Author Topic: URL:Mal hxxp://getusaaall.info/?e=svon&cht=2&dcu=1&cpatch=2&dcs=1&pf=1&unp=Azm9  (Read 6991 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Hello,

My antivirus is saying all the time that I have the virus  URL:Mal hxxp://getusaaall.info/?e=svon&cht=2&dcu=1&cpatch=2&dcs=1&pf=1&unp=Azm9CdOLv7DV

in svchost.exe.


Could someone help me out?


I just tried the OTL but I don't understand the log.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Attach your logs. (MBAM, FRST and aswMBR..!!)
Instructions: https://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
here are the logs

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
here are the logs
Start your own topic and post the requested logs there.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
@ianpierreg  please run the FRST scan

REDACTED

  • Guest
That was my logs (Ian7)


I'm sorry. I didn't notice I had 2 perfs

Here are my logs from OLT

REDACTED

  • Guest
@ianpierreg  please run the FRST scan

What is FRST scan?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
@ianpierreg  please run the FRST scan
What is FRST scan?
Follow the instructions in Reply #1.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Hello,


Here is my log from FRST.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Let me know if this cures it

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3325849&octid=EB_ORIGINAL_CTID&ISID=7e4fe43f-f503-4399-bf98-a0231430a2a5&SearchSource=58&CUI=&UM=5&UP=SP6DD53037-AB82-4167-96FC-9BC2190BF0AA&q={searchTerms}&SSPV=
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3325849&octid=EB_ORIGINAL_CTID&ISID=7e4fe43f-f503-4399-bf98-a0231430a2a5&SearchSource=58&CUI=&UM=5&UP=SP6DD53037-AB82-4167-96FC-9BC2190BF0AA&q={searchTerms}&SSPV=
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
2014-07-11 16:21 - 2014-07-11 16:21 - 06762112 _____ (ParetoLogic, Inc.) C:\Users\pamelaoliveirac\Downloads\RegCureProSetup.exe
2014-07-01 12:15 - 2014-07-01 12:15 - 00000000 ____D () C:\ProgramData\374311380
014-06-30 22:19 - 2014-07-01 12:16 - 00000000 ____D () C:\Users\pamelaoliveirac\AppData\Local\StormAlerts
CMD: bitsadmin /reset /allusers
CMD: DEL %TEMP%\*.* /F /S /Q
CMD: RD /S /Q %TEMP%
REBOOT:

 
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

REDACTED

  • Guest
I will try what you instructed me to do but I've got to say that Avast! no longer detects the virus but I think it is affecting my machine. Sometimes I can't play video from youtube (simply, the video starts but not keep going) and also sometimes I can't get sound from the video, movies, and musics.

My chrome icon is a white paper as well...


REDACTED

  • Guest
I just tried but I can't notice the difference, I'm listenning music from youtube, but it used to work sometimes. (but the google icon still a white paper. Here are the logs that I got.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
For the chrome icon delete it from the desktop and the using send to..  create a new shortcut

Then run this small programme and try the videos again

Clear Cache/Temp Files
Download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.  Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.

REDACTED

  • Guest
Hello there,

It didn't work  :(

Thank you for the assistance anyway.

What else can I do?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
The next step would be to update to windows 8.1 this will refresh the majority of system files