Author Topic: continual pop-ups about onlinesecuritymetere.in  (Read 4840 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
continual pop-ups about onlinesecuritymetere.in
« on: April 24, 2015, 09:08:23 PM »
Hi
I have today been bombarded with pop-ups from Avast Web Shield every few minutes telling me that it's blocked a harmful webpage or file.
It's always the same object
htxp://onlinesecuritymetre.in/index.php
The infection is always URL:Mal
and the process is C:\Windows\explorer.exe

How can i stop this?

« Last Edit: April 27, 2015, 08:16:15 AM by Milos »

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: continual pop-ups about onlinesecuritymetere.in
« Reply #1 on: April 24, 2015, 09:10:22 PM »
Logs to assist in cleaning malware

https://forum.avast.com/index.php?topic=53253.0
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: continual pop-ups about onlinesecuritymetere.in
« Reply #2 on: April 24, 2015, 11:26:04 PM »
Malwarebytes was my first port of call, but the threat still keeps appearing.  Anyway, attached are the scan from MalwareBytes, the FRST/Addition text files from the Farbar tool and the log from aswMBR.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: continual pop-ups about onlinesecuritymetere.in
« Reply #3 on: April 24, 2015, 11:42:32 PM »
Hi steve143,

Break that malicious link with hxtp. Why, just see here: https://www.virustotal.com/nl/url/2ec764a58bb529f123ffd72f128773f3b51240921de0c95f37e20fc2b653895e/analysis/1429911208/
Site is potentially harmfull: https://sitecheck.sucuri.net/results/onlinesecuritymetre.in
Quttera flags: domain is Malicious. Outdated Web Server Apache Found: Apache/2.2.22

It is a so-called Cloaked Scraper: http://www.ip-finder.me/93.190.140.145/  (blacklisted in three instances)
where one has to be careful because of some particular setting in the php.ini (index.php)
It is on the ZB Block-Blocklist for cloaked Spiders, Scrapers and Keywordsearchers who does not observe the rules

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: continual pop-ups about onlinesecuritymetere.in
« Reply #4 on: April 25, 2015, 09:34:10 AM »
Fix with Farbar Recovery Scan Tool

This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.


Scan with ComboFix

This is a very powerful tool that should be used only if advised by Malware Analyst.
Do not run ComboFix on your own!


Referring to this instruction, please download ComboFix by sUBs and save it to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on icon and select Run as Administrator to start the tool.
  • Accept the disclaimer and agree if prompted to install Recovery Console.
  • Do not take any actions while ComboFix goes through your System - it may cause it to stall!
  • This scan may take some time!
  • When finished - it will display a logfile (located also on your main drive, usually C:\ComboFix.txt).

Include that log in your next reply.
If you'll encounter any issues with internet connection after running ComboFix, please visit this link.
If an error about operation on the key marked for deletion will appear after running the tool, please reboot your machine.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: continual pop-ups about onlinesecuritymetere.in
« Reply #5 on: April 25, 2015, 09:54:11 AM »
Hello; I have had more or less the exact same problem, a constant barrage of URL: Mal warnings from Explorer.exe; typically one from onlinesecuritymeter.in, then usually five in rapid succession from it's IP address, all thankfully blocked.  This only started happening today.

I'm going on the assumption that I will need my own unique solution, but as the problem is entirely identical to this, I also assumed it would be easier to post here.

I have used Avast, MalwareBytes, SUPERAntiSpyware, both in and out of safe mode, tried to find anything with HijackThis, and even tried a system restore to a previous date, none of which worked.

The needed logs are attached.

I'll note in advance I'm going to be going out of town for the weekend, so I unfortunately won't be able to respond until Monday.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: continual pop-ups about onlinesecuritymetere.in
« Reply #6 on: April 25, 2015, 10:10:06 AM »
Hello; I have had more or less the exact same problem, a constant barrage of URL: Mal warnings from Explorer.exe; typically one from onlinesecuritymeter.in, then usually five in rapid succession from it's IP address, all thankfully blocked.  This only started happening today.
Start a new topic in V&W and post your logs there: https://forum.avast.com/index.php?action=post;board=4.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: continual pop-ups about onlinesecuritymetere.in
« Reply #7 on: April 25, 2015, 02:06:59 PM »
Hi twinheadedeagle

Thanks for helping me attached is the log from the Farbar tool and also the log from the ComboFix tool.

Cheers

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: continual pop-ups about onlinesecuritymetere.in
« Reply #8 on: April 25, 2015, 04:48:27 PM »
How is your PC behaving now?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: continual pop-ups about onlinesecuritymetere.in
« Reply #9 on: April 25, 2015, 07:04:15 PM »
No re-occurrences - thanks for your expert help.
Cheers
Steve :)

REDACTED

  • Guest
Re: continual pop-ups about onlinesecuritymetere.in
« Reply #10 on: April 25, 2015, 09:39:28 PM »
Hi I'm having the exact same issue. Avast and Anti-Malware Bytes doesn't seem to catch it. Can anyone provide some assistance?

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: continual pop-ups about onlinesecuritymetere.in
« Reply #11 on: April 25, 2015, 10:24:54 PM »
Hi I'm having the exact same issue. Avast and Anti-Malware Bytes doesn't seem to catch it. Can anyone provide some assistance?
Start your own topic.
Explain your problem and give us info as to OS and other security programs running. What version of Avast are you using ??
Attach the requested logs.

Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet