Avast WEBforum

Other => Viruses and worms => Topic started by: REDACTED on June 23, 2018, 08:51:16 AM

Title: Removal And Cleaning Virus - system32.exe
Post by: REDACTED on June 23, 2018, 08:51:16 AM
Hi all,

I need assistant to remove unwanted program in my laptop suspected a malware. I have attached reports from malware and frst as required. FYI, this is second laptop,4th modems since the first incident. The first laptop been hacked by IT expert and there's another story.. I hope the experts here can resolve this for me.. This malware override the antivirus and user account. No notification asked from avast. Lots of extension files and unknown program like Hyper V Powershell and consume 99-100% of the disk.
Title: Re: Removal And Cleaning Virus - system32.exe
Post by: Sass Drake on June 23, 2018, 05:45:11 PM
Code: [Select]
CHR NewTab: Default ->  Not-active:"chrome-extension://pepoggcjhfobfcdfmpfokfighfjnfhjk/newtabproduct.html", Not-active:"chrome-extension://maedhjefckjfcmahamefeenlgdcddpcc/productnewtab.html", Not-active:"chrome-extension://bhebhhjlpcpnoaipjkghnkplmekcbeeh/productnewtab.html", Not-active:"chrome-extension://fhphlengpfffhlebfagkmmahimbkfmgg/productnewtab.html", Not-active:"chrome-extension://mallpejgeafdahhflmliiahjdpgbegpk/stubby.html"
CHR DefaultSearchURL: Default -> hxxp://srchnet.com/search/{searchTerms}



Remove these Chrome extensions:

OnlineWorkSuite
FunCustomCreations
FromDocToPDF
Search for Chrome
FromDocToPDF
Title: Re: Removal And Cleaning Virus - system32.exe
Post by: REDACTED on June 24, 2018, 03:46:53 PM
Hi Sass,

Thank you so much. Attached is the fixlog report for your perusal.
Title: Re: Removal And Cleaning Virus - system32.exe
Post by: Sass Drake on June 24, 2018, 07:35:42 PM
Can you give us more details about "This malware override the antivirus and user account" and "Lots of extension files and unknown program like Hyper V Powershell and consume 99-100% of the disk". Screenshots would be very useful.