Author Topic: Issue with site blocked: hxxp://sso.anbtr.com/domain/wpad.work  (Read 4586 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
I've been getting notifications from Avast about a possible threat:
Object
hxxp://sso.anbtr.com/domain/wpad.work

Infection
URL:Mal

Process
C:\Windows\System32\svchost.exe

It seems to be the same issue as in this thread: https://forum.avast.com/?topic=189484.15

Any help would be greatly appreciated. I'll attach a malwarebytes report file below

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Issue with site blocked: hxxp://sso.anbtr.com/domain/wpad.work
« Reply #1 on: March 16, 2017, 05:30:23 PM »
follow instructions here and attach requested logs  >>  https://forum.avast.com/index.php?topic=194892.0

- Malwarebytes scan log
- Farbar Recovery Scan Tool diagnostic logs


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34060
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: Issue with site blocked: hxxp://sso.anbtr.com/domain/wpad.work
« Reply #3 on: March 16, 2017, 07:53:57 PM »
@Pondus I attached the malwarebytes scan log and FRST logs.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Issue with site blocked: hxxp://sso.anbtr.com/domain/wpad.work
« Reply #4 on: March 16, 2017, 08:00:43 PM »
Malware expert is notified, he will probably not be online before tomorrow



Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Issue with site blocked: hxxp://sso.anbtr.com/domain/wpad.work
« Reply #5 on: March 18, 2017, 08:29:41 AM »

Please run the following search with FRST.
  • Right click on FRST on your desktop and select "Run as Administrator..." When the tool opens click Yes to disclaimer.
  • Type sso.anbtr.com;wpad;SearchList into the Search Box.
  • Press the Search Registry button.
  • It will produce a log called search.txt or SearchReg.txt in the same directory the tool is run from.
  • Please attach the log file back here.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Issue with site blocked: hxxp://sso.anbtr.com/domain/wpad.work
« Reply #6 on: March 27, 2017, 06:06:05 PM »
Hi, dbrisendine, I apologize for the lack of response.

I've attached the search results.

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Issue with site blocked: hxxp://sso.anbtr.com/domain/wpad.work
« Reply #7 on: March 28, 2017, 08:11:25 AM »
Thanks for the SearchReg log.

Fix with Farbar Recovery Scan Tool
This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.

How is your system running now?
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Issue with site blocked: hxxp://sso.anbtr.com/domain/wpad.work
« Reply #8 on: March 28, 2017, 06:37:34 PM »
Attached the log below.

So I hadn't seen the popup for a while after my message from a few weeks ago. I did see it DURING the Farbar fix, but I haven't seen it since, although it's only been an hour or two. I can let you know if I see it again.

REDACTED

  • Guest
Re: Issue with site blocked: hxxp://sso.anbtr.com/domain/wpad.work
« Reply #9 on: March 30, 2017, 05:59:16 PM »
Hey dbrisendine, I just got a notification for this again when logging in today, this time from Malwarebytes.  :-\

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Issue with site blocked: hxxp://sso.anbtr.com/domain/wpad.work
« Reply #10 on: March 30, 2017, 06:34:15 PM »
Hey dbrisendine, I just got a notification for this again when logging in today, this time from Malwarebytes.  :-\
Do you have a malwarebytes log he can see? .... protection log


Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Issue with site blocked: hxxp://sso.anbtr.com/domain/wpad.work
« Reply #11 on: April 01, 2017, 08:31:02 AM »
Let's check to see if the OS file has been modified:


Fix with Farbar Recovery Scan Tool
This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Issue with site blocked: hxxp://sso.anbtr.com/domain/wpad.work
« Reply #12 on: April 03, 2017, 06:28:04 PM »
Okay, I've attached a Malwarebytes log for the protection event, as well as fixlog.txt

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Issue with site blocked: hxxp://sso.anbtr.com/domain/wpad.work
« Reply #13 on: April 06, 2017, 07:13:32 AM »

Please download Farbar Service Scanner to your desktop and double click on the file to run it.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE