Author Topic: Threat detected/ aborted connection on 172.86.120.188 infected with URL:Mal  (Read 6813 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Hey All,
 Let me start by saying I appreciate any help given! A few days ago I started getting a message saying threat secured/ aborted connection on 172.86.120. 188 infected with URL:MAL.

Threat name: URL:Mal
URL: http:172.86.120.188/current/runtime.exe
Process C:\windows\system32\svchost.exe
Detected by Web Shield
Status   Connection aborted

I think I followed the instructions in the sticky post and included my log files. Again, any help will be greatly appreciated!!!

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
This will restart your PC automatically so save your work before doing this.

  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
EmptyTemp:
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

REDACTED

  • Guest
Here it is..thanks again!

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
What is status now?

REDACTED

  • Guest
Same message from avast popping up every ten minutes or so.

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
cmd: bitsadmin /list /allusers /verbose
cmd: bitsadmin /reset /allusers
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

REDACTED

  • Guest
Posting now, status is the same just in case you needed that info. Avast warning popping up every ten min or so..Thanks again for helping!
« Last Edit: June 11, 2018, 12:58:38 AM by The Horror Above »

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
  • Please download PowerRun from here.
  • Extract it and run PowerRun_x64.exe
  • Right click on first entry in list (%SystemRoot%\System32\cmd.exe) and click on Run
  • Command Prompt window with SYSTEM privilegies should appear. Type this command and press Enter:
Code: [Select]
bitsadmin /reset /allusers
  • Make screenshot of Command Prompt window and attach it here please.


REDACTED

  • Guest
Here it is. Ive said before but I really appreciate the help!

REDACTED

  • Guest
sorry posted the wrong one..here is the right one ...

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Hmm. What is system status now? If same, please read carefully and follow again instructions I wrote.

REDACTED

  • Guest
This is what I'm seeing after slowly going step by step..

« Last Edit: June 12, 2018, 06:03:32 AM by The Horror Above »

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Are you still getting Avast notifications for blocked URL?

REDACTED

  • Guest
Yes I'm still getting them ,thanks!

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
cmd: bitsadmin /list /allusers /verbose
cmd: bitsadmin /reset /allusers
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.