Author Topic: SVCHOSt causes Mailicious URL popup  (Read 9997 times)

0 Members and 1 Guest are viewing this topic.

Wayno11

  • Guest
SVCHOSt causes Mailicious URL popup
« on: June 08, 2012, 03:32:21 AM »
I recently reinstalled Avast after a failed experiment with McAfee.  Now Avast has found a problem with SHCHost.exe that is causing the Malicious URL popup to come up constantly.  I have attached the rquired files.  I apologize ahead of time for doing attachemtns, but my files went over the 10000 character limit, even if I try to break it down in to seperate posts.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: SVCHOSt causes Mailicious URL popup
« Reply #1 on: June 08, 2012, 07:31:13 AM »
Quote
I apologize ahead of time for doing attachemtns,
that is what you are suppose to do.....attach

also attach a malwarebytes quick scan log......make sure MBAM is updated beforew you scan

wmcgee

  • Guest
Re: SVCHOSt causes Mailicious URL popup
« Reply #2 on: June 08, 2012, 01:25:50 PM »
I have the same malware on my computer an can not get rid of it? I did not see a fix on this post?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SVCHOSt causes Mailicious URL popup
« Reply #3 on: June 08, 2012, 01:27:35 PM »
I have the same malware on my computer an can not get rid of it? I did not see a fix on this post?

Start a new topic and attach your logs.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SVCHOSt causes Mailicious URL popup
« Reply #4 on: June 08, 2012, 03:05:38 PM »
@ Wayno11 you have a failed zero access installation on the system so lets kill it


Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run
To disable MBAM
Open the scanner and select the protection tab
Remove the tick from "Start with Windows"
Reboot and then run OTL


Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :OTL
    DRV - File not found [Kernel | On_Demand | Unknown] -- -- (.mrxsmb)
    DRV - File not found [Kernel | On_Demand | Unknown] -- -- (.i8042prt)
    O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
    O3 - HKU\S-1-5-21-1547161642-1647877149-839522115-1004\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
    O3 - HKU\S-1-5-21-1547161642-1647877149-839522115-1004\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
    O3 - HKU\S-1-5-21-1547161642-1647877149-839522115-1004\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    O4 - HKU\.DEFAULT..\Run: [Apple] C:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\Apple Computer\Apple\bjvavobwb.dll ()
    O4 - HKU\S-1-5-18..\Run: [Apple] C:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\Apple Computer\Apple\bjvavobwb.dll ()
    O4 - HKU\S-1-5-19..\Run: [Apple] C:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\Apple Computer\Apple\bjvavobwb.dll ()
    O4 - HKU\S-1-5-20..\Run: [Apple] C:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\Apple Computer\Apple\bjvavobwb.dll ()
    O4 - HKU\S-1-5-21-1547161642-1647877149-839522115-1004..\Run: [Apple] C:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\Apple Computer\Apple\bjvavobwb.dll ()
    O33 - MountPoints2\{1cbd9bd0-b399-11de-a4f2-806d6172696f}\Shell\AutoRun\command - "" = G:\Info.exe folder.htt 480 480

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks
  • Allow the installation of the recovery console




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Wayno11

  • Guest
Re: SVCHOSt causes Mailicious URL popup
« Reply #5 on: June 08, 2012, 04:29:30 PM »
Ok here is the most recent scan, with the most recent updates, from Malwarebytes.  Thank you

Wayno11

  • Guest
Re: SVCHOSt causes Mailicious URL popup
« Reply #6 on: June 08, 2012, 05:35:53 PM »
essexboy,

I did everything you suggested, and I am attaching the newest otl scan.  However, Combofix needed to download Recovery, and it is stuck at 22.7% download.  You said not to rerun it without reposting, so I am doing so.  Thanks

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SVCHOSt causes Mailicious URL popup
« Reply #7 on: June 08, 2012, 06:53:19 PM »
OK lets try the manual installation, if this should fail then run combofix without the recovery console

Go to Microsoft's website => http://support.microsoft.com/kb/310994
 
Scroll down to Step 1, and select the download that's appropriate for your Operating System. Download the file & save it as it's originally named.
 
Note: If you have SP3, use the SP2 package.
 
 
---------------------------------------------------------------------
 
 
 
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
 

 
 
  • Drag the setup package onto ComboFix.exe and drop it.
  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.

 
 
 
  • At the next prompt, click 'Yes' to run the full ComboFix scan.
  • When the tool is finished, it will produce a report for you.
Please post the C:\ComboFix.txt in your next reply.


Wayno11

  • Guest
Re: SVCHOSt causes Mailicious URL popup
« Reply #8 on: June 09, 2012, 05:23:11 AM »
Ok got it to work.  Here is the combofix.txt file.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SVCHOSt causes Mailicious URL popup
« Reply #9 on: June 09, 2012, 02:04:14 PM »
That killed it  ;D

How is the computer behaving now ?

Wayno11

  • Guest
Re: SVCHOSt causes Mailicious URL popup
« Reply #10 on: June 09, 2012, 02:40:56 PM »
Still getting the pop up I'm afraid, although about half as frequently.  And my web browser is not 100% right.  I seem to be missing a lot of icons and tabs on my web pages, especially games on Facebook.  One game I can not even play.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SVCHOSt causes Mailicious URL popup
« Reply #11 on: June 09, 2012, 02:51:20 PM »
Could you delete your current copy of OTL please and download a fresh copy

Also could you post a screenshot of the popup

Download OTL  to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
services.exe
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open one notepad window. 
    • Attach that log

Wayno11

  • Guest
Re: SVCHOSt causes Mailicious URL popup
« Reply #12 on: June 09, 2012, 03:38:59 PM »
Ok.  I downloaded OTL again and here is the new log.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SVCHOSt causes Mailicious URL popup
« Reply #13 on: June 09, 2012, 03:44:11 PM »
After the reboot from this fix could you check for alerts please

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run
To disable MBAM
Open the scanner and select the protection tab
Remove the tick from "Start with Windows"
Reboot and then run OTL


Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :OTL
    [2011/12/04 18:01:54 | 000,000,469 | ---- | C] () -- C:\Program Files\1204201117015432.bat
    [2011/11/09 10:14:22 | 000,002,048 | -HS- | C] () -- C:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\075d3cf2\@
    [2011/11/20 15:15:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\58CF0
    [2008/12/06 23:44:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\Artogon
    [2011/11/20 14:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\AS2ibD3pn5Q6W8R
    [2011/11/20 14:37:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\avD3onG4aH
    [2011/11/08 14:17:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\Awem
    [2011/11/20 15:19:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\BaQH6dWK7R9TqUe
    [2011/11/20 14:23:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\gqjYCekIVzN
    [2011/11/20 14:25:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\I3onG4aQHsKfLgX
    [2011/11/20 14:23:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\N6dEK8fRZhXjVlB
    [2011/11/20 15:24:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\NK7fRL9gTqUeIrP
    [2011/11/20 14:23:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\nYCwkUVrlNx0c2b
    [2011/11/20 14:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\OL8gRZqhYwUrOtP
    [2011/11/20 14:25:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\QF4pmH5sQ7E
    [2011/11/20 14:23:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\qSibFmG5a
    [2011/11/20 14:37:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\thYXwjUVeOtPy
    [2011/11/20 15:19:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\xIBrzPNyc1v2n4
    [2011/11/20 15:24:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\Y3onG4aQHs


    :Files
    ipconfig /flushdns /c
    C:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\075d3cf2

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Wayno11

  • Guest
Re: SVCHOSt causes Mailicious URL popup
« Reply #14 on: June 10, 2012, 04:57:28 AM »
Ok, I have attached two files.  One is the file created after running RUN FIX and rebooting.  The other is the OTL log after running QUICK SCAN.