Author Topic: hxxp://13.ppcclickfeed.com/ popping up  (Read 10249 times)

0 Members and 1 Guest are viewing this topic.

lucasbuck

  • Guest
hxxp://13.ppcclickfeed.com/ popping up
« on: September 14, 2012, 03:35:18 AM »
Anytime I do a search on google or yahoo avast warns of a malicious URL, http://13.ppcclickfeed.com/

It just started today, and I haven't done anything I can think of. Any ideas?
« Last Edit: September 15, 2012, 12:31:33 AM by lucasbuck »

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: http://13.ppcclickfeed.com/ popping up
« Reply #1 on: September 14, 2012, 03:39:13 AM »
Hi,
Follow this guide for running ( AdwCleaner ) Malwarebytes, OTL and aswMBR logreports.
http://forum.avast.com/index.php?topic=53253.0

Attach here logreports.

lucasbuck

  • Guest
Re: http://13.ppcclickfeed.com/ popping up
« Reply #2 on: September 14, 2012, 04:28:35 AM »
Thanks, will do. It seemed weird, I couldn't find any reference to it.
« Last Edit: September 14, 2012, 04:31:50 AM by lucasbuck »

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: http://13.ppcclickfeed.com/ popping up
« Reply #3 on: September 14, 2012, 12:05:55 PM »
Detecting malware can be a tricky thing.
Especially the detection of rootkits because some of them may lives outside of the windows operating system.

When and if you attach logs, I will be able to analyze them and tell you a little more.  ;)

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5639
  • Spartan Warrior
Re: http://13.ppcclickfeed.com/ popping up
« Reply #4 on: September 14, 2012, 12:47:50 PM »
hi lucasbuck,

Please modify the live http link in your first post to hXXp: to avoid infecting new or unsuspecting users. 

Doing so will make your link non-clickable.

http://zulu.zscaler.com/submission/show/f46040f77c57bc7d619757d96a28ed8c-1347618990
http://www.urlvoid.com/scan/13.ppcclickfeed.com/
http://urlquery.net/report.php?id=178756

http://sitecheck.sucuri.net/results/13.ppcclickfeed.com/  Securi is reporting a pay-per-click scheme under the Website Details tab/"List of links found" dropdown.
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

lucasbuck

  • Guest
Re: hxxp://13.ppcclickfeed.com/ popping up
« Reply #5 on: September 15, 2012, 01:37:48 AM »
If it helps, it happens running either IE or Firefox (the warning about the ppc site). I did do an Avast boot time scan, and it didn't find anything. Thanks again for the help.


lucasbuck

  • Guest
Re: hxxp://13.ppcclickfeed.com/ popping up
« Reply #6 on: September 15, 2012, 01:38:30 AM »
Other logs

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: hxxp://13.ppcclickfeed.com/ popping up
« Reply #7 on: September 15, 2012, 01:56:48 AM »
 Step#1 



Re-run OTL.exe.

  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.

Code: [Select]

:OTL
IE - HKU\S-1-5-21-3280474366-2115025290-3991797552-1001\..\SearchScopes\{B1E06153-F21B-44AD-A2D5-EF9B3509A0FD}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=NCH2&o=APN10111&src=kw&q={searchTerms}&locale=&apn_ptnrs=^A5M&apn_dtid=^YYYYYY^YY^US&apn_uid=4024961c-6880-4a57-b22c-ff0138b97e6b&apn_sauid=0A61987A-D1B9-4325-931E-6FC4CB860023
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://www.ask.com/?l=dis&o=APN10111&gct=hp"
[2012/06/17 09:34:22 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 6647546855.tpmpp
[2012/06/17 09:34:10 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 3294293522.tpmpp
[2012/06/17 09:34:02 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 2183182411.tpmpp
[2012/06/15 22:10:11 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 2182181399.tpmpp
[2012/06/15 22:09:22 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 7758757966.tpmpp
[2012/06/15 22:07:40 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 4325324633.tpmpp
[2012/06/15 22:06:16 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 7426435744.tpmpp
[2012/06/11 11:37:47 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 2183192411.tpmpp
[2012/06/11 11:37:01 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 4294213522.tpmpp
[2012/06/11 10:02:57 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 7648647855.tpmpp
[2012/06/11 10:02:17 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 3861879288.tpmpp
[2012/06/11 09:16:26 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 6769768177.tpmpp
[2012/06/11 01:49:42 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 6972971288.tpmpp
@Alternate Data Stream - 196 bytes -> C:\ProgramData\TEMP:8E5EA40F
@Alternate Data Stream - 181 bytes -> C:\ProgramData\TEMP:1A15E356
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:260575F1
@Alternate Data Stream - 1197 bytes -> C:\Users\User\AppData\Local\Temp:GQEvRFmplgbTdm5ko0GgrN

:files
C:\Users\User\AppData\Local\¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿ
ipconfig /flushdns /c

:commands
[CREATERESTOREPOINT]
[emptytemp]


  • Then click the Run Fix button at the top.
  • Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
************************
 Step#2 



> Download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.

> Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this or this Instruction.

How to disable avast:

  • Right-click on the avast! icon in the lower right corner of the screen and choose Open Avast! User Interface.
  • In the window that opens on the top right corner, click Settings.
  • In a new window that opens, choose the option Troubleshooting, Uncheck Enable avast! self-defense, and click OK.

  • Right-click on the avast! icon in the lower right corner of the screen and select avast! shield controls .
  • In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.
Note: Do not forget to turn on this option after the cleaning.



> Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix's window while it is running.
If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart computer once more.


> When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
  Attach log reports ( ComboFix.txt) back to topic.

lucasbuck

  • Guest
Re: hxxp://13.ppcclickfeed.com/ popping up
« Reply #8 on: September 15, 2012, 04:37:55 AM »
Okay, for the record neither program initiated a restart. I wasn't sure if that was okay.
What's the ¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈ..... file? I notice it didn't get removed or anything.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: hxxp://13.ppcclickfeed.com/ popping up
« Reply #9 on: September 15, 2012, 01:45:53 PM »
That folder should be gone by now...



Download TDSSKiller  and save it to your desktop

    Execute TDSSKiller.exe by doubleclicking on it.

  •     Press Start Scan

     
  •   If Suspicious object is detected, the default action will be Skip, click on Continue.
     
  •   If Malicious objects are found, select Cure.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt


Please post the contents of that log in your next reply.


*****************



Open notepad and copy/paste the text present inside the code box below:


Code: [Select]

ClearJavaCache::

Firefox::
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j8loigon.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com/?l=dis&o=APN10111&gct=hp




Save this as CFScript.txt



Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )

lucasbuck

  • Guest
Re: hxxp://13.ppcclickfeed.com/ popping up
« Reply #10 on: September 15, 2012, 03:57:39 PM »
TDS didn't find anything. Here's my logs and thanks for bearing with me!

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: hxxp://13.ppcclickfeed.com/ popping up
« Reply #11 on: September 15, 2012, 04:15:19 PM »
Open notepad and copy/paste the text present inside the code box below:


Code: [Select]

DeQuarantine::
C:\Qoobox\Quarantine\c\windows\SysWow64\drivers\hwinterface.sys.vir
Quit::



Save this as CFScript.txt



Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )


***********************



Re-run OTL.exe.

  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.

Code: [Select]

:processes
killallprocesses

:files
c:\windows\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP

:Commands
[Reboot]

  • Then click the Run Fix button at the top.
  • Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
***************

How's your computer running now?

lucasbuck

  • Guest
Re: hxxp://13.ppcclickfeed.com/ popping up
« Reply #12 on: September 15, 2012, 05:20:32 PM »
Combo just made a file called Dequarantine, I posted it and the OTL file. If it means anything, neither program rebooted the computer. I did do it manually when finished, and still have the warning when going to a search site.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: hxxp://13.ppcclickfeed.com/ popping up
« Reply #13 on: September 15, 2012, 05:28:37 PM »
Combofix Quarantine is Ok.

About OTL you should press RunFix not RunScan !
Again, run OTL Fix. Follow my guide carfile.



> Re-run OTL.exe.

  • Copy and paste the all following text written inside of the quote box into the Custom Scans/Fixes box.

Code: [Select]

:OTL
IE - HKU\S-1-5-21-3280474366-2115025290-3991797552-1001\..\SearchScopes\{B1E06153-F21B-44AD-A2D5-EF9B3509A0FD}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=NCH2&o=APN10111&src=kw&q={searchTerms}&locale=&apn_ptnrs=^A5M&apn_dtid=^YYYYYY^YY^US&apn_uid=4024961c-6880-4a57-b22c-ff0138b97e6b&apn_sauid=0A61987A-D1B9-4325-931E-6FC4CB860023
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - user.js - File not found
[2012/07/08 11:56:24 | 000,002,343 | ---- | M] () -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j8loigon.default\searchplugins\askcom.xml
[2012/09/14 22:02:14 | 000,000,000 | ---- | M] () -- C:\Users\User\AppData\Local\¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿ
[2012/06/17 09:34:22 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 6647546855.tpmpp
[2012/06/17 09:34:10 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 3294293522.tpmpp
[2012/06/17 09:34:02 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 2183182411.tpmpp
[2012/06/15 22:10:11 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 2182181399.tpmpp
[2012/06/15 22:09:22 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 7758757966.tpmpp
[2012/06/15 22:07:40 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 4325324633.tpmpp
[2012/06/15 22:06:16 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 7426435744.tpmpp
[2012/06/11 11:37:47 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 2183192411.tpmpp
[2012/06/11 11:37:01 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 4294213522.tpmpp
[2012/06/11 10:02:57 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 7648647855.tpmpp
[2012/06/11 10:02:17 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 3861879288.tpmpp
[2012/06/11 09:16:26 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 6769768177.tpmpp
[2012/06/11 01:49:42 | 000,000,051 | ---- | C] () -- C:\Users\User\AppData\Local\tmp. & 6972971288.tpmpp
@Alternate Data Stream - 1197 bytes -> C:\Users\User\AppData\Local\Temp:GQEvRFmplgbTdm5ko0GgrN

:files
c:\windows\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP

:commands
[emptytemp]

  • Then click the Run Fix button at the top.
  • Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.

lucasbuck

  • Guest
Re: hxxp://13.ppcclickfeed.com/ popping up
« Reply #14 on: September 15, 2012, 06:20:22 PM »
That was totally my fault. I reran, but still have the problem. Should I go and do the others you posted, but do runfix?