Frequent "blocked infection" and URL:Mal warnings for two websites

I have encountered the problem of frequent popup warnings from Avast when I visit Disqus and a baseball simulator forum that I participate in. The URL is: https://23.235.40.130:443

This only started happening to me yesterday. I ran Malwarebytes and Avast with nothing brought up as infected or suspicious.

Now, I have checked the site using the URL query programs that are mentioned in other topics. They all came up negative with nothing malicious. I have tried resetting Chrome and that did not stop the popups. Also, I tried opening up the websites in Incognito browsing and received the same popups. Sometimes they have different URL extensions after the main address that I listed above. The process is always listed as Google Chrome application in x86 folder.

Please help me work through this problem or offer some solutions. Thanks.

Domain doesn’t even exist.

What happens if you take the :443 off? This is the domain that keeps coming up every time.

https://forum.avast.com/index.php?topic=53253.0

You will have to excuse my ignorance for a moment. I have already run Malwarebytes and nothing came up. Will you be able to tell something else from the log file?

Here is the full address of one of the popups:

https://23.235.40.130:443/get?url=http%3A%2F%2Fwww.wnd.com%2Ffiles%2F2015%2F03%2Fwinnie_harlow-150x150.jpg&key=Aq_k0-LA-VQyJCGBucSA7g

Follow the instructions and attach the log files to your next post.

443 is probably the port used https://www.grc.com/port_443.htm

the important logs are the two diagnostic logs from Farbar Recovery Scan Tool

I am running Malwarebytes again to get the log from that. Then I will follow the recommended procedure and attach the logs from the Farbar tool. Thanks for your patience and your consideration. :slight_smile:

It appears that the certificate has been revoked on that site

I’d just like to comment saying that i’m getting the same exact notification (started today) with 23.235.40.130 getting blocked. mbam came up clean.

log file says ‘https://23.235.40.130 [L] URL:Mal (0)’

Certificate problem

Thanks for the repky, essexboy. For some strange reason I have not received any warning popups from either site today. What do I need to do to fix the certificate problem?

That’s interesting. My problem started yesterday. As I mentioned to essexboy, it has not happened today for some reason. Usually when there is a certificate problem I get that same screen as the screenshot. Nevertheless, the bad certificate screen has not appeared for me in this problem.