URL:MAL removal assistance

TheBoomBurst

New Member
Thread author
Jun 19, 2016
12
Hello,

I keep getting this annoying continuous Pop-ups from Avast Antivirus indicating that a threat is detected and stating a URL:MAL infection is blocked. This problem occurs with certain websites, but the problem is some of those websites are trusted, such as the WWE.com homepage, and at times- with Facebook and Twitter; but that's very rare.

I tried following the steps listed in one of your blogs (URL:Mal detected by Avast Antivirus. Is this a virus?) to remove the Malware but that didn't work! The Anti-Malware applications listed in the thread removed some infections but still, the URL:MAL is still there and it's extremely annoying!

I'm using Lenovo IdeaPad Z570, Windows 7 Home Premium 64-bit. I thought about using the OneKey Recovery tool to restore the system into it's initial state, but I thought I could try one last shot by contacting you.

Thank you for your time.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,


Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.

    x5o4gh.png

  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
 
  • Like
Reactions: TheBoomBurst

TheBoomBurst

New Member
Thread author
Jun 19, 2016
12
Thank you for taking the time to try to resolve my issue.
Much appreciated.

Here are the two text-files.
 

Attachments

  • FRST.txt
    41.8 KB · Views: 3
  • Addition.txt
    163 KB · Views: 5

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Please download Zemana AntiMalware and save it to your Desktop.
  • Install the program and once the installation is complete it will start automatically.
  • Without changing any options, press Scan to begin.
  • After the short scan is finished, if threats are detected press Next to remove them.
Note: If restart is required to finish the cleaning process, you should click Reboot. If reboot isn't required, please restart your computer manually.
  • Open Zemana AntiMalware again.
  • Click on
    4zu6vb.jpg
    icon and double click the latest report.
  • Now click File > Save As and choose your Desktop before pressing Save.
  • The only left thing is to attach saved report in your next message.



51a612a8b27e2-Zoek.png
Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    51a612a8b27e2-Zoek.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    Code:
    createsrpoint;
    autoclean;
    emptyclsid;
    emptyalltemp;
    ipconfig /flushdns >>"%temp%\log.txt";b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Upload it in your next reply.
 
  • Like
Reactions: TheBoomBurst

TheBoomBurst

New Member
Thread author
Jun 19, 2016
12
Hello,
Sorry for the delay.

I've done what you noted. Here are the text files:
 

Attachments

  • Zemana AntiMalware Report.txt
    3.4 KB · Views: 2
  • zoek-results.txt
    10.8 KB · Views: 2

TheBoomBurst

New Member
Thread author
Jun 19, 2016
12
The Malware is still associated with the same websites as before! Every time I hit those websites an alert pops-up.
 

TheBoomBurst

New Member
Thread author
Jun 19, 2016
12
No not at all.
Certain websites - the problem is it also happens with the WWE website! That what made me suspicious in the first place... I mean this is a pretty decent company and there site should be trusted. Don't you agree?
 

TheBoomBurst

New Member
Thread author
Jun 19, 2016
12
I tried Internet Explorer as well, it happens with the same website but more annoyingly. Should I try uninstalling avast and reinstalling it again? Will that help with the bug?
 

TheBoomBurst

New Member
Thread author
Jun 19, 2016
12
Btw, another thing... Avast sometimes doesn't give alerts!! And I'm talking about the same websites that usually activate the alerts
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Let's see if there is active infection:

FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition.txt option is checked.

    2873ryc.png

  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please attach report into your next reply.
 

TheBoomBurst

New Member
Thread author
Jun 19, 2016
12
Sorry I hit the Reply button too fast! Here you go:
 

Attachments

  • FRST.txt
    41.4 KB · Views: 1
  • FRST.txt
    41.4 KB · Views: 0
  • Addition.txt
    158.3 KB · Views: 1

TheBoomBurst

New Member
Thread author
Jun 19, 2016
12
I tried, didn't work!
I recovered my system to it's initial state STILL Avast gives the same alerts... that's VERY disturbing!
It usually looks like this:
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top