Avast WEBforum

Other => Viruses and worms => Topic started by: Tisoran on October 26, 2013, 06:45:42 AM

Title: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on October 26, 2013, 06:45:42 AM
So I've run a number of different scans since the initial Alert/block.

First it was Malwarebytes Pro that started blocking an IP: 66.45.56.109
I was starting to get a bit concerned when the same block occurred the next day. Started cleaning up and removed a significant amount of malware with malwarebytes and  adwcleaner/aswMBR and thought it was overwith.

Later did I install Avast Home edition 2014, thinking it wouldn't hurt to run both programs since the 'block' had shown up more often.
However, now avast is blocking a URL: http://clickered.com/cen?ag

I've looked for any sort of toolbar or program in RevoUninstaller that looked suspicious and I came across a GigaClicks Crawler installation. I've no idea what its from or what it does. When promted to uninstall Avast kicked it and moved some process to a chest.

I stumbled upon this (http://forum.avast.com/index.php?topic=133686.0) thread. Thinking I had a similar problem I followed the instructions for OTL off of this other thread (http://forum.avast.com/index.php?topic=53253.0).


And the OTL log is attached.

Any help to get rid of this would be very appreciated.

Much thanks.
Title: Re: Malicious URL Blocking/Detection
Post by: argus on October 26, 2013, 08:12:05 AM
Hello

Re-run OTL.exe.

Code: [Select]

:OTL
IE - HKU\S-1-5-21-3516740335-3617436455-440623508-1000\..\SearchScopes\{BB1F5DE8-681C-4096-B90E-4F20ECFB7A97}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3310511&CUI=UN14654307485881244&UM=2
O4 -
O4 - HKLM..\Run: []  File not found
O4 - HKU\.DEFAULT..\Run: [SearchProtect] \SearchProtect\bin\cltmng.exe File not found
O4 - HKU\S-1-5-18..\Run: [SearchProtect] \SearchProtect\bin\cltmng.exe File not found

:commands
[CREATERESTOREPOINT]
[emptytemp]

If the log doesn't appear, it can be found here:

c:\_OTL\MovedFiles\mmddyyyy_hhmmss.log


.






Please download zoek.zip or zoek.rar by smeenk ((http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png)) from here (http://hijackthis.nl/smeenk) or here (http://home.kpn.nl/stefsmeenk/zoek.exe) and save it to your Desktop.
Unpack the archive...
Code: [Select]
filesrcm;
startupall;
skipfix-iedefaults;
firefoxlook;
chromelook;
uninstall-list;
Title: Re: Malicious URL Blocking/Detection
Post by: Tisoran on October 26, 2013, 09:49:28 PM
I've run OTL and Zoek as instructed and the logs are attached, however the problem is still coming up.

Avast pops up with this:

" Object: http://clickered.com/cen?ag=a61d164abf0a767c25d33ee1a63e7473-11-3&g=BMW
 
  Infection: URL:Mal
 
  Process: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  "

or this url: http://clickered.com/cen?ag=c8841473129879da1cafddf323c7ad82-11-2&g=PIG

Thank you for the quick reply.

Title: Re: Malicious URL Blocking/Detection Alerts
Post by: argus on October 27, 2013, 05:06:26 AM
Download TDSSKiller (http://media.kaspersky.com/utilities/VirusUtilities/EN/tdsskiller.exe)  and save it to your desktop

  Execute TDSSKiller.exe by doubleclicking on it.
Confirm "End user Licence Agreement" and "KSN Statement" dialog box by clicking on Accept button.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt


Please post the contents of that log in your next reply.
.



----------- > Next








Please download Farbar Recovery Scan Tool (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/) by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


Title: Re: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on October 27, 2013, 06:12:20 AM
Alerts have still been coming in however Malwarebytes Pro has been blocking the original IP however its now under an avastsvc process.

Also I've run TDSSKiller, no suspicious or malicious objects detected.

I've also ran Farbar Recovery Scan Tool and the logs are attached.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: argus on October 27, 2013, 07:55:58 AM
Code: [Select]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job;f
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job;f
[-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB1F5DE8-681C-4096-B90E-4F20ECFB7A97}];r
FFdefaults;
chrdefaults;
iedefaults;
emptyalltemp;
autoclean;
emptyclsid;
ipconfig /flushdns >> %temp%\log.txt;b
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on October 27, 2013, 10:49:08 AM
I've run Zoek as instructed, I had to run it twice as I forgot to disable antivirus.

Alerts are still popping up.

 I dont know if it matters but I've been watching the Shields Activity from the Avast Statistics Monitoring, I've noticed the shields spike up when something accesses something along the lines of  "AppData\Temp\scoped dir_4383_25439\CRZ_INSTAL\Locales\vi\messages.json"

Logs are attached and Thank you for your quick reply.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: magna86 on October 27, 2013, 03:30:07 PM
Hi Tisoran,

Argus is busy these days. I will assist you.

Re-run zoek as you did before but using this script:

Code: [Select]
autoclean;
C:\Windows\SysNative\tasks\Escolade;f
C:\Users\Admin1\AppData\Roaming\iPumper;fs

Post me fresh created zoek log.



NEXT...

Re-run FRST, check box for Addition.txt and press [Scan] button. Post me fresh created FRST.txt and Additional.txt reports.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on October 27, 2013, 10:58:38 PM
Alright, Thank you magna.

I've re-run Zoek and as well as FRST, the logs are attached.

Title: Re: Malicious URL Blocking/Detection Alerts
Post by: magna86 on October 28, 2013, 01:09:41 PM
Posted logs looks good. Just one small fix...


1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Code: [Select]
Task: {2CB7B523-420B-48AF-9A35-5EA176DDF1AD} - \Escolade No Task File
2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.

================================


How's your computer running now?
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on October 28, 2013, 06:39:50 PM
I've run FRST with the fixlist.txt and the log is attached.

The system is running about as smooth as it did when I first formatted the drive however the Alerts from Avast are still coming in.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: magna86 on October 28, 2013, 06:48:51 PM
The system is running about as smooth as it did when I first formatted the drive however the Alerts from Avast are still coming in.

Can you please post me screenshot of that avast pop-up alert?

Also, re-run FRST and post me fresh FRST.txt log.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: magna86 on October 28, 2013, 06:51:24 PM
Also, re-run zoek tool with this script:

Code: [Select]
StandardSearch;
When zoek finished, post me fresh created zoek logs.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on October 29, 2013, 04:37:52 AM
I've posted a screenshot of the alerts, There was an instance where Malwarebytes and Avast blocked one at the same time. Both have been included in the picture as well as what Avast was scanning while the alert hit.

Re-ran FRST and Zoek, fresh logs have been attached.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on October 30, 2013, 07:19:13 AM
I don't know if it applies but I've been experiencing nearly the exact same symptoms in this thread. (http://forum.avast.com/index.php?topic=138362.0) With 2 different avast alerts back to back. The alerts range anywhere from 5-30 mins apart. I didn't notice the muting on Chrome until recently, as well as I've caught the 'spare' chrome with a radio station on mute.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: magna86 on October 30, 2013, 07:23:09 AM
Hi,

I see nothing active in the logs.

1. We shall deploy ComboFix. This powerful tool has useful routine for malware search + it shall clean junk, temp and cache files.




Scan with Combofix:
-----------------------------------------------------


2. Let's reset Chrome settings to default:


Code: [Select]
%LOCALAPPDATA%\Google\Chrome\User Data\Re-start Google Chrome.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on October 30, 2013, 01:01:57 PM
I've run ComboFix aswell as renamed the Default folder to Default.old the logs are attached.

I'll let you know if any alerts come in, so far just spikes in Avast's Shields activity.

Edit: Single alerts at first, now its they're back to back again.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: magna86 on October 30, 2013, 02:18:05 PM
Running ComboFix via CFScript:

Open notepad and copy/paste the text present inside the code box below:


Code: [Select]
ClearJavaCache::

Folder::
c:\users\Admin1\AppData\Local\lptmp1554647073

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)

RegNull::
[HKEY_USERS\S-1-5-21-3516740335-3617436455-440623508-1000\Software\SecuROM\License information*]
"datasecu"=hex:1c,46,80,3f,ff,80,b1,4f,a1,c8,1a,04,2f,21,35,e5,34,32,de,90,08,
   bd,10,3b,c6,c1,72,b2,d4,cd,67,38,b9,15,cd,55,a3,bf,65,29,cf,6a,2e,62,fa,e2,\
"rkeysecu"=hex:36,9e,fa,1f,34,da,ec,97,21,4d,1e,a0,6a,88,6e,f0

Save this as CFScript.txt

(http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif)

Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on October 31, 2013, 12:28:13 AM
I've Re-run ComboFix with the script as well as uninstalled Google Chrome via Revo-uninstaller.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: magna86 on October 31, 2013, 01:03:06 AM
Posted logs looks good. CF did his job. Any malware alerts?



edit:
You have been installed Webroot SecureAnywhere alongside avast. This isn't good and this isn't protection.
You may use only one AV per system. One of them you must uninstall. You choose witch one...


AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AV: Webroot SecureAnywhere *Disabled/Updated* {9C0666FC-6C7D-3E97-3C40-0C6B33FC7401}
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on October 31, 2013, 06:12:22 AM
I've uninstalled Webroot SecureAnywhere, I've been having it regularly disabled while using avast. Is there any way I can completely clear chrome/google from my desktop and reinstall chrome?

Re-installed chrome and alerts came back, Figure I'll just leave it uninstalled until everything is sorted out.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: magna86 on October 31, 2013, 02:26:01 PM
Hi,

Since I see nothing in posted logs (and we have been run&analyzed OTL,Zoek,FRST and ComboFix) and no one sees malware.
This may be avast FP's. Can't tell as you are malware free. I can only run powerfull AntiRootkit diagnosis as this checks works on a system-core level.


If you wish AntiRootkit Check, run Gmer tool:


Please download GMER, AntiRootkit tool from the link below and save it to your Desktop:

Gmer download link (http://www2.gmer.net/download.php)
Note: file will be random named



Double-clicking to run GMER.
> Attach here all Gmer logreports. (Gmer1; Gmer2 and Gmer3)
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on October 31, 2013, 10:24:12 PM
I've run Gmer and the 3 logs are attached, it readily found a number of hidden files with just the opening search.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: magna86 on October 31, 2013, 11:32:10 PM
Hi,

Just to let you know, do not be alarm on Gmer's "RootKit" pop-ups at Gmer primary and 3rd party scan. These flaged drivers...well they belong to avast.
But I want to perform some additional checks + to delete some non-active value key that Gmer pointed out ...
I shall use FRST's Script for that.


1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Code: [Select]
Start
REG: reg delete "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" /v "{23170F69-40C1-278A-1000-000100020000}" /f
File: C:\Windows\system32\conhost.exe
End

2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.



Title: Re: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on November 01, 2013, 11:19:07 AM
Alright, I've run FRST64 and the log is attached.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: magna86 on November 01, 2013, 06:57:01 PM
Hi,
I've seen your PC as malware free. It is time to remove used tools.


It is necessary to uninstall ComboFix :
Code: [Select]
ComboFix /Uninstall Note that there is a space between "  ComboFix  " and "  /Uninstall  " .

Wait for the uninstall process is complete.




------------------------------------------



Please download  DelFix (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix) by "Xplode" to your Desktop.

Run the tool and check the following boxes below;

Now click on "Run" button. Wait for the programme completes his work.
All the tools we used should be gone.
Tool will create and open an log report (DelFix.txt)
Note: The report will also be stored on C:\DelFix.txt


> I don't need DelFix log report.


--------------------------------------


I recommended to use MCShield if you will.
You may download MCShield from one of the following links:

MyCity -  Official download link (http://www.mcshield.net)
Softpedija - Mirror download link (http://www.softpedia.com/get/Antivirus/MCShield.shtml)

It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
And not only will prevent infection, but it will immediately clean flash drive, memory card or external HDD.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on November 02, 2013, 01:05:52 AM
Thanks for your help, Uninstalled Combofix and ran DelFix. When installing chrome again the alerts come back, I'll try using firefox for awhile.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: magna86 on November 02, 2013, 03:20:31 PM
Thanks for your help, Uninstalled Combofix and ran DelFix. When installing chrome again the alerts come back, I'll try using firefox for awhile.

Sorry. I can't fix what I don't see, as I can't find any problem. Try to run these tools aswell.
But know that if these tools find something, theye are only inactive remains ... maybe some of them revolt avast to create pop-ups ...


Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) by Xplode and save to your Desktop.

Double click on AdwCleaner.exe to run the tool.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.

THEN

(http://imageshack.us/a/img841/7292/thisisujrt.gif)  Please download Junkware Removal Tool (http://www.bleepingcomputer.com/download/junkware-removal-tool/) to your desktop.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: Tisoran on November 04, 2013, 11:11:30 AM
Sorry for the late reply, I've run both programs and attached both logs.
Title: Re: Malicious URL Blocking/Detection Alerts
Post by: magna86 on November 04, 2013, 04:58:37 PM
Just as I expected ... they find nothing.

Run AdwCleaner and hit [Uninstall] button. JRT delete manual.