Author Topic: Strange behaviour - virus?  (Read 3729 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Strange behaviour - virus?
« on: October 16, 2014, 01:12:54 AM »
Very frequently Firefox say -' impossible to reach the server' and sometime open a web page 'italian police pc lock' (an average of 1 or 2 time for week), or some like and Avast prompt that prevents from the Trojan html:FakeLock-F infected web page.
A following Scan find nothing. Same thing say Malwarebytes , Superantispyware and Microsoft Security Essential.
Also i tray to find on web a virus free program AdwCleaner without results. Avast lock the dowload because file infected. Were a safe link to program?
Thanks
« Last Edit: October 16, 2014, 02:31:10 AM by ataro »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Strange behaviour - virus?
« Reply #1 on: October 16, 2014, 05:14:12 AM »
Attach your basic logs. (MBAM, FRST and aswMBR..!!)
Instructions: https://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Strange behaviour - virus?
« Reply #2 on: October 16, 2014, 10:31:20 PM »
Attach your basic logs. (MBAM, FRST and aswMBR..!!)
Instructions: https://forum.avast.com/index.php?topic=53253.0
The logs.
Thanks

REDACTED

  • Guest
Re: Strange behaviour - virus?
« Reply #3 on: October 17, 2014, 10:21:19 AM »
Today starting Firefox, yet on about:home mozilla page, Avast say that locked web page http:\\94.249.192.104/chk.html{gzip} because infected by JS:ScriptlP-inf[Trj] ......
« Last Edit: October 17, 2014, 10:23:56 AM by ataro »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Strange behaviour - virus?
« Reply #4 on: October 17, 2014, 03:12:23 PM »
Does this occur on the same web page ?  As to me it appears to be a website infection

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
FF Extension: No Name - {F003DA68-8256-4b37-A6C4-350FA04494DF} [Not Found]
FF Extension: No Name - wrc@avast.com [Not Found]
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: Strange behaviour - virus?
« Reply #5 on: October 17, 2014, 06:31:58 PM »
The log in attach.
The web address redirect occur with a time chosen randomly. Not on the same page. The pages were on i navigate is surely safe, i navigate on it by the past 2 year without problems. Seems that FF redirect on an other page and this new page are blocked by Avast.
This morning i've done a hardware reset of the adsl router modem. After this Firefox dont say anymore 'impossible to connect to server'. I hope that it continue doing so.
« Last Edit: October 17, 2014, 06:50:10 PM by ataro »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Strange behaviour - virus?
« Reply #6 on: October 17, 2014, 07:08:01 PM »
You may have had a router infection, let me know of any change

REDACTED

  • Guest
Re: Strange behaviour - virus?
« Reply #7 on: October 17, 2014, 07:37:52 PM »
You may have had a router infection, let me know of any change
A router infection? How are this possible? How i can prevent this?
I'll let you know changes ...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Strange behaviour - virus?
« Reply #8 on: October 17, 2014, 08:34:50 PM »
The best way to prevent it is to change the router password from default, as the malware knows all the default passwords

REDACTED

  • Guest
Re: Strange behaviour - virus?
« Reply #9 on: October 18, 2014, 04:04:13 PM »
Good.
Also Windows have pass now (no before).
Since now seems no more problems and redirections.
Also i've done a scan vith new AdwCleaner 4.0
Follows log (there are something fixed).
The next week, also if i dont have anymore problem, i'll do a report (I hope the last one).

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Strange behaviour - virus?
« Reply #10 on: October 18, 2014, 04:10:09 PM »
That is good, when you are happy I will tidy up