Author Topic: Url:Mal pop-ups from seemly sound sources  (Read 38044 times)

0 Members and 1 Guest are viewing this topic.

jeffce

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #15 on: May 29, 2012, 04:27:45 AM »
Hi,

Good job running that. 

Download Combofix from either of the links below, and save it to your desktop. 
Link 1
Link 2

**Note:  It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

--------------------------------------------------------------------

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
    When finished, it will produce a report for you. 
  • Please post the C:\ComboFix.txt for further review.

Sprey

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #16 on: May 29, 2012, 11:31:38 AM »
Hi I've attached the combofix log. Looking at it it looks like I forgot to turn off windows defender, so if that's a problem just tell me and I'll run it again :)

jeffce

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #17 on: May 29, 2012, 01:56:52 PM »
No you ran it just fine.  If there were a problem I would just have you run it again.  :)
------------------

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
Code: [Select]
ClearJavaCache::

RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.



  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Attach the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
----------

Sprey

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #18 on: May 29, 2012, 04:37:23 PM »
Ok, combofix round two here we go :)

Also, I was just thinking (after getting another couple of pop-ups following this last round of combo fix, one from avast.setup and one from svchost.exe both Url:Mal) would it be worth reinstalling avast? Or is the problem definitely not with avast? It's just that, for example, the malwarebytes protection module is running now on my system and doesn't pick up these supposed malicious url connections, just avast...

EDIT: came back to my computer and the avast screensaver scan just found OTL.exe to be a threat of type malware-gen, but I downloaded it from your link so am I safe to "do nothing" with it?
« Last Edit: May 29, 2012, 11:43:01 PM by Sprey »

jeffce

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #19 on: May 30, 2012, 02:03:40 AM »
Hi,

Sorry been a bit busy today...sold house and looking for new one, but I will return as quickly as I can.

No you can leave OTL alone.  Some of the tools that we use will pop up on scanners but they are False Positives.  :)

jeffce

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #20 on: May 31, 2012, 02:45:41 PM »
Hi,

Sorry for the delay.  Be sure to PM me if you find I haven't responded in two days. 

Your ComboFix log looks good.  Are you still receiving the popups? 

Sprey

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #21 on: May 31, 2012, 03:07:39 PM »
Yes I am still receiving them :( and also Call of Duty MW3 was being a bit choppy yesterday when I booted it up (it isn't normally), but I can't remember the last time I played and thus I don't know if this is a response to malware, or one of the fixes that I ran under your instruction (ofc I'm not blaming you, the help was appreciated, I just can't tell what caused this sudden choppiness in game...)

What do you think the next step should be? (attached is my last pop-up from avast)

EDIT: don't worry about the delay, it sounds like you are very busy at the moment with your new house hunt :)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89014
  • No support PMs thanks
Re: Url:Mal pop-ups from seemly sound sources
« Reply #22 on: May 31, 2012, 03:25:15 PM »
<snip>
Sorry for the delay.  Be sure to PM me if you find I haven't responded in two days. 
<snip>

Jeff - Unfortunately forum members that have less than 20 posts aren't able to use the PM function, an anti-spam measure.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

jeffce

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #23 on: May 31, 2012, 04:30:18 PM »
Quote
Jeff - Unfortunately forum members that have less than 20 posts aren't able to use the PM function, an anti-spam measure.
Quite right sir.  Thank you.  :)

jeffce

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #24 on: May 31, 2012, 04:32:24 PM »
Hi,

To be on the safe side let's uninstall and then reinstall Chrome.  Be sure that you have all of your passwords and favorites/bookmarks saved so that you can put them back.    Let me know when you have those saved and I will get you the instructions on how to remove Chrome and then get a fresh copy.  :)

Sprey

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #25 on: May 31, 2012, 05:33:34 PM »
Ok, I've synced all my data so I should be ok to re-install and then get back all my settings/bookmarks etc. so I am ready for the re-install.


jeffce

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #26 on: May 31, 2012, 05:38:58 PM »
Hi,

Ok....

Please do the following:

Hold down the Windows key and press R to open a run box
type the following text into the run box

appwiz.cpl

This will open your Programs And Features. A list of installed programs will populate

Remove the following programs:

Google Chrome
----------

Then visit the page here >> https://www.google.com/chrome to download and install a new copy of Google Chrome. 

Once installed let me know if you are still receiving the popups.  :)

Sprey

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #27 on: May 31, 2012, 05:50:33 PM »
Haha, just after uninstall (untitled.png) and just after re-install (untitled2.png)

Problem is still here :(

(I am now going to reboot but I doubt that'll change much)

jeffce

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #28 on: May 31, 2012, 06:04:46 PM »
Run a new scan with OTL and attach the new log that is made. 

Sprey

  • Guest
Re: Url:Mal pop-ups from seemly sound sources
« Reply #29 on: May 31, 2012, 06:11:15 PM »
ok, ran a quick scan of all users with LOP and purity unchecked... OTL log 4 attached.