Author Topic: MALICIOUS URL BLOCKED! dances.us??? What is going on???  (Read 26141 times)

0 Members and 1 Guest are viewing this topic.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89116
  • No support PMs thanks
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #45 on: August 18, 2011, 01:07:21 PM »
I remember doing this scan, falling asleep for a bit, and waking up to my computers death! Not to sound ungrateful or anything but....IDK about this... :-\

Well this scan, is analytical to obtain a log file, it doesn't take any action, unless you give it directions (which you shouldn't without guidance).

So I don't know what happened but it certainly wasn't initiated by this scan. Your choice to run it or not, if you don't there will be no way to check this without using yet another tool to analyse the MBR and who is to say that would be any different.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #46 on: August 18, 2011, 07:50:06 PM »
Not really as aswMBR was just scanning - it will fix nothing until told to

Does the computer boot at all

MumtazG38

  • Guest
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #47 on: August 18, 2011, 08:00:36 PM »
If by boot you mean can I access f12 etc, or does it startup normally then yes. Nothing about startup has changed after the reinstall. I have the option to boot from usb/cd if its plugged in/inserted...

btw...log attached.
« Last Edit: August 18, 2011, 08:02:35 PM by MumtazG38 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #48 on: August 18, 2011, 08:39:13 PM »
The MBR looks good - so lets see if anything was transfered over during the re-install

Download OTL  to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
CREATERESTOREPOINT


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Post both logs

MumtazG38

  • Guest
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #49 on: August 19, 2011, 04:46:46 AM »
both of em....

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #50 on: August 19, 2011, 09:24:24 PM »
Found it - were you on Facebook recently ?

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :OTL
    IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 45 90 2A 06 B0 8F CD 40 9D C6 C5 4D 65 68 BE 84 [binary data]
    IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 45 90 2A 06 B0 8F CD 40 9D C6 C5 4D 65 68 BE 84 [binary data]
    IE - HKU\S-1-5-21-3562891666-3718405954-1392146742-1000\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 45 90 2A 06 B0 8F CD 40 9D C6 C5 4D 65 68 BE 84 [binary data]
    [2011/07/26 21:16:59 | 000,000,000 | ---D | M] (XUL Cache) -- C:\Users\Amna\AppData\Roaming\Mozilla\Firefox\Profiles\288d30p0.default\extensions\{00fc45be-c90e-43d7-8a1d-82b3fdbf6c41}
    O2 - BHO: (no name) - {062A9045-8FB0-40CD-9DC6-C54D6568BE84} - File not found
    O2 - BHO: (Facetheme) - {3fdba1ba-ae28-4045-9048-4ed2f3865629} - C:\Program Files (x86)\Object\bho_project.dll (InternetEngine)

    :Reg
    [HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
    XMLHTTP_UUID_Default=-
    [HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
    XMLHTTP_UUID_Default=-
    [HKU\S-1-5-21-3562891666-3718405954-1392146742-1000\SOFTWARE\Microsoft\Internet Explorer\Main]
    XMLHTTP_UUID_Default=-


    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

MumtazG38

  • Guest
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #51 on: August 20, 2011, 09:47:22 AM »
Well, yeah...I mean, I'm not much of a facebook-er but I do use it a bit. Mainly just to upload pics of my son so our family back home can see them. Should I stop using facebook then???

....log attached.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #52 on: August 20, 2011, 01:09:14 PM »
No but be very cautious on what links you click

One more to kill have the alerts ceased ?

 Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :OTL
    [2011/07/17 00:57:34 | 000,000,000 | ---D | M] (FaceTheme - Change your Facebook layout!) -- C:\PROGRAM FILES (X86)\OBJECT\FACETHEME


    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

MumtazG38

  • Guest
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #53 on: August 20, 2011, 04:51:30 PM »
YAY!!! I think that one done it!  :-* I'm so happy to finally rid my computer of that horrible thing, whatever it was.

Ok, gonna try that last fix you mentioned, just for good measure!

THANK YOU ESSEXBOY!!!!! ;D ;D ;D

MumtazG38

  • Guest
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #54 on: August 20, 2011, 05:06:06 PM »
Here's that log I promised! Hope everything looks dandy. :D

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #55 on: August 20, 2011, 05:17:08 PM »
You might actually consider binning Firefox and updating to IE9 - now there is a heretical statement

Any further problems ?

MumtazG38

  • Guest
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #56 on: August 20, 2011, 05:19:39 PM »
BIN FIREFOX??? Over my cold, limp and very dead body!!! Firefox is my love, sorry. Can't do it. IE scares me! Sorry, but if that is the choice I must make....then the answer remains the same. WE LOVE YOU FIREFOX!!!

 ::) ;)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #57 on: August 20, 2011, 05:24:40 PM »
BIN FIREFOX??? Over my cold, limp and very dead body!!! Firefox is my love, sorry. Can't do it. IE scares me! Sorry, but if that is the choice I must make....then the answer remains the same. WE LOVE YOU FIREFOX!!!

I agree with you.
But, you should add NoScript to FF, if you don't already have it.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

MumtazG38

  • Guest
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #58 on: August 20, 2011, 05:27:29 PM »
I did have that before the reinstall. Hadn't remembered to get it again...will do that now. Thanks.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MALICIOUS URL BLOCKED! dances.us??? What is going on???
« Reply #59 on: August 20, 2011, 05:27:48 PM »
We are actually discussing this elsewhere, purely from the malware point of view - so I just thought I would toss the hand grenade in and run  ;D

Edit : The initial post that started our discussion  http://www.geekstogo.com/forum/topic/304629-internet-explorer-9-security-best-once-again/
« Last Edit: August 20, 2011, 05:30:55 PM by essexboy »