Author Topic: I need help: my a! has gone mad  (Read 2273 times)

0 Members and 1 Guest are viewing this topic.

Adri.Pig

  • Guest
I need help: my a! has gone mad
« on: April 13, 2011, 03:46:28 AM »
Hi.
I keep getting this message every 2 minutes about the computer is being blocked from communicating with a dangerous site.
It's really drive me crazy.
What do I do with this?

The object is: 62.122.73.203/545/getcfg.php
The path is: C:\USERS\ADRY\APPdata\Tocal\Temp\dat6248.TMP.EXE

Im not precisely an expert... so be nice with me.

Thanks.
« Last Edit: April 13, 2011, 03:49:55 AM by Adri.Pig »

Offline DavidR

  • Avast √úberevangelist
  • Certainly Bot
  • *****
  • Posts: 88455
  • No support PMs thanks
Re: I need help: my a! has gone mad
« Reply #1 on: April 13, 2011, 04:16:51 AM »
The process responsible for probably trying to access malicious sites, C:\USERS\ADRY\APPdata\Tocal\Temp\dat6248.TMP.EXE, looks like an undetected piece of malware, probably a trojan downloader.

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page. You can't do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

If multiple scanners detect this it should be sent to avast:
Send the dat6248.TMP.EXE sample to avast as a Undetected Malware:
Open the chest and right click in the Chest and select Add, navigate to where you have the sample and add it to the chest (see image). Once in the chest, right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update.

~~~~
Now try and clear/empty all your temp folders, this may well be protected so it might not work.

So try this tool TFC - Temp File Cleaner by OldTimer
http://www.geekstogo.com/forum/files/file/187-tfc-temp-file-cleaner-by-oldtimer/
TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC. - So as you can see it is important to do the above work and send the sample to avast before running this tool.

####
Now - If you haven't already got this software (freeware), download, install, update and run it and report the findings (it should product a log file).

Don't worry about reported tracking cookies they are a minor issue and not one of security, allow SAS to deal with them though. - See http://en.wikipedia.org/wiki/HTTP_cookie.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 23.10.6086 (build 23.10.8563.800) UI 1.0.784/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Adri.Pig

  • Guest
Re: I need help: my a! has gone mad
« Reply #2 on: April 14, 2011, 04:39:41 AM »
Thank you very much.  :)

Offline DavidR

  • Avast √úberevangelist
  • Certainly Bot
  • *****
  • Posts: 88455
  • No support PMs thanks
Re: I need help: my a! has gone mad
« Reply #3 on: April 14, 2011, 02:45:16 PM »
You're welcome.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 23.10.6086 (build 23.10.8563.800) UI 1.0.784/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security