Help with a problem

Hello

I’ve been having this problem with avast giving me pop-up warnings periodicaly during the day.
It happens whatever I do,i dont even have to be on the computer,no programs need to be running but it will still give me the warning.
I have posted in a different subforum and they have directed me here,so here’s a link with more details.
http://forum.avast.com/index.php?topic=93781.0
And here’s a screenshot
http://oi44.tinypic.com/2yud8d3.jpg

Thanks in advance for all your help

Please attach your logs.
http://forum.avast.com/index.php?topic=53253.0

Done :slight_smile:

You have posted them in the Logs to assist in cleaning malware topic (with the bold red text not to post them there) they should be posted here as the other posts will be removed shortly. I will copy them here and remove the others.

Malwarebytes Anti-Malware 1.60.1.1000 www.malwarebytes.org

Database version: v2012.02.22.01

Windows 7 x86 NTFS
Internet Explorer 9.0.8112.16421
luka :: LUKA-PC [administrator]

22.2.2012 11:50:05
mbam-log-2012-02-22 (11-50-05).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 172462
Time elapsed: 3 minute(s), 25 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 3
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) → Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) → Quarantined and deleted successfully.
HKCU\Software\SkyMedia (Adware.SkyMedia) → Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)
(end)

Did you read the big red text there…?? ???

Well you could also modify your copy and paste text to make it clear the attachments shouldn’t be placed there but in the users own topic.

hmmmm…maybe Essexboy must change the big red text to big red and blinking text…with avast 4.8 sirene sound ;D

Sorry Dave, but the instructions from esseyboy (and yourself) are already as clear as they can be.
And 98% of the users understand quite well what to do. :wink:

Obviously not.

I feel that by putting it in the instructions to visit the topic, give an early notice of how to proceed before they even visit the topic, just another reminder.

It takes nothing other than a modification of your copy and paste text and if it helps stop it. Then we don’t get this ping pong time wasting in the topic about not posting in the Logs to assist in cleaning malware topic and no need to subsequently clean that up.

How man did we get till now…?? :wink:
But ok, suggest something appropriate.

I can see the miscreant but not where it is running from

So I will delete the file and see if anything shows itself

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL IE - HKU\S-1-5-21-2288190340-1075030667-3969066544-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.smartwebsearch.net/index.php?from=3 FF - prefs.js..keyword.URL: "http://smartwebsearch.net/results.php?q=" 2011.02.26 05:50:56 | 000,002,125 | ---- | M] () -- C:\Users\luka\AppData\Roaming\Mozilla\Firefox\Profiles\yshlrfc0.default\searchplugins\Searchster.xml

:Files
ipconfig /flushdns /c
C:\Users\luka\AppData\Local\Temp\iveainLendlessc.EXE

:Commands
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

First off,sorry for being retarded and posting in the wrong thread,once i read the instructions i realized it was moronic to post there since there was a las vegas style warning not to,i was just in a huge rush and performed the scans as quick as i could as i had to leave.

Secondly,here’s the attachment of the log performed after doing everything essexboy said.
Once i restarted and before doing the quick scan another log appeared,should i post it as well?

When you are up to your ass in alligators the last thing on your mind is draining the swamp.

Same happens when you are infected, reasoning seems to go out of the window. So we can help when giving the link to using the information and tools not to attach the logs in the advice topic.

This needs further analysis by a malware removal specialist: Go to this topic http://forum.avast.com/index.php?topic=53253.0 for information on Logs to assist in cleaning malware. [b]Use the information about getting and using the tools and attach the logs here, not in the LOGS topic[/b].

Thanks Dave…! :slight_smile:

You’re welcome.

I should probably inform you that the problem has stopped.
Still i would like info on what was causing it if possible?
Thanks a bunch,and again sorry for being tard with the posting and all.

It was being generated by the smartwebsearch / searchster plugins

Any further problems ?

None so far.
Thanks everyone :smiley:

Run OTL and hit the cleanup button to remove it ;D