Author Topic: Infection blocked when I visited https://us.etrade.com/home  (Read 1861 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Infection blocked when I visited https://us.etrade.com/home
« on: December 01, 2014, 06:50:16 PM »
Avast blocked infections this morning the first two times I attempted to log on to https://us.etrade.com/home.  Since then I have had nothing blocked.  When I looked in the log file I found something that appears to indicate an attempt to redirect. So I am now reluctant to trust logging on to ETrade even though Avast is no longer blocking anything.  Below are the pertinent log file entries.  Could anyone please tell me if I should be cocerned?  Thanks in advance for any help.

01.12.2014  08:49:33  Network Shield: blocked access to malicious site https://54.201.107.94 ([54.201.107.94]:443) [ C:\Program Files (x86)\Google\Chrome\Application\Chrome.exe ( 1264 ) ]

01.12.2014  08:50:07  Network Shield: blocked access to malicious site https://54.201.107.94 ([54.201.107.94]:443) [ C:\Program Files (x86)\Google\Chrome\Application\Chrome.exe ( 1264 ) ]

01.12.2014  08:50:09  Network Shield: blocked access to malicious site https://54.201.107.94:443/redir/505213/0/3449/461064/0/791533/0/0/922/1.ver?at=v&d=Conv&jsv=chl-1.4.2&csync=1&chl=&pg=https%3A%2F%2Fus.etrade.com%2Fhome&cus.aid= ([54.201.107.94]:443) [ C:\Program Files (x86)\Google\Chrome\Application\Chrome.exe ( 1264 ) ]

01.12.2014  08:50:09  Network Shield: blocked access to malicious site https://54.201.107.94:443/redir/505213/0/3449/461064/0/791533/0/0/922/1.ver?at=v&d=Conv&jsv=chl-1.4.2&csync=1&chl=&pg=https%3A%2F%2Fus.etrade.com%2Fhome&cus.aid= ([54.201.107.94]:443) [ C:\Program Files (x86)\Google\Chrome\Application\Chrome.exe ( 1264 ) ]

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Infection blocked when I visited https://us.etrade.com/home
« Reply #1 on: December 01, 2014, 07:03:49 PM »
IP history    https://www.virustotal.com/en/ip-address/54.201.107.94/information/

Could be some third party ads on that site, as the site itselfe has another IP