Author Topic: Avast continuously blocking malicious URL  (Read 3046 times)

0 Members and 3 Guests are viewing this topic.

CKtech

  • Guest
Avast continuously blocking malicious URL
« on: January 03, 2014, 01:44:54 AM »
Avast keeps blocking malicious URL's and I have done scans using Avast as well as Malwarebytes, but they have had little luck in finding the infections. I have tried running OTL, but it freezes whenever it starts 'scanning firefox settings'.  Any idea how to fix or get around this?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Avast continuously blocking malicious URL
« Reply #1 on: January 03, 2014, 01:48:56 AM »
attach (not copy and paste) OTL and aswMBR logs   http://forum.avast.com/index.php?topic=53253.0

if problems try run from safe mode.....



« Last Edit: January 03, 2014, 01:51:55 AM by Pondus »

CKtech

  • Guest
Re: Avast continuously blocking malicious URL
« Reply #2 on: January 03, 2014, 03:05:45 AM »
OTL won't finish scanning no matter what I do. Tried safe mode, and even completely uninstalled firefox and it still gets stuck at 'scanning firefox settings'. Got the aswmbr log though.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Avast continuously blocking malicious URL
« Reply #3 on: January 03, 2014, 03:07:56 AM »
the malware experts have more tools, check back tomorrow.....


CKtech

  • Guest
Re: Avast continuously blocking malicious URL
« Reply #4 on: January 03, 2014, 09:51:23 PM »
I let OTL run all night, and it finished at some point, so here is that log. What else do I need to do?

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Avast continuously blocking malicious URL
« Reply #5 on: January 03, 2014, 09:53:01 PM »
Just wait for an malware expert now. :)
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

CKtech

  • Guest
Re: Avast continuously blocking malicious URL
« Reply #6 on: January 09, 2014, 10:33:21 PM »
And how long does that generally take? Avast is no longer blocking anything at point.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Avast continuously blocking malicious URL
« Reply #7 on: January 09, 2014, 10:36:44 PM »
OBS...seems your topic has been overlooked

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast continuously blocking malicious URL
« Reply #8 on: January 09, 2014, 10:49:35 PM »
Apologies for missing you

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
IE - HKU\S-1-5-21-1078081533-602609370-839522115-1004\..\SearchScopes\{6E0D3723-B61C-4DDF-B481-FD54B771B4E2}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3287375&CUI=UN26835378731902015&UM=2
FF - prefs.js..browser.search.defaultenginename: "Vafmusic Customized Web Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Vafmusic Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3287375&CUI=UN17696071217641143&UM=2&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com Search"
FF - prefs.js..browser.search.selectedEngine: "Vafmusic Customized Web Search"
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT3287375&octid=CT3287375&SearchSource=61&CUI=UN17696071217641143&UM=2&UP=SPC38408AC-E496-4D0D-A340-3BA14ABE9E2E"
FF - prefs.js..extensions.enabledAddons: crossriderapp3026%40crossrider.com:0.88.175
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3287375&SearchSource=2&CUI=UN17696071217641143&UM=2&q="
[2013/02/08 13:22:26 | 000,000,000 | ---D | M] ("Software Assist") -- C:\Documents and Settings\ServerOnly\Application Data\Mozilla\Firefox\Profiles\p81vvfwx.default\extensions\crossriderapp3026@crossrider.com
[2013/12/16 12:28:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ServerOnly\Application Data\Mozilla\Firefox\Profiles\p81vvfwx.default\extensions\staged
[2013/02/08 13:22:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ServerOnly\Application Data\Mozilla\Firefox\Profiles\p81vvfwx.default\extensions\crossriderapp3026@crossrider.com\chrome\content\extensionCode
[2013/01/28 18:14:20 | 000,002,333 | ---- | M] () -- C:\Documents and Settings\ServerOnly\Application Data\Mozilla\Firefox\Profiles\p81vvfwx.default\searchplugins\askcom.xml
[2013/03/06 16:08:02 | 000,002,306 | ---- | M] () -- C:\Documents and Settings\ServerOnly\Application Data\Mozilla\Firefox\Profiles\p81vvfwx.default\searchplugins\askcomsearch.xml
[2013/05/09 16:24:39 | 000,000,993 | ---- | M] () -- C:\Documents and Settings\ServerOnly\Application Data\Mozilla\Firefox\Profiles\p81vvfwx.default\searchplugins\conduit.xml
O3 - HKU\S-1-5-21-1078081533-602609370-839522115-1004\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKU\.DEFAULT..\Run: [SearchProtect] C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\bin\cltmng.exe File not found
O4 - HKU\S-1-5-18..\Run: [SearchProtect] C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\bin\cltmng.exe File not found
[2014/01/02 15:38:36 | 000,000,081 | ---- | M] () -- C:\WINDOWS\System32\qiifpy.ibr
[2013/12/30 16:57:59 | 000,028,672 | ---- | M] () -- C:\WINDOWS\System32\mliye.ulq
[2013/12/30 16:57:59 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\heuccwb.eyg
[2013/12/30 16:47:38 | 000,000,064 | ---- | M] () -- C:\WINDOWS\System32\abrmis.yhm
[2013/12/30 16:31:43 | 000,101,213 | --S- | M] () -- C:\WINDOWS\System32\ycsqve.cus
[2013/12/30 16:57:59 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\mliye.ulq
[2013/12/30 16:47:58 | 000,000,081 | ---- | C] () -- C:\WINDOWS\System32\qiifpy.ibr
[2013/12/30 16:47:38 | 000,000,098 | ---- | C] () -- C:\WINDOWS\System32\heuccwb.eyg
[2013/12/30 16:47:38 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\abrmis.yhm
[2013/12/30 16:31:42 | 000,101,213 | --S- | C] () -- C:\WINDOWS\System32\ycsqve.cus
[2014/01/02 12:09:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ServerOnly\Application Data\SearchProtect

:Files
C:\Documents and Settings\ServerOnly\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jenkhamomijcoocoblchfbobohfabaff

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN

Please download Malwarebytes AntiRootkit and save it to your desktop.

Full instructions how to use MBAR
Please note: This is a beta version so please be sure to read the disclaimer and note of it.

• Unzip/unrar MBAR in a folder to your Desktop and MBAM shall run ...

• Click on Next > then on Update button to download fresh definitions.


• When database updates click Next

• In the following window ensure "Targets" scan for Drivers; Sectors; System are ticked. Then select "Scan button"


• If an infection/s are found ensure "Create Restore Point" is checked, then select the "Cleanup Button" to remove threats.
Or if you are sure any entries should not be kept, just untick them. A list of infected files will be listed.


• The Clean up procedure will be Scheduled for process.
• When complete pop-up will show you. Select the Yes button and the system should re-boot to complete the cleaning process.

>> Please attach the two following logs from the mbar folder:

system-log.txt
and
mbar-log-year-month-day (hour-minute-second).txt.