Avast WEBforum

Other => Viruses and worms => Topic started by: gleits on May 02, 2014, 10:33:30 PM

Title: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 02, 2014, 10:33:30 PM
Since yesterday even when nothing is running on my computer I've occasionally had a pop up from Avast! that it has blocked a malicious website. Clicking on the most recent message it gives me the following message in the browser:

URL:   h_go_wvydeo_com__resultsa__?x
Infection:   URL:Mal

Not sure what info is needed, but this Win7 Home, a full scan of Avast! 2014.9.0.2018 found nothing, Malwarebytes 2.0.1.1004 database 2014.05.02.11 found nothing of significance either. I'm not sure where to find any logs within Avast!

Thanks for any help.   
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Asyn on May 02, 2014, 10:34:56 PM
Attach your logs. (MBAM, OTL and aswMBR..!!)
Instructions: http://forum.avast.com/index.php?topic=53253.0
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 02, 2014, 10:45:18 PM
Monitoring.
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 03, 2014, 02:52:20 AM
Here's the results of the scans.

(http://i57.tinypic.com/dxqh4.png)
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 03, 2014, 07:06:54 AM
Hi gleits, :)

Code: [Select]
:Commands
[createrestorepoint]

:OTL
[2014/05/02 11:50:15 | 000,000,000 | --S- | C] () -- C:\Windows\system32\xczb.msh
[2014/05/01 15:25:45 | 000,000,069 | ---- | C] () -- C:\Windows\system32\bzzeum.hjq
[2014/05/01 15:16:02 | 000,000,028 | ---- | C] () -- C:\Windows\SysWow64\u
[2014/05/01 15:15:21 | 000,000,064 | ---- | C] () -- C:\Windows\system32\iktyw.ikn
[2014/05/01 15:15:21 | 000,000,000 | ---- | C] () -- C:\Windows\system32\jbfr.xlp
[2014/05/01 14:59:20 | 000,239,175 | --S- | C] () -- C:\Windows\system32\vrtsp.udl

:Commands
[emptytemp]









Regards,
Valinorum
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 03, 2014, 02:47:29 PM
    Required Log(s):
        OTL Fix Log;
        RogueKiller Report;
        ComboFix Log;
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 03, 2014, 02:48:57 PM
    Required Log(s):
        Farbar Recovery Scan Tool Log(s) -
            FRST.txt
            Addition.txt
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 03, 2014, 03:03:48 PM
Hi gleits, :)

Code: [Select]
File::
C:\Windows\system32\xczb.msh
C:\Windows\system32\bzzeum.hjq
C:\Windows\system32\iktyw.ikn
C:\Windows\system32\jbfr.xlp
C:\Windows\system32\vrtsp.udl

FCopy::
c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7601.17514_none_c7f0e16b547f887d\rpcss.dll | c:\windows\system32\rpcss.dll



Re-do Step 5.



Regards,
Valinorum
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 03, 2014, 03:47:05 PM
  • ComboFix will now scan your system for malwares and will attempt to remove them.
  • Note: ComboFix performs fifty steps during this fix. Please be patient.
  • After the scan your system will reboot and a log will be produced. The log is automatically saved in C:\ComboFix.txt.
  • ComboFix will now run a scan on your system. After the scan finishes, it will execute the script and reboot your computer automatically. Don't reboot your computer manually, let ComboFix do it. Once your computer is rebooted, ComboFix will start preparing a log. Please let it do so unhindered. After a few minutes, it shall produce a log for you.
I believe I followed your instructions exactly, but neither time did the computer reboot. The log file was generated after the program was finished with no reboot.

Anyway, see attached.
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 03, 2014, 05:44:52 PM
Hi gleits, :)

Tell me how the system is running after applying the fix.



Code: [Select]
Start
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} -  No File
2014-05-03 07:48 - 2014-05-03 07:48 - 00000028 _____ () C:\Windows\SysWOW64\u
2014-05-02 11:50 - 2014-05-02 11:50 - 00000000 ____S () C:\Windows\system32\xczb.msh
2014-05-01 15:25 - 2014-05-03 08:50 - 00000069 _____ () C:\Windows\system32\bzzeum.hjq
2014-05-01 15:15 - 2014-05-01 15:15 - 00000064 _____ () C:\Windows\system32\iktyw.ikn
2014-05-01 15:15 - 2014-05-01 15:15 - 00000000 _____ () C:\Windows\system32\jbfr.xlp
2014-05-01 14:59 - 2014-05-01 14:59 - 00239175 ____S () C:\Windows\system32\vrtsp.udl
End



Regards,
Valinorum
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 03, 2014, 06:30:14 PM
System seems fine, barring one freeze, with no programs having been opened by me, save Firefox to get to this site. I've been having this issue randomly for a couple of months though. :(

    Required Log(s):
        FRST Fix Log
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 03, 2014, 06:35:29 PM
I require the FRST Fix Log. It is located in the same folder of FRST.exe and which program is freezing?
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 03, 2014, 06:44:05 PM
Oops, sorry.

It's not any specific program, it's the entire system. Nothing responds, I can't ctrl+alt+del. 
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 03, 2014, 06:47:54 PM
Isn't there any file named Fixlog.txt on your Desktop? Attach it please. Since when the freezing started?
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 03, 2014, 07:04:32 PM
The computer has been having the occasional freezes for a couple of months now.
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 03, 2014, 07:10:19 PM
Hi gleits, :)

Finally we removed the main culprit.





Regards,
Valinorum
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 03, 2014, 08:57:35 PM
    Required Log(s):
        AdwCleaner Log
        Junkware Removal Tool Log
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 03, 2014, 09:15:43 PM
How is your system running?
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 03, 2014, 09:28:02 PM
Very good! Thank you for all your help. :)
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 03, 2014, 09:40:43 PM
Hi gleits, :)





Regards,
Valinorum
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 04, 2014, 05:52:46 PM
The last I saw ESET Online Scanner was at 80 something percent... I'm not sure it finished totally but no one was anywhere around the computer to move the mouse so I'm a little confused about that.
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 04, 2014, 06:33:26 PM
Hi gleits, :)

Rest Google Chrome by perusing this (https://support.google.com/chrome/answer/3296214?hl=en).



Code: [Select]
Start
C:\Users\Julie\Downloads\ccsetup413.exe
C:\Users\Julie\Downloads\FileZilla_3.8.0_win32-setup.exe
H:\Backup\AppData\Local\CRE\jiolcnbhkfmdecgpaacbpnalfeaechdi.crx
H:\Backup\AppData\Local\Microsoft\Windows\Temporary Internet Files\
H:\Backup\AppData\Roaming\Mozilla\Firefox\Profiles\rvg0be6f.default\extensions\plugin@yontoo.com
H:\Backup\Downloads\Brothersoft_downloader_For_GrabURL.exe
H:\Backup\Downloads\ccsetup321.exe
H:\Backup\Downloads\cnet2_Mipony-Installer_exe.exe
H:\Backup\Downloads\Mipony-Installer.exe
H:\Backup\Temp\dta\ebook\ringtones\ccsetup319.exe
H:\Backup\Temp\
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-06-23 190006\Backup files 92.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-06-23 190006\Backup files 93.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-07-28 202714\Backup files 1.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-09-01 190030\Backup files 2.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-09-01 190030\Backup files 3.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-09-01 190030\Backup files 5.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-09-10 142406\Backup files 1.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-09-10 142406\Backup files 3.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-09-15 190008\Backup files 7.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-09-29 190023\Backup files 5.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-10-20 190104\Backup files 1.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-10-27 190011\Backup files 5.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-11-03 190004\Backup files 3.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-11-03 190004\Backup files 4.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-11-17 190002\Backup files 5.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-11-24 190005\Backup files 3.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-12-15 190002\Backup files 5.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2013-12-29 190119\Backup files 3.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2014-01-12 190002\Backup files 4.zip
H:\JULIE-PC\Backup Set 2013-06-23 190006\Backup Files 2014-01-26 190004\Backup files 4.zip
H:\JULIE-PC\Backup Set 2014-02-02 190004\Backup Files 2014-02-02 190004\Backup files 93.zip
H:\JULIE-PC\Backup Set 2014-02-02 190004\Backup Files 2014-02-02 190004\Backup files 95.zip
H:\JULIE-PC\Backup Set 2014-02-02 190004\Backup Files 2014-02-02 190004\Backup files 97.zip
H:\JULIE-PC\Backup Set 2014-02-02 190004\Backup Files 2014-02-02 190004\Backup files 98.zip
H:\JULIE-PC\Backup Set 2014-02-02 190004\Backup Files 2014-02-09 190006\Backup files 3.zip
H:\JULIE-PC\Backup Set 2014-02-02 190004\Backup Files 2014-02-09 190006\Backup files 5.zip
H:\JULIE-PC\Backup Set 2014-02-02 190004\Backup Files 2014-02-23 190003\Backup files 3.zip
H:\JULIE-PC\Backup Set 2014-02-02 190004\Backup Files 2014-03-02 190004\Backup files 5.zip
H:\Julie_Backup\2011-07-06_19-37-31\Memeo\2011-07-06_19-37-31\C_\download\aim553599.exe
H:\Julie_Backup\2011-07-06_19-37-31\Memeo\2011-07-06_19-37-31\C_\download\download\
H:\Julie_Backup\2011-07-06_19-37-31\Memeo\2011-07-06_19-37-31\C_\temp\
H:\Julie_Backup\2011-07-06_19-37-31\Memeo\2011-07-06_19-37-31\C_\Users\Julie\Downloads\ccsetup315.exe
H:\Julie_Backup\2011-07-06_19-37-31\Memeo\2011-07-06_19-37-31\C_\Users\Julie\Downloads\FLVPlayerSetup.exe
H:\Julie_Backup\2011-07-06_19-37-31\Memeo\2011-07-06_19-37-31\C_\Users\Julie\Downloads\Mipony-Installer.exe
H:\Julie_Backup\2011-07-06_19-37-31\Memeo\2011-07-06_19-37-31\C_\Users\Julie\Downloads\wrar_4.rar
H:\Julie_Backup\2012-08-02_13-02-19\Memeo\2012-08-02_13-02-19\C_\download\aim553599.exe
H:\Julie_Backup\2012-08-02_13-02-19\Memeo\2012-08-02_13-02-19\C_\download\download\aim553599.exe
H:\Julie_Backup\2012-08-02_13-02-19\Memeo\2012-08-02_13-02-19\C_\temp\dta\ebook\ringtones\ccsetup319.exe
End



How is your PC running?



Regards,
Valinorum
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 04, 2014, 08:30:53 PM
The FRST Fix Log is too large to post as an attachment and any compressed format is not allowed to upload. How should I send the file?
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 04, 2014, 09:01:43 PM
Post it in Private Paste with one month expiry.
http://privatepaste.com/
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 04, 2014, 09:06:28 PM
It's still too big. The file is 1875 kb.  ???
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Secondmineboy on May 04, 2014, 09:07:32 PM
Can you upload it to wikisend.com and provide the link?

Max. size is 100 MB there. Default lifetime is 7 days, can be changed in properties.
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 04, 2014, 09:10:59 PM
Thank you, Steven.  :)
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 04, 2014, 09:12:00 PM
Part 1
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 04, 2014, 09:12:31 PM
Part 2
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 04, 2014, 09:14:21 PM
How is your system running?
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Secondmineboy on May 04, 2014, 09:15:21 PM
Thank you, Steven.  :)

No problem :)
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 04, 2014, 09:17:22 PM
Ignore my two previous posts.

Here's the file:
Fixlog.txt (http://wikisend.com/download/494958/Fixlog.txt)

Apologies, those older back ups should have been deleted.

Computer is running fine.
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 04, 2014, 09:21:27 PM
Perusing your logs, I see no infection currently present in your system. Unless you are having any issue(s), the machine appears to be Malware-free as we speak.



♣ Removal of Tools and Quarantined Files ♣



Despite the tools we have used are clean, they are powerful removal tools and made in a way so that they carry out any commands given to them without (most cases) asking for a confirmation. In the hands of an inept person, they can make the machine un-bootable -- a scenario we do not wish to see. Also, we need to remove the quarantined files/folders from your system as a dormant malware can be as bad as an active one if given the proper environment. I shall now give you the guidelines to remove the tools and the quarantined files from your system.

It is time to uninstall Combofix. Please follow the instructions:
ComboFix will now uninstall itself from your computer and remove any backups and quarantined files. When it has finished you will be greeted by a dialog box stating that ComboFix has been uninstalled. You can now delete the ComboFix.exe program from your computer. ComboFix has now been uninstalled from your Windows Vista or Windows 7 computer.



♣ Prevention and Future Guidelines ♣



Prevention is better than cure -- goes the old saying. As much as we love to see you visit our site, we do not want to see you having your PC infected by malwares again.

Regards,
Valinorum
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: gleits on May 04, 2014, 09:37:43 PM
Thank you for all your help!

# DelFix v10.7 - Logfile created 04/05/2014 at 15:33:35
# Updated 27/04/2014 by Xplode
# Username : Julie - JULIE-PC
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\_OTL
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\Julie\Desktop\RK_Quarantine
Deleted : C:\ComboFix.txt
Deleted : C:\Users\Julie\Desktop\Addition.txt
Deleted : C:\Users\Julie\Desktop\AdwCleaner.exe
Deleted : C:\Users\Julie\Desktop\AdwCleaner[S0].txt
Deleted : C:\Users\Julie\Desktop\aswMBR.txt
Deleted : C:\Users\Julie\Desktop\esetsmartinstaller_enu.exe
Deleted : C:\Users\Julie\Desktop\Extras.Txt
Deleted : C:\Users\Julie\Desktop\Fixlog.rar
Deleted : C:\Users\Julie\Desktop\Fixlog.txt
Deleted : C:\Users\Julie\Desktop\fixlog1.txt
Deleted : C:\Users\Julie\Desktop\fixlog2.txt
Deleted : C:\Users\Julie\Desktop\fixlog3.txt
Deleted : C:\Users\Julie\Desktop\fixlog4.txt
Deleted : C:\Users\Julie\Desktop\FRST.txt
Deleted : C:\Users\Julie\Desktop\FRST64.exe
Deleted : C:\Users\Julie\Desktop\JRT.exe
Deleted : C:\Users\Julie\Desktop\JRT.txt
Deleted : C:\Users\Julie\Desktop\MBR.dat
Deleted : C:\Users\Julie\Desktop\OTL.Txt
Deleted : C:\Users\Julie\Desktop\OTL05032014_073627.txt
Deleted : C:\Users\Julie\Desktop\RKreport[0]_S_05032014_075711.txt
Deleted : C:\Users\Julie\Desktop\RogueKillerX64.exe
Deleted : C:\Users\Julie\Desktop\Shortcut.txt
Deleted : C:\Users\Julie\Downloads\aswmbr.exe
Deleted : C:\Users\Julie\Downloads\OTL.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #30 [ComboFix created restore point | 05/04/2014 19:31:28]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########
Title: Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
Post by: Valinorum on May 04, 2014, 09:38:41 PM
Surf safely. :)