Author Topic: Pop-up Message from Avast  (Read 4805 times)

0 Members and 3 Guests are viewing this topic.

trezomd

  • Guest
Pop-up Message from Avast
« on: July 14, 2013, 06:04:57 PM »
Infection Details
   http://mciupdate.com/mcicidupdate.php?ci...
Process:   C:\Users\Deborah\AppData\Local\Temp\Tray...
Infection:   URL:Mal

I keep getting this message from Avast.  What is it and do I need to do anything?  Thanks.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Pop-up Message from Avast
« Reply #1 on: July 14, 2013, 06:11:15 PM »
Do you have Anti-phishing Domain Advisor on your computer

trezomd

  • Guest
Re: Pop-up Message from Avast
« Reply #2 on: July 14, 2013, 06:41:09 PM »
I do not.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Pop-up Message from Avast
« Reply #3 on: July 14, 2013, 06:49:40 PM »
Could you follow the inital steps here http://forum.avast.com/index.php?topic=53253.0
Up to and including OTL and then attach the logs in this thread :)

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Pop-up Message from Avast
« Reply #4 on: July 14, 2013, 06:51:11 PM »
Hello,

The Website is blacklisted by Norton. Cause it has an Drive-By-Download on it.

http://sitecheck.sucuri.net/results/mciupdate.com/mcicidupdate.php
http://safeweb.norton.com/report/show?url=mciupdate.com%2Fmcicidupdate.php

The Last one is in German.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

trezomd

  • Guest
Re: Pop-up Message from Avast
« Reply #5 on: July 15, 2013, 03:48:21 PM »
Attached are the first log (S1) AdwCleaner and mbam-log.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Pop-up Message from Avast
« Reply #6 on: July 15, 2013, 04:01:39 PM »
OK the main data will be in the OTL log, are you still getting the alerts ?

trezomd

  • Guest
Re: Pop-up Message from Avast
« Reply #7 on: July 15, 2013, 04:12:56 PM »
Attached are OTL.Txt and Extras.Txt logs.  I got an alert earlier while I was in the middle of running the scans.

trezomd

  • Guest
Re: Pop-up Message from Avast
« Reply #8 on: July 15, 2013, 04:16:22 PM »
Do I need to do anything about this post?  Thanks.

The Website is blacklisted by Norton. Cause it has an Drive-By-Download on it.

http://sitecheck.sucuri.net/results/mciupdate.com/mcicidupdate.php

trezomd

  • Guest
Re: Pop-up Message from Avast
« Reply #9 on: July 15, 2013, 04:23:00 PM »
I just got a message again "URL Blocked"

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Pop-up Message from Avast
« Reply #10 on: July 15, 2013, 05:43:34 PM »
Does this occur in all browser or just one ?

Also did you install this programme InboxAce


Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1257237249-4141612660-2727000358-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-1257237249-4141612660-2727000358-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AutoLoader] C:\Users\Deborah\AppData\Local\Temp\Traymonitor.exe ()

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

trezomd

  • Guest
Re: Pop-up Message from Avast
« Reply #11 on: July 16, 2013, 02:06:35 AM »
Pop-up occurs in Google and Firefox.

trezomd

  • Guest
Re: Pop-up Message from Avast
« Reply #12 on: July 16, 2013, 02:08:31 AM »
I have not run InboxAce.  Shall I do that now?  Then OTL again?

trezomd

  • Guest
Re: Pop-up Message from Avast
« Reply #13 on: July 16, 2013, 02:28:35 AM »
I ran the OTL Run Fix and attached the log.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Pop-up Message from Avast
« Reply #14 on: July 16, 2013, 03:35:51 PM »
No I was just curious as to whether you had installed the programme

Are you still getting the alerts