Avast WEBforum

Other => Viruses and worms => Topic started by: Wayno11 on June 08, 2012, 03:32:21 AM

Title: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 08, 2012, 03:32:21 AM
I recently reinstalled Avast after a failed experiment with McAfee.  Now Avast has found a problem with SHCHost.exe that is causing the Malicious URL popup to come up constantly.  I have attached the rquired files.  I apologize ahead of time for doing attachemtns, but my files went over the 10000 character limit, even if I try to break it down in to seperate posts.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Pondus on June 08, 2012, 07:31:13 AM
Quote
I apologize ahead of time for doing attachemtns,
that is what you are suppose to do.....attach

also attach a malwarebytes quick scan log......make sure MBAM is updated beforew you scan
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: wmcgee on June 08, 2012, 01:25:50 PM
I have the same malware on my computer an can not get rid of it? I did not see a fix on this post?
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Asyn on June 08, 2012, 01:27:35 PM
I have the same malware on my computer an can not get rid of it? I did not see a fix on this post?

Start a new topic and attach your logs.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 08, 2012, 03:05:38 PM
@ Wayno11 you have a failed zero access installation on the system so lets kill it


Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run
To disable MBAM
Open the scanner and select the protection tab
Remove the tick from "Start with Windows"
Reboot and then run OTL
(http://i1224.photobucket.com/albums/ee362/Essexboy3/mbamstop.jpg)

Run OTL
THEN

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)
(http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png)

(http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png)

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 08, 2012, 04:29:30 PM
Ok here is the most recent scan, with the most recent updates, from Malwarebytes.  Thank you
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 08, 2012, 05:35:53 PM
essexboy,

I did everything you suggested, and I am attaching the newest otl scan.  However, Combofix needed to download Recovery, and it is stuck at 22.7% download.  You said not to rerun it without reposting, so I am doing so.  Thanks
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 08, 2012, 06:53:19 PM
OK lets try the manual installation, if this should fail then run combofix without the recovery console

Go to Microsoft's website => http://support.microsoft.com/kb/310994 (http://support.microsoft.com/kb/310994)
 
Scroll down to Step 1, and select the download that's appropriate for your Operating System. Download the file & save it as it's originally named.
 
Note: If you have SP3, use the SP2 package.
 
 
---------------------------------------------------------------------
 
 
 
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
 
(http://img.photobucket.com/albums/v666/sUBs/RC1-4.gif)
 
 
(http://img.photobucket.com/albums/v706/ried7/whatnext.png)
 
 
 
Please post the C:\ComboFix.txt in your next reply.

Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 09, 2012, 05:23:11 AM
Ok got it to work.  Here is the combofix.txt file.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 09, 2012, 02:04:14 PM
That killed it  ;D

How is the computer behaving now ?
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 09, 2012, 02:40:56 PM
Still getting the pop up I'm afraid, although about half as frequently.  And my web browser is not 100% right.  I seem to be missing a lot of icons and tabs on my web pages, especially games on Facebook.  One game I can not even play.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 09, 2012, 02:51:20 PM
Could you delete your current copy of OTL please and download a fresh copy

Also could you post a screenshot of the popup

Download OTL (http://oldtimer.geekstogo.com/OTL.exe)  to your Desktop
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
services.exe
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
CREATERESTOREPOINT

Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 09, 2012, 03:38:59 PM
Ok.  I downloaded OTL again and here is the new log.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 09, 2012, 03:44:11 PM
After the reboot from this fix could you check for alerts please

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run
To disable MBAM
Open the scanner and select the protection tab
Remove the tick from "Start with Windows"
Reboot and then run OTL
(http://i1224.photobucket.com/albums/ee362/Essexboy3/mbamstop.jpg)

Run OTL
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 10, 2012, 04:57:28 AM
Ok, I have attached two files.  One is the file created after running RUN FIX and rebooting.  The other is the OTL log after running QUICK SCAN.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 10, 2012, 01:58:17 PM
That looks good, any remaining problems ?
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 10, 2012, 03:09:47 PM
Oh yes.  Still have the pop up, and IE has "red X's" all over the place.  And I can't play games on Facebook.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 10, 2012, 03:56:19 PM
Could you attach a screenshot of the popup please

Download the latest version of TDSSKiller from here (http://support.kaspersky.com/downloads/utils/tdsskiller.exe) and save it to your Desktop.
 
 
(http://dl.dropbox.com/u/73555776/TDSSEnd.JPG)
 
Please copy and paste its contents on your next reply.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 10, 2012, 06:51:38 PM
.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 10, 2012, 07:05:57 PM
Here are the two screen shots.  One is the pop up, the other is the TDSS report.  The pop up seems to have gone away since running TDSS, but I still have red X's and can't play games.  I have updated both Shockwave and Flash player but they did not help.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 10, 2012, 09:04:33 PM
Could you run TDSSKiller again please and attach the report
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 10, 2012, 10:37:52 PM
For some reason I can not copy/paste the report that is generated by TDSSKiller.  In fact, right clicking the mouse gives me no pop up box to work with.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 10, 2012, 11:11:13 PM
Could you just attach the log please
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 11, 2012, 12:06:04 AM
That's what I'm saying, I can't copy and save it to Notepad.  I can hi light the log, but when I right-click my mouse I get no pop up block to work with.  Does the file save some where on my PC?  In a file somewhere?
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: DonZ63 on June 11, 2012, 12:28:46 AM
TDSSKiller logs should be in your root directory i.e. C:\
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 11, 2012, 02:37:45 AM
Ahh thank you very much.  Here you go.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 11, 2012, 03:47:09 PM
Rerun TDSSKiller with the same parameters and when you get the following select delete :

\Device\Harddisk0\DR0 ( TDSS File System )

Once done we will look at the remaining problems
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 11, 2012, 04:06:58 PM
Ok Done  here is the new report if you need it.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 11, 2012, 04:13:02 PM
Ok list the remaining problems to be resolved  ;D
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 11, 2012, 04:51:21 PM
The only remaining problem is the internet.  I still have red X's and can not play games on Facebook, which I assume are related.  It happened after running one of the programs during this fix, but I do not recall which one.  It was near the beginning of the fix, possibly after running OTL for the first or second time.  I have reinstalled Shockwave and Flash Player, but this did not help.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 11, 2012, 05:20:24 PM
OK for flash ..  We will do a full uninstal and then reinstal

Download and run the uninstaller from here http://helpx.adobe.com/flash-player/kb/uninstall-flash-player-windows.html
Then download the latest version from here http://get.adobe.com/flashplayer/

Uninstall Shockwave Player 10 via the Control Panel.
Go to Add/Remove programs, and choose Macromedia or Adobe Shockwave Player.
Download the latest version from here http://www.adobe.com/products/shockwaveplayer/

Now let me know if the problem is cured
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 11, 2012, 07:21:48 PM
Well I tried a couple of things and still no luck.  First I unistalled both and then reinstalled, without a reboot.  The I rebooted after uninstalling, and reinstalling.  I also added a macromedia from Adobe that appeared to not be working on my system.  None of this helped.  I still have red X's and no games playable.  I also unistalled Java and reinstalled a newer version.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 11, 2012, 08:28:25 PM
Is this in IE ?

If so go to control panel > Internet Options
Go to the Advanced tab
Click reset to default

Reboot the computer and try again
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 11, 2012, 09:46:40 PM
Yes it is IE.  I did as suggested, but still no changes.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 11, 2012, 10:21:01 PM
Looks like I may need to do a bit of research on this one, bear with me
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 12, 2012, 01:25:10 AM
Ok thank you.  I have done a bit of research on the net about this, and read quite a few times that this may be virus/malware related.  When I ran TDSSKiller, there were about 14 errors found, and we repaired one of them.  Could this issue be related to one of the other errors found?  Should I delete those other errors?
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 12, 2012, 05:18:22 AM
I did some research on my own, and found that uninstalling IE8 and reinstalling it was a potential fix.  I did this and everything seems to be working fine now.  The pop up is gone, the red X's are gone, and my games work.  THANK YOU SO MUCH FOR YOUR HELP!!!!!! 
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 12, 2012, 03:44:29 PM
OK you beat me to that one,  ;D  The other files noted by TDSSKiller are not a threat.  It sounds as though there may have been a corruption within IE

Any further problems ?
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: Wayno11 on June 13, 2012, 09:34:51 PM
Nothing so far, after a couple of days of being fixed.  Your thoughts on IE being corrupted makes sense as my web browsing has acted up recently.  It was slow and had other various issues from time to time.  Thank you again for your help.  I'm pretty computer savy, and I was lost as to what to do to fix this.
Title: Re: SVCHOSt causes Mailicious URL popup
Post by: essexboy on June 13, 2012, 10:14:09 PM
No problem, a fresh set of eyes can help to see the wood for the trees  ;D