Avast WEBforum

Other => Viruses and worms => Topic started by: REDACTED on June 14, 2015, 04:35:43 PM

Title: Outgoing malware attempt
Post by: REDACTED on June 14, 2015, 04:35:43 PM
I've seen this question answered a few times here, but the answers are all system specific, so here it goes again.

I've got a new Lenovo laptop, and must have gotten hit with malware as I was setting it up. On start up or wake up, I get ~16 notifications of avast blocking outgoing attempts to contact sites such as simplesitescan, bestdriverstar, anythichicago, etc.

I've run full antivirus scan with avast and Microsoft's malicious software removal tool and found nothing.

Thanks in advance for the help, I really appreciate it!
Title: Re: Outgoing malware attempt
Post by: Asyn on June 14, 2015, 04:37:04 PM
Attach your basic diagnostic logs. (MBAM, FRST and aswMBR)
Instructions: https://forum.avast.com/index.php?topic=53253.0
Title: Re: Outgoing malware attempt
Post by: REDACTED on June 14, 2015, 08:54:01 PM
Monitoring.
Title: Re: Outgoing malware attempt
Post by: REDACTED on June 14, 2015, 08:58:31 PM
Thanks, the .txt files are attached!
Title: Re: Outgoing malware attempt
Post by: REDACTED on June 15, 2015, 05:54:41 AM
Code: [Select]
Start
CreateRestorePoint:
CloseProcesses:
EmptyTemp:
IE trusted site: HKU\.DEFAULT\...\amazon.com -> amazon.com
SearchScopes: HKLM -> DefaultScope {A0C2CB86-D8F7-4628-BF70-0F77D955ED22} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1094611925-3861376224-1484579070-1001 -> DefaultScope {A0C2CB86-D8F7-4628-BF70-0F77D955ED22} URL =
End
[/list]





Regards,
Valinorum
Title: Re: Outgoing malware attempt
Post by: REDACTED on June 15, 2015, 02:08:41 PM
I ran both fixes, reports are attached. I haven't had any notifications of blocked activity since applying the fixes and rebooting.

Thanks for your help!
Title: Re: Outgoing malware attempt
Post by: REDACTED on June 15, 2015, 02:11:46 PM
Re-run Malwarebytes' Anti-Malware and remove everything it finds.
Title: Re: Outgoing malware attempt
Post by: REDACTED on June 16, 2015, 01:44:01 AM
Malware Bytes found nothing. Hopefully I'm all good, now.

Seems like a lot of the messages on the board are about this malware, it must get boring fixing the same thing over and over!

Thanks for all your help!
Title: Re: Outgoing malware attempt
Post by: REDACTED on June 16, 2015, 09:38:20 AM
Perusing your logs, I see no infection currently present in your system. Unless you are having any issue(s), the machine appears to be Malware-free as we speak.



♣ Removal of Tools and Quarantined Files ♣



Despite the tools we have used are clean, they are powerful removal tools and made in a way so that they carry out any commands given to them without (most cases) asking for a confirmation. In the hands of an inept person, they can make the machine un-bootable -- a scenario we do not wish to see. Also, we need to remove the quarantined files/folders from your system as a dormant malware can be as bad as an active one if given the proper environment. I shall now give you the guidelines to remove the tools and the quarantined files from your system.



♣ Prevention and Future Guidelines ♣



Prevention is better than cure -- goes the old saying. As much as we love to see you visit our site, we do not want to see you having your PC infected by malwares again.

My help is free but if you feel like making my day you may donate any amount you wish by clicking the 'donate' button. I really appreciate your kindness.
(https://www.paypalobjects.com/en_US/i/btn/btn_donate_SM.gif) (https://www.paypal.com/cgi-bin/webscr?cmd=_donations&business=valinorum%40gmail%2ecom&lc=US&item_name=Malware%20Removal%20Assistance&item_number=avast%21&currency_code=USD&bn=PP%2dDonationsBF%3abtn_donateCC_LG%2egif%3aNonHosted)

Regards,
Valinorum
Title: Re: Outgoing malware attempt
Post by: REDACTED on June 16, 2015, 10:09:04 PM
Thanks again, I plan on donating.
Title: Re: Outgoing malware attempt
Post by: REDACTED on June 17, 2015, 07:48:57 AM
You are welcome. Surf safely. :)