URL:Mal Please Help!

So I don’t know what I did, but since today on amost all websites I go on I get 1 or 2 warnings from avast saying that it’s blocked URL:Mal. I think I may have clicked on a dodgey link on skype or something but I don’t know how to get rid of this! Please help me :frowning:
When I go for more details, it says…
URL:h_198_47_127_11__AdServer__AdServerServlet?pubId
Infection: URL:Mal

I think it may only appear on websites with adverts on them? I really don’t know. Please help!

attch Malwarebytes and OTL logs … follow instructions. http://forum.avast.com/index.php?topic=53253.0

Malwarebytes:
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 20/05/2014
Scan Time: 20:40:16
Logfile:
Administrator: Yes

Version: 2.00.1.1004
Malware Database: v2014.05.20.09
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Ben

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 260046
Time Elapsed: 9 min, 25 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 2
PUP.Optional.InstallCore.A, HKU\S-1-5-21-471658976-2310088993-199742357-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [e61ad42cc63a60a0e7b57926bf432dd3],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-471658976-2310088993-199742357-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [4cb4649c778953add4d06f46e41f2dd3],

Registry Values: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-471658976-2310088993-199742357-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0T1F1P1F1C0U2W, Quarantined, [4cb4649c778953add4d06f46e41f2dd3]

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 1
PUP.Optional.RightSurf.A, C:\Users\Ben\AppData\Local\Temp\is1914646434\34444991_stp\RightSurfSetup.exe, Quarantined, [bb4507f9fa06fb05e2c3f72cc93bf60a],

Physical Sectors: 0
(No malicious items detected)

(end)

OTL:

removal experts are notified

Same here, almost every page I visit including newspapers, etc. - It’s got to be something gone wrong in one of Avast auto updates.

Perhaps, I hope so anyway.
An example of a site that this doesn’t happen on would be Youtube, same with you?

Hi BenShen,

I do not see any loaded malware in posted logs. Let’s run additional checks …

Please download zoek.zip or zoek.rar by smeenk (
http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png
) from here or here and save it to your Desktop.
Unpack the archive…

[*]Close any open browsers
[*] Temporarily disable your AntiVirus program. (If necessary)
If you are unsure how to do this please read this or this Instruction.

[*]Double click on zoek.exe to run the tool .
Please wait while the tool does not start…

[*]Copy the text present inside the code box below and paste it into the large window in the zoek tool:

C:\Program Files (x86)\MyTurboPC.com;vs
StandardSearch;

[*] Click on
http://www.mcshield.net/personal/magna86/Images/Run%20Script%20by%20zoek.png
button.
Please wait until a logreport will open (this can be after reboot)

[*]Save notepad to your Desktop and attach here zoek-results.log
Note: It will also create a log in the C:\ directory named “zoek-results.log

.

Please download GMER, the AntiRootKit tool from the link below and save it to your Desktop:

Gmer download link
Note: file will be random named

Double-clicking to run GMER.

[*]Wait for initial scan to finish - if there is any query, click No;
[*]Click [ Scan ] button and wait until the full scan is complete;
[*]Click [ Save … ] button - save the report to the Desktop (named ARK );

Please attach here Gmer’s (ARK.txt) logreports.

Same thing here my pc freaks out when i try to visit ebay.co.uk

Hi coli,

Open new topic for yourself and post the logs for assist in malware removal (MBAM and OTL). Someone will assit you … :wink:

Btw, this could be FP as well, non-malware related issue

@coli. read this info

http://forum.avast.com/index.php?topic=150485.msg1093793#msg1093793

http://www.dailymail.co.uk/sciencetech/article-2635053/Use-eBay-Then-change-password-NOW-Site-requests-users-change-personal-details-dont-explain-why.html

http://www.businessinsider.com/ebay-paypal-password-changes-2014-5

This blocked url happened in my laptop also. I didn’t thought of asking my query here, instead I take help of Click4Support company regarding this issue as I was completely clueless of the reason why this was happening. Their technicians explain the things to me that I should checked the LAN settings under tools to see if the proxy server is checked. If it was there then it means that I have a bug and Avast is doing its job on the computer. Then I have to restart my computer and tap F8 key till it asks about safe mode with networking. Then they asked me to download malwarebytes and run a full scan through it. Then I looked at the log to see that all the infections were removed. Next I run full scan with my antivirus for more safety.