Avast WEBforum

Other => Viruses and worms => Topic started by: REDACTED on December 23, 2014, 05:24:50 PM

Title: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 23, 2014, 05:24:50 PM
I have a suspicion that this may have come from a zip file containing mulitple files including a image editor picture that was sent to me to edit for work, but I could be wrong.

Tried multiple tools to clean in safe mode, uninstalled/reinstalled brower (lasted 2 days without a detection), and now it's back again.  Detections on multiple page browsing.

Thank you for the help.


Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 26, 2014, 09:58:46 PM
New logs (since windows updates and add'l scans)

Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: Eddy on December 26, 2014, 10:30:25 PM
For a start, remove Spybot.
It is by far from as good as it once was.
Nowadays we advise to use MBAM.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 27, 2014, 04:20:28 PM
For a start, remove Spybot.
It is by far from as good as it once was.
Nowadays we advise to use MBAM.

TY for the info!  I unistalled Spybot S&D.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 27, 2014, 05:55:40 PM
Hi bb211, :)

My name is Valinorum and I will be the acolyte today. Before we proceed, please, acknowledge yourself the following(s):





Regards,
Valinorum
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 27, 2014, 09:34:27 PM
My system did not auto-reboot after running combofix.  So, I didn't reboot on my own.

As instructed, I've attached the log.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 28, 2014, 04:50:33 AM
Are you still having avast! warnings?
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 28, 2014, 05:09:08 PM
So far, so good.  No detections have appeared yet.  When I did disk clean-ups before, it took about 2 days to start getting detections again.  Is it okay to keep this thread open for a little while?

Thank you!
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 28, 2014, 05:47:46 PM
I spoke to soon.

I got a detection of URL:MAL -

http://69.39.239.161/

C:\Program Files\Internet Explorer|iexplorer.exe

Then another detection of URL:MAL -

Http://48896.bd429d.6715.5da.39.bff7c.f9b....(the rest would allow me copy)

C:\Program Files\Internet Explorer|iexplorer.exe

After this detection, I had multiple .exe's start eating a ton cpu memory.  It was like a memory leak where everything was slowing in speed.  They include, but are not limited to:

dplaysvr.exe
wextract.exe
upnpcont.exe
fixmapi.exe

I closed my programs, disconnected from the net, and shut down.  Upon reboot, the system regained stability for now.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 28, 2014, 06:04:44 PM
Latest detection (which was the most common before)

URL:MAL

http://www.shavethis.com/favicon.ico

C:\ProgramFiles(x86)\MSN\MSNCoreFiles\msn.exe
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 28, 2014, 06:31:12 PM
Post a fresh FRST scan log.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 28, 2014, 07:42:58 PM
Here you go.  Thanks!
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 29, 2014, 05:50:25 AM
Please uninstall Spybot - Search & Destroy for now.




Code: [Select]
Start
CreateRestorePoint:
CloseProcesses:
EmptyTemp:
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-408397430-2629080013-721727374-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
URLSearchHook: HKU\S-1-5-21-408397430-2629080013-721727374-1000 - Default Value = (value not set)
SearchScopes: HKLM-x32 -> {1E43ED7E-11D6-4C6F-B068-949A4DD67685} URL =
SearchScopes: HKLM-x32 -> {39EE7564-711E-45B6-99D0-5609954268A3} URL =
SearchScopes: HKLM-x32 -> {5B377FAC-EC59-417D-929C-10F5404D7823} URL =
SearchScopes: HKLM-x32 -> {68D0842A-2A9A-47DB-B072-F693B1948911} URL =
SearchScopes: HKU\S-1-5-21-408397430-2629080013-721727374-1000 -> {1E43ED7E-11D6-4C6F-B068-949A4DD67685} URL =
SearchScopes: HKU\S-1-5-21-408397430-2629080013-721727374-1000 -> {39EE7564-711E-45B6-99D0-5609954268A3} URL =
SearchScopes: HKU\S-1-5-21-408397430-2629080013-721727374-1000 -> {5B377FAC-EC59-417D-929C-10F5404D7823} URL =
SearchScopes: HKU\S-1-5-21-408397430-2629080013-721727374-1000 -> {68D0842A-2A9A-47DB-B072-F693B1948911} URL =
SearchScopes: HKU\S-1-5-21-408397430-2629080013-721727374-1000 -> {FB962F7A-C3E8-4FDB-B715-52410CBFFD6E} URL = http://www.mypoints.com/emp/u/mysearch.vm?q={searchTerms}&mypoints_brw=1
Toolbar: HKU\S-1-5-21-408397430-2629080013-721727374-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
CMD: ipconfig /flushdns
End





Regards,
Valinorum
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 29, 2014, 06:32:53 AM
Previously, I uninstalled Spybot S&D and found no traces of it in the add/remove programs.  I was just able to delete the shortcut.

Here's the requested logs. Ty!
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 29, 2014, 06:33:57 AM
How is your PC?
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 29, 2014, 06:37:18 AM
It seems stable at the moment.  I haven't had any detections since logging in (almost exactly at the time I first replied (maybe 20 mins. to follow your instructions - I didn't do any browsing).
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 29, 2014, 06:39:47 AM
Continue normal internet works and report myself the result.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 29, 2014, 06:44:33 AM
Okay.  I'll continue my standard behavior and keep you apprised.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 29, 2014, 07:11:47 AM
Continue normal internet works and report myself the result.

Just got a detection

I just began to look at the sites that this pops up on.  I've had it happen on ebay and other innocuous sites.  The most recent was: 

http://propstore.auctionserver.net/view-auctions/catalog/id/10/lot/1315/

 &

http://slickdeals.net/forums/forumdisplay.php?f=9

Here's a pic of one of the pop-ups (will included more as they appear, but this is the most common)

(http://s10.postimg.org/oe9vn6nbt/detection1.jpg) (http://postimage.org/)
 (http://postimage.org/)

I didn't get to capture another detection, but it was this:

http://bns.binachio.org/fsyap.swf [L] SWF:Malware-gen [Trj]
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 29, 2014, 08:15:48 AM
I'm being prompted to do windows updates, but they are only optional i.e. updates for Microsoft Office.  Should I just ignore for now?

Also, I found some old file folders for Spybot S&D.  Should I delete those?
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 29, 2014, 06:45:01 PM
Please allow the updates and report me back.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 29, 2014, 07:22:14 PM
Getting multiple detections from shavethis.com/favicon.ico (as pictured above)

I was browsing ebay and this thread when the most recent detection popped up.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 30, 2014, 01:40:12 PM
Are you using MSN?
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 30, 2014, 04:42:28 PM
Are you using MSN?

Correct.  I use MSN Explorer 11.00.0028.1500

Also, I use Internet Explorer 10

BTW - I get detections that hit msn.exe and iexplorer.exe.  It doesn't seem to matter what browser I'm utilizing at the time.

Thank you!
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on December 31, 2014, 05:45:33 PM


Regards,
Valinorum
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 02, 2015, 05:44:44 PM
Hello,

Per request, attached is the adwcleaner log.

Ty.

P.S. Still having the same favicon detection from general browsing (this site included) after the scan.

Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 03, 2015, 07:31:41 AM
Please provide myself a fresh FRST scan log. Do you take part in online monetizing sites?
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 03, 2015, 06:37:51 PM
Yes, I have taken part in mypoints and inboxdollars for many years.  Those were the toolbars represented in my program list.  However, I haven't downloaded anything new from either of them in a few years.  And, the toolbars existed on my system well before the infection (if this is, indeed, an infection).

Here's the new FRST log.  I only did the scan and didn't "fix".

Ty!
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 04, 2015, 02:35:32 PM
Please re-install your MSN browser and check if you are still getting the warnings.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 05, 2015, 02:03:29 AM
Just did a clean reinstall...will let you know if I get any detections.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 05, 2015, 07:47:43 PM
I got another detection today.

The same favicon detection as before.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 06, 2015, 02:01:32 PM
Are you using automatic synchronization option of the MSN browser?
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 06, 2015, 08:58:40 PM
The only option that I see checked in my browser is "Synchronize before signing out."  It seems to only be for email messages.  Other than that, I can't seem to find an automatic synchronization option.

This is getting frustrating.


Also, I let windows update my Internet Explorer from 10 to 11 (along with the corresponding updates to the browser).

I found these sites re: the shavethis favicon, but didn't know if it was reliable info.

http://windowsproblemshelpcenter.blogspot.com/2015/01/remove-wwwshavethiscomfaviconico-pop-up.html (http://windowsproblemshelpcenter.blogspot.com/2015/01/remove-wwwshavethiscomfaviconico-pop-up.html)

http://computervirusmanualremval.blogspot.com/2015/01/remove-wwwshavethiscomfaviconico-popup.html (http://computervirusmanualremval.blogspot.com/2015/01/remove-wwwshavethiscomfaviconico-popup.html)

P.S. I did try to uninstall and reinstall the MSN browser again.  I got a detection as my email box was loading/repopulating my emails.  I even got a detection when going into my control panel.


Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 08, 2015, 01:58:13 PM
Can you remove the check mark and uninstall the program? Also can you try a different browser to check if the detection comes back?
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 09, 2015, 08:46:26 PM
I will do that and report back to you.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 10, 2015, 11:29:14 PM
Ok...I did this and didn't see any detections through iexplorer.exe with casual browsing. 

Upon a clean reinstall of msn, the detection came back (same as before).
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 11, 2015, 10:04:25 AM
it looks like the infection is related to MSN. Is this your main browser?
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 12, 2015, 09:22:14 PM
Yes. This is my main browser and email interface (multilpe accounts).  Also, this is a paid subscription service from MSN.

Ty
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 23, 2015, 01:02:28 AM
it looks like the infection is related to MSN. Is this your main browser?

Any other ideas?  Got the same detection today when browsing Ebay and this site.

P.S. During this interim, I downloaded CCleaner.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 23, 2015, 05:59:31 AM
Are you connected to the internet via router?
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 23, 2015, 07:16:42 AM
Are you connected to the internet via router?

Yes. I use a Comcast Xfinity router.

I don't have the info on the model# in front of me, but it's the first device on this comcast link.

http://customer.comcast.com/help-and-support/internet/comcast-supported-routers-gateways-adapters/

Fyi - I do use the home wifi network feature, but keep it password protected. Also, I didn't have the device enabled or set-up for wifi until after the detections started.

Ty
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 24, 2015, 10:15:30 AM
Can you reset your router to factory setting?
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 26, 2015, 03:04:00 AM
Can you reset your router to factory setting?

Did this today...will.report back.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 26, 2015, 05:05:13 AM
Okay. :)
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 27, 2015, 01:19:29 AM
Got the same favicon detection again today.

Ty
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 30, 2015, 10:12:37 AM
Since this problem is still persisting for over a month, do you think a reinstallation of the O/S would work? Or, will it not matter due to the msn browser being used (and possibly exploited)?
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 30, 2015, 10:15:09 AM
I'd try a different browser first. If the problem is persistent, we can try a complete re-installation.
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on January 31, 2015, 09:45:25 AM
It seems that I only get the detection when using the msn browser.  I haven't noticed any conflicts with IE.

When I uninstalled the msn browser, I used Revo.  I've read that revo doesn't support 64bit. Is it possible that infected fragments were left behind? If so, should I use advanced uninstaller pro instead and then run any scans afterwards before reinstalling? Also I use Cccleaner, but am tentative about using the registry cleaner option (there are entries listed but I'm not proficient enough to distinguish safe from garbage).

I'm just brainstorming ideas before an O/S reinstall if necessary  I'm concerned that my license key to MS office may not work after reformatting (possibly used too many times on work computers)  Therefore, I would have to purchase a new license. I know that there is an upgrade option with the O/S reinstall that will keep files and programs, but wasn't sure if the infection would remain.  Do you believe that my computer is infected or is it a browser issue and/or otherwise?
Title: Re: URL:MAL Problem - favicon.ico/pop-up - Help Please! (Logs Attached)
Post by: REDACTED on February 01, 2015, 06:46:01 AM
I am inclined to believe it a browser issue. Please, refrain from using any kind of Registry cleaners. They do more harm than good.