MALWARE: svchost.exe URL:Mal

Please help!

whenever I start my computer Avast will pop up saying it blocked a harmful webpage or file.

http://reddie.net/3333/ProcedureSystem_142264157719958.dll
Infection: URL:Mal
Process: C:\Windows\System32\svchost.exe

Hi nustud00, :slight_smile:

My name is Valinorum and I will be the acolyte today. Before we proceed, please, acknowledge yourself the following(s):

[*]Please do not create any new threads on this while we are working on your system as it wastes another volunteer’s time. If you are being helped/have solved the issue/no longer wish to continue, notify me in your reply and I will quickly close this thread. Failing to comply will result in denial of future assistance.
[*]Please do not install any new software while we are working on this system as it may hinder our process.
[*]Malware removal is a complicated process so don’t stop following the steps even if the symptoms are not found. Keep up with me until I declare you clean.
[*]Please do not try to fix anything without being ask.
[*]Please do not attach your logs or put them inside code/quote tags. Do a Copy/Paste of the entire contents of the log file and submit it inside your post unless directed otherwise.
[*]Please print or save the instructions I give you for quick reference. We may be using Safe mode which will cut you off from internet and you will not always be able to access this thread.
[*]Back up your data. I will not knowingly suggest your any course that might damage your system but sometimes Malware infections are so severe that only option we have is to re-format and re-install the operating system.
[*]If you are confused about any instruction, stop and ask. Do not keep on going.
[*]Do not repeat the steps if you face any problems.
[*]I am not an omniscient. There are things even I cannot foresee. But what I know took years to learn and perfect the skill. This site is run by volunteers who help people in need in their own free time. I would ask you to respect their time and be patient as sometimes real life demands our time and replies to you can be delayed.
[*]Private Message(PM) if and only if I have not responded to your thread within three days or your query is offtopic and personal. Do not PM me under any other circumstances. Your thread is the only medium of communication.
[*]The fixes are for your system only. Please refrain from using these fixes on other system as it may do serious damage.


Uninstall Spybot - Search and Destroy for now. You may re-install it when your PC is malware free. In addition, please, do not run every malware removal tool you can find in the internet. Some of them are specialised tool and should be used for special occasion.


[*]Step #1 Fix with FRST
Make sure that you still have FRST.exe on your Desktop. If you do not have it, download the suitable version from here to your Desktop.
[*]Open Notepad.exe. Do not use any other text editor software;
[*]Copy and Paste the contents inside the code-box to your Notepad

Start
CreateRestorePoint:
CloseProcesses:
EmptyTemp:
CMD: type "C:\Users\Ksenia\Desktop\JRT.txt"
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4004006323-3007112563-2943426927-1001\...\MountPoints2: {2933c7b9-d349-11e4-8262-34de1a677a7c} - "D:\start.exe" 
HKU\S-1-5-21-4004006323-3007112563-2943426927-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {2933c7b9-d349-11e4-8262-34de1a677a7c} - "D:\start.exe"
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
2015-04-30 19:53 - 2015-04-30 19:53 - 04525536 _____ (LionSea Software ) C:\Users\Ksenia\Downloads\Smart_Svchost_Exe_Fixer_Pro_Setup (1).exe
Task: {87F6E814-65E5-4147-AE86-15E6D4CDDDD0} - \PCDoctorBackgroundMonitorTask No Task File <==== ATTENTION
Task: {97D3D92E-DF46-48DC-A351-A4F6854516B3} - \Optimize Start Menu Cache Files-S-1-5-21-4004006323-3007112563-2943426927-1001 No Task File <==== ATTENTION
Task: {C53B1294-4A71-4959-AAD0-EAA107642EE2} - \PCDEventLauncherTask No Task File <==== ATTENTION
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns
End

[*]Click on File > Save as…
[list][*]Inside the File Name box type fixlist.txt
[*]From the Save as type drop down list, choose All Files
[*]Save the file to your Desktop;
[*]Re-run FRST.exe and click Fix;
[*]Note: If FRST advises there is a new updated version to be downloaded, do so/allow this.[]After the completion, a log will be produced;
[
]Attach the log in your next reply.[/list]


[*]Required Log(s):
[*]FRST Fix Log

Regards,
Valinorum

attached is the fix log

How is your PC?