Malicious URL's and malware blocked by avast. Gets way more frequent wEthernet

Every time I connect my router to my computer via an Ethernet cord it starts blocking malicious URL’s?
My computer works absolutely perfect until I plug in the hard line connection and then Avast starts picking up these malicious URL readings? I already reset the router and set it up again with new password but when I plugged it in avast still found the URL’s. I don’t know what else to do.

PLEASE HELP ME !!

When I connect this router wirelessly to another computer, everything works perfect. However when I plug in the Ethernet cord to my desktop Avast starts blocking these malicous URL’s.

Should I try to restore the computer back to default conditions again and then plug the router ( which I will reset) back into it?

Actually just now, after I disconnected the Ethernet cord, avast network shield is still blocking the URL’s. So they are now popping up while I am not even connected to the Internet, even though they are not as frequent as when the Ethernet is plugged in.

!!!
Thank you in advance

So they are now popping up while I am not even connected to the Internet, even though they are not as frequent as when the Ethernet is plugged in.
this indicate possible infection

follow this guide and attach logs…not copy and paste http://forum.avast.com/index.php?topic=53253.0

run in order listed
AdwCleaner / Malwarebytes / OTL / aswMBR

when done, malware experts will be notified and help you
when finish, all tools used will be removed

Do I remove the things that were found in the registry on Adwcleaner? And I am in the process of the other scans…

Delete the two clsid

Key Found : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Key Found : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}

Here are the other scan logs as requested…The Pop ups are still popping up relentlessly :-[

Thanks again for your help,
Mac

Should I “FixMBR” in aswMBR ? Or will this cause more problems?

Do not fix anything! Wait for Essexboy reply!

Disclaimer:

• Please refrain from making any further changes to your computer (Install/Uninstall programs, delete files, edit the registry, etc...) • Please DO NOT run any other tools or scans whilst you are being helped.

Does this occur with all users or just one ?

Also McAfee is running and will need to be removed. Full instructions are here http://service.mcafee.com/FAQDocument.aspx?id=TS101331

Start reading from here 1.Uninstall your McAfee home user products using Add/Remove Programs in the Windows Control Panel:

There is just one user on the computer…And McAfee has been removed.

What now?

Thanks,
Mac

Could you attach a screenshot of the Avast alert as there is a lot more data in that

Here is the screenshot as requested. And the object is almost always different…but it always has /task/23/ at the end of it???

Process is always the same. There has been up to 22 of them pile up like that.

Thanks,
Mac

Thanks that showed me the probable location

Download the latest version of TDSSKiller from here and save it to your Desktop.

[*]Doubleclick on TDSSKiller.exe to run the application

https://dl.dropbox.com/u/73555776/tdss%20start.JPG

[*]Then click on Change parameters.

https://dl.dropbox.com/u/73555776/tdss%20Change%20param.JPG

[*]Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

[*]Click the Start Scan button.

[*]If a suspicious object is detected, the default action will be Skip, click on Continue.

https://dl.dropbox.com/u/73555776/tdss%20threat.JPG

[*]If malicious objects are found, they will show in the Scan results and offer three (3) options.
[*]Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

[*]Get the report by selecting Reports

https://dl.dropbox.com/u/73555776/tdss%20report.JPG

[*]Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

Please copy and paste its contents on your next reply.

It found a “Rootkit- Harbinger…” and I cured it and then I rebooted before I got the report :-[

But since I have rebooted I do not have any pop-ups now! I have not had one alert since the restart!!!

Here is the post restart scan by TDSS Killer. It found no threats!

Thanks again,
Mac

OK that ruled that avenue out

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
  3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Do I need to do combofix if my problem seems to be already fixed??? TDSS Killer found a Rootkit Harbinger but I restarted in order to finish cure before I hit report :-[

But the avast alerts and adware are all completely gone now!

Do I need to run this,
Mac

Somehow I missed the one post that stated you had to reboot… Which means the problem is cured as it was an MBR like I thought

Scrub Combofix, it is not required but could you attach the initial log that TDSSKiller generated please it will be at C:\TDSSKiller date time

OK…I found it! The computer is running faster than normal and no popups or alerts from Avast!

Thanks so much,
Mac

OK that looks good, Avast may pick up on the TDSS quarantine folder so I would recommend that you delete that now

Then run the system as normal and if all is well tomorrow I will tidy up :slight_smile:

TDSS Quarantine in (C:) deleted!

Thank you so much for your help,
Mac