URL:Mal again

Please help me, my svchost.exe is infected by URL:Mal. I don’t know what to do with that. Avast keeps warning me. :cry:

Think it is time to scan your system with malware scanners. They will each produce a log on completion of scan, please attach each one in your next reply. Download and run the first three programs listed in the link below:
https://forum.avast.com/index.php?topic=53253.0

Once that is done, a certified malware removal expert will be contacted for you. Be patient.

Please help me as soon as possible. My laptop is running extremely low. :-[

Monitoring …

We just find what is couse of this. I shall give you the reply soon. Hang in there …

Please help me, my svchost.exe is infected by URL:Mal.
URL:mal is not a infection, it just say that the URL blocked is on a blacklist for whatever reason however, you may have a infection trying to connect to that URL.....

See attached below:

[EDIT:] MBAM log shows a virtual adware city is living inside your computer.

[list]Hello, first you need to uninstall the PUP/AdWare from your system. From ControlPanel / Programs and Features uninstall/remove the following and then reboot the computer:

PC Optimizer Pro
Snap.Do
TornTV

While we are here … warning!

Multiple Antivirus Programs

You are running more than 1 Antivirus program!

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}

Running - more than one - antivirus program is not recommended because:
[*]They can conflict with each other.
[*]Report the other antivirus software as malicious.
[*]Antivirus programs use an enormous amount of computer’s resources… actively scanning your computer.
[*]Can cause your computer to become unstable…run slowly and even, in rare cases, BSOD crash…etc
I strongly suggest you uninstall one of them. Which one, is your decision.

Next … the following zoekscript shall fix your problem but know that we are not done yet. Stay with me untill I give you all clear.

Please download zoek by smeenk (
http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png
) from here or here and save it to your Desktop.
Unpack the archive…

[*]Close any open browsers
[*] Temporarily disable your AntiVirus program. (If necessary)
If you are unsure how to do this please read this or this Instruction.

[*]Double click on zoek.exe to run the tool .
Please wait while the tool does not start…

[*]Copy the text present inside the code box below and paste it into the large window in the zoek tool:

bitsadmin /reset /allusers;b EmptyFoldersCheck;Delete Uninstall-List; C:\Users\BILLBAO\AppData\Local\CocCoc\Browser\Application\browser.exe;i C:\Program Files (x86)\temp;vs PC Optimizer Pro;u {D5E50D52-C658-4C16-9722-9F9B057B5F0F};u 1ClickDownload;u C:\Program Files\PC Optimizer Pro;fs {02478D38-C3F9-4efb-9B51-7695ECA05670};c {5C255C8A-E604-49b4-9D64-90988571CECB};c {ae07101b-46d4-4a98-af68-0333ea26e113};c {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA};c EmptyCLSID; IEDefaults; C:\Program Files (x86)\mozilla firefox\browser\searchplugins\baambootratuav.xml;fs C:\Program Files (x86)\mozilla firefox\browser\searchplugins\creativecommons.xml;fs firefox@browsefox.com;ff iihfmx.eaoa@aepwjar-kh.com;ff trtv3@trtv.com;ff zsscfsh_o@eiahmmvw.org;ff C:\Users\BILLBAO\AppData\Roaming\Mozilla\Firefox\Profiles\tp3glchs.default\Extensions\{013899a5-99b9-01d6-6b15-fb61bef59d6c};f {0d45f140-f048-43a8-8755-71bde9e9f4e6}.xpi;ff iihfmx.eaoa@aepwjar-kh.com;ff FFDefaults; aldfcglpddncohiipflmgleefemjibgj;chr jllhclahphcmohljkmlcmbfmpgmhlecj;chr CHRDefaults; X6va011;s X6va012;s X6va022;s ipconfig /flushdns >> %temp%\log.txt;b EmptyAllTemp;

[*] Click on
http://www.mcshield.net/personal/magna86/Images/Run%20Script%20by%20zoek.png
button.
Please wait until a logreport will open (this can be after reboot)

[*]Save notepad to your Desktop and attach here zoek-results.log
Note: It will also create a log in the C:\ directory named “zoek-results.log

I did as you’d said but I couldn’t unistall Snap.do. It said that the installation for that product wans’t available (I enclose an image in this post). Others are fine.
Thanks for all your supports. :slight_smile:

Hi,

Do not worry, I will target that. Are you using ‘CocCocBrowser’?

Now run this zoekscript …

Reboot;
bopakagnckmlgajfccecajhnimjiiedh;chr
[-HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5E50D52-C658-4C16-9722-9F9B057B5F0F}];r
AutoClean;
QuickScan;

When zoek reboot the mashine post me the fresh zoek logfile …

Yes, I am using CocCoc browser. It’s similar to Chrome but I’d much rather use it (Just because it supports Vietnamese :P).

Ok, I needed to ask as I see that is well loaded in system. Zoek log has done nice job in cleaning …

Enable avast! and tell me how is the computer behavior now?

Wow, it runs much faster than I thought. Avast stops warning me about URL:Mal as well. Thank you really much! I really appreciate that :). Almost forgot, should I unistall tools we used to clean my laptop?

Wow, it runs much faster than I thought.

I know 8)

Avast stops warning me about URL:Mal as well.

As it should. I tell zoek to fix the problem it caused the warning as well.

Almost forgot, should I unistall tools we used to clean my laptop?

Yes you should. DelFix shall do that …

The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
[i]
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Remove disinfection tools

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Create registry backup

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Purge System Restore [/i]
Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:[b]DelFix.txt[/b])

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.