The other day I posted a message stating that I got my url blocked issue solved ( you can see it below this para). My apologies. I take it back. When I did not get Malicious URL message blocked pop up by avast for 2 days I was under the impression that I got rid of it for good. I formatted my system last night and got it updated online- Windows XP Service pack 3. Today when I went online I had the same Malicious URL blocked pop up message. At least now I am relived because I know that my system is not infected!
Infection Details
URL: ://t o v a r o t e k a s.eu/111
Process: C:\Program Files\Mozilla Firefox\firefox…
Infection: URL:Mal
For more 3 weeks, I had this Malicious URL Blocked Pop up from Avast every time I visited some reliable websites. It occurred only when I browsed using Firefox but as I searched online I got to know that it is not just Firefox, people get this pop up on other browsers as well.
I spent 2 weeks trying to get rid of it and even took malware experts help. Nothing worked. I was not even aware of what this virus was called. Wish I knew because it would have saved a lot of time.
After searching all over the internet I realised what I had was Google redirect virus. A browser Hijacker. So I followed the direction here http://www.2-viruses.com/how-to-fix-google-results-hijacker-google-redirect-virus-problem and I also ran Sophos Virus removal tool. http://www.sophos.com/en-us/products/free-tools/virus-removal-tool.aspx The first link does ask you to buy some of the malware product to clean up ( spyhunter/spyware doctor) don’t buy them. Run malwarebyes and Sophos Virus removal tool. Both are free. Sopohos is not an antivirus software. It only scans your machine and removes the infection. Warning! It is very slow.
When you change/remove entries from the host file, make sure you save a copy so that if it doens’t work, you can place it back.
When I ran sophos it detected 5 infections (which was not detected by Avast/ Malwarebyes/and some other virus removal/detection tools )
There is another guide to remove google redirect virus here. http://atechjourney.com/google-redirect-virus-remove-manually.html/ I have not done this on my system so I don’t know whether it works.
I am not sure what fixed my problem/ removing the suspicious entries from host file or Sophos. The truth is I am not getting this annoying pop up when I go online now. The uncomfortable truth is I still some have infection on my system because when I run combofix it is detecting something called AntiVir Desktop. I have no idea what it is and I even used Avira registry cleaner but I cannot get rid of this. Perhaps I will have to format my system.
If any of you know how to deactivate/remove this stupid AntiVir Desktop, please let me know ( please don’t suggest that I run 10 tools and post the log files here, I did that for one week to get rid of that URL blocked pop up
I am not a techie so I do not know whether this post will help others who have the same issue (searching online I realized too many people have this URL blocked pop up). And some have even called this an Avast scam and glitch! This is absolutely baseless. In my case, it was Avast pop up that made me realise there was something wrong. In order to test whether it was indeed a false alarm I deactivated Avast and went online, soon I had an unwanted pleasant looking guest “Live Security Platinum”. This one also disguises itself as Windows security shield and this blocks antivirus software and browser. In order to get rid of it I ran my machine on safe mode and then used Malwarebytes.
This may help some of you who have this annoying pop up message which cannot be fixed by various virus removal tools.