finished.

I do use AVAST internet also…

Please help.

After these runs could you let me know if the alerts have ceased

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Download the attached Fixlist.txt to the same location as FRST
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.

Thank you and before I reboot from FRST here is the fixlog. As it is getting late where I am, I am going to call it a night and run the other in the morning.

Ok I have run the other program.

The results are attached.

It seems to have solved the problem, do I need to take any further action? ilivid has been installed for about a year, and it has not caused any issues… Did something infect it? Do I dare to try to reinstall it?

Thank you for your help.

See: https://www.mywot.com/en/scorecard/ilivid.com?utm_source=addon&utm_content=popup-donuts

Not reputation rated very highly.

I wouldn’t re-install. Read some of user comments.

Ok I will, thank you. Though have used it for a long time, with no problems. But I probably will not re-install after reading those comments. thanks.

I still think I may have some problem with SVCHOST.EXE. I just got one notification of a possible intrusion but it was blocked. I have gotten only one since fixing the problems, so I dont know if it was random or not.

ATM, we’re waiting for essexboy to come back with personalised and specific fixes for your system. Make any changes you like after the cleansing routine is done and when essexboy gives you the all clear.

Have you received any further alerts ?

It was working fine, but this morning after a reboot it came back, and I know exactly why… I downloaded a program called YTD Downloader to replace the ilivid software I can no longer use, unfortuantely, even though this software has an editor’s rating it is full of malware also. I am very disappointed in CNET. I am sorry to trouble you again for another fix.

Malwarebytes is showing clean.

So I ran AWB and the results are attached. I have already uninstalled the YTD software, but of course that doesn’t help.

AWB results attached, I did not clean yet. In addition the Malwarebytyes software keeps popping up a SVCHOST.EXE problem…

See my sig below. It can help you if you use it.

Yes, I actually did visit your site to check on that site, http://www.ytddownloader.com/ before I installed it. As I did not install MyPCBackup, and figured out how not to install it, I figured I would be fine. but I was wrong. I will use your site more often for other software I wish to install in the future. It’s a nice site, and I will be adding my own comments about these two vicious programs soon.

Could you run a fresh FRST scan please including the additions…

This also may be of help :

A small tool that may help when you download programmes

http://unchecky.com/

Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder

Right click on the Unchecky_setup
http://i1059.photobucket.com/albums/t432/cinjo23/uncheckysetupicon.png
or folder and choose to Run as Administrator

Once open click the Install button.

http://i1059.photobucket.com/albums/t432/cinjo23/uncheckysetupwindow.png

Then click on Finish

http://i1059.photobucket.com/albums/t432/cinjo23/uncheckyfinishsetupwindow.png

Unchecky is now installed and will help you keep unwanted check boxes unchecked :wink:

Attached are the two files you wanted.

And unchecky looks like a great program, though I always slowly go through new software to uncheck all the boxes, including the one that caused this problem. Just that this particular software was no good to begin with even without any checked boxes… sigh…

OK lets do a deep check

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
  3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Dang, this one is more problematic than the last one? I was hoping for a quick fix like the last one… I have used combofix before, but it always worries me it could do more harm… alright, I will download and proceed.

This appears to be the latest one which hides from my other scans

Ok here is the log file.

Some interesting things happened during the process. 1. I had to approve the program to run about 4 times during the process, is this normal? 2. I had some registry keys that it couldn’t access. 3. I had no permissions as an admin to save that logfile so I saved it to a USB pen instead. 4. After reboot seems no issues.

Most importantly FireFox window stayed open during the procedure, not sure if this influenced anything. When the system told me don’t run any programs during the process I shut it down while it prepared the log file, so I am not sure if this influenced the output or not… I closed everything else except FF. As I wanted to have the instructions handy.

It appears to have run correctly, if all is well tomorrow let me know and I will tidy up

Everything seems to be working ok. of course still getting the URL:MAL message and SVCHOST issue from Malwarebytes, but other than that, all the programs I usually use any way are working fine. I cannot go through all of them. But there were no error messages after reboot.

Could you screenshot the MBAM alert please