Author Topic: Threat Blocked: http://sso.anbtr.com/domain/wpad.work  (Read 11332 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« on: August 04, 2016, 10:45:41 PM »
Avast continues to alert me fairly regularly of this

Object
hxtp://sso.anbtr.com/domain/wpad.work

Infection
URL:Mal

Process
C:\\Windows\System32\svchost.exe

Scanning with avast has proven to be ineffective, I've also uninstalled and reinstalled chrome (the only browser I use regularly)  This seemed to ramp up after uninstalling forticlient which we were required to add to access a client remotely.  Any help would be appreciated.

I've attached logs from Malwarebytes, Farbar, and aswMBR
« Last Edit: August 05, 2016, 09:25:39 AM by Milos »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #1 on: August 04, 2016, 10:54:16 PM »
https://virustotal.com/en/url/8e11fb274ae4f96d9c0dc009f84cd4510dc3d36dabc73b7ee04c1a4f35789f69/analysis/1470343853/

Quote
Dr.Web > known infection source
Websense ThreatSeeker > bot networks. compromised websites


@dbrisendine  is notified, it may take some hours before he is online




Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89679
  • No support PMs thanks
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #2 on: August 05, 2016, 12:18:01 AM »
Avast continues to alert me fairly regularly of this

Object  -  hXXp://sso.anbtr.com/domain/wpad.work
Infection  -  URL:Mal
Process -  C:\\Windows\System32\svchost.exe
<snip>

Can you modify your link to the suspect site in your post to avoid accidental exposure, change the http to hXXp (not active/clickable) as I have done in a quote of your post.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Sirmer

  • Avast team
  • Sr. Member
  • *
  • Posts: 324
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #3 on: August 05, 2016, 07:30:26 AM »
This detection is correct, this link belongs to Angler Exploit Kit

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #4 on: August 05, 2016, 07:53:38 AM »


FIRST >>>>

Please go to START (Windows Orb) >> Control Panel >> Uninstall a Program or Programs and Features and remove the following (if listed):

QuickTime 7

To do so, left clicking on the name once and then click Uninstall/Change at the bar above the list window. 

Follow the prompts of the uninstaller BUT please read carefully any questions it asks before answering; some uninstallers will try and deceive you into keeping the software.


SECOND >>>>

Fix with Farbar Recovery Scan Tool
This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.


LAST >>>>

Run a search with FRST.
  • Right click on FRST on your desktop and select "Run as Administrator..." When the tool opens click Yes to disclaimer.
  • Type wpad into the Search Box.
  • Press the Search Registry button.
  • It will produce a log called search.txt or SearchReg.txt in the same directory the tool is run from.
  • Please attach the log file back here.
« Last Edit: August 05, 2016, 09:02:02 AM by dbrisendine »
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #5 on: August 05, 2016, 04:29:00 PM »
Here's what I found.  I'm still getting an alert from avast
« Last Edit: August 05, 2016, 04:30:54 PM by corey34 »

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #6 on: August 06, 2016, 08:19:53 AM »

Fix with Farbar Recovery Scan Tool
This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #7 on: August 08, 2016, 03:58:35 PM »
I haven't had an alert since I applied the last fix. Here is the log, hopefully this took care of it.  I'll be back to donate or update later.

REDACTED

  • Guest
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #8 on: August 08, 2016, 04:01:28 PM »
No sooner than I posted that reply I got another alert with the same information as before.

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #9 on: August 08, 2016, 05:53:12 PM »
Stubborn thing this is .....

FIRST >>>

Run a search with FRST.
  • Right click on FRST on your desktop and select "Run as Administrator..." When the tool opens click Yes to disclaimer.
  • Type sso.anbtr.com;wpad.work into the Search Box.
  • Press the Search Registry button.
  • It will produce a log called search.txt or SearchReg.txt in the same directory the tool is run from.
  • Please attach the log file back here.


SECOND >>>>

AdwCleaner by Xplode

Download AdwCleaner from here or from here. Save the file to the desktop.


NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.

Close all open windows and browsers.

  • Vista/7/8 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
    You will see the following console:

  • Click the Scan button and wait for the scan to finish.
  • After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: Waiting for action. Please uncheck elements you don't want to remove.
  • Click the Clean button.
  • Everything checked will be deleted.
  • When the program has finished cleaning a report appears.
  • Once done it will ask to reboot, allow this

  • On reboot a log will be produced; please attach that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[C#].txt

    Optional:

    NOTE: If you see AVG Secure Search being targeted for deletion, Here's Why and Here. You can always Reinstall it.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #10 on: August 08, 2016, 07:41:03 PM »
Here are the files, I got a pop up before I could even type the reply

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #11 on: August 08, 2016, 11:36:14 PM »
When you removed and re-installed Chrome, did you create a fresh new profile or did you re-use your existing profile?


Download zoek.exe from here: Bleepingcomputer
  • Close/disable all anti virus and anti malware programs so they do not interfere download or run of Zoek.exe (Here or here you can read a manual how to disable your security applications.)
  • Doubleclick zoek.exe to start the program.
  • Click the More Options button and select the "Do a Deep Scan" option.  Also, make sure the Scan All Users option is selected.
  • Close any open browsers.
  • Click the "Run script" button and wait patiently.
  • When finished the logfile will be opened in notepad.
  • The zoek-results.log can also be found on your system drive.
  • Please post the logfile for further review in your next comment.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #12 on: August 09, 2016, 04:14:30 PM »
I didn't initially create a new profile, I just uninstalled and reinstalled.  This morning I went ahead and created a fresh new profile for chrome then ran zoek.

I've attached the logfile

Chrome automatically resinstalled Avast and Google Docs extensions

Got an alert pop up as soon as I re enabled Avast
« Last Edit: August 09, 2016, 04:20:50 PM by corey34 »

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #13 on: August 11, 2016, 07:25:18 AM »

Download zoek.exe from here: Zoek.exe at Bleepingcomputer (if you don't have it any more.)
  • Close/disable all anti virus and anti malware programs so they do not interfere with the download or running of Zoek.exe
       (Here or here you can read a manual on how to disable your security applications.)
  • Doubleclick zoek.exe to start the program.
  • Copy and paste the following script in the code box:
  • Note: This script is written for usage on this users computer, do not use it on another computer even if the problems are similar :!:
Code: [Select]
createsrpoint;
autoclean;
iedefaults;
chrdefaults;
FFdefaults;
bitsadmin /reset /allusers >>"%temp%\log.txt";b
ipconfig /flushdns >>"%temp%\log.txt";b
emptyalltemp;
resetIEproxy;
  • Close any open browsers.
  • Click the Run script button and wait patiently.
  • When finished the logfile will be opened in notepad.
  • If a reboot is needed the logfile will be opened after reboot.
  • The zoek-results.log can also be found on your system drive.
  • Please post the logfile for further review in your next comment.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Threat Blocked: http://sso.anbtr.com/domain/wpad.work
« Reply #14 on: August 11, 2016, 04:14:10 PM »
ran the script, machine rebooted, I opened outlook, chrome, and slack then the notepad with the zoek log popped up. 

Just got another avast alert.

Attaching the zoek file.