Shortcut virus and cmd execution every time pc start

Hey
yesterday my SD card picked up a virus from a friend now every time that I’ve inserted an USB in the pc my files turned into shortcuts.
I right-clicked one of the shortcuts, and looked at where its target location is, and it’s somewhere in System32. When I open its target location, it takes me to System32, and the file in System32 that it highlights is cmd.exe and every time i start my pc an error shows after i deleted virus with avast

http://i61.tinypic.com/296c9wm.jpg

how can I delete this virus? Thank you in advance

follow instructions here https://forum.avast.com/index.php?topic=53253.0
attach Malwarebytes and Farbar Recovery Scan Tool logs

then scroll down to SPECIFIC INFECTIONS LOGS and follow MCShield instructions

when logs are attached, a malware expert willl assist you…

i cant attach them but there they are
and i add adwcleaner log

Malwarebytes Anti-Malware

Addition

FRST

.txt/] AdwCleaner

Did you run MCShield ?

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: F - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: G - G:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {048127da-465a-11e4-b838-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {048127e8-465a-11e4-b838-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {05a64c55-45a9-11e4-9244-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {05a64c64-45a9-11e4-9244-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {1dbcbcdf-605b-11e4-a7f8-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {24237cfb-6ab9-11e1-9362-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {4ec8a69e-7485-11e2-9434-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {4ec8a6ae-7485-11e2-9434-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {50ab6e65-7f3e-11e1-a19c-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {638f02d7-e9ed-11de-b316-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {860929c4-d454-11e2-b7a8-002522268ef4} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {c8012cfe-aeac-11e3-80f4-002522268ef4} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {ce420037-52d7-11e3-a74d-002522268ef4} - F:\LaunchU3.exe -a HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {d0660d9e-e8a5-11e3-affe-582c80139263} - F:\LGAutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {e17f7ad5-765f-11e4-bd7e-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {e17f7ae5-765f-11e4-bd7e-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {e17f7af4-765f-11e4-bd7e-001e101f8aaa} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {e6a226d3-548b-11e4-8d2b-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {e6a226e3-548b-11e4-8d2b-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {ee635d1b-5ce1-11e4-97a4-002522268ef4} - F:\AutoRun.exe HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\...\MountPoints2: {ee635d28-5ce1-11e4-97a4-002522268ef4} - F:\AutoRun.exe CHR HKU\S-1-5-21-3493774133-2983331093-3550604417-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.6.0_07\bin\jp2ssv.dll No File Toolbar: HKLM - No Name - !{8dcb7100-df86-4384-8842-8fa844297b3f} - No File U3 ugliiuoc; \??\C:\Users\AZIZET~1\AppData\Local\Temp\ugliiuoc.sys [X] 2014-12-15 22:12 - 2014-12-15 22:13 - 00170962 _____ () C:\Users\azizetamal\Downloads\mmffncokckfccddfenhkhnllmlobdahm_main.crx 2014-12-17 18:06 - 2014-10-28 18:29 - 00000000 _RSHD () C:\Skypee 2014-12-17 17:27 - 2011-10-17 14:09 - 00000000 ____D () C:\Intel 2014-12-17 17:22 - 2014-10-28 18:28 - 00000000 _RSHD () C:\Google Task: {6F1EBE99-1C34-414E-A716-D9730CD03BE7} - \TaskUserUpdate_wp No Task File <==== ATTENTION EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.

thnx no more cmd
i run MCSheild
this is frst fix log
FRST
and i dont have any problem accroding to adwcleaner
and i ll run an other malware scan and ill post the log

How is the computer behaving now ?

When i click on this forum link avast blocks a virus and the page wont load and some times thepc restart without any warning

OK fixed it … It was the code in my fix that avast did not like … All gone now :slight_smile:

thnx for help but is there a way to make my pc faster and get rid of ineeded files like FRST that deleted 5.8 GB of temp fies

For temp files then I generally find that this one goes the deepest

Clear Cache/Temp Files
Download TFC by OldTimer to your desktop

[*] Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
[*]It will close all programs when run, so make sure you have saved all your work before you begin.
[*]Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
[*]Once it’s finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.

As for speeding up then disable all unneeded start up items, generally all you need is the AV starting

should i remove those

http://i62.tinypic.com/2vc99g3.jpg

and for services is this ok?

http://i58.tinypic.com/w8ualj.jpg

Yes that should do, there is no need for chrome to start with windows