Malicious URL Blocked on Start Up

Hello,

I’ve been having the problem upon start up of a malicious URL being blocked by Avast before I access any websites. The text on the “more details” screen indicates it was from the URL “hxxp://www.godzhell.com/clients/updates/h.class” and is a “Java:Downloader-DL [Trj]” infection. I followed the instructions posted in this forum to generate text documents that will aid others in helping me. I will attach them to this post. If any further action is required of me, please let me know. Thank you for your help.

Hi this may be caused by your runescape updater module, let me know if this stops it

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF


:Commands
[CREATERESTOREPOINT]

:OTL
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2158377362-2866332831-440043687-1000\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - No CLSID value found.
O4 - Startup: C:\Users\JCC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RuneScapeQuickLoader.jar ()

:Files
C:\Users\JCC\Downloads\AudioConverterSetup.exe

:Commands
[resethosts]
[emptytemp]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Hi essexboy. I ran what you asked and am attaching the OTL file. The popup did not come up when I rebooted by PC. Thank you for the help.

Looks like it was the runescape updater as I surmised

If all is well tomorrow let me know and I will tidy up :slight_smile: