Author Topic: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal  (Read 15671 times)

0 Members and 1 Guest are viewing this topic.

gleits

  • Guest
URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« on: May 02, 2014, 10:33:30 PM »
Since yesterday even when nothing is running on my computer I've occasionally had a pop up from Avast! that it has blocked a malicious website. Clicking on the most recent message it gives me the following message in the browser:

URL:   h_go_wvydeo_com__resultsa__?x
Infection:   URL:Mal

Not sure what info is needed, but this Win7 Home, a full scan of Avast! 2014.9.0.2018 found nothing, Malwarebytes 2.0.1.1004 database 2014.05.02.11 found nothing of significance either. I'm not sure where to find any logs within Avast!

Thanks for any help.   

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #1 on: May 02, 2014, 10:34:56 PM »
Attach your logs. (MBAM, OTL and aswMBR..!!)
Instructions: http://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Valinorum

  • Guest
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #2 on: May 02, 2014, 10:45:18 PM »
Monitoring.

gleits

  • Guest
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #3 on: May 03, 2014, 02:52:20 AM »
Here's the results of the scans.


Valinorum

  • Guest
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #4 on: May 03, 2014, 07:06:54 AM »
Hi gleits, :)

  • Step #1 Fix with OTL
    • Re-run OTL by right clicking and choosing Run as administrator;
    • Under the Custom Scans/Fixes Box copy and paste the following contents inside the code box.
Code: [Select]
:Commands
[createrestorepoint]

:OTL
[2014/05/02 11:50:15 | 000,000,000 | --S- | C] () -- C:\Windows\system32\xczb.msh
[2014/05/01 15:25:45 | 000,000,069 | ---- | C] () -- C:\Windows\system32\bzzeum.hjq
[2014/05/01 15:16:02 | 000,000,028 | ---- | C] () -- C:\Windows\SysWow64\u
[2014/05/01 15:15:21 | 000,000,064 | ---- | C] () -- C:\Windows\system32\iktyw.ikn
[2014/05/01 15:15:21 | 000,000,000 | ---- | C] () -- C:\Windows\system32\jbfr.xlp
[2014/05/01 14:59:20 | 000,239,175 | --S- | C] () -- C:\Windows\system32\vrtsp.udl

:Commands
[emptytemp]
    • Click on "Run Fix" and let the program run unhindered;
    • Your PC will reboot automatically and a log will be opened;
    • Please attach it in your next reply.



  • Step #2 Scan with RogueKiller


  • Step #3 Run ComboFix
    Download ComboFix by sUBs from one of the suitable locations listed below and save it to your Desktop.
    Download Link #1
    Download Link #2
    Donwload Link #3

    Warning
    Please acknowledged yourself this warning beforehand. The tool, ComboFix, is an extremely powerful malware removal tool if not one of the most powerful tools ever created. In the hands of an inept person or a simple mistake can render your machine un-bootable. Peruse every step I listed below unless you want a dreadful occurrence.
    ***

    • Disable your security software. For more information, peruse this thread;
    • Right-click and choose Run as administrator to run the program.
    • As a buit-in process, ComboFix will check if you system has Microsoft Windows Recovery Console installed. Let Combofix download and install Microsoft Windows Recovery Console.
      • It requires an active internet connection.
      • If your system already has Microsoft Windows Recovery Console installed, this step will be skipped
    • ComboFix will now scan your system for malwares and will attempt to remove them.
      • Note: ComboFix performs fifty steps during this fix. Please be patient.
    • After the scan your system will reboot and a log will be produced. The log is automatically saved in C:\ComboFix.txt.
    • Attach the log in your next reply.
    Crucial Notes:
    • Do not mouse-click when ComboFix is running as it may stall.
    • Do not re-run ComboFix if you face a problem. Ask for my instruction here.
    • ComboFix will make Internet Explorer your default browser and will change number of different Internet Explorer settings.
    • ComboFix prevents autorun functions of all CD and USB devices to assist with malware removal and increase security. If this is an issue or makes it difficult for you, please tell me.
    • It is possible that ComboFix, even on its first run, may have fixed the problems you are having. We strongly suggest that you still post your log into the topic that you are receiving help as you most likely will have infections left over that your helper will need to analyze further.
    • ComboFix will disconnect your system from internet for security measures. The connection is automatically restored after the scan but if it does not, it can be restored by rebooting the PC.


  • Step #5 Scan with Farbar Recovery Scan Tool
    • Please download Farbar Recovery Scan Tool by Farbar to your Desktop from the link below.
      Download link for 32 bit system
      Download link for 64 bit system
    • Right-click on the program and choose Run as administrator;
    • Put tick-mark on all boxes under Whitelist and Optional Scan;
    • Click on Scan;
    • After the scan two notepad files will be opened --
      • FRST.txt;
      • Addition.txt
    • Attach the contents of the logs in your next reply.


  • Required Log(s):
    • OTL Fix Log;
    • RogueKiller Report;
    • ComboFix Log;
    • Farbar Recovery Scan Tool Log(s) -
      • FRST.txt
      • Addition.txt
Regards,
Valinorum

gleits

  • Guest
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #5 on: May 03, 2014, 02:47:29 PM »
    Required Log(s):
        OTL Fix Log;
        RogueKiller Report;
        ComboFix Log;

gleits

  • Guest
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #6 on: May 03, 2014, 02:48:57 PM »
    Required Log(s):
        Farbar Recovery Scan Tool Log(s) -
            FRST.txt
            Addition.txt

Valinorum

  • Guest
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #7 on: May 03, 2014, 03:03:48 PM »
Hi gleits, :)

  • Step #6 Run ComboFix Script
    Make sure that you still have Combofix on your Desktop. If not, download it from here.
    • Open Notepad.exe. Do not use any other text editor software;
    • Copy and Paste the contents inside the code-box to your Notepad --
Code: [Select]
File::
C:\Windows\system32\xczb.msh
C:\Windows\system32\bzzeum.hjq
C:\Windows\system32\iktyw.ikn
C:\Windows\system32\jbfr.xlp
C:\Windows\system32\vrtsp.udl

FCopy::
c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7601.17514_none_c7f0e16b547f887d\rpcss.dll | c:\windows\system32\rpcss.dll
    • Click on File > Save as...
      • Inside the File Name box type CFScript.txt
      • From the Save as type drop down list, choose All Files
    • Save the file to your Desktop;
    • Make sure your security programs are disabled while performing the actions. If you have difficulties, peruse this thread;
    • Drag CFScript.txt into ComboFix.exe as shown in the screenshot below --

    • ComboFix will now run a scan on your system. After the scan finishes, it will execute the script and reboot your computer automatically. Don't reboot your computer manually, let ComboFix do it. Once your computer is rebooted, ComboFix will start preparing a log. Please let it do so unhindered. After a few minutes, it shall produce a log for you.
    • Please attach the C:\ComboFix.txt in your next reply.



Re-do Step 5.



  • Required Log(s):
    • ComboFix Log;
    • Farbar Recovery Scan Tool Log(s) -
      • FRST.txt
      • Addition.txt
Regards,
Valinorum

gleits

  • Guest
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #8 on: May 03, 2014, 03:47:05 PM »
  • ComboFix will now scan your system for malwares and will attempt to remove them.
  • Note: ComboFix performs fifty steps during this fix. Please be patient.
  • After the scan your system will reboot and a log will be produced. The log is automatically saved in C:\ComboFix.txt.
  • ComboFix will now run a scan on your system. After the scan finishes, it will execute the script and reboot your computer automatically. Don't reboot your computer manually, let ComboFix do it. Once your computer is rebooted, ComboFix will start preparing a log. Please let it do so unhindered. After a few minutes, it shall produce a log for you.
I believe I followed your instructions exactly, but neither time did the computer reboot. The log file was generated after the program was finished with no reboot.

Anyway, see attached.

Valinorum

  • Guest
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #9 on: May 03, 2014, 05:44:52 PM »
Hi gleits, :)

Tell me how the system is running after applying the fix.



  • Step #7 Fix with FRST
    Make sure that you still have FRST.exe on your Desktop. If you do not have it, download the suitable version from here to your Desktop.
    • Open Notepad.exe. Do not use any other text editor software;
    • Copy and Paste the contents inside the code-box to your Notepad --
Code: [Select]
Start
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} -  No File
2014-05-03 07:48 - 2014-05-03 07:48 - 00000028 _____ () C:\Windows\SysWOW64\u
2014-05-02 11:50 - 2014-05-02 11:50 - 00000000 ____S () C:\Windows\system32\xczb.msh
2014-05-01 15:25 - 2014-05-03 08:50 - 00000069 _____ () C:\Windows\system32\bzzeum.hjq
2014-05-01 15:15 - 2014-05-01 15:15 - 00000064 _____ () C:\Windows\system32\iktyw.ikn
2014-05-01 15:15 - 2014-05-01 15:15 - 00000000 _____ () C:\Windows\system32\jbfr.xlp
2014-05-01 14:59 - 2014-05-01 14:59 - 00239175 ____S () C:\Windows\system32\vrtsp.udl
End
    • Click on File > Save as...
      • Inside the File Name box type fixlist.txt
      • From the Save as type drop down list, choose All Files
    • Save the file to your Desktop;
    • Re-run FRST.exe and click Fix;
      • Note: If FRST advises there is a new updated version to be downloaded, do so/allow this.
    • After the completion, a log will be produced;
    • Attach the log in your next reply.



  • Required Log(s):
    • FRST Fix Log
Regards,
Valinorum

gleits

  • Guest
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #10 on: May 03, 2014, 06:30:14 PM »
System seems fine, barring one freeze, with no programs having been opened by me, save Firefox to get to this site. I've been having this issue randomly for a couple of months though. :(

    Required Log(s):
        FRST Fix Log

Valinorum

  • Guest
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #11 on: May 03, 2014, 06:35:29 PM »
I require the FRST Fix Log. It is located in the same folder of FRST.exe and which program is freezing?

gleits

  • Guest
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #12 on: May 03, 2014, 06:44:05 PM »
Oops, sorry.

It's not any specific program, it's the entire system. Nothing responds, I can't ctrl+alt+del. 

Valinorum

  • Guest
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #13 on: May 03, 2014, 06:47:54 PM »
Isn't there any file named Fixlog.txt on your Desktop? Attach it please. Since when the freezing started?

gleits

  • Guest
Re: URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal
« Reply #14 on: May 03, 2014, 07:04:32 PM »
The computer has been having the occasional freezes for a couple of months now.