Author Topic: Harmful Webpage  (Read 19179 times)

0 Members and 1 Guest are viewing this topic.

denebuff

  • Guest
Re: Harmful Webpage
« Reply #15 on: April 09, 2014, 02:19:10 AM »
Ok Steve
here is what I got.

denebuff

  • Guest
Re: Harmful Webpage
« Reply #16 on: April 09, 2014, 02:20:58 AM »
Ok Steve here is what I got.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Harmful Webpage
« Reply #17 on: April 09, 2014, 02:35:04 AM »
Essex is asleep. Check back tomorrow...
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

denebuff

  • Guest
Re: Harmful Webpage
« Reply #18 on: April 09, 2014, 02:42:29 AM »
OK Thank You Will Do.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Harmful Webpage
« Reply #19 on: April 09, 2014, 12:43:02 PM »
Hi there, I have two possibilities in mind so lets see which it is

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

denebuff

  • Guest
Re: C:\ComboFix.
« Reply #20 on: April 09, 2014, 10:53:22 PM »
As soon as I turned on my AVAST it started again with the Thereat has been detected. :(
I have attached the log from combo fix

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Harmful Webpage
« Reply #21 on: April 09, 2014, 10:59:00 PM »
Got it, it appears that blackbeard has changed and is now targeting XP
 
1. Close any open browsers.
 
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 
 
3. Open notepad and copy/paste the text in the quotebox below into it:
 
Quote

FCopy::
c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll|c:\windows\system32\rpcss.dll


 
Save this as CFScript.txt, in the same location as ComboFix.exe
 
 
 
 
Refering to the picture above, drag CFScript into ComboFix.exe
 
When finished, it will produce a log for you at C:\ComboFix.txt which I will require in your next reply.

denebuff

  • Guest
Re: Harmful Webpage
« Reply #22 on: April 09, 2014, 11:43:04 PM »
OK I did what you asked and attached the New Log. As soon as I got back on the net and turned on my AVAST I got the threat message that "a threat has been detected".  are we getting close :)

denebuff

  • Guest
Re: Harmful Webpage
« Reply #23 on: April 09, 2014, 11:56:39 PM »
Now the threat as a new name. "colombus45 and a few other names I think we have them on the run!

denebuff

  • Guest
Re: Harmful Webpage
« Reply #24 on: April 10, 2014, 12:01:02 AM »
stupid question, but should I be doing a reboot after each run? before I get back on line?

denebuff

  • Guest
Re: Harmful Webpage
« Reply #25 on: April 10, 2014, 12:05:20 AM »
Here is the other name on the warning.
I don't know if this makes a difference or not.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Harmful Webpage
« Reply #26 on: April 10, 2014, 12:07:33 AM »
Essexboy is in bed now since its midnight in the UK.

Check back tomorrow. :)
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

denebuff

  • Guest
Re: Harmful Webpage
« Reply #27 on: April 10, 2014, 12:13:45 AM »
OK Thank You for all your continued support.
I will be back on line after 11:30 am Eastern Standard Time, as I live In PA. USA

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Harmful Webpage
« Reply #28 on: April 10, 2014, 02:48:43 AM »
Ust to explain a little bit... You were infected by the "Blackbeard" Trojan. It has modified svchost or made a new one to contact these domains to further infect your PC. To address your comment "I think we have it on the run", while Essex directly targets the malware,yes we do.

The process responsible is svchost, which most likely they'll be 5+ of them in task manager, so don't try to kill it since it most likely has a restore reg key to relaunch it.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

denebuff

  • Guest
Re: Harmful Webpage
« Reply #29 on: April 10, 2014, 03:47:08 AM »
Michael
I can not thank the people of the site for all there help. as of right now AVAST is not giving me the alert Malwarebytes is.