system
August 16, 2011, 5:53am
1
So I’m in the same boat as a few other people. avast! keeps pulling up the “Malicious URL Blocked” notice with it constantly blocking C:\WINDOWS\system32\midimap32.exe
It only blocked it at first, but now it’s actively redirecting the Google searches.
Pondus
August 16, 2011, 5:58am
2
can you post one more log
Essexboy is notified an will check the logs when he arrive, usually around 08:00pm - 11:59pm uk time…
system
August 16, 2011, 6:05am
3
Sorry about that, here we go.
system
August 16, 2011, 8:00am
4
Hi onibi808
Submit for analysis at the Virus Total http://www.virustotal.com/
C:\WINDOWS\System32[b]mchgrcoi32.exe[/b]
C:\WINDOWS\System32[b]midimap32.exe[/b]
Copy the link with reports of.
system
August 16, 2011, 9:31am
5
system
August 16, 2011, 9:47am
6
Run OTL
Under the Custom Scans/Fixes box at the bottom, paste in the following
:Commands
[purity]
[emptytemp]
[resethosts]
[EMPTYFLASH]
[Reboot]
Then click the Run Fix button at the top
Let the program run unhindered, reboot the PC when it is done
Post the log it produces in your next reply.
system
August 16, 2011, 4:40pm
7
Okay, so I ran the fix, and… I’m still getting it.
Log attached for OTL custom fix.
system
August 16, 2011, 5:38pm
8
Please visit this webpage for download links, and instructions for running ComboFix tool:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Please ensure you read this guide carefully and install the Recovery Console first.
Please continue as follows:
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
Remember to re-enable them afterwards.
Click Yes to allow ComboFix to continue scanning for malware.
When the tool is finished, it will produce a report for you.
Please include the following reports for further review, and so we may continue cleansing the system:
C:\ComboFix.txt
system
August 17, 2011, 3:24am
9
Okay, here are the results from ComboFix.
system
August 17, 2011, 6:57am
10
Open notepad and copy/paste the text present inside the code box below:
File::
c:\windows\system32\mchgrcoi32.exe
c:\windows\system32\mmutilse32.dll
c:\windows\system32\midimap32.exe
c:\windows\system32\atiiiexx32.dll
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C9A7B50-86E9-4658-A342-751DBC0020Ae}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-
Driver::
SamSs32
Save this as CFScript to desktop.
http://img213.imageshack.us/img213/1218/cfscript1.gif
Drag CFScript.txt into Combofix.exe. ComboFix will re-run.
When finished, it will produce a log for you.
Copy/paste the contents of the log in your next reply. (typical location: C:[b]ComboFix.txt[/b] )
system
August 17, 2011, 6:59am
11
c:\documents and settings\Administrator\My Documents[b]Downloads[/b]\ComboFix.exe
Cut / paste combofix to desktop
system
August 17, 2011, 7:47am
12
Alright, thanks very much, you guys. If I come up with anything else, I’ll be in touch. Just in case you need it, here’s the result scans from the last ComboFix run.
system
August 17, 2011, 7:57am
14
Ironically, right when I was about to tell you “Yep, everything’s good,” avast! blocked it again.
system
August 17, 2011, 8:09am
15
Open notepad and copy/paste the text present inside the code box below:
File::
c:\windows\system32\atiiiexx32.exe
c:\windows\system32\mmsystem32.dll
Driver::
stisvc32
Save this as CFScript to desktop.
http://img213.imageshack.us/img213/1218/cfscript1.gif
Drag CFScript.txt into Combofix.exe. ComboFix will re-run.
When finished, it will produce a log for you.
Copy/paste the contents of the log in your next reply. (typical location: C:[b]ComboFix.txt[/b] )
system
August 17, 2011, 9:47am
17
Ok now you have a problem?
system
August 17, 2011, 10:03am
18
Fingers crossed, I’m saying I don’t. Thanks again for the help, argus. I’ll be back if the problem arises again.
system
August 17, 2011, 10:22am
19
onibi808
Need to uninstall Combofix
Start > Run > Copy/Paste
Combofix /Uninstall
enter.