Url Mal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by page28, Nov 6, 2014.

  1. page28

    page28 Private E-2

    On the 11/4, I started getting many alerts from Avast about blocking various web sites that contained url mal. I also found that changes had been made in IE (yes I know it's not a good browser) including deleting my history and changing the ability to download any file. I had to unplug it from Wifi to stop the notices. Next day since it was continuing I Googled url mal and found a site for removing it from my system. It entailed using Mbam, AdwCleaner, Hitman Pro and Emisoft. I followed directions for each though at one point, using the AdwCleaner, I lost wifi. Thought all was ok but then the notices started again from Avast and this time, the Emisoft detected a couple of tries to install msiexec dot exe into C;\ProgramData\Windows Genuine advantage.

    I've virtually lost any ability to use wifi on that pc for more than a couple of minutes and then my wifi has also goes down again. I downloaded all the files to another pc and copied them there. When using CCleaner, it locked up at 25% and I had to force a shut down. Restarted in safe mode and was able to finish. The other scans were able to be completed in normal mode but please note the Hitman Pro is from yesterday as I couldn't access the internet today on that pc.

    Thanking you in advance for any help you can give me.

    Page
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  3. page28

    page28 Private E-2

    Thank you for your super fast response! Logs are attached.

    Page
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. :)

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.


    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Please attach the above two log first before you continue with the below.
    Also at this point, I want to double check the status of Poweliks by having you run another scan with FRST like in my last message and attach the new FRST.txt and Addition.txt logs.
     

    Attached Files:

  5. page28

    page28 Private E-2

    Do you want me to attach FRST.txt and Addition.txt logs along with Fixlog.txt
    C:\MGlogs.zip ? Thanks!
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please.
     
  7. page28

    page28 Private E-2

    A new addition txt was not made for some reason. I'm attaching yesterday's with the new logs from today. Thank you :)!
     

    Attached Files:

  8. page28

    page28 Private E-2

    I went ahead and ran FRST64 again and this time I marked addition.txt so I do have a new one from today. Thanks!
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Could you re run RogueKiller now please and attach log. :)
     
  10. page28

    page28 Private E-2

    Yep, here it is. It also opened up the home page of ADLice which mentioned something about a IAT/EAT hook. Trying to be optimistic here ;).
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nothing to worry about in the RK log. ;)

    Delete as many temp files as Windows let you from this folder:
    • C:\Users\Page\AppData\Local\Temp

    Explain how things are running. The logs look clean. :)
     
  12. page28

    page28 Private E-2

    It's been quiet around here :). No alerts from Avast or Emisoft! PC seems to be working fine. THANK YOU!!!:clap

    I wasn't able to delete all the files that you mentioned. There were 4 and a folder that included some files.

    Is it ok to run Avast along with Emisoft (I've gotten to like that program)?
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    From what I understand you should use one OR the other. Not both. Worth asking about that in the software forum perhaps. ;)

    For the temp files do this:

    Download Cleano 0.61

    Download it to your desktop, Right click the cleano.exe file and run as admin > and place check marks in the boxes as follows (click on link below to see image)

    View attachment 148092
    Click clean now and exit the program.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  14. page28

    page28 Private E-2

    The temp folder still has files in it even after running Cleano and rerunning CCleaner. Just wanted to make sure it's not a problem before I put everything back to normal. Thanks so much!
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It's not a problem, there will always be a few that will not delete as they are in use that day. ;)
     
  16. page28

    page28 Private E-2

    I must be a little dense here ;). I don't see C:\MGtools\enableUAC.reg file nor the MGclean.bat file in C. I see the zip file (but neither are in it) and the .exe. What am I doing wrong? Thanks!

    Edited: scratch that. Not enough coffee this morning. I found it :).
     
    Last edited: Nov 10, 2014
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm a huge coffee fan too. :) Glad you sorted it.
     
  18. page28

    page28 Private E-2

    I ran a scan with Emsisoft. I'm going to post the report as it said it detected four things and wanted to quarantine them (I did not yet). Hopefully they are from one of the programs you has me use but I don't know. Thanks Kestrel 13!
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is new, I saw no signs of Task manager or the Windows Registry being disabled prior to this.

    Let Emisoft address what it finds then and then rescan and see if the log is clean or not.
     
  20. page28

    page28 Private E-2

    After it quarantined them, it found nothing else. Only other problems I see are Avast not working right (won't scan rootkits), if I try to scan a specific file rather than "file name/running" I get "????/running" and it takes forever for it to scan one little file, and some icons in IE (history) have changed from the little IE icon to computer icon. Sigh.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You could try uninstalling avast and reinstalling it. As for the other issue you mentioned, you can further discuss that in the software forum. :)
     
  22. page28

    page28 Private E-2

    I wanted to give things a couple of days. I reinstalled Avast and that took care of it's problem :). Have had no more problems so wanted to thank you one more time Kestrel13!. Sincere appreciation from me!
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome, page 28. ;) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds