Avast WEBforum

Other => Viruses and worms => Topic started by: REDACTED on June 17, 2018, 02:30:48 PM

Title: Avast URL:MAL message every 10 minutes
Post by: REDACTED on June 17, 2018, 02:30:48 PM
I am getting the same message from avast every 10 minutes or so.
Attached you can find said message. Sorry, it's a german PC ;)

Thanks for your help in advance!
Title: Re: Avast URL:MAL message every 10 minutes
Post by: Asyn on June 18, 2018, 05:41:47 AM
Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892
Title: Re: Avast URL:MAL message every 10 minutes
Post by: REDACTED on June 18, 2018, 09:26:50 AM
Here you go. Thank you! :)
Title: Re: Avast URL:MAL message every 10 minutes
Post by: Asyn on June 18, 2018, 09:28:24 AM
OK, now you've to wait for one of the malware experts...
Title: Re: Avast URL:MAL message every 10 minutes
Post by: REDACTED on June 18, 2018, 09:51:34 AM
Alright, thanks again!
Title: Re: Avast URL:MAL message every 10 minutes
Post by: Sass Drake on June 18, 2018, 06:29:36 PM
Code: [Select]
CloseProcesses:
cmd: sc stop BITS
Task: {332B247D-1284-4648-9096-DACE4C681F0D} - System32\Tasks\Windows Cryptography Service => C:\Program Files (x86)\Common Files\Cryptography\Hasher\xmr-stak.exe
Task: {FD024C7F-E7A3-4F02-954B-DF608D80D43E} - System32\Tasks\Windows Cryptography Service Updater => C:\Program Files (x86)\Common Files\Cryptography\Hasher\ConfigUpdate.bat [2018-05-22] () <==== ACHTUNG
C:\Program Files (x86)\Common Files\Cryptography
EmptyTemp:
Title: Re: Avast URL:MAL message every 10 minutes
Post by: REDACTED on June 18, 2018, 08:01:47 PM
There you go :)
Title: Re: Avast URL:MAL message every 10 minutes
Post by: Sass Drake on June 18, 2018, 08:25:22 PM
What is situation now?
Title: Re: Avast URL:MAL message every 10 minutes
Post by: REDACTED on June 18, 2018, 08:32:27 PM
Sadly, i'm still getting the notification every 10 minutes when the pc is turned on.  :P
Title: Re: Avast URL:MAL message every 10 minutes
Post by: Sass Drake on June 18, 2018, 08:43:56 PM
Code: [Select]
sc stop BITS
RemoveDirectory: C:\ProgramData\Microsoft\Network\Downloader
Reboot:
Title: Re: Avast URL:MAL message every 10 minutes
Post by: REDACTED on June 18, 2018, 09:03:13 PM
There you go.
and i am happy to say that i did not get another notification since the last restart! Nice! :D
Does this mean my PC is clean, or should i do some more testing?
Title: Re: Avast URL:MAL message every 10 minutes
Post by: Sass Drake on June 18, 2018, 09:11:46 PM
Report if notification returns.

Rename FRST64 to uninstall and run it. It should uninstall FRST.
Title: Re: Avast URL:MAL message every 10 minutes
Post by: REDACTED on June 18, 2018, 09:17:51 PM
Will do. Thank you so much!
Can you explain in layman's terms what exactly happened?
It seems like it was a Trojan that kept trying to download a payload via a blocked website, am i correct?
Any way i can find out how it got on my PC? And how is it possible that Avast did not notice it in the first place? And why did not even Malwarbytes detect it?
Sorry for the many questions, i am just very interested and confused. :)
Title: Re: Avast URL:MAL message every 10 minutes
Post by: Sass Drake on June 18, 2018, 09:45:09 PM
Trojan that was run on PC created BITS download job and deleted itself. Payload was meant to be downloaded using Windows but it was blocked by Avast.