Avast WEBforum
Other => Viruses and worms => Topic started by: Freespirit on July 05, 2011, 01:45:25 PM
-
URL Blocked
progs used MBAM Combofix
so far unable to resolve
OTL log below
Thank you
Charlie
link to log
http://www.mediafire.com/?2aost5h8z553dc9
-
URLVoid: domain does not excist or is not accesible
-
Hello, I know but when I try to use a search engine it redirects all the time to random sites
Thank you
Charlie
-
You haven't given the full details about the alert, e.g. what process was responsible for the connection attempt which was blocked.
This is the latest analysis tool, so you should use that.
Unfortunately no two attacks are the same so first I will need to see what you have.
Download OTS (http://oldtimer.geekstogo.com/OTS.exe) to your Desktop and double-click on it to run it
- Make sure you close all other programs and don't use the PC while the scan runs.
- Select All Users
- Under additional scans select the following
Reg - Disabled MS Config Items
Reg - Drivers32
Reg - NetSvcs
Reg - SafeBoot Minimal
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check
- Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
volsnap.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%\*. /mp /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
CREATERESTOREPOINT
- Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
- When the scan is complete Notepad will open with the report file loaded in it.
- Please attach the log in your next post.
Note: this says attach the file (to big for copy and paste, use the Additional Options in the Reply window to attach the file.
-
Hello, I did and the log is on my first post via mediafire link
Thank you
Charlie
-
The log you posted on mediafire is an OTL log, not an OTS log as suggested.
Also if the log file is less than 200KB it can be attached to the post, saves people having to connect to an outside source.