Avast WEBforum

Other => Viruses and worms => Topic started by: searz on January 23, 2013, 12:39:28 AM

Title: Malicious URL Pop-up keeps appearing approximately every 30 mins.
Post by: searz on January 23, 2013, 12:39:28 AM
Hi there,
I keep getting a pop-up on avast while browsing Chrome that says something along the lines of "malicious URL detected."
I've attached the logs to the post, the Malware Bytes scan came out with no threat, any help is greatly appreciated!
Note: I'm not very savvy with computers so simple instructions would be great, thanks!
Update: The messages gave stopped popping up, however I still want to make sure I'm clean, thanks.
Title: Re: Malicious URL Pop-up keeps appearing approximately every 30 mins.
Post by: Pondus on January 23, 2013, 01:53:25 AM
malware removers are notified, check back tomorrow.  ;)
Title: Re: Malicious URL Pop-up keeps appearing approximately every 30 mins.
Post by: searz on January 23, 2013, 02:42:47 AM
Great! Thank you very much.
Title: Re: Malicious URL Pop-up keeps appearing approximately every 30 mins.
Post by: magna86 on January 23, 2013, 06:47:28 AM
Hi,

> Please go to systemroot ( C:\ ) partitions and attach AdwCleaner[S1].txt logreport.

> Also, on desktop you shuld have Extras.Txt logreport from OTL. Please attach it here too.

----   ----   ----   ----   ----   ----   ----   ----   ----   ----   ----   ----   ----   ----   ----


(http://imageshack.us/a/img841/7292/thisisujrt.gif)  Please download Junkware Removal Tool (http://www.bleepingcomputer.com/download/junkware-removal-tool/) to your desktop.

----   ----   ----   ----   ----   ----   ----   ----   ----   ----   ----   ----   ----   ----   ----


Re-run OTL.exe.

Code: [Select]

:Otl
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.easylifeapp.com/
IE - HKLM\..\SearchScopes\%EasyLifeSearch_IESearchEngineGuid%: "URL" = http://search.easylifeapp.com/?q={searchTerms}
IE - HKU\S-1-5-21-2519709015-738426140-1624564586-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.easylifeapp.com/
IE - HKU\S-1-5-21-2519709015-738426140-1624564586-1000\..\SearchScopes\%EasyLifeSearch_IESearchEngineGuid%: "URL" = http://search.easylifeapp.com/?q={searchTerms}
O33 - MountPoints2\{6ace6e47-3685-11e2-90c0-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{6ace6e47-3685-11e2-90c0-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Install.exe -- [2011/03/23 10:44:19 | 002,098,520 | R--- | M] (Logitech(c))

:files
dir C:\Users\Shane\AppData\Local\Deployment /c
dir C:\Program Files (x86)\EasyLife /c

:commands
[CREATERESTOREPOINT]
[emptytemp]

ps: If notepad don't pop-up, then try to find fixreport in C:\_OTL folder. I need to see that report.

***************

How's your computer running now? Any new avast warnings?
Title: Re: Malicious URL Pop-up keeps appearing approximately every 30 mins.
Post by: searz on January 23, 2013, 10:12:25 PM
Hi there, I really appreciate you taking the time to help me out!
Unfortunately I could not find the OTL extras notepad on my desktop, where would the file be located?
I've attached the new OTL report, and the ADW (S1) along with the Junkware removal one. Fortunately I haven't gotten a warning since yesterday so hopefully that's a good sign!
Title: Re: Malicious URL Pop-up keeps appearing approximately every 30 mins.
Post by: magna86 on January 25, 2013, 06:58:34 PM
Quote
I could not find the OTL extras notepad on my desktop
It does not matter...  :)

Quote
Fortunately I haven't gotten a warning since yesterday so hopefully that's a good sign!
Aha ...  :)

We will remove used tools. If later you get a certain malware problems, down&run fresh OTL.exe and aswMBR.exe tools and attach their reports here.



> Re-run OTL and click on CleanUp! button.
ps: follow this step, it is important to do it.
You will be asked to reboot the machine to finish the cleanup process, choose Yes.
After the reboot all the tools we used should be gone.
Note: Some more recently created tools may not yet be removed by OTL. Feel free to manually delete any tools it leaves behind.