Author Topic: Skegnessasc Malware. Help!  (Read 2207 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Skegnessasc Malware. Help!
« on: September 19, 2017, 11:06:47 AM »
Hi there,

Throughout today I have been receiving alerts from avast that it has blocked the threat skegnessasc.org. I have run a full system scan and also run a Malwarebytes scan, both have come back with nothing. I hope someone here can help!

Attached are the logs as per the pinned topic.

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Skegnessasc Malware. Help!
« Reply #1 on: September 19, 2017, 11:29:25 AM »
Can you make screenshot of Avast message?

REDACTED

  • Guest
Re: Skegnessasc Malware. Help!
« Reply #2 on: September 19, 2017, 11:46:16 AM »
This is the avast popup.

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Skegnessasc Malware. Help!
« Reply #3 on: September 19, 2017, 12:26:07 PM »
This will restart your system so save your work before this.

  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
RemoveProxy:
cmd: reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" /v SearchList /d "" /f
Reboot:
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

REDACTED

  • Guest
Re: Skegnessasc Malware. Help!
« Reply #4 on: September 19, 2017, 12:45:08 PM »
I have done that, here is the log. Thanks for your help

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Skegnessasc Malware. Help!
« Reply #5 on: September 19, 2017, 05:18:41 PM »
Does Avast still shows alerts for Skegnessasc?

REDACTED

  • Guest
Re: Skegnessasc Malware. Help!
« Reply #6 on: September 20, 2017, 12:38:44 AM »
It does, yes

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Skegnessasc Malware. Help!
« Reply #7 on: September 20, 2017, 01:02:10 AM »
  • Run FRST
  • Paste following text in text box
Code: [Select]
skegnessasc.org
  • Click on Search registry
  • Attach Search.txt to your message

REDACTED

  • Guest
Re: Skegnessasc Malware. Help!
« Reply #8 on: September 20, 2017, 01:24:34 AM »
Here is the log, doesn't show anything though

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Skegnessasc Malware. Help!
« Reply #9 on: September 20, 2017, 02:05:27 AM »
  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
Hosts:
cmd: bitsadmin /RESET /ALLUSERS
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

REDACTED

  • Guest
Re: Skegnessasc Malware. Help!
« Reply #10 on: September 20, 2017, 02:12:43 AM »
Here is the log. Thanks again for your help. What shall I do now?

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Skegnessasc Malware. Help!
« Reply #11 on: September 20, 2017, 10:53:55 AM »
Are you still getting popups for blocked URLs?

REDACTED

  • Guest
Re: Skegnessasc Malware. Help!
« Reply #12 on: September 20, 2017, 10:48:37 PM »
Hello

I was still getting popups, but since restarting I have not seen any. Should it be gone now? I was never able to pick it up on scans so it is hard to tell. Thanks for your help!

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Skegnessasc Malware. Help!
« Reply #13 on: September 20, 2017, 11:36:54 PM »
Yup, it is gone now.

Sledeća procedura će implementirati završno čišćenje.

:arrow:  Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

[size=10]Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.[/size]