Author Topic: JS:HideMe-F [Trj] - how do i get rid of it??  (Read 2083 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
JS:HideMe-F [Trj] - how do i get rid of it??
« on: January 05, 2016, 03:07:07 PM »
So i have the avast free version on windows 10. I keep getting that annoying popup when i'm on google chrome with and alarm sound AND a woman talking. I seem to have contracted the trojan horse JS:HideMe-F [Trj]. can anyone tell me how to get rid of it? i've searched google but none of the solutions i found actually worked... i've scanned the pc with malwarebites and that didn't work either. and the avast scan didn't pick up anything.

I've done what user Pondus told me to and attached the logs of Adware Cleaner and Farbar Recovery Scan Tool

thanks

REDACTED

  • Guest
Re: JS:HideMe-F [Trj] - how do i get rid of it??
« Reply #1 on: January 05, 2016, 03:11:03 PM »
Sorry i just realized i forgot to run the FRST thing as administrator. i ran it again, this time as administrator and it only gave me an FSRT file, no additions file. i've attached it to this reply.
« Last Edit: January 05, 2016, 03:13:12 PM by Suzanne23 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: JS:HideMe-F [Trj] - how do i get rid of it??
« Reply #2 on: January 05, 2016, 03:47:16 PM »
Could you let me know if this stops it

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
BHO: No Name -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> No File
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx <not found>
2015-10-09 12:25 - 2015-10-09 12:25 - 0000000 _____ () C:\Users\Tiago\AppData\Local\{82B523D7-ED50-4138-BFD9-E7AC08969EA3}
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: JS:HideMe-F [Trj] - how do i get rid of it??
« Reply #3 on: January 05, 2016, 04:01:08 PM »
Hero you go!
and thanks for your help

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: JS:HideMe-F [Trj] - how do i get rid of it??
« Reply #4 on: January 05, 2016, 05:18:26 PM »
Are you still getting alerts ?