Avast WEBforum

Other => Viruses and worms => Topic started by: denebuff on April 08, 2014, 10:13:03 PM

Title: Harmful Webpage
Post by: denebuff on April 08, 2014, 10:13:03 PM
I was hoping someone could give me some help, Im not a computer tec. just a average guy tired of spending money to people that can't fix a problem.
I had my XP desktop worked on because of a virus. 5 days later and $70.00 for the repair now I get a pop up every 3 to 4 minutes  with the attached picture. I called AVAST Tec Surport but they wanted $170.00 to fix problem. I can't do that.
Title: Re: Harmful Webpage
Post by: Secondmineboy on April 08, 2014, 10:21:32 PM
Thats some malware that wants to call home :)

Follow this guide and attach the logs from Malwarebytes, OTL and aswMBR: http://forum.avast.com/index.php?topic=53253.0

Windows XP is not getting anymore Updates and is very insecure now, Hackers collected Security leaks over the last months.
Its recommended to switch to Windows 7 or 8 if possible.
Title: Re: Harmful Webpage
Post by: denebuff on April 08, 2014, 10:29:59 PM
Stven can you please explain what attach the logs from Malwarebytes, OTL and aswMBR: means
Title: Re: Harmful Webpage
Post by: Secondmineboy on April 08, 2014, 10:31:59 PM
Click the Attachments and other options function under the answer Box and select the logs to attach them.
(See screenshot)

Mine is in German but the placement is the same.
Title: Re: Harmful Webpage
Post by: Michael (alan1998) on April 08, 2014, 10:55:58 PM
Just a little more in depth to what Steven said.

When you finish running the programs, they'll produce logs. (MBAM=1, OTL=2 on first run and aswMBR=1). Following Stevens pictures, which is in (Dutch?) I believe. When you make your next post, there is a option called Attachments & Other Options. CLick it

The picture is in german, Michael. :)

Sorry, lol, thought that was dutch.
Title: Re: Harmful Webpage
Post by: Secondmineboy on April 08, 2014, 10:57:48 PM
The picture is in german, Michael. :)
Title: Re: Harmful Webpage
Post by: denebuff on April 08, 2014, 11:08:36 PM
Ok Thank you both, I'm running the scan as we speak, I'll keep you posted. so far it has found 3 objects and still running.
Title: Re: Harmful Webpage
Post by: essexboy on April 08, 2014, 11:14:04 PM
Monitoring, this may be an infected system file
Title: Re: Harmful Webpage
Post by: denebuff on April 08, 2014, 11:25:54 PM
OK it finished put I just got another pop up, also the 3 are quarantined   it did not ask me to do a reboot should I reboot .
Title: Re: Harmful Webpage
Post by: Secondmineboy on April 08, 2014, 11:27:29 PM
If its not asking for a reboot there is no need to reboot.

Save the log and attach it here later. :)
Title: Re: Harmful Webpage
Post by: denebuff on April 08, 2014, 11:58:32 PM
I'm running the OTL but forgot to past this in.
netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
c:\program files (x86)\Google\Desktop
c:\program files\Google\Desktop
dir "%systemdrive%\*" /S /A:L /C
/md5start
rpcss.dll
/md5stop
CREATERESTOREPOINT
Title: Re: Harmful Webpage
Post by: Secondmineboy on April 09, 2014, 12:01:38 AM
Just abort the scan and run it from scratch please.

Be sure to attach the correct log.
Title: Re: Harmful Webpage
Post by: denebuff on April 09, 2014, 12:06:26 AM
OK Will do.
Title: Re: Harmful Webpage
Post by: denebuff on April 09, 2014, 01:28:22 AM
OK Here is the log.


Title: Re: Harmful Webpage
Post by: Secondmineboy on April 09, 2014, 01:37:01 AM
Now please run aswMBR and attach the logs from aswMBR and Malwarebytes. ;)

Then essexboy will check the logs.
Title: Re: Harmful Webpage
Post by: denebuff on April 09, 2014, 02:19:10 AM
Ok Steve
here is what I got.
Title: Re: Harmful Webpage
Post by: denebuff on April 09, 2014, 02:20:58 AM
Ok Steve here is what I got.
Title: Re: Harmful Webpage
Post by: Michael (alan1998) on April 09, 2014, 02:35:04 AM
Essex is asleep. Check back tomorrow...
Title: Re: Harmful Webpage
Post by: denebuff on April 09, 2014, 02:42:29 AM
OK Thank You Will Do.
Title: Re: Harmful Webpage
Post by: essexboy on April 09, 2014, 12:43:02 PM
Hi there, I have two possibilities in mind so lets see which it is

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)
(http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png)

(http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png)

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Title: Re: C:\ComboFix.
Post by: denebuff on April 09, 2014, 10:53:22 PM
As soon as I turned on my AVAST it started again with the Thereat has been detected. :(
I have attached the log from combo fix
Title: Re: Harmful Webpage
Post by: essexboy on April 09, 2014, 10:59:00 PM
Got it, it appears that blackbeard has changed and is now targeting XP
 
1. Close any open browsers.
 
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 
 
3. Open notepad and copy/paste the text in the quotebox below into it:
 
Quote

FCopy::
c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll|c:\windows\system32\rpcss.dll


 
Save this as CFScript.txt, in the same location as ComboFix.exe
 
 
(http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif) 
 
Refering to the picture above, drag CFScript into ComboFix.exe
 
When finished, it will produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Title: Re: Harmful Webpage
Post by: denebuff on April 09, 2014, 11:43:04 PM
OK I did what you asked and attached the New Log. As soon as I got back on the net and turned on my AVAST I got the threat message that "a threat has been detected".  are we getting close :)
Title: Re: Harmful Webpage
Post by: denebuff on April 09, 2014, 11:56:39 PM
Now the threat as a new name. "colombus45 and a few other names I think we have them on the run!
Title: Re: Harmful Webpage
Post by: denebuff on April 10, 2014, 12:01:02 AM
stupid question, but should I be doing a reboot after each run? before I get back on line?
Title: Re: Harmful Webpage
Post by: denebuff on April 10, 2014, 12:05:20 AM
Here is the other name on the warning.
I don't know if this makes a difference or not.
Title: Re: Harmful Webpage
Post by: Secondmineboy on April 10, 2014, 12:07:33 AM
Essexboy is in bed now since its midnight in the UK.

Check back tomorrow. :)
Title: Re: Harmful Webpage
Post by: denebuff on April 10, 2014, 12:13:45 AM
OK Thank You for all your continued support.
I will be back on line after 11:30 am Eastern Standard Time, as I live In PA. USA
Title: Re: Harmful Webpage
Post by: Michael (alan1998) on April 10, 2014, 02:48:43 AM
Ust to explain a little bit... You were infected by the "Blackbeard" Trojan. It has modified svchost or made a new one to contact these domains to further infect your PC. To address your comment "I think we have it on the run", while Essex directly targets the malware,yes we do.

The process responsible is svchost, which most likely they'll be 5+ of them in task manager, so don't try to kill it since it most likely has a restore reg key to relaunch it.
Title: Re: Harmful Webpage
Post by: denebuff on April 10, 2014, 03:47:08 AM
Michael
I can not thank the people of the site for all there help. as of right now AVAST is not giving me the alert Malwarebytes is.
Title: Re: Harmful Webpage
Post by: denebuff on April 10, 2014, 04:09:54 AM
This is what pops up now when I open my email.
See attached.
Title: Re: Harmful Webpage
Post by: denebuff on April 10, 2014, 04:19:18 AM
I forgot to mention my email program I use is outlook express 6.
Title: Re: Harmful Webpage
Post by: essexboy on April 10, 2014, 03:31:25 PM
So the Avast alerts have now ceased ?

Download the latest version of TDSSKiller from here (http://media.kaspersky.com/utilities/VirusUtilities/EN/tdsskiller.exe) and save it to your Desktop.
 
 
(https://dl.dropbox.com/u/73555776/tdss%20report.JPG)
 
Please copy and paste its contents on your next reply.Download the attached Fixlist.txt to the same location as FRST
Run FRST and press Fix
On completion a log will be generated please post that
Title: Re: Harmful Webpage
Post by: denebuff on April 10, 2014, 05:57:11 PM
Here is the results, the program found nothing.
Title: Re: Harmful Webpage
Post by: essexboy on April 10, 2014, 06:55:26 PM
Have the Avast alerts ceased ?

Have you emptied your deleted e-mails folder
Title: Re: Harmful Webpage
Post by: denebuff on April 10, 2014, 11:43:50 PM
having trouble getting on this site. Yes Avast alerts have ceased, and yes I have deleted my delete box and did a reboot, as soon as I open my email program wither I'm on line or not I get a continues pop up from Malwarebytes informing me of the bad file or website. I have attache a copy of the warning as it apears on my screen.
Title: Re: Harmful Webpage
Post by: denebuff on April 10, 2014, 11:59:23 PM
having trouble getting on this site. Yes Avast alerts have ceased, and yes I have deleted my delete box and did a reboot, as soon as I open my email program wither I'm on line or not I get a continues pop up from Malwarebytes informing me of the bad file or website. I have attache a copy of the warning as it apears on my screen.
Title: Re: Harmful Webpage
Post by: essexboy on April 11, 2014, 03:29:48 PM
Do you have any draft e-mails or e-mails in the outbox that you do not recognise
Title: Re: Harmful Webpage
Post by: denebuff on April 11, 2014, 04:37:01 PM
essexboy
I have check my outbox and draft nothing in them at all they are empty. I also deleted any sent and deleted message.
I'm still getting that pop up.
Title: Re: Harmful Webpage
Post by: essexboy on April 11, 2014, 05:05:29 PM
Could you replace Outlook Express with windows live mail http://www.microsoft.com/en-gb/download/details.aspx?id=3945  it will offer several programmes but only accept live mail (OE is so far out of date now)
Title: Re: Harmful Webpage
Post by: denebuff on April 11, 2014, 05:17:05 PM
if I do that will I lose all my contacts and my saved folders, and if not ,I don't think I know how to import that info into the new program. Most of all will that eliminate the bad file?
Title: Re: Harmful Webpage
Post by: essexboy on April 11, 2014, 05:24:30 PM
Follow the instructions here on exporting OE6 and importing to live mail http://www.pcdon.com/080113OutlookExpress-WindowsLiveMail.html
Title: Re: Harmful Webpage
Post by: denebuff on April 11, 2014, 10:58:34 PM
Essexboy
Thank You for all your help with this, as I type this I have installed windows Live and trying to import all my contacts. Is that infected file still in my computer? 
Title: Re: Harmful Webpage
Post by: essexboy on April 11, 2014, 11:42:41 PM
Once you have transfered your contacts over, live mail will then download fresh copies of your e-mails so anything bad will be gone.  It may have been an infection in OE as it is many years out of date.

Once done launch live mail and let me know how that goes

OE can then be disabled by using the control panel Add/remove > remove windows features
Title: Re: Harmful Webpage
Post by: denebuff on April 11, 2014, 11:51:24 PM
Essexboy
I will keep you posted as the weekend gives me more time to spend more time on this project.
Again I sincerity appreciate all you time and help.
Respectfully
Denny G. 
Title: Re: Harmful Webpage
Post by: denebuff on April 12, 2014, 12:37:41 PM
Essexboy
Guess what poped up right after I lodged into Live mail.
Title: Re: Harmful Webpage
Post by: essexboy on April 12, 2014, 03:54:04 PM
What is the ISP that you use for your e-mal ?  e.g. mine is @Hotmail.co.uk
Title: Re: Harmful Webpage
Post by: denebuff on April 12, 2014, 03:56:37 PM
@ptd.net
Title: Re: Harmful Webpage
Post by: essexboy on April 12, 2014, 03:58:33 PM
Hmm that is in the US.   Could you check the accounts that are active in Live mail and ensure that they are ones you know about
Title: Re: Harmful Webpage
Post by: denebuff on April 12, 2014, 04:28:59 PM
Ok
I'm not home but as soon as I return in a couple of hours I will take a look and let you know.
Title: Re: Harmful Webpage
Post by: essexboy on April 12, 2014, 04:42:50 PM
OK, also apart from that how is the computer behaving ? 
Title: Re: Harmful Webpage
Post by: denebuff on April 12, 2014, 05:44:06 PM
Everything seems the same as it was. No big changes I guess that could be a good thing.
Title: Re: Harmful Webpage
Post by: essexboy on April 12, 2014, 06:15:00 PM
So we just need to figure out why MBAM is alerting
Title: Re: Harmful Webpage
Post by: denebuff on April 12, 2014, 06:43:07 PM
essexboy
I just checked the contacts in Windows Live and there are only 2 and I know who they are and there both Gmail accounts, I still have not figured out how to import my email contacts from Outlook 2000 into Windows Live.
Title: Re: Harmful Webpage
Post by: essexboy on April 12, 2014, 07:00:46 PM
From outlook 2000 export the contacts as a windows CSV file, then import that into live mail 
Title: Re: Harmful Webpage
Post by: denebuff on April 12, 2014, 07:33:49 PM
Essexboy
Can you explain with a little more detail? After 60 the mind is the 2ed thing to go!
Title: Re: Harmful Webpage
Post by: denebuff on April 12, 2014, 07:43:23 PM
I was able to import my file folders but can't figure how to get all my email address into WL
Title: Re: Harmful Webpage
Post by: essexboy on April 12, 2014, 08:14:07 PM
Is this OE6 or outlook 2000
Title: Re: Harmful Webpage
Post by: denebuff on April 12, 2014, 08:20:27 PM
Outlook 2000
Title: Re: Harmful Webpage
Post by: essexboy on April 12, 2014, 08:40:12 PM
OK ..  Export the outlook 2000 files to outlook express 6

Open OUTLOOK EXPRESS & import all the messages, contacts & calender entries from Outlook 2000's ".pst" file
Then from Live mail import them all
Title: Re: Harmful Webpage
Post by: denebuff on April 12, 2014, 10:20:51 PM
Essexboy
I know I have outlook express but after I did the windows live thing just outlook showed up, I also knew that was on my PC, but for the life of me I can't find Express. :(
Title: Re: Harmful Webpage
Post by: essexboy on April 12, 2014, 11:35:25 PM
OK after a tortuous search ..  Nice one MS :) I found these instructions to export them http://office.microsoft.com/en-gb/outlook-help/export-contacts-HA101870639.aspx
Title: Re: Harmful Webpage
Post by: denebuff on April 13, 2014, 12:34:48 AM
I got dragged to a BBQ
Will have to pick this up in the AM
Essexboy take the rest of the night off.
Thank you for all your help today.
Title: Re: Harmful Webpage
Post by: denebuff on April 13, 2014, 02:55:34 PM
Essexboy
The directions from MS are for outlook 2010
I have 2000, there is no Options tab under file.
Title: Re: Harmful Webpage
Post by: denebuff on April 13, 2014, 03:13:00 PM
I found Outlook Express 6 and all my email address are in it, how do I get them into Windows Live.
Title: Re: Harmful Webpage
Post by: essexboy on April 13, 2014, 03:19:10 PM
Copy the *ENTIRE* OE message store folder to the desktop. (Folders.dbx must be included).
Open WLMail and: File > Import > Messages > Microsoft Outlook Express 6 and browse to the desktop where you saved it.
Title: Re: Harmful Webpage
Post by: denebuff on April 13, 2014, 04:37:32 PM
I tried doing that but for some reason it will not let me. What am I doing wrong?
I also tried In Outlook Express, click on Addresses>File>Export and follow the prompts, which give options for exporting different types of address books. If uncertain about which type to choose, try a CSV (comma separated values) file. This will create a plain text list with the various items such as Name and Email Address separated by commas. Give the file a name along with a .txt extension. This should make the data easily found and importable into Windows Live Mail Contacts.
But EXPORT is Grayed out.
Title: Re: Harmful Webpage
Post by: essexboy on April 13, 2014, 05:08:22 PM
Within the OE folders should be an address book file with the 3 letter extension .wab have you got that ?
Title: Re: Harmful Webpage
Post by: denebuff on April 13, 2014, 05:17:53 PM
How do I find the 0E folder
Title: Re: Harmful Webpage
Post by: essexboy on April 13, 2014, 05:33:44 PM
They should be in one of these locations, the GUID is a string of numbers  :

C:\Windows\Application Data\Outlook Express\{GUID}
or
C:\Documents and Settings\<User>\Local Settings\Application Data\Identities\{GUID}\Microsoft\Outlook Express

You may need to show hidden files :

1. Click Start, and then click Control Panel.
2.Click Appearance and Themes, and then click Folder Options.
3. On the View tab, under Hidden files and folders, click Show hidden files and folders.
 
Title: Re: Harmful Webpage
Post by: denebuff on April 13, 2014, 06:53:58 PM
is there any way we can do a remote?
Title: Re: Harmful Webpage
Post by: Secondmineboy on April 13, 2014, 07:14:37 PM
You could use Team Viewer: http://www.teamviewer.com/en/

Or via Avast remote assistance.
Title: Re: Harmful Webpage
Post by: essexboy on April 13, 2014, 07:24:26 PM
We need to determine a time when we are both on and can use the Avast remote connection
Title: Re: Harmful Webpage
Post by: denebuff on April 13, 2014, 09:52:34 PM
I have Team Viewer, You let me know whats good for you. I know your 5 hours ahead of me.
Title: Re: Harmful Webpage
Post by: essexboy on April 13, 2014, 10:41:54 PM
Would 8 pm (my time) be good for you that would be 1500 for you

I would like to use Avast as I do not have team viewer

To use Avast

It is Help > Remote assistance
Click Get assistance and a code will be generated
PM me that code
Leave Avast open on the desktop, as the minute you close it the connection becomes invalid.
If you want to break the connection at any time then just close Avast using the X 

(https://dl.dropboxusercontent.com/u/73555776/remote.JPG)
Title: Re: Harmful Webpage
Post by: Secondmineboy on April 13, 2014, 10:49:27 PM
By the way essexboy, TeamViewer is free legit software.
Title: Re: Harmful Webpage
Post by: essexboy on April 13, 2014, 10:53:26 PM
I will bring it down and have a play :)

Title: Re: Harmful Webpage
Post by: denebuff on April 13, 2014, 10:53:41 PM
Thats fine I'll use AVAST, 1500 hours is 3:00PM my time does that mean tomorrow?
Title: Re: Harmful Webpage
Post by: essexboy on April 13, 2014, 10:59:36 PM
We can use team viewer if you have it ..  I have just downloaded it and it looks very straight forward

Yep I will make sure I am available for that time tomorrow :)

Currently reading up on OE as I have not used it for many a year
Title: Re: Harmful Webpage
Post by: denebuff on April 13, 2014, 11:20:56 PM
Ok
1500
Hours. I will pm you at that time and give you the numbers.
I can't thank you  enough for all the time you have spent on this.
 
Title: Re: Harmful Webpage
Post by: essexboy on April 14, 2014, 09:33:59 PM
Are they all in now ?  Sorry about the faffing around but I have my system set to single click ..  I was forgetting to double click :)
Title: Re: Harmful Webpage
Post by: denebuff on April 14, 2014, 11:24:09 PM
Essexboy
Yes everything is in and 100% complete.
After you logged  out I grabbed  the Denny file from Recycle on my USB memory stick and used it in my laptop running 7 and with windows live and that worked. Thank God I was paying attention  to what you did.
Thank You and everyone that helped with this problem, I hope some day I can do the something for someone else. I'm a full time commercial photographer and not much of a computer guy other then the software that I use. If I can be of help when it comes to photography I would be more then happy to help.

Respectful


Title: Re: Harmful Webpage
Post by: essexboy on April 14, 2014, 11:31:12 PM
Glad to help, lets tidy up now and see how it runs

Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Download and run Delfix (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix)

(https://dl.dropboxusercontent.com/u/73555776/delfix.JPG)

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent (http://www.foolishit.com/vb6-projects/cryptoprevent/) install this programme to lock down and prevent crypto ransome ware

(https://dl.dropboxusercontent.com/u/73555776/CryptoPrevent.JPG)

Malwarebytes (http://www.malwarebytes.org/mbam-download.php).

Update and run weekly to keep your system clean


It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read this little guide  Best security practices  (http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/)Keep safe  :wave:
Title: Re: Harmful Webpage
Post by: denebuff on April 15, 2014, 12:23:44 AM
I ran both of the programs, can i use them in myBrides computer she also runs XP and my lap top runs 7?
I have AVAST already, thats how I found you guys!! Thank God.
Title: Re: Harmful Webpage
Post by: essexboy on April 15, 2014, 03:14:37 PM
It depends really what you want to do..  Delfix does the following :

Clears all restore points and creates a new one
Removes all tools I have used for malware cleaning/analysis
Reset system files back to hidden

Cryptoprevent I would recommend for any computer that you have as it blocks currently known Ransom malware

Further programmes that may be useful :

A small tool that may help when you download programmes that may be bundled with adware

http://unchecky.com/

Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder


Right click on the Unchecky_setup(http://i1059.photobucket.com/albums/t432/cinjo23/uncheckysetupicon.png) or folder and choose to Run as Administrator

Once open click the Install button.

(http://i1059.photobucket.com/albums/t432/cinjo23/uncheckysetupwindow.png)

Then click on Finish

(http://i1059.photobucket.com/albums/t432/cinjo23/uncheckyfinishsetupwindow.png)

Unchecky is now installed and will help you keep unwanted check boxes unchecked ;)

General tidying up of junk files

Clear Cache/Temp Files
Download TFC by OldTimer (http://oldtimer.geekstogo.com/TFC.exe) to your desktop
Title: Re: Harmful Webpage
Post by: denebuff on April 15, 2014, 08:49:23 PM
Essexboy
thank you for the software, the only way I can run Uncheckey in the Administrator mode is in Safe mode and Uncheckey will not allow me to run it in Safe Mode. :(
Title: Re: Harmful Webpage
Post by: essexboy on April 15, 2014, 08:52:29 PM
For unchecky it just needs to be installed, after that it works silently in the background.  Only activating itself when it needs to
Title: Re: Harmful Webpage
Post by: denebuff on April 15, 2014, 09:42:28 PM
OK Thanks!!! ;)