Help Needed With URL:MAL Pop Up Warning

I have just started to receive network shield warning pop ups for the URL:MAL virus. It is not happening every time with one exception - when I go to the web site BOSTON.COM which is the online newspaper site for the Boston area. There is no way that BOSTON.COM is a malicious site so I do not understand why the warning pops up all the time when I am on that site. I have run full Avast and Malwarebytes scans and everything looked clean.

I also noticed that the AVAST pop up warning indicated that the process running was chrome.exe so I tried a couple of things. I used Chrome Incognito setting and I do not get the URL:MAL warning. Also if I use IE I do not get the warning. I only get the warning in chrome.

My computer is only a couple of months old so I am concerned and I hope that you can help me get rid of this. I have attached logs AdwCleaner, mbam, OTL, and aswMBR.

There is no way that BOSTON.COM is a malicious site
you mean it cant be hacked. ;)

URL:mal means they are on a block list…for whatever reason

this seems not listed?
http://www.urlvoid.com/scan/boston.com/

you may report it here if you think it is wrong
http://www.avast.com/en-us/contact-form.php

Hi Pondus

Yes I suppose that the site, like any site, could get hacked. I guess I meant that I do not think it is likely that there is something malicious with the site.

I have just started getting the warning today and it is the first time. It also is not just the boston.com site. I have gotten the warning a couple of times just doing a google search.

I am not clear what you are telling me in your reply. if I do not have a problem why did this start to happen and why only in chrome and not in chrome incognito or IE. Do I have a problem that needs to be looked at by a removal expert?

Yes I suppose that the site, like any site, could get hacked. I guess I meant that I do not think it is likely that there is something malicious with the site.
they find a new infected website every 3.5 sek there is a link to that story in here somwhere....cant find it when i need it ;D

anyway malware removers are notified and will check your logs…guessing you have to wait untill tomorrow as it is midnight here in europe now

Pondus

I understand that I have to wait, no problem. I assume that the AVAST pop up is blocking a potential infection so even though I am getting the warning my computer is not infected with anything?

if you get warnings from not doing anything…or from lots of websites, it may indicate a infection

the removal expert will tell after looking at the logs…

Pondus

OK. I assume that you and the removal expert are volunteers so thank you to all that provide this valuable service to clueless users like me.

Hi and welcome! :slight_smile:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.

[*]Disable any script blocking protection
[*]Right-click and Run as Administrator dds to run the tool.
[*]When done, two DDS.txt’s will open.
[*]Save both reports to your desktop.

Please include the contents of the following in your next reply:

DDS.txt

Attach.txt

Hello and thank you for the continued assistance. Since my initial post I am having random pop up warnings so I hope that this can be resolved.

I have attached DDS.txt and Attach.txt.

Hi,

ComboFix

Download Combofix from the link below, and save it to your desktop.
Link

Note: It is important that it is saved directly to your desktop
If you get a message saying “Illegal operation attempted on a registry key that has been marked for deletion”, please restart your computer.


IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here


Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
When finished, it will produce a report for you.
[*]Please post the C:\ComboFix.txt for further review.


Hello

ComboFix.TXT is attached. Thank you.

Hi,

How is your system running now?

I am still getting occasional MAL warning pop ups. It is happening with both IE and Chrome.

Do the scans show anything?

Thank you.

Hello

Is there any follow up instructions that I need to perform? I clicked on the pop up to look at infection details and the URL it shows is hxxx://afe.specificclick.net/?l Is this a virus and/or is any of this information helpful to stop this issue that I have?

I uninstalled and reinstalled Chrome in hopes that this MAL pop up issue would stop. I deleted all of my cookies and put a block on specificclick. Has not helped and I am still getting warning.

Thank you.

Hi bossfan,

Break that link, using htxp for instance. Why, read here: http://www.mywot.com/en/scorecard/afe.specificclick.net?utm_source=addon&utm_content=contextmenu
The malware has been closed after 2012-11-12 03:09:10 evidence comes from Safe PHISH viewer
Offending raw content logged a.o.
Query terms are ambiguous. The query is assumed to be:

“n 216.178.47.37”

Created socket 5.
Releasing 0x0000000000dbd290 (new refcount 1).

polonus

I have broken the link. Sorry about that.

I am still hoping for a removal expert to tell me if there is any more that I can do to stop these random pop ups.

I am considering downloading Microsoft Security Essentials but I am afraid to do that now because if I do have a real infection of some kind it looks like Avast is blocking it and if Microsoft Essentials does not block what might be a real infection then I am gong to be worse off.

Thank you.

Hi,

Go ahead and run a new scan with OTL and attach the log that is created.

I hav attached a new OTL log.

Hi,

http://imageshack.us/a/img841/7292/thisisujrt.gif
Please download Junkware Removal Tool to your desktop.

[]Shut down your protection software now to avoid potential conflicts.
[
]Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select “Run as Administrator”.
[]The tool will open and start scanning your system.
[
]Please be patient as this can take a while to complete depending on your system’s specifications.
[]On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
[
]Post the contents of JRT.txt into your next message.

http://i1224.photobucket.com/albums/ee380/jeffce74/OTL.jpg
Run OTL.exe

[*]Copy/paste the following text written inside of the quote box into the Custom Scans/Fixes box located at the bottom of OTL

:Services

:OTL
IE:64bit: - HKLM..\SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM..\SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-2139726159-2736912696-858409131-1004..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2139726159-2736912696-858409131-1004..\SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
O3 - HKLM..\Toolbar: (no name) - Locked - No CLSID value found.
O15 - HKU\S-1-5-21-2139726159-2736912696-858409131-1004..Trusted Domains: //@surf.mar@/ (money in Local intranet)
[4 C:\Program Files (x86)*.tmp files → C:\Program Files (x86)*.tmp → ]
[2012/10/15 17:52:45 | 000,000,075 | RHS- | C] () – C:\Windows\CT4CET.bin

:Files
ipconfig /flushdns /c

:Commands
[emptytemp]
[start explorer]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot when it is done
[*]Then run a new scan and post a new OTL log ( don’t check the boxes beside LOP Check or Purity this time )


Hi Jeffce

I will do as you instructed when I get a chance.

May I ask are you having me run all these scan tools because you do not see any evidence of a problem or infection, or have you seen something and you are having me run scans in an attempt to remove it?

Also someone else has recently posted in thread title POPUP ALERT MALFUNCTION that he is all of a sudden getting these pop up warnings. As I am running all these different tools is there any indication that Avast needs to investigate a possible false positive that is starting to be detected?