Malware infection I cannot remove


I have a clever malware infection that I can’t remove with avast, malwarebytes, numerous rootkit removers… its just nasty

At first it infected my svchost file under the windows32 directory. Now it has infected a file called PID 528… It continues to call on other websites pulling in further bad items of nastiness.

First here is a snapshot of when Avast blocks its intent to contact the outside world

Avast comes up clean
Malwarebytes comes up clean
TDSSKiller comes up with nothing.

Malwarebytes log here

Malwarebytes Anti-Malware

Scan Date: 6/05/2015
Scan Time: 6:17:25 PM
Logfile: junk.txt
Administrator: Yes

Malware Database: v2015.05.06.01
Rootkit Database: v2015.04.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Jim bob

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 465085
Time Elapsed: 26 min, 15 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


hey and welcome to the avast forum

please follow this guide and attach the logs from frst+addtion.

good luck

Hi, thanks

Here are logs,

hey agian thanks for attaching the needed logs a malware expert will help you one is online.

Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

[*]Right-click on
icon and select
Run as Administrator to start the tool.
[]Wait patiently until the main console will appear, it may take a minute or two.
]In the main box please paste in the following script:

bitsadmin /reset /allusers;b
ipconfig /flushdns;b

[*]Make sure that Scan All Users option is checked.
[*]Push Run Script and wait patiently. The scan may take a couple of minutes.
[*]When the scan completes, a zoek-results logfile should open in notepad.
[*]If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Post its content into your next reply.

Hi Argus, thank you for helping with my problem and Mikael, thank you for showing interest in my problem.

I have run Zoek by Smeenk and attached the log.

I think this may have removed the malware but will wait until you confirm.

Re-run zoek and run this script:

C:\Users\Jim bob\AppData\Local\Google\Chrome\User Data\Default\Preferences;f
bitsadmin /reset /allusers;b
ipconfig /flushdns;b

Post its content into your next reply.


Just this one fix

Hi Argus,
I have run the new script.

File attached.


Is everything ok now?

Hi Argus,

Everything appears ok. Am I virus free now?


The following will implement some post-cleanup procedures:

Download DelFix by Xplode and save it to your desktop.

[*]Run the tool by right click on the
icon and Run as administrator option.
[*]Make sure that these ones are checked:

[]Remove disinfection tools
]Purge system restore
[*]Reset system settings

[*]Push Run and wait until the tool completes his work.
All tools we used should be gone. Tool will create an report for you (C:[B]DelFix.txt)

[SIZE=1]The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.

Thank you Argus, this has been a big help. I’ll make a donation to you know.

You Rock

Thank you :slight_smile: