I am running Windows 8 and just recovered my hard drive from a back up image file. I started getting the Avast Malicious URL blocked message almost every time I click to open an email. I ran CCleaner, Malware Byte and Avast full scans already without any success. This is a Dell 530 Inspiron with 3 Gigs RAM and 500 GB hard drive. I looked at a thread on this subject but it said some of the solution was not yet compatible with Windows 8.
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
Here we go. The problem only occurs when I open emails. It seems to be random and I don’t recall it happening twice on the same email. I am attaching the OTL quick scan and also the aswMBR scan results. In addition I did an updated Malwarebytes scan and have attached that result also. Thanks much for your help.
As a rule I try to keep my trash folder empty about two to three times per week. Should there be an email address that I do not recognize I try to view the full header before opening. Those that I do not recognize I will send to the trash folder and deleted after. Thanks again.
The only pattern that I have seen is the URL blocked most time is HTTP://89.151.88.145 See the attachment. A few times I recall something else being blocked.
Yes I am using a trusted email provider. I got a notification that a trojan horse was blocked when I clicked on a link on your page. i am unsure what is going on.
Download ComboFix from one of the following locations: Link 1 Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks