Author Topic: URL:Mal  (Read 16127 times)

0 Members and 2 Guests are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: URL:Mal
« Reply #15 on: June 23, 2012, 01:15:00 PM »
No if you are happy without Firefox then leave it

If you could run an OTL quick scan selecting all users I will check for orphans

davidle

  • Guest
Re: URL:Mal
« Reply #16 on: June 24, 2012, 07:11:58 AM »
Today I am getting warnings for pretty much every page I surf, again using Chrome. Here is a screen shot, https://dl.dropbox.com/u/28272193/warning.jpg

OTL files:
https://dl.dropbox.com/u/28272193/OTL.Txt
https://dl.dropbox.com/u/28272193/Extras.Txt

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: URL:Mal
« Reply #17 on: June 24, 2012, 12:33:17 PM »
Could you attach the OTL log please as it is garbled in drop box


davidle

  • Guest
Re: URL:Mal
« Reply #18 on: June 25, 2012, 01:26:26 AM »
Hope this works.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89667
  • No support PMs thanks
Re: URL:Mal
« Reply #19 on: June 25, 2012, 01:29:31 AM »
It should be OK, though it is now almost 12.30am in the UK so essexboy is probably off line now. So it may be later today before he is able to analyse it.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

davidle

  • Guest
Re: URL:Mal
« Reply #20 on: June 25, 2012, 01:31:18 AM »
Thanks for your reply and info DavidR

I thought I'd better attach the other file just incase too.

davidle

  • Guest
Re: URL:Mal
« Reply #21 on: June 25, 2012, 01:32:57 AM »
Extras.txt file attached

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: URL:Mal
« Reply #22 on: June 25, 2012, 07:01:45 PM »
Some VShare remnants to kill

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


    Quote
    :OTL
    IE - HKLM\..\SearchScopes\{12A2DC1B-BAA9-4713-9658-2924B3159FEC}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=bb799703-1dab-11e1-a6bb-ea7e163ecfb7&q={searchTerms}
    IE - HKU\S-1-5-21-406408613-659197658-631921654-1001\..\SearchScopes,DefaultScope = {12A2DC1B-BAA9-4713-9658-2924B3159FEC}
    IE - HKU\S-1-5-21-406408613-659197658-631921654-1001\..\SearchScopes\{12A2DC1B-BAA9-4713-9658-2924B3159FEC}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=bb799703-1dab-11e1-a6bb-ea7e163ecfb7&q={searchTerms}
    O2:64bit: - BHO: (VshareComplete) - {08337871-0e50-4031-9110-3bd21ca3c065} - C:\Users\David Le\AppData\Roaming\VshareComplete\64\VshareComplete64.dll (SimplyGen)
    [2011/12/03 22:41:16 | 000,000,000 | ---D | M] -- C:\Users\David Le\AppData\Roaming\VshareComplete

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

davidle

  • Guest
Re: URL:Mal
« Reply #23 on: June 26, 2012, 01:25:08 PM »
Here's the OTL log essexboy!

dobber82

  • Guest
Re: URL:Mal
« Reply #24 on: June 26, 2012, 01:31:35 PM »
Hello Essexboy

I am having the very same problem with the same pop ups for every web page I visit in Chrome with the same warnings.

Any chance you can guide me to some help?

Thanks,

David

davidle

  • Guest
Re: URL:Mal
« Reply #25 on: June 26, 2012, 01:36:53 PM »
You have to create your own thread.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89667
  • No support PMs thanks
Re: URL:Mal
« Reply #26 on: June 26, 2012, 01:40:18 PM »
@ dobber82
Go to this topic http://forum.avast.com/index.php?topic=53253.0 for information on Logs to assist in cleaning malware. Use the information about getting and using the tools and start your own new topic and attach the logs there, not in the LOGS topic.

- Please create your own new topic, here http://forum.avast.com/index.php?board=4.0 in the viruses and worms forum (click the New topic button at the top of the page see image) and we will try and help you there.
« Last Edit: June 26, 2012, 01:42:21 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: URL:Mal
« Reply #27 on: June 26, 2012, 04:28:53 PM »
I think I got all the Vshare that time, have the alerts ceased

dobber82

  • Guest
Re: URL:Mal
« Reply #28 on: June 26, 2012, 07:14:12 PM »
Thanks DavidR for the advice. I went ahead and ran all the scans and posted all the logs under my own thread under the worms section and it's called "Malicious URL Blocked Issue (same as problem in davidle thread)".

If you and/or Essexboy could take a look when you get a moment then I would really appreciate it.


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89667
  • No support PMs thanks
Re: URL:Mal
« Reply #29 on: June 26, 2012, 08:03:09 PM »
It will be essexboy or one of the other qualified malware removal specialists. I see that jeffce has already picked that one up.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security