Malicious URL blocked

hi,

When I visit some sites Avast promts me about blocking the malicious url. I already did scanning with OTL. I’m attaching logs.

Would you be so kind and instruct me what to do next.

aso attach the aswMBR log and Malwarebytes quick scan log

removal specialist is notified…may take several hours before he arrive

you may also post the URLs you have problems with so we can check them

post them unclickable… http as hxxp and www as wxw

I attached mbam log

URLs are
hxxp://wxw.durini.si/
hxxp://wxw.sdtempo.si

tanx.

I do not see your MBAM or aswBR logs attached. Can you attach them again? Thank you.

sorry

I posted wrong URLs

Right url is hxxp://lohnrnnpvvtxedfl.ru/runforestrun?sid…

MBAM looks clean. How about attaching your aswMBR log?

sorry but I’dont know wher to get it.

Check the information on the first post of this thread under Virus/Worms for you to check your machine for malware: http://forum.avast.com/index.php?topic=53253.0.

Scroll down the pages and follow the directions of obtaining an aswMBR log. Post the log as an attachment (Additional Options > Attach > Post).

After posting the log, do not make any changes to your machine. Do not sync anything to your machine and try not to use it.

I am notifying a malware specialist to assist you. Thank you.

Also, please let us know if your machine is acting differently (describe how it is different).

Does this happen on any specific sites ? Or is it random

Also is this in Firefox, IE or both

It happens only on these sites for now. These sites are on same server and I manage them.

hxxp://www.durini.si/
hxxp://www.sdtempo.si
hxxp://www.busman.si

OK that would suggest to me that the site has been hacked

I will ask iDonovan to look at the site as your logs appear clean

edit your post above…post links unclickable

yepp…those websites are bad…see scan result

http://urlquery.net/report.php?id=85252
http://sitecheck.sucuri.net/results/durini.si/
http://zulu.zscaler.com/submission/show/ec81fb6d98e86cdcd331790159087519-1341745011

http://urlquery.net/report.php?id=85251
http://sitecheck.sucuri.net/results/sdtempo.si/
http://zulu.zscaler.com/submission/show/cf79cdc830b85dbac1a7bf272414580f-1341745063

http://urlquery.net/report.php?id=85250
http://sitecheck.sucuri.net/results/www.busman.si
http://zulu.zscaler.com/submission/show/22b429aadee484338e377a50b18031ab-1341745205

Ataching aswMBR log. It happens in firefox and iexplorer

Yep it is the sites and not your system that has the infection

Detection is correct. All 3 contain the algorithm that leads to one of the Pseudo-Random .ru websites based on date.

Because avast! blocked the sites, you are protected. :wink:

You can read about it here: http://www.symantec.com/connect/blogs/blackhole-exploit-kit-gets-upgrade-pseudo-random-domains

Cheers ;D