Avast WEBforum

Other => Viruses and worms => Topic started by: Codyth on April 24, 2013, 01:37:05 AM

Title: New OS, Avast spamming URL blocked from C:\Windows\SysWOW64\svchost.exe
Post by: Codyth on April 24, 2013, 01:37:05 AM
Hello, I'm in the process of fixing my siblings computer, and I've re-installed Windows 7 on their computer, it's a fresh OS, not sure if the iso was infected, or not.  The link I got it from is : http://msft.digitalrivercontent.net/win/X17-58997.iso . It was posted on the microsoft website answer forums, so I'm doubting it. Every time I start up, Avast spams the computer with over 20 "Threat detected" "Malicious URL Blocked" or something else in that process.. This then proceeds to blue screen the computer making it very hard to use. Here's an image:
(http://i.imgur.com/6bLc5u4.png) .

 I have no idea if this is a virus. The only thing's I've downloaded are the drivers from a website. I doubt one was a virus..but mabye. Any help would be amazing as I've been dealing with this for 3 painful days. Thank you a bunch. I'm currently trying to install malewarebytes to do a scan also.
Title: Re: New OS, Avast spamming URL blocked from C:\Windows\SysWOW64\svchost.exe
Post by: Pondus on April 24, 2013, 01:49:05 AM
attach (not copy and paste) the requested logs, then a removal expert will check tomorrow
http://forum.avast.com/index.php?topic=53253.0

AdwCleaner
Malwarebytes
OTL
aswMBR


Title: Re: New OS, Avast spamming URL blocked from C:\Windows\SysWOW64\svchost.exe
Post by: Codyth on April 24, 2013, 03:06:39 AM
Here are all my scan logs. Thanks a ton...


I didn't have any more attachment space, so heres the extras.txt
http://pastebin.com/f4ePK4PU
Thanks a ton.
Title: Re: New OS, Avast spamming URL blocked from C:\Windows\SysWOW64\svchost.exe
Post by: magna86 on April 24, 2013, 04:00:54 AM
Hi,

Step#1

Download TDSSKiller (http://support.kaspersky.com/downloads/utils/tdsskiller.exe)  and save it to your desktop

    Execute TDSSKiller.exe by doubleclicking on it.

Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt


Please post the contents of that log in your next reply.



**************************


Step#2



Please download Malwarebytes AntiRootkit and save it to your desktop.
http://www.malwarebytes.org/products/mbar/

Full instructions how to use MBAR
http://www.bleepingcomputer.com/virus-removal/how-to-use-malwarebytes-anti-rootkit

    Please note: This is a beta version so please be sure to read the disclaimer and note of it.

>> Please attach the two following logs from the mbar folder:

system-log.txt
and
mbar-log-year-month-day (hour-minute-second).txt.




**************************


Step#3




Please download zoek.exe (http://home.kpn.nl/stefsmeenk/zoek.exe/) and save it to your desktop.

Code: [Select]

filesrcm;
startupall;
firefoxlook;
chromelook;

Title: Re: New OS, Avast spamming URL blocked from C:\Windows\SysWOW64\svchost.exe
Post by: Codyth on April 26, 2013, 01:09:00 AM
I'm sorry it took me so long! Here are the logs you've requested...
Title: Re: New OS, Avast spamming URL blocked from C:\Windows\SysWOW64\svchost.exe
Post by: magna86 on April 26, 2013, 11:59:45 AM
Hi,



Note:It will also create a log in the C:\ directory.


********************



Re-run zoek.exe as you did before but use this script:

Code: [Select]
svchost.exe;z
Click on RunScript button and attach here fresh zoek log.
Title: Re: New OS, Avast spamming URL blocked from C:\Windows\SysWOW64\svchost.exe
Post by: Codyth on April 26, 2013, 12:20:28 PM
Hello, Thank you so very much for helping me. Here are those two logs attached to this reply.
Title: Re: New OS, Avast spamming URL blocked from C:\Windows\SysWOW64\svchost.exe
Post by: magna86 on April 26, 2013, 08:28:48 PM
Hi,

You have interrupted TDSSKiller scan.


06:11:04.0362 2420  Scan interrupted by user!
06:11:04.0362 2420  ================ Scan global ===============================
06:11:04.0362 2420  Scan interrupted by user!
06:11:04.0362 2420  ================ Scan MBR ==================================
06:11:04.0362 2420  Scan interrupted by user!
06:11:04.0362 2420  ================ Scan VBR ==================================
06:11:04.0362 2420  Scan interrupted by user!



Re-run TDSSKiller as you did before with Changed parametres and if you see this entry:

Quote
\Device\Harddisk0\DR0 ( TDSS File System )

Use Delete options for that.

----------------------


How's your computer running now?

Title: Re: New OS, Avast spamming URL blocked from C:\Windows\SysWOW64\svchost.exe
Post by: Codyth on April 26, 2013, 09:00:36 PM
Hello, I re-ran the scan and used the delete option for what you said. Then I re-scan and nothing was found. Is my computer fully cured now? If so, could you possibly inform me on what type of virus this was? Thanks
Also, Avast is not detecting anything or spamming anymore.
Title: Re: New OS, Avast spamming URL blocked from C:\Windows\SysWOW64\svchost.exe
Post by: magna86 on April 26, 2013, 09:45:04 PM
Hi,

You had an powerfull TDL4 rootkit variant know to us as Pihar rootkit. They are also know as MBR Rootkits. It lives outside of operating system, creating his own file system and do peyload into system.

http://en.wikipedia.org/wiki/Rootkit

Rootkit has been removed. Your system looks clean.

It is necessary to remove used tool for an some post-cleaning.


Download "Delfix by Xplode" (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix)
Run the tool ... Check the boxes ...
Click on "Run" button.

I don't need DelFix log report.
-------------------------


I recommended to keep Malwarebytes AntiMalware and to use MCShield if you will.
You may download MCShield from one of the following links:

MyCity -  Official download link (http://amf.mycity.rs/mcshield/)
Softpedija - Mirror download link (http://www.softpedia.com/get/Antivirus/MCShield.shtml)

It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
And not only will prevent infection, but it will immediately clean flash drive, memory card or external HDD.
Title: Re: New OS, Avast spamming URL blocked from C:\Windows\SysWOW64\svchost.exe
Post by: Codyth on April 26, 2013, 09:59:20 PM
Alright. I thank you very much in the aid of removing this rootkit. You're very kind. ^_^ I used that removal tool. Again, thank you very much for your help.