Author Topic: Blocked web keep poping  (Read 14948 times)

0 Members and 1 Guest are viewing this topic.

coffecat

  • Guest
Blocked web keep poping
« on: May 23, 2012, 01:13:59 PM »
At the start there was a .zip file in my mail and i opened it (it was from well known companie) later i discover in their forum that it was attack from some hackers that send thise .zip files to their clients.

I made a full scan on my computer.
A pop-up keep poping saying that URL is being blocked, then it increased to 4 URL's. Now they keep poping on my screen, i dont enter their websites.

What are my chances?
Thanks/
« Last Edit: May 23, 2012, 01:33:56 PM by coffecat »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89056
  • No support PMs thanks
Re: Blocked web keep poping
« Reply #1 on: May 23, 2012, 02:22:18 PM »
Can you post an image of the avast alert window (attach it to your post using the "Attachments and other options" link below the reply window).

- This needs further analysis by a malware removal specialist:
Go to this topic http://forum.avast.com/index.php?topic=53253.0 for information on Logs to assist in cleaning malware. Use the information about getting and using the tools and attach the logs here, not in the LOGS topic.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

coffecat

  • Guest
Re: Blocked web keep poping
« Reply #2 on: May 23, 2012, 03:35:15 PM »
please excuse me for the background

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89056
  • No support PMs thanks
Re: Blocked web keep poping
« Reply #3 on: May 23, 2012, 04:16:27 PM »
Looks like something is misusing wuauclt.exe, Windows Update AutoUpdate Client, to connect to malicious sites (assuming that this is a legit wuauclt.exe file), http://www.neuber.com/taskmanager/process/wuauclt.exe.html. There would obviously be no legit reason for this file to connect to this site.

So avast is preventing it download more malware.

- This needs further analysis by a malware removal specialist:
Go to this topic http://forum.avast.com/index.php?topic=53253.0 for information on Logs to assist in cleaning malware. Use the information about getting and using the tools and  attach the logs here, not in the LOGS topic.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

coffecat

  • Guest
Re: Blocked web keep poping
« Reply #4 on: May 23, 2012, 06:10:54 PM »
Ok there are the logs, sorry for renaming the first one (i copied it and paste it in new .txt file, sorry) its from MalwareBytes, wich is blocking a malware.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89056
  • No support PMs thanks
Re: Blocked web keep poping
« Reply #5 on: May 23, 2012, 06:35:49 PM »
OK, it may be a little while before one of the malware removal specialists can check them out (time zone).
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

coffecat

  • Guest
Re: Blocked web keep poping
« Reply #6 on: May 23, 2012, 07:13:02 PM »
Ok i will wait, but one question. I did a scan with Avast! Free but the malware was still inside my computer (they were 3).

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89056
  • No support PMs thanks
Re: Blocked web keep poping
« Reply #7 on: May 23, 2012, 07:53:12 PM »
What were the file names, folders and malware name of the detections ?

Hopefully essexboy should be on-line soon, he should be back from work soon.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Blocked web keep poping
« Reply #8 on: May 23, 2012, 08:01:11 PM »
Hi I will need to use something a tad stronger

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks
  • Allow the installation of the recovery console




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89056
  • No support PMs thanks
Re: Blocked web keep poping
« Reply #9 on: May 23, 2012, 08:12:38 PM »
Thanks for joining the topic essexboy.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

coffecat

  • Guest
Re: Blocked web keep poping
« Reply #10 on: May 23, 2012, 08:36:43 PM »
I pressed Exit on MalwareBytes, then ComboFix asked me to make other machine. MalwareBytes turned on after the reboot was done.
Im sure i saw MalwareBytes blocked that incoming malicious website after the reboot, once.
« Last Edit: May 23, 2012, 08:38:36 PM by coffecat »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Blocked web keep poping
« Reply #11 on: May 23, 2012, 08:38:44 PM »
Is Avast still alerting now ?


coffecat

  • Guest
Re: Blocked web keep poping
« Reply #12 on: May 23, 2012, 08:43:33 PM »
MalwareBytes just alerted now, Avast! didnt

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Blocked web keep poping
« Reply #13 on: May 23, 2012, 08:48:53 PM »
I must admit I am getting a tad tired of the aggressive nature of MBAM in its blocking

Could you post the blocking log please so that I can see what it is alerting on


coffecat

  • Guest
Re: Blocked web keep poping
« Reply #14 on: May 23, 2012, 08:58:11 PM »
The after scan window says No malicious items were detected.