Author Topic: http://getusaaall.info avast popup. How to remove it?  (Read 6670 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
http://getusaaall.info avast popup. How to remove it?
« on: July 15, 2014, 11:36:40 PM »
Hello,

Like many users I am having the same problem. From 10 to 10 minutes my avast shows a popup with the blocked http://gteusaaall.info object

URL:MAL

Process: C: \ \ Windows \ System32 \ svchost.exe

I'm using Windows 7 64bit and already ran the Recovery Farbar scan tool.

Attached I send the FRST and the Addition logs generated by Farbar.

Does Anyone know how to remove this thing?

Thanks in advance :)

REDACTED

  • Guest
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #1 on: July 16, 2014, 10:26:33 AM »
Anybody? :/

Thank you

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #2 on: July 16, 2014, 10:35:43 AM »
Please be patient, there are many requests atm.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #3 on: July 16, 2014, 12:30:22 PM »
This should stop it

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

REDACTED

  • Guest
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #4 on: July 16, 2014, 11:30:51 PM »
Attached I send the log generated by Combofix.

To uninstall Combofix I just delete the .exe file located on my desktop?

After you analyse the log can I delete it?

I'll wait and then i'll tell you if it worked.

Thanks

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #5 on: July 17, 2014, 04:46:52 PM »
I will uninstall the programmes safely when we are completed

1. Close any open browsers.
 
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 
 
3. Open notepad and copy/paste the text in the quotebox below into it:
 
Quote

FCopy::
c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll|c:\windows\system32\user32.dll

 
Save this as CFScript.txt, in the same location as ComboFix.exe
 
 
 
 
Refering to the picture above, drag CFScript into ComboFix.exe
 
When finished, it will produce a log for you at C:\ComboFix.txt which I will require in your next reply.

REDACTED

  • Guest
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #6 on: July 17, 2014, 11:17:15 PM »
I no longer have the Combofix .exe file on my desktop :(

Can I do that by downloading again Combofix (but not running it)?

But anyway, I think that the http:\\getusaaall.info popup was removed. It no longer pops up since I used Combofix.

Do we need to do that step anyway?

Thank you once again.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #7 on: July 18, 2014, 02:15:24 PM »
Well your user32.dll is not showing a legitimate MD5 so it may be infected.  But the choice is yours

REDACTED

  • Guest
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #8 on: July 18, 2014, 03:19:15 PM »
Ok, but my only doubt is:

"3. Open notepad and copy/paste the text in the quotebox below into it:
 
Quote


    FCopy::
    c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll|c:\windows\system32\user32.dll"


For doing this step and drag the text file to Combofix, do I need to run Combofix all over again? Or can I just download Combofix and drag the notepad with the text you post without running combofix again?

Thank you once again :)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #9 on: July 18, 2014, 03:23:32 PM »
Do you still have FRST ?  If so then use that

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote

Replace: c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll c:\windows\system32\user32.dll
REBOOT:

 
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #10 on: July 18, 2014, 03:52:59 PM »
I don't have Farbar anymore :(

But can I download it again and make the last step you wrote?

Replace: c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll c:\windows\system32\user32.dll
REBOOT:


But what will this do to my computer exactly?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #11 on: July 18, 2014, 04:07:30 PM »
It will replace the suspect file with a good known copy


REDACTED

  • Guest
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #12 on: July 18, 2014, 05:07:15 PM »
But won't it do anything wrong to my Windows?

I don't have Farbar anymore :(

But can I download it again and make the last step you wrote?

    Replace: c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll c:\windows\system32\user32.dll
    REBOOT:


 
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #13 on: July 18, 2014, 05:12:39 PM »
Please download Farbar Recovery Scan Tool and save it to your Desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

This should not affect windows at all

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote

Replace: c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll c:\windows\system32\user32.dll
REBOOT:

 
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: http://getusaaall.info avast popup. How to remove it?
« Reply #14 on: July 18, 2014, 05:55:04 PM »
But before I open notepad and copy paste this:

    Replace: c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll c:\windows\system32\user32.dll
    REBOOT:


Should I ran FRST first? Or can put the fixlist.txt into FRST folder without running FRST again?

Thanks