Avast WEBforum

Other => Viruses and worms => Topic started by: REDACTED on July 01, 2015, 06:22:50 AM

Title: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 01, 2015, 06:22:50 AM
URL: http://wpad.browserupdatecheck.in/wpad.dat
Infection: URL:Mal
Process: C:\Program Files\AVAST Software\Avast\avastui.exe

URL: http://wpad.browserupdatecheck.in/wpad.dat
Infection: URL:Mal
Process: C:\Windows\System32\svchost.exe

Apparently this is happening to a lot of people.
I keep getting the popup from Avast! from processes from Chrome to Steam.
No clue what caused it.

Oh, I also ran zoek since every thread I've come across for the same problem here asked for it.
Other logs were made after.
I'll provide it separately since only 4 attachments are allowed per post.

Let me know if I missed anything, thanks in advance.

Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 01, 2015, 06:23:42 AM
zoek
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 01, 2015, 10:35:06 AM
Wait.
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 01, 2015, 10:47:48 AM
Pirate tool named AutoKMS for Microsoft Office has been detected in your system. You are, hereby, given the benefit of doubt and are asked to remove any pirated software located in your system. Future help will be denied if you choose to reiterate.



Code: [Select]
Start
CreateRestorePoint:
CloseProcesses:
EmptyTemp:
Task: {6EBB8686-5E0A-46E1-9358-81305A5712BB} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2015-06-08] ()
Task: {B2A10FB7-1369-40CE-977E-AF6251B739CD} - \avastBCLRestart_chrome.exe No Task File <==== ATTENTION
Task: {DDB32216-C227-4AF6-ACCF-FEFE4F529845} - \NOJDL1 No Task File <==== ATTENTION
Task: C:\Windows\Tasks\NOJDL1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
HKU\S-1-5-21-3439836924-162193635-2986529140-1001\...\MountPoints2: {d67e7345-08c3-11e5-8262-ac9e174dad4f} - "F:\SETUP.EXE"
CHR HKU\S-1-5-21-3439836924-162193635-2986529140-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bghejdcdajlenjngcknlkkoakmmjfanb] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3439836924-162193635-2986529140-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [eeafbffkmccheohnooflcnppngmobeoe] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3439836924-162193635-2986529140-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ellbonkjdmgdghkojcjmomekmjpdffde] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3439836924-162193635-2986529140-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fllgpcmelbfhcligbphaaplminjpbiad] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3439836924-162193635-2986529140-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [jmnkgjdfgnjhmnopgmkcpigenfhgajdj] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3439836924-162193635-2986529140-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kfbhfniohjdklgcmbmemnpaimpdaikea] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3439836924-162193635-2986529140-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [oaobejgaaiojgggjojlcpbembaoajbmc] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bghejdcdajlenjngcknlkkoakmmjfanb] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eeafbffkmccheohnooflcnppngmobeoe] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ellbonkjdmgdghkojcjmomekmjpdffde] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fllgpcmelbfhcligbphaaplminjpbiad] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gihfmmedoddijgnhkgfgnkeohkpbipol] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jmnkgjdfgnjhmnopgmkcpigenfhgajdj] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [kfbhfniohjdklgcmbmemnpaimpdaikea] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [manaobgbdfpjjjnheogfghmjbikhjnlf] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [oaobejgaaiojgggjojlcpbembaoajbmc] - https://clients2.google.com/service/update2/crx
CMD: bitsadmin /reset /allusers
End



Regards,
Valinorum
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 01, 2015, 03:09:08 PM
I ended up running it twice because I forgot to uninstall Office after the first time and then I found that I couldn't uninstall it through the control panel at all.
At first it said that I didn't have permission from Admin and every time after that it has a Setup Error that says "The language of this installation package is not supported by your system"
It tells me that Office is running in another program when I try to delete it manually but doesn't say where and I don't see it on Task Manager.
Here's the second log from FRST, I deleted the first one by accident because I didn't think I'd need it.
PLThanks for response.
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 02, 2015, 09:48:04 AM
Are your facing your initial issue?
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 02, 2015, 02:06:44 PM
Yes, it's appearing less often, but it still happens every time I open Chrome or Steam and in general every few hours or so from svchost.
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 02, 2015, 02:08:15 PM
Please post a fresh FRST scan log for my perusal.
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 02, 2015, 03:22:43 PM
Here you go.
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 02, 2015, 07:34:04 PM
Code: [Select]
Start
CreateRestorePoint:
CloseProcesses:
EmptyTemp:
2015-06-08 07:46 - 2015-06-09 07:46 - 00000000 ____D C:\Windows\AutoKMS
2015-06-02 14:01 - 2015-04-25 05:18 - 00295424 _____ (Groom-A-Zebu (tm) ) C:\Windows\system32\ysxja.exe
015-06-02 14:00 - 2015-05-14 03:03 - 00007680 _____ C:\Windows\cfsvc.exe2015-06-02 14:00 - 2015-04-25 05:18 - 00295424 _____ (Groom-A-Zebu (tm) ) C:\Windows\cygavb.exe2015-06-02 14:00 - 2015-04-25 05:18 - 00053248 _____ C:\Windows\zlib.dll2015-06-02 14:00 - 2013-12-05 07:36 - 00003542 _____ C:\Windows\mstdcvtr.bat2015-06-02 14:00 - 2013-06-05 08:38 - 00004122 _____ C:\Windows\plofgye2015-06-02 14:00 - 2013-06-05 08:37 - 00004194 _____ C:\Windows\soxe2015-06-02 14:00 - 2013-06-05 08:36 - 00000038 _____ C:\Windows\initcvtr.bat
Task: {4CEF2583-DA21-4E22-9A6A-E616D9D3BF0A} - \avastBCLRestart_chrome.exe No Task File <==== ATTENTION
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
CMD: bitsadmin /reset /allusers
End



Regards,
Valinorum
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 02, 2015, 10:46:45 PM
Fixlog.
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 03, 2015, 09:44:35 AM
Use the following script instead of the previous one for fixlist.txt and press "fix'. Tell me if the issue has resolved.
Code: [Select]
CloseProcesses:
2015-06-02 14:00 - 2015-05-14 03:03 - 00007680 _____ C:\Windows\cfsvc.exe
2015-06-02 14:00 - 2015-04-25 05:18 - 00295424 _____ (Groom-A-Zebu (tm) ) C:\Windows\cygavb.exe
2015-06-02 14:00 - 2015-04-25 05:18 - 00053248 _____ C:\Windows\zlib.dll
2015-06-02 14:00 - 2013-12-05 07:36 - 00003542 _____ C:\Windows\mstdcvtr.bat
2015-06-02 14:00 - 2013-06-05 08:38 - 00004122 _____ C:\Windows\plofgye
2015-06-02 14:00 - 2013-06-05 08:37 - 00004194 _____ C:\Windows\soxe
2015-06-02 14:00 - 2013-06-05 08:36 - 00000038 _____ C:\Windows\initcvtr.bat
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
CMD: bitsadmin /reset /allusers
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 03, 2015, 10:02:27 AM
Not resolved.
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 04, 2015, 11:11:25 AM
Hi,

This is a new malware so please be patient. I shall perform two new scans to locate the source--

Code: [Select]
:filefind
*browserupdatecheck*
*wpad*
*wpad.browserupdatecheck.in*

:folderfind
*browserupdatecheck*
*wpad*
*wpad.browserupdatecheck.in*

:Regfind
browserupdatecheck
wpad
wpad.browserupdatecheck.in



Re-run FRST64.exe(or, FRST.exe) and type the following in the Search box.
Code: [Select]
browserupdatecheck;wpad.browserupdatecheck.in;wpad;Click on Search Registry.
After the search, FRST will produce a log called Search.txt. Attach the log in your next reply.



Regards,
Valinorum
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 04, 2015, 04:52:36 PM
No problem, I appreciate the help.
Broken link for SystemLook 64-bit.
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 04, 2015, 04:56:24 PM
Search.txt
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 04, 2015, 06:14:03 PM
Code: [Select]
Start
CreateRestorePoint:
CloseProcesses:
Reg: reg delete "HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad" /f
Reg: reg add "HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad" /f
Reg: reg delete "HKEY_USERS\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad" /f
Reg: reg add "HKEY_USERS\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad" /f
Reboot:
End



Download TCPIP.reg (http://download.bleepingcomputer.com/win-services/7/Tcpip.reg) to your Desktop. Righ-click on it and choose 'Merge'. Click 'OK' to the warning messages. Restart the PC after the merge is complete. Report me the result.



Regards,
Valinorum
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 04, 2015, 08:16:46 PM
Fixlog.
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 05, 2015, 09:47:27 AM
Have you merged the registry file I linked in my previous post and restarted your PC? How is your PC?
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 05, 2015, 07:18:48 PM
Oh, oops didn't see that.
Just did it and the problem appears to be solved, no more warnings from Avast.
Is there anything else I need to do?
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 05, 2015, 08:59:51 PM
Perusing your logs, I see no infection currently present in your system. Unless you are having any issue(s), the machine appears to be Malware-free as we speak.



♣ Removal of Tools and Quarantined Files ♣



Despite the tools we have used are clean, they are powerful removal tools and made in a way so that they carry out any commands given to them without (most cases) asking for a confirmation. In the hands of an inept person, they can make the machine un-bootable -- a scenario we do not wish to see. Also, we need to remove the quarantined files/folders from your system as a dormant malware can be as bad as an active one if given the proper environment. I shall now give you the guidelines to remove the tools and the quarantined files from your system.



♣ Prevention and Future Guidelines ♣



Prevention is better than cure -- goes the old saying. As much as we love to see you visit our site, we do not want to see you having your PC infected by malwares again.

My help is free but if you feel like making my day you may donate any amount you wish by clicking the 'donate' button. I really appreciate your kindness.
(https://www.paypalobjects.com/en_US/i/btn/btn_donate_SM.gif) (https://www.paypal.com/cgi-bin/webscr?cmd=_donations&business=valinorum%40gmail%2ecom&lc=US&item_name=Malware%20Removal%20Assistance&item_number=avast%21&currency_code=USD&bn=PP%2dDonationsBF%3abtn_donateCC_LG%2egif%3aNonHosted)

Regards,
Valinorum
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 06, 2015, 04:51:43 AM
Awesome, thank you so much for fixing my problem.
Have a good one.  :)
Quote
# DelFix v1.010 - Logfile created 05/07/2015 at 22:47:51
# Updated 26/04/2015 by Xplode
# Username : Oli - OLICOMP
# Operating System : Windows 8.1  (64 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\zoek_backup
Deleted : C:\zoek-results.log
Deleted : C:\Users\Oli\Desktop\Addition.txt
Deleted : C:\Users\Oli\Desktop\aswmbr.exe
Deleted : C:\Users\Oli\Desktop\aswMBR.txt
Deleted : C:\Users\Oli\Desktop\Fixlog.txt
Deleted : C:\Users\Oli\Desktop\FRST.txt
Deleted : C:\Users\Oli\Desktop\FRST64.exe
Deleted : C:\Users\Oli\Desktop\MBR.dat
Deleted : C:\Users\Oli\Desktop\Search.txt
Deleted : C:\Users\Oli\Desktop\zoek-results.txt
Deleted : C:\Users\Oli\Desktop\zoek.exe

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #15 [zoek.exe restore point | 07/01/2015 03:38:09]
Deleted : RP #17 [Restore Point Created by FRST | 07/01/2015 12:44:43]
Deleted : RP #18 [Removed Microsoft Office Professional Plus 2013 | 07/01/2015 12:52:02]
Deleted : RP #19 [PROPLUS | 07/01/2015 12:52:40]
Deleted : RP #21 [Restore Point Created by FRST | 07/02/2015 20:41:36]
Deleted : RP #23 [Restore Point Created by FRST | 07/04/2015 18:13:12]
Deleted : RP #25 [Restore Point before Microsoft Office Professional Plus 2013 was removed using Program Install and Uninstall troubleshooter | 07/05/2015 17:15:38]
Deleted : RP #27 [ Microsoft Office Professional Plus 2013  | 07/05/2015 17:23:06]
Deleted : RP #28 [Installed LibreOffice 4.4.4.3 | 07/05/2015 18:16:56]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########
Title: Re: http://wpad.browserupdatecheck.in/wpad.dat
Post by: REDACTED on July 06, 2015, 09:26:06 AM
Surf safely. :)