Author Topic: this new malware redirect virus  (Read 3462 times)

0 Members and 1 Guest are viewing this topic.

celtic_crossing1975

  • Guest
this new malware redirect virus
« on: July 07, 2011, 08:30:23 PM »
heres the new notepad text...and im still getting the malicious url blocked message from avast


All Processes Killed
[Registry - Safe List]
Registry value HKEY_USERS\S-1-5-21-3038147022-3846470096-3322562731-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found.
Registry value HKEY_USERS\S-1-5-21-3038147022-3846470096-3322562731-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
[Files/Folders - Modified Within 30 Days]
File C:\ProgramData\~38067960 not found!
File C:\ProgramData\~38067960r not found!
File C:\ProgramData\38067960 not found!
File C:\Users\carol\AppData\Roaming\7E3A.568 not found!
[Files - No Company Name]
File C:\ProgramData\~38067960 not found!
File C:\ProgramData\~38067960r not found!
File C:\ProgramData\38067960 not found!
File C:\Users\carol\AppData\Roaming\7E3A.568 not found!
[Empty Temp Folders]
 
 
User: All Users
 
User: carol
->Temp folder emptied: 184581 bytes
->Temporary Internet Files folder emptied: 1030296 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 470 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 608 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 49554 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 1.00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: carol
->Flash cache emptied: 0 bytes
 
User: Default
->Flash cache emptied: 0 bytes
 
User: Default User
->Flash cache emptied: 0 bytes
 
User: Public
 
Total Flash Files Cleaned = 0.00 mb
 
Restore point Set: OTS Restore Point
< End of fix log >
OTS by OldTimer - Version 3.1.44.0 fix logfile created on 07072011_130044

Files\Folders moved on Reboot...
C:\Users\carol\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Users\carol\AppData\Local\Temp\~DF17D812D6DF0F827D.TMP not found!
File\Folder C:\Users\carol\AppData\Local\Temp\~DF1B0BEF3B91F9BB4A.TMP not found!
File\Folder C:\Users\carol\AppData\Local\Temp\~DF30CAF70597E7F622.TMP not found!
File\Folder C:\Users\carol\AppData\Local\Temp\~DF3722B3F469BD5135.TMP not found!
File\Folder C:\Users\carol\AppData\Local\Temp\~DF5DF534D25C91779A.TMP not found!
File\Folder C:\Users\carol\AppData\Local\Temp\~DF744C5A7A2CF63C01.TMP not found!
File\Folder C:\Users\carol\AppData\Local\Temp\~DF9F91012669441A98.TMP not found!
File\Folder C:\Users\carol\AppData\Local\Temp\~DFA3F8373DD821E576.TMP not found!
File\Folder C:\Users\carol\AppData\Local\Temp\~DFE09CE4CFF8D07DD9.TMP not found!
File\Folder C:\Users\carol\AppData\Local\Temp\~DFFE3A7FC559893065.TMP not found!
C:\Users\carol\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
File move failed. C:\Windows\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89116
  • No support PMs thanks
Re: this new malware redirect virus
« Reply #1 on: July 07, 2011, 09:29:55 PM »
Can you keep this with your existing topic, http://forum.avast.com/index.php?topic=81210.0 otherwise it makes it hard for essexboy to keep track of the information.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

com155

  • Guest
Re: this new malware redirect virus
« Reply #2 on: July 09, 2011, 06:27:27 AM »
try downloading mbam from here:
http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html

do a full scan and hit remove selected if it shows anything in the results.

post the log fie in next comment.


regards,
com155.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89116
  • No support PMs thanks
Re: this new malware redirect virus
« Reply #3 on: July 09, 2011, 03:00:33 PM »
Did you read my post, the OP has an open topic already, so this one shouldn't be used.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security