Avast constantly warning about URL:Mal, help please!

Greetings, recently I’ve noticed a decline in computer performance, and AVG/MWB weren’t picking up anything so I installed Avast. This picked up something, which keeps popping up with this popup (Speedcap link) : http://speedcap.net/sharing/files/d0/bf/d0bfbd330942020028cd4a069c482d1f.png
Note: The URL’s constantly change, and as i finish this post it’s had 50 blocked attempts.

EDIT: Also, this is what AVG popped up with, but it has no actions to modify this.
http://speedcap.net/sharing/files/f4/f9/f4f91297a1d5c100b5859c34eaa2a3ee.png

Attached are logs from TDSSKiller, MBAR, And Zoek which I heard in another thread which had similar problems, but the problem isn’t going away even afterwards!

Thank you for your help!

Re-run zoek with this script and attach here fresh zoek log results.

C:\Windows\Sysnative\dtiyrpw.etr;f
C:\Windows\Sysnative\giolz.laj;f
C:\Windows\Sysnative\yicol.ltl;f
C:\Windows\Sysnative\hmumns.anw;f
C:\Windows\Sysnative\dubj.nmp;f
autoclean;
emptyclsid;
emptyalltemp;
rpcss.dll;z

Sorry for the lengthy wait, I was at work :confused: Did that scan, here’s the log. Had to run it in safemode, for some reason my computer wasn’t booting until I started in safemode. Still doing it, unfortunately

When did this happened, after the Zoek fix? Did you do something on your own? Like installing AVG along with Avast?

Always had avg installed. But it was pre zoek, post 3 logs I sent. Don’t know why. I tried a combo fix but it didn’t do much of anything. Should I fetch new logs?

Are you able to use Normal mode?

Attach ComboFix report…

Sorry, couldn’t find the combofix report from before, so I scanned again. Also, the FRST was run last night as well, so it’s included. But the combofix is new. Sorry for confusion. I tried taking proactive steps, with no luck.

EDIT: While the effect still persists, the URL’s all have pigeon something in the name, which is slightly humorous, except for you know, the infection.

Open notepad and copy/paste the text present inside the code box below:

FCOPY:: 
c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7600.16385_none_c5bfcda3579104e3\rpcss.dll|c:\windows\system32\rpcss.dll

File::
C:\Windows\system32\yicol.ltl
C:\Windows\system32\giolz.laj
C:\Windows\system32\hmumns.anw
C:\Windows\system32\dubj.nmp

ClearJavaCache::

Save this as CFScript.txt

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:[b]ComboFix.txt[/b] )

Thank you for your help btw! Here’s the log. During the first run, I think one of my anti virus programs (AVG) started up, because it took over 20 minutes on the creating a log screen. So, I restarted the scan, and here’s the log from that (it rebooted my computer).

Ok, re-run FRST again and attach fresh report…

Wasn’t sure if you wanted the Additional stuff, so I did that one too. Both are attached!

Ok, we’re nearly done :slight_smile:

1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Unlock: C:\Windows\system32\hmumns.anw
Unlock: C:\Windows\system32\dubj.nmp
Unlock: C:\Windows\system32\giolz.laj
Unlock: C:\Windows\system32\yicol.ltl
C:\Windows\system32\hmumns.anw
C:\Windows\system32\dubj.nmp
C:\Windows\system32\yicol.ltl
C:\Windows\system32\giolz.laj
cmd: ipconfig /flushdns

2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.

Then…

Re-run FRST and attach fresh report…

Are you some sort of computer magician? Also, here’s the logs!

PC seems clean, how are the things now?

Well, I haven’t seen a popup since running the CFix script you gave me, so hoping that it’s worked well. If anything changes, I’ll make a new topic/reply to this one if it’s in a day or two. Thank you so much for your help!

You have two antiviruses running simultaneously:

  • avast! Free Antivirus
  • AVG 2014

You need to remove one of them…

You can use these utilities to clean possible remnants:

Removed AVG as it didn’t catch this last infection. Any other tips you would offer? Thanks again for your help!

Nothing else, we’re done :slight_smile:

Please download DelFix by “Xplode” to your Desktop.

Run the tool and check the following boxes below;

[] Remove disinfection tools
[
] Create registry backup
[*] Purge System Restore

Now click on “Run” button. Wait for the programme completes his work.
All the tools we used should be gone.
Tool will create and open an log report (DelFix.txt)
Note: The report will also be stored on C:\DelFix.txt

I don’t need DelFix log report.