Author Topic: multiple avast webshield blocked webpage keeps popping up  (Read 11138 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
multiple avast webshield blocked webpage keeps popping up
« on: November 13, 2014, 11:09:52 AM »
it keeps popping up everytime i am connected to the internet (i noticed that at least). i suppose it started after i downloaded the software YTD Video downloader. Please Help! i am quite troubled   :'(

Thank YOU very much :)

i already downloaded the malwarebytes anti malware a while ago and currently scanning my pc now though.

any response would be greatly appreciated. i"ll wait  :)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #1 on: November 13, 2014, 11:23:38 AM »
Attach your basic logs. (MBAM, FRST and aswMBR..!!)
Instructions: https://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #2 on: November 13, 2014, 11:33:44 AM »
Attach your basic logs. (MBAM, FRST and aswMBR..!!)
Instructions: https://forum.avast.com/index.php?topic=53253.0

ok ill do that. thanks :)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #3 on: November 13, 2014, 11:38:25 AM »
You're welcome, awaiting your logs...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #4 on: November 13, 2014, 11:42:25 AM »
here are from malwarebytes

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #5 on: November 13, 2014, 11:44:17 AM »
here are from malwarebytes
It doesn't look complete. ;) Anyway, the most important ones are your FRST logs.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #6 on: November 13, 2014, 12:00:02 PM »
any more?  :D let me know if i missed any thing.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #7 on: November 13, 2014, 12:03:30 PM »
Now you've to wait a bit...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #8 on: November 13, 2014, 12:06:38 PM »
ok  ;D

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #9 on: November 13, 2014, 01:38:20 PM »
Your other thread @ https://forum.avast.com/index.php?topic=160147.0

Desktop.ini is normal. Don't delete it. FRST automatically un hides these files for scanning. They will be re-hidden at the end.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #10 on: November 13, 2014, 02:07:07 PM »
Your other thread @ https://forum.avast.com/index.php?topic=160147.0

Desktop.ini is normal. Don't delete it. FRST automatically un hides these files for scanning. They will be re-hidden at the end.

many thanks, now i know. i thought it was done by a virus avast coudn't detect. thanks again

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #11 on: November 13, 2014, 02:09:06 PM »
You're very welcome.

Wait until someone arrives. I presume Asyn PM'd the removal team. I hope.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #12 on: November 13, 2014, 03:12:30 PM »
Now you've to wait a bit...

Just message me anytime you're done yes? I'll catch it up as soon as I can. Thank you  ;D

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #13 on: November 13, 2014, 04:53:31 PM »
Hi there, the first thing you must do is uninstall Chrome as it has been changed to the developer version, this means there are no safeguards and security restrictions in place

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
Startup: C:\Users\jbmalunao\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com) 
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
BHO: GOSave -> {0563d5ef-f5fd-43fe-94ce-75c30f5c7527} -> C:\Program Files (x86)\GOSave\KSgOcUwXYnL1Cu.x64.dll ()
BHO: No Name -> {40ac3779-0203-46fd-b63a-89149d6e0bdf} ->  No File
BHO-x32: GOSave -> {0563d5ef-f5fd-43fe-94ce-75c30f5c7527} -> C:\Program Files (x86)\GOSave\KSgOcUwXYnL1Cu.dll ()
BHO-x32: No Name -> {40ac3779-0203-46fd-b63a-89149d6e0bdf} ->  No File
R2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36936 2014-09-10] (Just Develop It) <==== ATTENTION
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
Task: {0E60A852-52D4-4588-84BD-CC447371A323} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {E0FB9B8E-B82E-4657-AF09-CE9475B63A97} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Users\jbmalunao\AppData\Local\Google\Chrome\User Data\Default
C:\Program Files (x86)\MyPC Backup
C:\Program Files (x86)\GOSave

EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

REDACTED

  • Guest
Re: multiple avast webshield blocked webpage keeps popping up
« Reply #14 on: November 14, 2014, 08:10:55 AM »
Hi there, the first thing you must do is uninstall Chrome as it has been changed to the developer version, this means there are no safeguards and security restrictions in place

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
Startup: C:\Users\jbmalunao\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com) 
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
BHO: GOSave -> {0563d5ef-f5fd-43fe-94ce-75c30f5c7527} -> C:\Program Files (x86)\GOSave\KSgOcUwXYnL1Cu.x64.dll ()
BHO: No Name -> {40ac3779-0203-46fd-b63a-89149d6e0bdf} ->  No File
BHO-x32: GOSave -> {0563d5ef-f5fd-43fe-94ce-75c30f5c7527} -> C:\Program Files (x86)\GOSave\KSgOcUwXYnL1Cu.dll ()
BHO-x32: No Name -> {40ac3779-0203-46fd-b63a-89149d6e0bdf} ->  No File
R2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36936 2014-09-10] (Just Develop It) <==== ATTENTION
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
Task: {0E60A852-52D4-4588-84BD-CC447371A323} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {E0FB9B8E-B82E-4657-AF09-CE9475B63A97} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Users\jbmalunao\AppData\Local\Google\Chrome\User Data\Default
C:\Program Files (x86)\MyPC Backup
C:\Program Files (x86)\GOSave

EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.


here is the first log :)
kindly check if something might be wrong because I forgot to uninstall first my chrome before I ran the FRST and fixed it. I did the fixing with FRST twice though.  :-\
« Last Edit: November 14, 2014, 08:43:49 AM by jenniferAOI »