Author Topic: Need Help On Blocked Malicious URL  (Read 28882 times)

0 Members and 1 Guest are viewing this topic.

circumstances

  • Guest
Re: Need Help On Blocked Malicious URL
« Reply #30 on: March 29, 2011, 11:18:14 PM »
i don't see a file name. it moved it to quarantine. it said process pid 2272 if that helps.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need Help On Blocked Malicious URL
« Reply #31 on: March 29, 2011, 11:19:14 PM »
Ok it is in memory so it may be part of combofix

circumstances

  • Guest
Re: Need Help On Blocked Malicious URL
« Reply #32 on: March 29, 2011, 11:20:29 PM »
do i need to disable MSE and avast before i run the asw thing i downloaded?

doktornotor

  • Guest
Re: Need Help On Blocked Malicious URL
« Reply #33 on: March 29, 2011, 11:23:43 PM »
do i need to disable MSE and avast before i run the asw thing i downloaded?

Well if you are running both then you should not disable but rather uninstall one.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Need Help On Blocked Malicious URL
« Reply #34 on: March 29, 2011, 11:25:25 PM »
do i need to disable MSE and avast before i run the asw thing i downloaded?
Never install two antivirus (see reply from quietman7)
http://www.bleepingcomputer.com/forums/index.php?s=7c8217673a726b92cfc91ecfd4294a29&showtopic=260844&view=findpost&p=1441638

circumstances

  • Guest
Re: Need Help On Blocked Malicious URL
« Reply #35 on: March 29, 2011, 11:27:12 PM »
i'd like to keep both programs for on-demand scanning, but i don't need both of them doing real time protection at the same time. the avast gave me the heads up on the borekoso thing when mse said nothing, and mse found the trojan caberp.c thing when avast said nothing. which one should i keep for real time scanning, and how do i disable the other one from doing the same, yet leave it on my computer for on-demand scanning?

doktornotor

  • Guest
Re: Need Help On Blocked Malicious URL
« Reply #36 on: March 29, 2011, 11:28:34 PM »
i'd like to keep both programs for on-demand scanning, but i don't need both of them doing real time protection at the same time. which one should i keep for real time scanning, and how do i disable the other one from doing the same, yet leave it on my computer for on-demand scanning?

You simply cannot do this with avast! nor with MSE. They are not intended to be used on-demand.

circumstances

  • Guest
Re: Need Help On Blocked Malicious URL
« Reply #37 on: March 29, 2011, 11:32:14 PM »
thanks doktor. i will uninstall MSE. i have had malwarebytes and superantispyware forever, and eset for several weeks, none of which are doing any real time scanning on my system. should i uninstall all of them as well?

doktornotor

  • Guest
Re: Need Help On Blocked Malicious URL
« Reply #38 on: March 29, 2011, 11:33:36 PM »
MBAM and SAS is fine... ESET is another realtime one, uh. You really are lucky the machine still boots.  :o

circumstances

  • Guest
Re: Need Help On Blocked Malicious URL
« Reply #39 on: March 29, 2011, 11:35:11 PM »
you said it! i'm lucky to find the "power" button!

essexboy, here is the aswmbr log:

aswMBR version 0.9.4 Copyright(c) 2011 AVAST Software
Run date: 2011-03-29 17:30:00
-----------------------------
17:30:00.578    OS Version: Windows 5.1.2600 Service Pack 3
17:30:00.578    Number of processors: 2 586 0x209
17:30:00.593    ComputerName: DGX34231  UserName: Robert
17:30:01.328    Initialize success
17:33:14.406    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
17:33:14.406    Disk 0 Vendor: IC35L060AVV207-0 V22OA66A Size: 57220MB BusType: 3
17:33:16.406    Disk 0 MBR read successfully
17:33:16.406    Disk 0 MBR scan
17:33:18.406    Disk 0 scanning sectors +117178110
17:33:18.406    Disk 0 scanning C:\WINDOWS\system32\drivers
17:33:33.421    Service scanning
17:33:34.812    Disk 0 trace - called modules:
17:33:34.843    ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
17:33:34.843    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b339ab8]
17:33:34.843    3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8b385d98]
17:33:34.843    Scan finished successfully

circumstances

  • Guest
Re: Need Help On Blocked Malicious URL
« Reply #40 on: March 29, 2011, 11:49:24 PM »
ESET uninstalled. MSE uninstalled. (that) crisis averted! thanks doktor.

circumstances

  • Guest
Re: Need Help On Blocked Malicious URL
« Reply #41 on: March 29, 2011, 11:59:02 PM »
while i'm waiting for essexboy to review that last aswmbr information, i got a different warning:

MALICIOUS URL BLOCKED
Object: borekoso.com/set/first.html
Infection: URL:Mal
Action: Blocked
Process: C:\Windows\system32\svchost.exe

circumstances

  • Guest
Re: Need Help On Blocked Malicious URL
« Reply #42 on: March 30, 2011, 01:48:12 PM »
and yet another one this morning:

MALICIOUS URL BLOCKED
Object: borekoso.com//cfg/miniav.plugfirst.html
Infection: URL:Mal
Action: Blocked
Process: C:\Windows\system32\svchost.exe

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need Help On Blocked Malicious URL
« Reply #43 on: March 30, 2011, 07:42:05 PM »
OK big hammer time now

Download ComboFix from one of these locations:


Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.




Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:




Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you.  Please include the C:\ComboFix.txt in your next reply.

circumstances

  • Guest
Re: Need Help On Blocked Malicious URL
« Reply #44 on: March 30, 2011, 07:46:00 PM »
essexboy, welcome back! i'm at work (again), so i will do as you say as soon as i return home. you remember that i downloaded combofix when you instructed me to previously (so it is already present on my desktop), and when i tried to run it i lost my monitor, and you had me reboot?