Author Topic: URL:Mal infections messages everytime computer 'wakes up'  (Read 1843 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
URL:Mal infections messages everytime computer 'wakes up'
« on: July 03, 2015, 10:15:50 PM »
Could you please advise me how to eliminate any threats and the detection messages that are very frequently occurring due to a URL:Mal infection  ?

After every resumption of a Windows session from hibernation, and new session, we see a set of detection messages for something called URL:Mal coming from svchost.exe to a variety of addresses.  There don't appear to be any other issues with the computer , but we're concerned that these detections are inidcating a problem that needs to be resolved.  At minimum, the messages are annoying and we'd like to eliminate them.

I have followed the instructions at the "Logs to assist" topic, and attached the files indicated.

Here's an example, we see many of these 6 - 20 every day all at once, and then never again until a session resumes or a new session.
---------------
URL: http://alwaysisobar.com/4141/SystemVisual_142669159165880.dll
Infection: URL:Mal
Process: C:\Windows\System32\svchost.exe
---------------

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: URL:Mal infections messages everytime computer 'wakes up'
« Reply #1 on: July 03, 2015, 10:18:43 PM »
Hello,


Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on icon and select Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
Code: [Select]
createsrpoint;
autoclean;
bitsadmin /reset /allusers;b
emptyalltemp;
ipconfig /flushdns;b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)
Post its content into your next reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: URL:Mal infections messages everytime computer 'wakes up'
« Reply #2 on: July 04, 2015, 06:03:23 PM »
OK.  Ran Zoesk.  PC rebooted.  Notepad displayed zoesk-results file now attached.

Haven't seen any errors yet, but it might be too soon to declare victory.
Please advise if there are any other steps you'd recommend.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: URL:Mal infections messages everytime computer 'wakes up'
« Reply #3 on: July 04, 2015, 06:34:49 PM »
Let me know in few hours if everything is fine.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: URL:Mal infections messages everytime computer 'wakes up'
« Reply #4 on: July 05, 2015, 11:11:28 PM »
All is good here.  No issues since my last post, so it seems like you've solved it.

Thanks very much for your help.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: URL:Mal infections messages everytime computer 'wakes up'
« Reply #5 on: July 06, 2015, 10:31:35 AM »
Post-cleanup procedures:


Download DelFix by Xplode and save it to your desktop.
  • Run the tool by right click on the icon and Run as administrator option.
  • Make sure that these ones are checked:
    • Remove disinfection tools
    • Purge system restore
    • Reset system settings
  • Push Run and wait until the tool completes his work.
  • All tools we used should be gone. Tool will create an report for you (C:\DelFix.txt)
The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE