Avast WEBforum

Other => Viruses and worms => Topic started by: daamole on November 08, 2012, 10:46:54 PM

Title: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: daamole on November 08, 2012, 10:46:54 PM
My computer/internet is now slow and sometimes computer reboots to do Windows update without success. I have followed the steps to scan and attached the logs.

MBAM log is below

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.11.08.07

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Manager :: SERVER1 [administrator]

08/11/12 11:14 AM
mbam-log-2012-11-08 (11-14-30).txt

Scan type: Full scan (C:\|D:\|R:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 356091
Time elapsed: 1 hour(s), 25 minute(s), 2 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 2
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|Load (PUM.UserWLoad) -> Data: C:\Users\Manager\LOCALS~1\Temp\8748ffff.com -> Delete on reboot.
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|Load (Trojan.Ransom) -> Data: C:\Users\Manager\LOCALS~1\Temp\8748ffff.com -> Delete on reboot.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: Pondus on November 08, 2012, 11:04:15 PM
malware removers are notified. it may take hours before one arrive, so be patient
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: essexboy on November 08, 2012, 11:25:25 PM
Hi lets stop this

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:OTL
F3 - HKU\S-1-5-21-938368789-2980352900-4278257160-1000 WinNT: Load - (C:\Users\Manager\LOCALS~1\Temp\8748ffff.com) - C:\Users\Manager\Local Settings\Temp\8748ffff.com ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-938368789-2980352900-4278257160-1000\Software\Policies\Microsoft\Internet Explorer\restrictions present
[2012/03/20 16:43:04 | 000,000,288 | ---- | C] () -- C:\Users\Manager\AppData\Roaming\A5E277B.reg
[2012/01/20 14:11:27 | 000,007,889 | ---- | C] () -- C:\Users\Manager\AppData\Roaming\1bc216c9
[2012/01/20 14:11:27 | 000,007,858 | ---- | C] () -- C:\Users\Manager\AppData\Local\13cc6577
[2012/01/20 14:11:27 | 000,007,788 | ---- | C] () -- C:\ProgramData\22cd857d
[2011/10/07 09:55:04 | 000,000,312 | ---- | C] () -- C:\ProgramData\~6DSS92c31Apgjk
[2011/10/07 09:55:04 | 000,000,208 | ---- | C] () -- C:\ProgramData\~6DSS92c31Apgjkr
[2011/10/07 09:55:00 | 000,000,336 | ---- | C] () -- C:\ProgramData\6DSS92c31Apgjk
[2011/06/10 14:44:46 | 000,000,128 | ---- | C] () -- C:\ProgramData\~35053304r
[2011/06/10 14:44:46 | 000,000,112 | ---- | C] () -- C:\ProgramData\~35053304
[2011/06/10 14:44:44 | 000,000,336 | ---- | C] () -- C:\ProgramData\35053304
[2011/04/29 19:52:49 | 000,012,554 | -HS- | C] () -- C:\ProgramData\1607314106
[2011/04/29 11:20:50 | 000,012,420 | -HS- | C] () -- C:\Users\Manager\AppData\Local\ka5tv6a3a53h
[2011/04/29 11:20:50 | 000,012,420 | -HS- | C] () -- C:\ProgramData\ka5tv6a3a53h

:Files
C:\Users\Manager\AppData\Local\{494bd9ca-098c-68bd-e7d5-94eb1a3b30ed}

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
THEN

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)
(http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png)

(http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png)

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: daamole on November 09, 2012, 03:47:16 AM
Thanks for the prompt response. You guys are amazing. I have followed the steps and attached the logs. I am still monitoring the system but I have not had the alerts since running Combofix. I await your response. Thanks.
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: essexboy on November 09, 2012, 01:30:09 PM
Any outstanding problems ?
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: daamole on November 10, 2012, 04:32:56 PM
Yes I am still getting the alerts. Please see attached screenshots for example
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: essexboy on November 10, 2012, 05:10:40 PM
Could you run a fresh OTL scan please
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: daamole on November 10, 2012, 09:03:10 PM
Ok. Do I need to include any particular script for the OTL scan?
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: essexboy on November 10, 2012, 09:21:38 PM
Run as per the initial one, there will only be one log this time
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: daamole on November 10, 2012, 10:22:05 PM
Here it is. Thanks.


Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: essexboy on November 10, 2012, 10:45:22 PM
Let me know if this kills it

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:OTL
FF - prefs.js..extensions.enabledItems: helperbar@helperbar.com:1.0
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
[2012/10/26 17:49:06 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: daamole on November 17, 2012, 06:15:14 PM
Thanks. I followed the required step and here is the log. Thanks.
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: daamole on November 17, 2012, 06:15:51 PM
And btw I am still getting all those Malicious URL alerts
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: essexboy on November 17, 2012, 08:30:53 PM
Does this only occur when firefox is open ?

Download the latest version of TDSSKiller from here (http://support.kaspersky.com/downloads/utils/tdsskiller.exe) and save it to your Desktop.
 
 
(https://dl.dropbox.com/u/73555776/tdss%20report.JPG)
 
Please copy and paste its contents on your next reply.
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: daamole on November 18, 2012, 12:37:53 AM
it occurs even without any browsers opened. I downloaded the TDSSKiller file but when I clicked on it to run it it doesnt run. Please advise.
Title: Re: Please help. I keep getting malicious url blocked alert from Avast even without
Post by: essexboy on November 18, 2012, 01:18:38 PM
OK put TDSSKiller in the recycle bin
Then restore from the recycle bin and retry to run it

Could you also check the following for me
Reboot the computer and immediately press then hold F8
On the menu that is presented is there an option "Repair my Computer" ?