Author Topic: Mal:Url  (Read 2270 times)

0 Members and 1 Guest are viewing this topic.

xenrayven

  • Guest
Mal:Url
« on: January 10, 2014, 02:37:16 AM »
This is being stubborn as hell, not coming up on malwarebytes scan, avast scan, OR hitman pro
« Last Edit: January 10, 2014, 02:38:50 AM by xenrayven »

xenrayven

  • Guest
Re: Mal:Url log 2
« Reply #1 on: January 10, 2014, 02:39:32 AM »
here is the aswmbr

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Mal:Url
« Reply #2 on: January 10, 2014, 12:11:19 PM »
Post the MBAM Log.

Remover Notified
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Mal:Url
« Reply #3 on: January 10, 2014, 02:27:38 PM »
I see that you have run combofix, could you attach the log please and also take a screen shot of the Avast alert

xenrayven

  • Guest
Re: Mal:Url
« Reply #4 on: January 11, 2014, 01:48:36 AM »
couldn't get  a screen shot, did attach log though of the shield

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Mal:Url
« Reply #5 on: January 11, 2014, 01:36:14 PM »
OK Avast does not like the server that AVG secure search is using

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
SRV - [2014/01/05 18:22:01 | 001,771,544 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe -- (vToolbarUpdater17.3.0)
DRV:64bit: - [2013/11/14 16:18:58 | 000,046,368 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.3.0\\npsitesafety.dll ()
[2013/10/15 12:28:32 | 000,000,000 | ---- | M] () -- C:\Users\Whimsy\AppData\Roaming\Mozilla\Firefox\Profiles\9lr6u9na.default\searchplugins\safeguard-secure-search.xml
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49 [2014/01/05 18:22:08 | 000,000,000 | ---D | M]
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.3.0\ViProtocol.dll (AVG Secure Search)
[2014/01/02 17:46:52 | 000,000,000 | ---D | C] -- C:\Users\Whimsy\AppData\Local\AVG Secure Search
[2014/01/09 20:17:36 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\Whimsy\Desktop\aswmbr.exe

:Files
C:\Program Files (x86)\Common Files\AVG Secure Search

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

xenrayven

  • Guest
Re: Mal:Url
« Reply #6 on: January 11, 2014, 01:46:51 PM »
here you go and thank you for your help

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Mal:Url
« Reply #7 on: January 11, 2014, 01:47:46 PM »
Have the alerts now ceased ?

xenrayven

  • Guest
Re: Mal:Url
« Reply #8 on: January 11, 2014, 01:55:47 PM »
They were so once in a blue moon. I haven't had one since. I'll let you know in 72 hours :) Thank you so much for your help