Shortcut virus - location: cmd (C:\Windows\System32) ????

These files was turned into shortcuts and its location is on windows/system32 cmd

Need help guys thank you ;D

Attach your basic logs. (MBAM, FRST and aswMBR…!!)
Instructions: https://forum.avast.com/index.php?topic=53253.0

Note: Unplug your USB first…!!

HERE ARE THE LOGS

Good job, now you’ve to wait a bit…

Re-run FRST.exe as you did before …

[*] Download fixlist.txt that you find attached at the bottom of this post and save it same place you
[*] Press the Fix button once and wait.
[*] FRST will process fixlist.txt
[*] When finished, it will produce a log fixlog.txt and will keep that log in the same folder where FRST.exe is.

Attach here fixlog.txt logreport.

Edit:

You have two antivirus Avira and MSE. Remove one.
Remove USBGuard.exe.

Will I uninstall it or just turn it off ?

@ARGUs i turned off my avira and uninstall my usbguard.

here are the log :smiley:

You can only have 1 antivirus installed
http://blog.kaspersky.com/multiple-antivirus-programs-bad-idea/

It is ok for having MICROSOFT SECURITY ESSENTIALS, MALWAREBYTES-ANTIMALWARE and MCShield to protect my computer or it is bad ? ::slight_smile:

MCShield log.

Under Logs tab (in Control Center) for AllScans.txt log section click on Save button. AllScanst.txt report shall be located on your Desktop.

=> Post here AllScanst.txt

Here .

If you’re using avast!, then you need to take Security Essentials out of that mix. The others are fine.

If I’m not using avast. It is fine right ?

If you’re not using avast!, why are you here asking for help cleaning up a corruption ???
Why not ask Microsoft since they’re the ones who let you get infected in the first place. ???
I’m not trying to be rude but I don’t understand your logic and I’m sure argus will still continue to help you.

Its only a “if” sorry ;D

How is the situation now?

It is okay if the cmd.exe is still there ? :-\ or its not corrupted anymore ? I got 3 laptops that is corrupted by this malware/virus or whatever it is :frowning:

http://www.speedyshare.com/9Uj5f/Video-2014-09-07-111519.wmv

MCShield log - video

Scan with Combofix:

[*] Please download ComboFix by sUBs and save it to your Desktop.
You may read how Combofix works here.

[*] Temporarily disable your AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix.
If you are unsure how to do this please read this or this Instruction.

[*] Run ComboFix. Click on I Agree! & follow the prompts.
Note: If you see a message like “Illegal operation attempted on a registry key that has been marked for deletion” just restart your computer.

[*] When finished, it will produce a report for you. Please attach log reports (ComboFix.txt) back to topic.
(typical log location: C:\ComboFix.txt )

.

Then connect a pendrive and attach here the log.

Here are the log for the combo fix but i can’t understand what are you saying about the “pendrive and the logs”