URL blocked

I did a quick scan and didn’t see this topic.

My Avast keeps showing it’s blocking URLs even when I’m not online. It’s the Network Shield. What exactly does this mean?

I’m a new-bie to Avast.

EDIT: Malicious URL Blocked is what it’s saying.

Please give information on the network shield alert, either a screenshot of the alert window or the full text of the alert.

If posting URL details - Please ‘modify’ your post change the URL from http to hXXp, to break the link and avoid accidental exposure to suspect sites, thanks.

Infection Details
URL: hXXp://geturlbyword.com/?q
Process: \.\globalroot\systemroot\svchost.exe
Infection: URL:Mal

This is from the Avast site when I click “Details” in the Malicious URL Box that keeps popping up. There are like 11 seperate URLs it keeps finding. As I said it’s popping even when I’m not online. I have run MalwareBytes. It doesn’t stay up long enough to get a screen shot. It pops every 2/3 minutes
The URLs are very long

EDIT: Here are the URLs per Avast “more details”
hxxp://searchthetext.com/?q
hxxp://findthewordservice.com/?q
hxxp://bestwordsearcher.com/?q
hxxp://mclarenz.net/?id (not sure what this , because there is no such website that I personally have formed)
hxxp://worldwidetextsearch.com/?q
hxxp://look-up-word.com/?q
Most of these are multiples

Please attach your logs. (AdwCleaner, MBAM, OTL and aswMBR…!!)
Instructions: http://forum.avast.com/index.php?topic=53253.0

Here are the logs for OTL, Ad, and Malware attached

Included are the last 2 malware logs. 1-20 was a full scan
1-21 was a quick scan

A malware removal specialist has been informed of your topic.

Hi there lets get you cleaned up

Download the latest version of TDSSKiller from here and save it to your Desktop.

[*]Doubleclick on TDSSKiller.exe to run the application

https://dl.dropbox.com/u/73555776/tdss%20start.JPG

[*]Then click on Change parameters.

https://dl.dropbox.com/u/73555776/tdss%20Change%20param.JPG

[*]Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

[*]Click the Start Scan button.

[*]If a suspicious object is detected, the default action will be Skip, click on Continue.

https://dl.dropbox.com/u/73555776/tdss%20threat.JPG

[*]If malicious objects are found, they will show in the Scan results and offer three (3) options.
[*]Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

[*]Get the report by selecting Reports

https://dl.dropbox.com/u/73555776/tdss%20report.JPG

[*]Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

Please attach the log found at C:\TDSSKiller date time.

THEN

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF


:OTL
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2737658
IE - HKU\S-1-5-21-2582325821-2654065426-3825525098-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2737658
FF - prefs.js..extensions.enabledItems: searchtoolbar@zugo.com:1.2
IE - HKU\S-1-5-21-2582325821-2654065426-3825525098-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:58687
[2011/05/21 15:18:53 | 000,000,000 | ---D | M] (Search Toolbar) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\8dhf54zu.default\extensions\searchtoolbar@zugo.com
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2582325821-2654065426-3825525098-1000\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-2582325821-2654065426-3825525098-1000\Software\Policies\Microsoft\Internet Explorer\restrictions present
[2013/01/21 08:15:59 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\svchost.exe
[2013/01/01 20:53:19 | 000,026,279 | ---- | M] () -- C:\ProgramData\1357095179.3416.bin
[2013/01/01 20:53:19 | 000,000,189 | ---- | M] () -- C:\ProgramData\1357095179.2180.bin
[2013/01/01 20:53:18 | 000,002,049 | ---- | M] () -- C:\ProgramData\1357095179.4716.bin
[2013/01/01 20:51:42 | 000,027,690 | ---- | M] () -- C:\ProgramData\1357094971.bdinstall.bin
[2011/12/26 16:20:03 | 000,001,428 | -HS- | C] () -- C:\Users\John\AppData\Local\8soj4ivu81j52gj4p2layk
[2011/12/26 16:20:03 | 000,001,428 | -HS- | C] () -- C:\ProgramData\8soj4ivu81j52gj4p2layk
[2011/07/23 13:02:51 | 000,001,486 | -HS- | C] () -- C:\Users\John\AppData\Local\15ho16v480qtjopuusb031qp2362v1q
[2011/07/23 13:02:51 | 000,001,486 | -HS- | C] () -- C:\ProgramData\15ho16v480qtjopuusb031qp2362v1q
[2011/07/23 13:02:49 | 000,000,000 | ---- | C] () -- C:\Users\John\AppData\Local\yjxs.exe
[2011/07/23 13:02:49 | 000,000,000 | ---- | C] () -- C:\Users\John\AppData\Local\vjld.exe
[2011/07/23 13:02:49 | 000,000,000 | ---- | C] () -- C:\Users\John\AppData\Local\ulfu.exe
[2011/07/23 13:02:49 | 000,000,000 | ---- | C] () -- C:\ProgramData\hloq.exe
[2011/07/23 13:02:49 | 000,000,000 | ---- | C] () -- C:\ProgramData\gxwr.exe
[2011/07/23 13:02:49 | 000,000,000 | ---- | C] () -- C:\Users\John\AppData\Local\eynt.exe
[2011/07/23 13:02:49 | 000,000,000 | ---- | C] () -- C:\ProgramData\cfvq.exe
[2011/07/23 13:02:49 | 000,000,000 | ---- | C] () -- C:\ProgramData\altr.exe

:Files
C:\Program Files (x86)\Search Toolbar

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.