so i was watching videos and then all of a sudden avast starts sending me 4 messages at a time and it’s been going on for a while and it says something about 102f.net/al1000.html and idk what it is i need help
Follow the instructions as instructed in the sticky in this forum.
im not sure what to do here
Follow instructions here
Logs to assist in cleaning malware https://forum.avast.com/index.php?topic=53253.0
i think it worked and it said it got rid of some other stuff too, thanks!
You still need to attach the log files.
yeah as soon as i posted that the messages came, so i need to download the other things too?
what are the log files and where do i find them?
Please download Farbar Recovery Scan Tool and save it to your Desktop.
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
[*]Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
[*]Select additions at the bottom
[*]Press Scan button.
https://dl.dropboxusercontent.com/u/73555776/frst.JPG
[*]It will produce a log called FRST.txt in the same directory the tool is run from.
[*]Please attach both logs generated.
so i saved the logs to a folder and im confused when it said “post that log here” also i tried downloading “farbar recovery scan tool” but avast blocked it and said it was harmful and i tried downloading both versions and they said “failed-Download error”
Disable avast while running Farbar.
And the instructions say to ATTACH the logs, not to post them.
how do i attach them?
In the posting area click the link attachments and other options
Then select browse
Finally select the logs on the desktop
oh sorry i didnt see it at the bottom im doing the steps one by one so i dont get lost
so i did (mostly) everything it asked me to do but do i have to also do the one labeled “specific infection logs”? and if not then am i done?
Nope that will do for now if you could attach the logs please
hello?
Run Farbar and attach the logs to your post as instructed/explained.
these are the logs i think
Let me know if this stops the alerts
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint: AppInit_DLLs: C:\ProgramData\Fast And Safe\FastAndSafe_x64.dll => C:\ProgramData\Fast And Safe\FastAndSafe_x64.dll File not found AppInit_DLLs-x32: c:\progra~3\fastan~1\fastan~1.dll => "c:\progra~3\fastan~1\fastan~1.dll" File not found AutoConfigURL: [S-1-5-21-3010351082-3950412394-1341811930-1000] => anything Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File CustomCLSID: HKU\S-1-5-21-3010351082-3950412394-1341811930-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File Task: {6507DC08-A3A8-45AC-ABF0-C47124215588} - System32\Tasks\System Updater => C:\Users\Admin\AppData\Roaming\Updater\winupd.exe <==== ATTENTION C:\Users\Admin\AppData\Roaming\Updater C:\ProgramData\Fast And Safe Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f RemoveProxy: EmptyTemp: CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.