Avast WEBforum

Other => Viruses and worms => Topic started by: JHD3 on August 30, 2012, 09:16:52 PM

Title: url:mal issue
Post by: JHD3 on August 30, 2012, 09:16:52 PM
I'm working on a clients PC virus/malware removal. I keep getting a url:mal notice from the network shield when I run avast and malware bytes they come up clean. I downloaded and ran OTL I will attach the logs. When I tried running the aswMBR.exe I get a pop up window that states "aswMBR.exe is not a valid Win32 application." Help please and thank you.
Title: Re: url:mal issue
Post by: JHD3 on August 30, 2012, 09:24:00 PM
The otl log is too big to post its 204KB and the max is 192. So i'm going to split it into to txt files.
Title: Re: url:mal issue
Post by: JHD3 on August 30, 2012, 09:25:33 PM
and otl log part 2
Title: Re: url:mal issue
Post by: mikaelrask on August 31, 2012, 10:16:37 AM
hey a malware expert will guide from here when one is on.
Title: Re: url:mal issue
Post by: essexboy on August 31, 2012, 07:27:21 PM
This is a sirfef infection but they are in the process of changing at the moment so I am not sure if Combofix will work.  If it stalls we will run a second programme

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Reg
[HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32]
""="%systemroot%\system32\wbem\wbemess.dll"
[-HKCU\Software\Classes\clsid\{12d0253a-7c96-815c-11e0-3034bbd97cc0}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS]
"DisplayName"="@%SystemRoot%\\system32\\qmgr.dll,-1000"
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
  6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"Description"="@%SystemRoot%\\system32\\qmgr.dll,-1001"
"ObjectName"="LocalSystem"
"ErrorControl"=dword:00000001
"Start"=dword:00000002
"DelayedAutoStart"=dword:00000001
"Type"=dword:00000020
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,45,00,76,00,65,00,\
  6e,00,74,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,00,00,00
"ServiceSidType"=dword:00000001
"RequiredPrivileges"=hex(7):53,00,65,00,43,00,72,00,65,00,61,00,74,00,65,00,47,\
  00,6c,00,6f,00,62,00,61,00,6c,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,\
  67,00,65,00,00,00,53,00,65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,00,6e,\
  00,61,00,74,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,\
  00,00,53,00,65,00,54,00,63,00,62,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,\
  00,67,00,65,00,00,00,53,00,65,00,41,00,73,00,73,00,69,00,67,00,6e,00,50,00,\
  72,00,69,00,6d,00,61,00,72,00,79,00,54,00,6f,00,6b,00,65,00,6e,00,50,00,72,\
  00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,6e,00,\
  63,00,72,00,65,00,61,00,73,00,65,00,51,00,75,00,6f,00,74,00,61,00,50,00,72,\
  00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00
"FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
  00,01,00,00,00,60,ea,00,00,01,00,00,00,c0,d4,01,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
  00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
  71,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Performance]
"Library"="bitsperf.dll"
"Open"="PerfMon_Open"
"Collect"="PerfMon_Collect"
"Close"="PerfMon_Close"
"InstallType"=dword:00000001
"PerfIniFile"="bitsctrs.ini"
"First Counter"=dword:000007d2
"Last Counter"=dword:000007e2
"First Help"=dword:000007d3
"Last Help"=dword:000007e3
"Object List"="2002"
"PerfMMFileName"="Global\\MMF_BITS_s"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Security]
"Security"=hex:01,00,14,80,90,00,00,00,a0,00,00,00,14,00,00,00,34,00,00,00,02,\
  00,20,00,01,00,00,00,02,c0,18,00,00,00,0c,00,01,02,00,00,00,00,00,05,20,00,\
  00,00,20,02,00,00,02,00,5c,00,04,00,00,00,00,02,14,00,ff,01,0f,00,01,01,00,\
  00,00,00,00,05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,\
  20,00,00,00,20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,04,\
  00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,01,02,\
  00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,00,05,20,00,00,\
  00,20,02,00,00

:Files
C:\Users\Owner\AppData\Local\{cb3e6b12-5653-e901-2e17-28ed00402f87}
ipconfig /flushdns /c
netsh int ip reset c:\resetlog.txt  /c
ipconfig /release /c
ipconfig /renew /c

:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
THEN

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)
(http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png)

(http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png)

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

IF COMBOFIX STALLS

(http://i1224.photobucket.com/albums/ee362/Essexboy3/RogueKiller/RGKRScan.png)   
 (http://i1224.photobucket.com/albums/ee362/Essexboy3/RogueKiller/RGKRDelete.png)     
Please post:    All RKreport.txt text files located on your desktop.
Title: Re: url:mal issue
Post by: JHD3 on September 03, 2012, 09:34:42 PM
I'm running OTL with the commands you provided. When it got to the host part a message box appeared stating "otl
cannot create file C:\windows\system32\drivers\etc\hosts." I clicked ok the box disappeared and otl started the "resetting of the HOSTS file". It has been stuck there for an hour I haven't closed out of otl, but I think its froze. Should I restart otl or do something different.
Title: Re: url:mal issue
Post by: essexboy on September 03, 2012, 10:35:06 PM
Close out OTL as that is the last command and continue with the rest
Title: Re: url:mal issue
Post by: JHD3 on September 04, 2012, 02:02:43 AM
quickscan log. running combofix now.
Title: Re: url:mal issue
Post by: JHD3 on September 04, 2012, 02:56:22 AM
combofix stalled while writing the log files. Restarted and ran RK here are the log files.
Title: Re: url:mal issue
Post by: JHD3 on September 04, 2012, 03:08:55 AM
Still getting the notification.
Title: Re: url:mal issue
Post by: JHD3 on September 04, 2012, 03:15:30 AM
Sorry I overlooked the combofix.txt file attaching it now.
Title: Re: url:mal issue
Post by: essexboy on September 04, 2012, 04:28:16 PM
Are you still getting alerts?  Could you post a screenshot

Download AdwCleaner from here (http://general-changelog-team.fr/en/tools/15-adwcleaner) to your desktop
Run AdwCleaner and select Delete

(https://dl.dropbox.com/u/73555776/AdwCleaner.GIF)

Once done it will ask to reboot, allow this
On reboot a log will be produced please attach that
Title: Re: url:mal issue
Post by: JHD3 on September 05, 2012, 01:32:59 AM
adwcleaner logs.
Title: Re: url:mal issue
Post by: JHD3 on September 05, 2012, 01:49:38 AM
Screen shots of alerts. I had edit down the screen shots to fit it within the 200 KB limit.
Title: Re: url:mal issue
Post by: essexboy on September 05, 2012, 04:16:53 PM
Do they occur just in firefox or is it all browsers.

Could you delete your current copy of OTL please and download the latest version  (had some firefox refinements added)

Download OTL (http://oldtimer.geekstogo.com/OTL.exe)  to your Desktop
(https://dl.dropbox.com/u/73555776/OTL_Main_Tutorial.gif)
netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
qmgr.dll
/md5stop
%systemdrive%\$Recycle.Bin|@;true;true;true
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS /s
CREATERESTOREPOINT

Title: Re: url:mal issue
Post by: JHD3 on September 05, 2012, 09:53:06 PM
firefox is the only browser that gives me the alerts. There was only the OTL.txt log, no extra.txt.
Title: Re: url:mal issue
Post by: Pondus on September 05, 2012, 09:54:36 PM
the extra.txt is only at first OTL run 
Title: Re: url:mal issue
Post by: JHD3 on September 05, 2012, 09:59:53 PM
Pondus, am I doing something wrong? I deleted the previous OTL.exe and downloaded the latest version. Downloaded to desktop, copied/pasted the custom commands selected all users check box. closed out of everything and clicked quickscan like instructed.
Title: Re: url:mal issue
Post by: Pondus on September 05, 2012, 10:15:25 PM
Quote
Pondus, am I doing something wrong?
why...what do you mean ?
Title: Re: url:mal issue
Post by: essexboy on September 05, 2012, 10:30:09 PM
OK this should stop it

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:OTL
FF - prefs.js..extensions.enabledAddons: {0A208142-C88F-11E1-8270-B8AC6F996F26}:2.0.14
FF:64bit: - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll (Best Buy)
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll (Best Buy)
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{0A208142-C88F-11E1-8270-B8AC6F996F26}: C:\Users\Owner\AppData\Local\{0A208142-C88F-11E1-8270-B8AC6F996F26}\ [2012/07/07 19:54:14 | 000,000,000 | ---D | M]
[2012/07/07 19:54:14 | 000,000,000 | ---D | M] (Mozilla Safe Browsing) -- C:\USERS\OWNER\APPDATA\LOCAL\{0A208142-C88F-11E1-8270-B8AC6F996F26}
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [SelectRebates] C:\Program Files (x86)\SelectRebates\SelectRebates.exe File not found

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
Title: Re: url:mal issue
Post by: JHD3 on September 05, 2012, 10:58:17 PM
ok I ran the fix. After the restart I Opened OTL and only clicked quick scan I didn't change any setting(ex: checking the scan all users, I left this unchecked since no instructions were given to check it).
Title: Re: url:mal issue
Post by: essexboy on September 05, 2012, 11:00:20 PM
Could you now check for alerts please
Title: Re: url:mal issue
Post by: JHD3 on September 06, 2012, 01:40:59 AM
ok no alerts! There is still some issues. I'm not sure if it's related to the infection or the result of it, but when the screen goes to sleep and you wake it back up the desktop is distorted/corrupted (opening a window clears it. I can attach a screen shot if you like), and the windows defender update has repeatedly failed and is the only important update that won't install (before your help none of the updates would even download). Have you come across others with these issues that have had the same infection as I have? Anyway thank you so much for the help. I appreciate everything you have done. Thank you.
Title: Re: url:mal issue
Post by: essexboy on September 06, 2012, 04:22:58 PM
Lets have a look at the services then

run farbar service scanner (http://download.bleepingcomputer.com/farbar/FSS.exe)

(https://dl.dropbox.com/u/73555776/FSS.GIF)

Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.
Title: Re: url:mal issue
Post by: JHD3 on September 06, 2012, 05:51:47 PM
FSS.txt log
Title: Re: url:mal issue
Post by: essexboy on September 06, 2012, 07:40:47 PM
The ServiceDll of WinDefend: "%ProgramFiles(x86)%\Windows Defender\mpsvc.dll".

This is the problem, it can be cured by manually editing the registry


Go Start > Run
Type in Regedit and press OK
Navigate to the following key
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\windefend
Select sub key Parameters
Right click Service.dll select modify
In the box that opens remove the (x86)  part only
You should be left with %ProgramFiles%\Windows Defender\mpsvc.dll
Click OK
Close out of regedit and then try windefender
Title: Re: url:mal issue
Post by: JHD3 on September 08, 2012, 05:01:55 AM
Windows defender is working properly now thank you for the help.
Title: Re: url:mal issue
Post by: essexboy on September 08, 2012, 02:18:16 PM
Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Run OTLRemove ComboFix

Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself. 

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
(http://users.telenet.be/bluepatchy/miekiemoes/images/javaicon.gif)
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.

 Upgrading Java:
SPRING CLEAN

To manually create a new Restore Point
 Now we can purge the infected ones
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
(http://img233.imageshack.us/img233/7729/mbamicontw5.gif)
Malwarebytes (http://www.malwarebytes.org/mbam-download.php).  Update and run weekly to keep your system clean

Download and install FileHippo update checker (http://www.filehippo.com/updatechecker/) and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit
To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ? (http://www.geekstogo.com/forum/topic/225044-preventing-malware-and-safe-computing/)

Keep safe  :wave: