Author Topic: HELP URL:MAL infection  (Read 2967 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
HELP URL:MAL infection
« on: February 17, 2015, 01:22:38 AM »
Attached are the logs i ran from the listed programs.

REDACTED

  • Guest
Re: HELP URL:MAL infection
« Reply #1 on: February 17, 2015, 01:27:41 AM »
Here is a pic if it helps. It started out about a week ago and now it just barrages my computer when i am using chrome.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31078
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: HELP URL:MAL infection
« Reply #2 on: February 17, 2015, 01:35:06 AM »
Please provide all requested logs:
https://forum.avast.com/index.php?topic=53253.0

REDACTED

  • Guest
Re: HELP URL:MAL infection
« Reply #3 on: February 17, 2015, 01:38:57 AM »
Sorry for the confusing file name MAL is the malware bytes log file and the second is the FRST 64 log files. Im sorry if this isnt correct, computers are not my thing.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31078
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: HELP URL:MAL infection
« Reply #4 on: February 17, 2015, 02:28:31 AM »
Farbar is producing two logs.
frst.txt and addition.txt

REDACTED

  • Guest
Re: HELP URL:MAL infection
« Reply #5 on: February 17, 2015, 02:46:01 AM »
I pasted the additional one at the bottom of the other.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31078
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: HELP URL:MAL infection
« Reply #6 on: February 17, 2015, 02:52:17 AM »
No, you didn't.

REDACTED

  • Guest
Re: HELP URL:MAL infection
« Reply #7 on: February 17, 2015, 03:07:18 AM »
It is pasted at the bottom of the FRST.txt. When i open it the frst.txt log ends on page 13 and the additional txt starts directly below it.Here is a picture.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31078
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: HELP URL:MAL infection
« Reply #8 on: February 17, 2015, 03:09:50 AM »
Please read and follow the instructions.
each log need to be attached to your post separately.
That means you need to attach 4 separate logs.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: HELP URL:MAL infection
« Reply #9 on: February 17, 2015, 04:27:36 PM »
Hi there, the first thing you must do is uninstall Chrome, you may re-install on completion

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
BHO: No Name -> {bae02736-bc92-4469-951b-02a35585bdd3} ->  No File
BHO: No Name -> {d1ff5c53-afa5-4a79-9dcc-5ba5921a058c} ->  No File
BHO: No Name -> {f544da1c-4744-4c00-b864-f05908c1d690} ->  No File
BHO-x32: No Name -> {bae02736-bc92-4469-951b-02a35585bdd3} ->  No File
BHO-x32: No Name -> {d1ff5c53-afa5-4a79-9dcc-5ba5921a058c} ->  No File
BHO-x32: No Name -> {f544da1c-4744-4c00-b864-f05908c1d690} ->  No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
CHR HomePage: Default -> https://www.google.com/
CHR StartupUrls: Default -> "https://www.google.com/"
CHR Profile: C:\Users\Neal\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Neal\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-02-09]
CHR Extension: (Bookmark Manager) - C:\Users\Neal\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-02-09]
CHR Extension: (Google Wallet) - C:\Users\Neal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-09]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-02-16]
2015-02-01 18:33 - 2015-02-09 09:28 - 00000000 ____D () C:\Program Files (x86)\SaveLLots
2015-02-01 17:33 - 2015-02-01 18:33 - 00000000 ____D () C:\ProgramData\18022051246368858053
2015-01-25 12:07 - 2015-01-25 12:07 - 00000000 ____D () C:\ProgramData\fa1b301fa7b39fc5
2015-01-25 12:06 - 2015-01-25 12:07 - 00000000 ____D () C:\ProgramData\AlLLCCheapPrice
Task: {38E3482B-EC6F-49CE-9EE7-AEB94BD44D46} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-11] (Google Inc.)
Task: {B3758857-9F28-459D-A08B-6787AF65379E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-11] (Google Inc.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Users\Neal\AppData\Local\Google\Chrome
C:\Program Files (x86)\Google\Chrome
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.