Avast WEBforum

Other => Viruses and worms => Topic started by: Crying_zombie on September 22, 2011, 03:40:21 PM

Title: Malicious URL keep blocked
Post by: Crying_zombie on September 22, 2011, 03:40:21 PM
please help this thing driving me crazy

here's the report:

Infection Details

URL:   hxtp://ahps.intelbackupsrv.su/sys/afbk1.txt
Process:   file://C:\Users\MYCOMP~1\AppData\Local\Temp\tmp183.exe
Infection:   al
Title: Re: Malicious URL keep blocked
Post by: polonus on September 22, 2011, 03:51:26 PM
Hi Crying_zombie,

Make that link there non-click-through, like with hxtp
This is the malware http://www.xandora.net/xangui/malware/view/5dd929f124001011879be861d98d9232
Wait for essexboy to help you with the cleansing if necessary,

polonus
Title: Re: Malicious URL keep blocked
Post by: Crying_zombie on September 22, 2011, 03:56:08 PM
Oops..sorry 'bout that

Yeah I already open the link that you gave but I still doesn't understand what to do since I'm still a newbie here  :'(

P.S.: I already used TDSSKiller from Kaspersky but it didn't find any infection
Title: Re: Malicious URL keep blocked
Post by: polonus on September 22, 2011, 04:12:22 PM
We still just have to establish if this was succesfully blocked. Just wait for essexboy and everything will be fine,

pol
Title: Re: Malicious URL keep blocked
Post by: Pondus on September 22, 2011, 05:02:50 PM
follow this guide here and attach the logs, then essexboy will have a look when he arrive here. Usually around 08:00pm - 11:59pm UK time

http://forum.avast.com/index.php?topic=53253.0



lower left corner > additional options > attach
if logs are to big, upload to http://www.mediafire.com/  and post download link here
Title: Re: Malicious URL keep blocked
Post by: Crying_zombie on September 22, 2011, 07:59:16 PM
well I already have the logs for OTL but after i saved it it disappear,any suggestions?

fortunately for aswMBR it didn't make any problems..here you go:
Title: Re: Malicious URL keep blocked
Post by: Pondus on September 22, 2011, 08:29:58 PM
Quote
well I already have the logs for OTL but after i saved it it disappear,any suggestions?
the logs are saved in the same location as the OTL program..........and OTL is recomended to be saved and run from desktop
Title: Re: Malicious URL keep blocked
Post by: Crying_zombie on September 22, 2011, 09:22:05 PM
Quote
well I already have the logs for OTL but after i saved it it disappear,any suggestions?
the logs are saved in the same location as the OTL program..........and OTL is recomended to be saved and run from desktop
yes I did all of those procedures so it should be in the desktop,right? still can't find it anyway  :(
Title: Re: Malicious URL keep blocked
Post by: essexboy on September 22, 2011, 09:29:00 PM
Could you re-run please and do not allow Avast to sandbox it
Title: Re: Malicious URL keep blocked
Post by: Crying_zombie on September 22, 2011, 10:44:31 PM
ah yes i forgot about this sandbox stuff,so here are the OTL logs:
Title: Re: Malicious URL keep blocked
Post by: essexboy on September 22, 2011, 11:02:37 PM
On completion could you let me know if the alerts cease

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Run OTL
Title: Re: Malicious URL keep blocked
Post by: Crying_zombie on September 23, 2011, 06:44:16 AM
Sry I just woke up,yeah now it stopped popping..but do I still need to do the procedures above?  ???
Title: Re: Malicious URL keep blocked
Post by: DavidR on September 23, 2011, 03:17:07 PM
Essexboy won't be back on the forums until later today around 7pm (now 2:15pm).

But yes, I would say that you should run this fix as it has been specifically crafter for your system.

Then run OTL again and attach the new log, so he has something to work with when he gets on-line after work. Then he can confirm that the system is clean also.
Title: Re: Malicious URL keep blocked
Post by: Crying_zombie on September 25, 2011, 06:41:33 AM
Sorry I went out of town in the last 2days and I just come back now,yeah I've done it and these are the logs:

Title: Re: Malicious URL keep blocked
Post by: essexboy on September 25, 2011, 12:50:57 PM
What are your current problems ?
Title: Re: Malicious URL keep blocked
Post by: Crying_zombie on September 26, 2011, 02:37:52 PM
no more problems with the pop-out message but somehow my system is getting slower..thanks for you help anyway,guys!!
Title: Re: Malicious URL keep blocked
Post by: essexboy on September 26, 2011, 02:40:20 PM
Lets remove the tools and give a quick tidy up

Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Run OTLRun OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself. 

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
(http://users.telenet.be/bluepatchy/miekiemoes/images/javaicon.gif)
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.

 Upgrading Java:
SPRING CLEAN

To manually create a new Restore Point
 Now we can purge the infected ones
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
(http://img233.imageshack.us/img233/7729/mbamicontw5.gif)
Malwarebytes (http://www.malwarebytes.org/mbam-download.php).  Update and run weekly to keep your system clean

Download and install FileHippo update checker (http://www.filehippo.com/updatechecker/) and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit
To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ? (http://www.geekstogo.com/forum/topic/225044-preventing-malware-and-safe-computing/)

Keep safe  :wave:
Title: Re: Malicious URL keep blocked
Post by: Crying_zombie on September 28, 2011, 04:27:32 PM
done it all thanks  :)