Infection: URL:Mal [MALICIOUS URL BLOCKED ALERT]

I have been searching a solution for following alerts for two weeks. But unfortunately I couldn’t find out.

During these two weeks of period, the process changed 3-4 times (Please see the image below). Initially it was AvastSvc.exe. Now protectehstorage.dll

I tried following tools/methods as per discussed in various forms but failed.

1.Restored system to 3 weeks back (This issue was not there at that time.)
2.OTC
3.Malware Bite
4.TDSSKiller
5.aswMBR
6.attk_far_gui_x64
7.SUPERAntiSpyware
8.OPSWATAppRemover

Can anyone please help me on this?

http://i.imgur.com/Z4pcAzD.png?1

Please attach your logs. (AdwCleaner, MBAM, OTL and aswMBR…!!)
Instructions: http://forum.avast.com/index.php?topic=53253.0

OK sure. I’ll do that within next few hrs.

Hi

Please find the attached logs for AdwCleaner, OTL and aswMBR . MBAM logs will be attached in next reply.

Thanks for your consideration.

Please find the attached MBAM logs here.

When I search this time, found a threat and deleted but unfortunately issue still exists.

Thanks for your consideration.

Ahh a new twist on an old friend Zero access. When we have cleaned you up could you upload some files to Avast for analysis, I will give instructions later

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF


:OTL
SRV:64bit: - [2013/02/27 00:10:10 | 001,723,392 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\protectehstorage.dll -- (ProtectehStorage)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
[2013/02/27 00:10:10 | 001,723,392 | ---- | M] () -- C:\Windows\SysNative\protectehstorage.dll
[2013/02/07 17:55:31 | 000,000,973 | ---- | C] () -- C:\Windows\SysNative\ProtectehStorage.ocx

:Files
C:\$RECYCLE.BIN\S-1-5-18\$1b20b8d8e930590c05e5e6437a073398

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
  3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

It seems YES!!! I didn’t get any alerts since OTL costume fix. :slight_smile:

Here I attached following 3 log files.

  1. 02282013_002852.log – This automatically came up when PC restart after OTL costume fix.
  2. OTL.txt - This is what I got from Quick Scan as per your instructions.
  3. ComboFix.txt – ComboFix log file as per your instructions.

Thank you very much for your kind help and support, really appreciate.

Bad news :cry: it came up with another process now.

http://i.imgur.com/E0VR4Jj.png

OK search and destroy time I feel, lets remove the current crop and then look for a hidden starter

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF


:OTL
SRV:64bit: - [2013/02/07 16:31:45 | 002,067,968 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\msmpsyc.dll -- (MsMpSyc)
IE - HKU\S-1-5-21-2266926829-3848745124-1763009038-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-21-2266926829-3848745124-1763009038-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.0.99:80
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
[2013/02/27 23:21:26 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
[2013/02/07 18:27:14 | 005,927,424 | ---- | M] () -- C:\Windows\rvvo.exe
[2013/02/07 16:53:05 | 000,000,950 | ---- | M] () -- C:\Windows\SysNative\MsMpSyc.ocx
[2013/02/07 16:31:45 | 002,067,968 | ---- | M] () -- C:\Windows\SysNative\msmpsyc.dll
[2013/02/04 19:43:05 | 005,927,424 | ---- | M] () -- C:\Windows\mpk.exe

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download the GMER Rootkit Scanner. to your Desktop, it will be a randomly named .exe file .

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click the file you downloaded. The program will begin to run.

https://dl.dropbox.com/u/73555776/GMER_Open.JPG

Caution
These types of scans can produce false positives. Do NOT take any action on any “<— ROOKIT” entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
[*]Click NO
[*]In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
[*]Now click the Scan button.
Once the scan is complete, you may receive another notice about rootkit activity.
[]Click OK.
[
]GMER will produce a log. Click on the [Save…] button, and in the File name area, type in “GMER.txt
[*]Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.

Alerts didn’t appear since new OTL custom fix.

Please find the attached OTL logs and GMER-1 log files.

Due to size restriction, I have divided GMER log file into two. GMER-2 will be attached in next post.

It’s almost 3:00 AM here. So I call it a night.

If you have any further instruction, kindly request you to post. First thing in the morning I’ll follow them and get back to you.

Thanks for your time and help. :slight_smile:

Go get some sleep I will check the logs and have something for you to do in the morning ;D

Please find the attached GMER-2.

Thanks

OK could you now go to windows explorer and locate this folder C:_OTL
Right click the folder and select Send To…
Select Compressed (ZIP) folder
Then could you upload the ZIP file to Mediafire http://www.mediafire.com/ (You will need to create a free account )
And post the sharing link here… I will forward to Avast and sUBs plus other interested parties

Please find the media-fire link for _OTL.zip file below.

http://www.mediafire.com/?bwbb96sgpm4e483

My PC seems OK until now. No more alters for today.

Anyway I’ll update you evening about the situation.

Thanks again for your kind help.

Thanks rakitha!! ;D

Files have been reported to virus AT avast DOT com.

Also These will be upoaded to mbam too :wink:

Seems like problem solved permanently. :slight_smile: I didn’t get any alerts since morning.

Many thanks.