Author Topic: Skegnassasc Pop-up/Malware (?)  (Read 2282 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Skegnassasc Pop-up/Malware (?)
« on: September 16, 2014, 04:12:38 AM »
I've been getting the lovely bouncing alert from Avast for a few days now and whenever I click it this is what the webpage shows:

Infection blocked
URL   hxxp://skegnessasc.org/accounts/restorefunction.css
Infection   URL:Mal

Logs are attached of what I could get; aswMBR didn't seem to work for me.  Any ideas/help would be amazing, thanks!

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Skegnassasc Pop-up/Malware (?)
« Reply #1 on: September 16, 2014, 10:06:20 AM »
Hello,




1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Code: [Select]
CloseProcesses:
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
BHO: No Name -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} ->  No File
Hosts:
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
EmptyTemp:
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS

2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.




.




Please download AdwCleaner by Xplode and save to your Desktop.

Double click on AdwCleaner.exe to run the tool.
  • Click on the Scan button.
  • After the scan has finished click on the Clean button.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.

  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Post logfile will also be saved in the C:\AdwCleaner folder.
.



Then reset Google Chrome browser back to there defaults settings. Here is how;
https://support.google.com/chrome/answer/3296214?hl=en





=> Tell me how is the computer behavior now?

REDACTED

  • Guest
Re: Skegnassasc Pop-up/Malware (?)
« Reply #2 on: September 16, 2014, 03:44:46 PM »
Here's the new logs.  The notification kept happening while the fixes were going, but hopefully it's gone now, I'll keep you posted. :3

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Skegnassasc Pop-up/Malware (?)
« Reply #3 on: September 16, 2014, 03:47:42 PM »
Fix went great. It has been clean a large number of junk files. Monitor computer and AV's behavior and let me know.

If all is good, I shall remove my tools.  ;)

REDACTED

  • Guest
Re: Skegnassasc Pop-up/Malware (?)
« Reply #4 on: September 16, 2014, 06:20:09 PM »
Has been working great!  Thank you so much!  ;D

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Skegnassasc Pop-up/Malware (?)
« Reply #5 on: September 16, 2014, 10:16:57 PM »
Cool.  :)

- Run AdwCleaner and press the Uninstall button;
- Delete FRST tool, logs and his related C:\FRST folder;
- Just delete aswMBR tool, keep Malwarebytes installed if you will.

Cheers