Please help me, my svchost.exe is infected by URL:Mal. I don’t know what to do with that. Avast keeps warning me. ![]()
Think it is time to scan your system with malware scanners. They will each produce a log on completion of scan, please attach each one in your next reply. Download and run the first three programs listed in the link below:
https://forum.avast.com/index.php?topic=53253.0
Once that is done, a certified malware removal expert will be contacted for you. Be patient.
Please help me as soon as possible. My laptop is running extremely low. :-[
Monitoring …
We just find what is couse of this. I shall give you the reply soon. Hang in there …
Please help me, my svchost.exe is infected by URL:Mal.URL:mal is not a infection, it just say that the URL blocked is on a blacklist for whatever reason however, you may have a infection trying to connect to that URL.....
See attached below:
[EDIT:] MBAM log shows a virtual adware city is living inside your computer.
[list]Hello, first you need to uninstall the PUP/AdWare from your system. From ControlPanel / Programs and Features uninstall/remove the following and then reboot the computer:
PC Optimizer Pro
Snap.Do
TornTV
While we are here … warning!
Multiple Antivirus Programs
You are running more than 1 Antivirus program!
AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
Running - more than one - antivirus program is not recommended because:
[*]They can conflict with each other.
[*]Report the other antivirus software as malicious.
[*]Antivirus programs use an enormous amount of computer’s resources… actively scanning your computer.
[*]Can cause your computer to become unstable…run slowly and even, in rare cases, BSOD crash…etc
I strongly suggest you uninstall one of them. Which one, is your decision.
Next … the following zoekscript shall fix your problem but know that we are not done yet. Stay with me untill I give you all clear.
Please download zoek by smeenk (
http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png
) from here or here and save it to your Desktop.
Unpack the archive…
[*]Close any open browsers
[*] Temporarily disable your AntiVirus program. (If necessary)
If you are unsure how to do this please read this or this Instruction.
[*]Double click on zoek.exe to run the tool .
Please wait while the tool does not start…
[*]Copy the text present inside the code box below and paste it into the large window in the zoek tool:
bitsadmin /reset /allusers;b EmptyFoldersCheck;Delete Uninstall-List; C:\Users\BILLBAO\AppData\Local\CocCoc\Browser\Application\browser.exe;i C:\Program Files (x86)\temp;vs PC Optimizer Pro;u {D5E50D52-C658-4C16-9722-9F9B057B5F0F};u 1ClickDownload;u C:\Program Files\PC Optimizer Pro;fs {02478D38-C3F9-4efb-9B51-7695ECA05670};c {5C255C8A-E604-49b4-9D64-90988571CECB};c {ae07101b-46d4-4a98-af68-0333ea26e113};c {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA};c EmptyCLSID; IEDefaults; C:\Program Files (x86)\mozilla firefox\browser\searchplugins\baambootratuav.xml;fs C:\Program Files (x86)\mozilla firefox\browser\searchplugins\creativecommons.xml;fs firefox@browsefox.com;ff iihfmx.eaoa@aepwjar-kh.com;ff trtv3@trtv.com;ff zsscfsh_o@eiahmmvw.org;ff C:\Users\BILLBAO\AppData\Roaming\Mozilla\Firefox\Profiles\tp3glchs.default\Extensions\{013899a5-99b9-01d6-6b15-fb61bef59d6c};f {0d45f140-f048-43a8-8755-71bde9e9f4e6}.xpi;ff iihfmx.eaoa@aepwjar-kh.com;ff FFDefaults; aldfcglpddncohiipflmgleefemjibgj;chr jllhclahphcmohljkmlcmbfmpgmhlecj;chr CHRDefaults; X6va011;s X6va012;s X6va022;s ipconfig /flushdns >> %temp%\log.txt;b EmptyAllTemp;
[*] Click on
http://www.mcshield.net/personal/magna86/Images/Run%20Script%20by%20zoek.png
button.
Please wait until a logreport will open (this can be after reboot)
[*]Save notepad to your Desktop and attach here zoek-results.log
Note: It will also create a log in the C:\ directory named “zoek-results.log”
I did as you’d said but I couldn’t unistall Snap.do. It said that the installation for that product wans’t available (I enclose an image in this post). Others are fine.
Thanks for all your supports. ![]()
Hi,
Do not worry, I will target that. Are you using ‘CocCocBrowser’?
Now run this zoekscript …
Reboot;
bopakagnckmlgajfccecajhnimjiiedh;chr
[-HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5E50D52-C658-4C16-9722-9F9B057B5F0F}];r
AutoClean;
QuickScan;
When zoek reboot the mashine post me the fresh zoek logfile …
Yes, I am using CocCoc browser. It’s similar to Chrome but I’d much rather use it (Just because it supports Vietnamese :P).
Ok, I needed to ask as I see that is well loaded in system. Zoek log has done nice job in cleaning …
Enable avast! and tell me how is the computer behavior now?
Wow, it runs much faster than I thought. Avast stops warning me about URL:Mal as well. Thank you really much! I really appreciate that :). Almost forgot, should I unistall tools we used to clean my laptop?
Wow, it runs much faster than I thought.
I know 8)
Avast stops warning me about URL:Mal as well.
As it should. I tell zoek to fix the problem it caused the warning as well.
Almost forgot, should I unistall tools we used to clean my laptop?
Yes you should. DelFix shall do that …
• The following will implement some post-cleanup procedures:
=> Please download DelFix by Xplode to your Desktop.
Run the tool and check the following boxes below;
[i]
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Remove disinfection tools
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Create registry backup
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Purge System Restore [/i]
Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:[b]DelFix.txt[/b])
The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.