URL:h_go_wvydeo_com__resultsa__?x Infection:URL:Mal

Since yesterday even when nothing is running on my computer I’ve occasionally had a pop up from Avast! that it has blocked a malicious website. Clicking on the most recent message it gives me the following message in the browser:

URL: h_go_wvydeo_com__resultsa__?x
Infection: URL:Mal

Not sure what info is needed, but this Win7 Home, a full scan of Avast! 2014.9.0.2018 found nothing, Malwarebytes 2.0.1.1004 database 2014.05.02.11 found nothing of significance either. I’m not sure where to find any logs within Avast!

Thanks for any help.

Attach your logs. (MBAM, OTL and aswMBR…!!)
Instructions: http://forum.avast.com/index.php?topic=53253.0

Monitoring.

Here’s the results of the scans.

http://i57.tinypic.com/dxqh4.png

Hi gleits, :slight_smile:

[*]Step #1 Fix with OTL
[*]Re-run OTL by right clicking and choosing Run as administrator;
[*]Under the Custom Scans/Fixes Box copy and paste the following contents inside the code box.

:Commands
[createrestorepoint]

:OTL
[2014/05/02 11:50:15 | 000,000,000 | --S- | C] () -- C:\Windows\system32\xczb.msh
[2014/05/01 15:25:45 | 000,000,069 | ---- | C] () -- C:\Windows\system32\bzzeum.hjq
[2014/05/01 15:16:02 | 000,000,028 | ---- | C] () -- C:\Windows\SysWow64\u
[2014/05/01 15:15:21 | 000,000,064 | ---- | C] () -- C:\Windows\system32\iktyw.ikn
[2014/05/01 15:15:21 | 000,000,000 | ---- | C] () -- C:\Windows\system32\jbfr.xlp
[2014/05/01 14:59:20 | 000,239,175 | --S- | C] () -- C:\Windows\system32\vrtsp.udl

:Commands
[emptytemp]

[*]Click on “Run Fix” and let the program run unhindered;
[]Your PC will reboot automatically and a log will be opened;
[
]Please attach it in your next reply.


[*]Step #2 Scan with RogueKiller
[*]Download Rogue Killer from one of the suitable links below to your Desktop.
Download link for 32 bit system
Download link for 64 bit system
[*]Let the pre-scan finish. After that click on Scan;
[*]The scan won’t take long;
[*]A log has been created on your Desktop;
[*]Attach the content of the log in your next reply.


[*]Step #3 Run ComboFix
Download ComboFix by sUBs from one of the suitable locations listed below and save it to your Desktop.
Download Link #1
Download Link #2
Donwload Link #3

Warning
Please acknowledged yourself this warning beforehand. The tool, ComboFix, is an extremely powerful malware removal tool if not one of the most powerful tools ever created. In the hands of an inept person or a simple mistake can render your machine un-bootable. Peruse every step I listed below unless you want a dreadful occurrence.
***

[]Disable your security software. For more information, peruse this thread;
[*]Right-click and choose Run as administrator to run the program.
[*]As a buit-in process, ComboFix will check if you system has Microsoft Windows Recovery Console installed. Let Combofix download and install Microsoft Windows Recovery Console.
[list][*]It requires an active internet connection.
[*]If your system already has Microsoft Windows Recovery Console installed, this step will be skipped
[*]ComboFix will now scan your system for malwares and will attempt to remove them.
[*]Note: ComboFix performs fifty steps during this fix. Please be patient.
[*]After the scan your system will reboot and a log will be produced. The log is automatically saved in C:\ComboFix.txt.
[
]Attach the log in your next reply.[/list]

Crucial Notes:
[*]Do not mouse-click when ComboFix is running as it may stall.
[*]Do not re-run ComboFix if you face a problem. Ask for my instruction here.
[*]ComboFix will make Internet Explorer your default browser and will change number of different Internet Explorer settings.
[*]ComboFix prevents autorun functions of all CD and USB devices to assist with malware removal and increase security. If this is an issue or makes it difficult for you, please tell me.
[]It is possible that ComboFix, even on its first run, may have fixed the problems you are having. We strongly suggest that you still post your log into the topic that you are receiving help as you most likely will have infections left over that your helper will need to analyze further.
[
]ComboFix will disconnect your system from internet for security measures. The connection is automatically restored after the scan but if it does not, it can be restored by rebooting the PC.


[*]Step #5 Scan with Farbar Recovery Scan Tool
[*]Please download Farbar Recovery Scan Tool by Farbar to your Desktop from the link below.
Download link for 32 bit system
Download link for 64 bit system
[*]Right-click on the program and choose Run as administrator;
[*]Put tick-mark on all boxes under Whitelist and Optional Scan;
[*]Click on Scan;
[]After the scan two notepad files will be opened –
[list][
]FRST.txt;
[]Addition.txt[]Attach the contents of the logs in your next reply.[/list]


[*]Required Log(s):
[]OTL Fix Log;
[
]RogueKiller Report;
[]ComboFix Log;
[
]Farbar Recovery Scan Tool Log(s) -
[list][]FRST.txt
[
]Addition.txt
[/list]

Regards,
Valinorum

Required Log(s):
    OTL Fix Log;
    RogueKiller Report;
    ComboFix Log;
Required Log(s):
    Farbar Recovery Scan Tool Log(s) -
        FRST.txt
        Addition.txt

Hi gleits, :slight_smile:

[*]Step #6 Run ComboFix Script
Make sure that you still have Combofix on your Desktop. If not, download it from here.
[*]Open Notepad.exe. Do not use any other text editor software;
[*]Copy and Paste the contents inside the code-box to your Notepad

File::
C:\Windows\system32\xczb.msh
C:\Windows\system32\bzzeum.hjq
C:\Windows\system32\iktyw.ikn 
C:\Windows\system32\jbfr.xlp
C:\Windows\system32\vrtsp.udl

FCopy::
c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7601.17514_none_c7f0e16b547f887d\rpcss.dll | c:\windows\system32\rpcss.dll

[*]Click on File > Save as…
[list][*]Inside the File Name box type CFScript.txt
[*]From the Save as type drop down list, choose All Files
[*]Save the file to your Desktop;
[*]Make sure your security programs are disabled while performing the actions. If you have difficulties, peruse this thread;
[*]Drag CFScript.txt into ComboFix.exe as shown in the screenshot below –

http://i.imgur.com/2dOKdBt.gif

[*]ComboFix will now run a scan on your system. After the scan finishes, it will execute the script and reboot your computer automatically. Don’t reboot your computer manually, let ComboFix do it. Once your computer is rebooted, ComboFix will start preparing a log. Please let it do so unhindered. After a few minutes, it shall produce a log for you.
[*]Please attach the C:\ComboFix.txt in your next reply.[/list]


Re-do Step 5.


[*]Required Log(s):
[]ComboFix Log;
[
]Farbar Recovery Scan Tool Log(s) -
[list][]FRST.txt
[
]Addition.txt
[/list]

Regards,
Valinorum

I believe I followed your instructions exactly, but neither time did the computer reboot. The log file was generated after the program was finished with no reboot.

Anyway, see attached.

Hi gleits, :slight_smile:

Tell me how the system is running after applying the fix.


[*]Step #7 Fix with FRST
Make sure that you still have FRST.exe on your Desktop. If you do not have it, download the suitable version from here to your Desktop.
[*]Open Notepad.exe. Do not use any other text editor software;
[*]Copy and Paste the contents inside the code-box to your Notepad

Start
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} -  No File
2014-05-03 07:48 - 2014-05-03 07:48 - 00000028 _____ () C:\Windows\SysWOW64\u
2014-05-02 11:50 - 2014-05-02 11:50 - 00000000 ____S () C:\Windows\system32\xczb.msh
2014-05-01 15:25 - 2014-05-03 08:50 - 00000069 _____ () C:\Windows\system32\bzzeum.hjq
2014-05-01 15:15 - 2014-05-01 15:15 - 00000064 _____ () C:\Windows\system32\iktyw.ikn
2014-05-01 15:15 - 2014-05-01 15:15 - 00000000 _____ () C:\Windows\system32\jbfr.xlp
2014-05-01 14:59 - 2014-05-01 14:59 - 00239175 ____S () C:\Windows\system32\vrtsp.udl
End

[*]Click on File > Save as…
[list][*]Inside the File Name box type fixlist.txt
[*]From the Save as type drop down list, choose All Files
[*]Save the file to your Desktop;
[*]Re-run FRST.exe and click Fix;
[*]Note: If FRST advises there is a new updated version to be downloaded, do so/allow this.[]After the completion, a log will be produced;
[
]Attach the log in your next reply.[/list]


[*]Required Log(s):
[*]FRST Fix Log

Regards,
Valinorum

System seems fine, barring one freeze, with no programs having been opened by me, save Firefox to get to this site. I’ve been having this issue randomly for a couple of months though. :frowning:

Required Log(s):
    FRST Fix Log

I require the FRST Fix Log. It is located in the same folder of FRST.exe and which program is freezing?

Oops, sorry.

It’s not any specific program, it’s the entire system. Nothing responds, I can’t ctrl+alt+del.

Isn’t there any file named Fixlog.txt on your Desktop? Attach it please. Since when the freezing started?

The computer has been having the occasional freezes for a couple of months now.

Hi gleits, :slight_smile:

Finally we removed the main culprit.

[*]Step #8 Fix with AdwCleaner
[*]Download AdwCleaner by Xplode to your Desktop from the following link.
[list][]Download Link #1
[
]Download Link #2
[*]Right-click on AdwCleaner.exe and choose Run as administrator;
[*]Click on Scan and let the program run unhindered;
[*]When done, click on Clean and allow the system to reboot after it is done;
[]A log will be opened automatically after the restart;
[
]Attach the log in your reply.[/list]


[*]Step #9 Fix with Junkware Removal Tool
Download Junkware Removal Tool by thisisu to your Desktop from the link below.
Download Link 1
Download Link 2
[]Disable your anti-virus to avoid potential conflicts. For more information please acknowledge yourself this article;
[*]Run the program either by double-clicking(Windows XP) or Right-clicking and choosing Run as administrator(Windows Vista and above);
[*]Please be patient as the tool cleans your system;
[*]After completion of the process a log named JRT.txt will automatically open and is save to your Desktop;
[
]Attach the log in your next reply.


[*]Required Log(s):
[]AdwCleaner Log
[
]Junkware Removal Tool Log

Regards,
Valinorum

Required Log(s):
    AdwCleaner Log
    Junkware Removal Tool Log

How is your system running?

Very good! Thank you for all your help. :slight_smile:

Hi gleits, :slight_smile:

[*]Step #10 Scan with Malwarebytes’ Anti-Malware
[*]Download Malwarebytes’ Anti-Malware from the suitable link below –
[list][]Download Link #1
[
]Download Link #2
[]Download Link #3
[*]Double-click mbam-setup.exe to install the application.
[*]Before clicking Finish perform the following actions –
[*]Un-check the box beside Enable free trial of Malwarebytes Anti-Malware Premium.
[*]Check the box beside Launch Malwarebytes Anti-Malware
[*]Once the program has loaded, The MBAM dashboard will appear with an alert to update - click the green button Update Now;
[*]Click on Setting
[*]Navigate to the tab Detection and Protection and check all the boxes under Detection Options
[*]From the Dashboard click on Scan Now;
[*]If threats are detected click on Apply actions. If the program asks to reboot your PC, let it do so;
[*]On completion of the scan click on View Detailed Log after that click on Export Button, select Text File and save the log to your Desktop;
[
]Attach the log in your next reply.[/list]


[*]Step #11 ESET Online Scanner
Disable your security programs which includes but not limited to anti-virus, anti-malware, anti-spyware et cetera. Peruse this for additional information.
[*]Download esetsmartinstaller_enu.exe by clicking here.
[*]Right-click on the program and choose Run as administrator.
[*]Accept their terms and condition and proceed.
[*]Install Add-On/Active X if prompted.
[*]From the Computer Scan Setting
[list][*]Uncheck the box beside Remove Found Threats;
[*]Check the box beside Scan archives
[*]Click on Advanced Setting and check the following boxes–
[*]Scan for potentially unwanted applications
[*]Scan for potentially unsafe applications
[*]Enable Anti-Stealth Technology
[*]Click on Start and wait for the virus signature database to update.
[*]The online scan will begin automatically and can take several hours.
[*]Note: Do not touch either the Mouse or keyboard during the scan. Otherwise it may stall.
[*]After the Scan finishes –
[*]If no threats were found:
[list][*]Put a checkmark in Uninstall application on close.
[*]Close the program and report that nothing was found
[*]If threats were found:
[*]Open the file located in C:\Program Files\ESET\ESET Online Scanner\log.txt (32-bit) or C:\Program Files (x86)\ESET\ESET Online Scanner\log.txt (64-bit).
[*]Copy and Paste contents of the log file in your next reply.[/list][/list]
Note: Enable your security programs afterwards.


[*]Required Log(s):
[]Malwarebytes’ Anti-Malware Log
[
]ESET Scan Log

Regards,
Valinorum