Author Topic: Yes, yet another constant Malicious URL blocked pop up problem  (Read 8024 times)

0 Members and 1 Guest are viewing this topic.

MikeB97

  • Guest
Yes, yet another constant Malicious URL blocked pop up problem
« on: September 07, 2012, 04:39:01 AM »
I started having this problem a couple of days ago; at first I was seeing the same colexity/espeak URL's that others were reporting but today there's a different, larger batch. MWB is apparently finding the problem but not fixing it. Avast scans turned up a couple of false positives. One thing I noticed before the popups started was a bunch of weird redirects in Google searches and 'connection was reset' pages. Once those cleared up the popups started.  FWIW, I have an XP machine on the same network that doesn't appear to be affected; one difference is that machine is rarely use for browsing. Thanks for the help!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #1 on: September 07, 2012, 08:11:44 AM »
could you also attach AdwCleaner and aswMBR logs.....see the guide   

http://forum.avast.com/index.php?topic=53253.0

argus

  • Guest
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #2 on: September 07, 2012, 09:17:22 AM »
Hello,


Re-run OTL.exe.

  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.

Code: [Select]
:files
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\{400f82ac-9f5d-edc0-6938-035420770c0a}
C:\Windows\System32\config\systemprofile\AppData\Local\{400f82ac-9f5d-edc0-6938-035420770c0a}
C:\Windows\Installer\{400f82ac-9f5d-edc0-6938-035420770c0a}
ipconfig /flushdns /c

:commands
[CREATERESTOREPOINT]
[emptytemp]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
*










> Download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.

> Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this or this Instruction.

How to disable avast:

  • Right-click on the avast! icon in the lower right corner of the screen and choose Open Avast! User Interface.
  • In the window that opens on the top right corner, click Settings.
  • In a new window that opens, choose the option Troubleshooting, Uncheck Enable avast! self-defense, and click OK.

  • Right-click on the avast! icon in the lower right corner of the screen and select avast! shield controls .
  • In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.
Note: Do not forget to turn on this option after the cleaning.



> Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix's window while it is running.
If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart computer once more.


> When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
  Attach log reports ( ComboFix.txt) back to topic.

MikeB97

  • Guest
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #3 on: September 07, 2012, 04:19:08 PM »
Thanks, guys, I'll try these and upload the logs this evening.

MikeB97

  • Guest
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #4 on: September 08, 2012, 03:33:33 AM »
Thanks for the help so far, here are the log files; I also ran the custom fix in OTL and attached that log file. Looks like like I'm back to the original colexity/espeak URL's this evening.

argus

  • Guest
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #5 on: September 08, 2012, 08:05:02 AM »
Mike, Combofix log not released.
Please follow the instructions, now I'm working with you.
« Last Edit: September 08, 2012, 08:06:37 AM by argus »

MikeB97

  • Guest
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #6 on: September 08, 2012, 07:10:36 PM »
Hi Argus, here's the combofix log:

argus

  • Guest
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #7 on: September 08, 2012, 07:37:49 PM »
Mike, how's your computer behaving now?

MikeB97

  • Guest
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #8 on: September 08, 2012, 07:49:33 PM »
Argus, I'm still getting the pop-ups. Performance wise, the machine seems to be operating normally.

argus

  • Guest
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #9 on: September 08, 2012, 07:55:45 PM »
Re-run OTL.exe.

  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.

Code: [Select]
/md5start
services.exe
/md5stop
  • Then click the Run Fix button at the top.
  • Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.

argus

  • Guest
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #10 on: September 08, 2012, 07:59:19 PM »
Opsss sorry,   click the RunScan

MikeB97

  • Guest
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #11 on: September 08, 2012, 08:10:53 PM »
Here you go.

argus

  • Guest
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #12 on: September 08, 2012, 10:12:03 PM »
Download TDSSKiller  and save it to your desktop

    Execute TDSSKiller.exe by doubleclicking on it.

  •     Press Start Scan

     
  •   If Suspicious object is detected, the default action will be Skip, click on Continue.
     
  •   If Malicious objects are found, select Cure.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt


Please post the contents of that log in your next reply.

MikeB97

  • Guest
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #13 on: September 08, 2012, 10:49:07 PM »
Hi, Argus, here are the TDSS log files.

argus

  • Guest
Re: Yes, yet another constant Malicious URL blocked pop up problem
« Reply #14 on: September 08, 2012, 11:11:33 PM »
  • Re-run TDSSKiller.exe and click on Change parametres.
  • Under Additional options check the boxes next to Verify Driver Digital Signature and Detect TDLFS file system, then click OK
  • Click on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • Click the Report button and attach the contents of it into your next reply
Note:It will also create a log in the C:\ directory.

***


Step2


>> Delete old Combofix icon and download fresh Combofix from here:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe


Open notepad and copy/paste the text present inside the code box below:

Code: [Select]
File::
c:\windows\svchost.exe

Save this as CFScript.txt



Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )