Author Topic: URL:Mal & Other Popups  (Read 18400 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
URL:Mal & Other Popups
« on: November 15, 2017, 10:29:24 PM »
For the past few months ( since around September ), I have been getting antivirus popups from AVG, Malwarebytes and now Avast from different outbound connections onto my machine, one of the most frequent one being from URL:Mal. I do not have AVG anymore, and I have MWB installed, and am currently primarily using Avast as my antivirus software, but every one that I have tried has always had many outbound connection alerts.

I have gone through AVG tech support. This did not work. I am currently still going through MWB tech support and so far nothing is working. The link I am providing below is so far every single step I have tried, but nothing is solving these outbound connections that my antivirus programs keep detecting. I no longer have any free trial of AVG, MWB or Avast, so this is worrysome that something more dangerous is getting through.

These have been happening since I formatted my computer back in September. As I stated before, the link below helps explain more in detail, and is extremely text-heavy in things that I have already tried. Listing a few here, I have tried: ADW Cleaner, Sophos Virus Removal Tool, CCleaner, FRST64, RogueKiller, and Zemana AntiMalware. None of these have stopped these popups or have detected anything at all as far as I have seen. About twenty minutes before posting this I did get another alert from Avast stating it had an outbound connection from URL:Mal. I can provide screenshots if need be, more than the one I am also providing in this topic.

Can someone please help me fix whatever is wrong with my computer?

I'm also not exactly sure how to attach images, so I am providing a link for the popup Avast gave me recently. I have not attempted the latest fix yet on my MWB forum topic because I am waiting for it to be opened again.

https://forums.malwarebytes.com/topic/212373-continuous-website-blocked-reports/

https://i.imgur.com/lDHLSoy.png
« Last Edit: November 15, 2017, 10:30:55 PM by Twobees »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: URL:Mal & Other Popups
« Reply #1 on: November 15, 2017, 10:46:14 PM »
Having created and saved your screenshot on your system.
Use the Attachments and other options below the reply window.
-
Click to expand it.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

REDACTED

  • Guest
Re: URL:Mal & Other Popups
« Reply #2 on: November 15, 2017, 11:08:06 PM »
Didn't even see that option, thanks. Here's the most recent popup that I've gotten from Avast. AVG and MWB have had similar ones, both from Chrome and Skype sometimes.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: URL:Mal & Other Popups
« Reply #3 on: November 15, 2017, 11:31:45 PM »
Since this appears to be coming from chrome.exe, which presumably is your default browser ?

There may well be an add-on that is trying to connect to that URL.  Presumably you aren't intentionally connecting to that site and there isn't a default home page set to ling to there.  Sorry I don't use chrome so I don't know what it gets up to.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

REDACTED

  • Guest
Re: URL:Mal & Other Popups
« Reply #4 on: November 16, 2017, 02:41:08 AM »
If I'm remembering this correctly, I wiped my computer clean and the first two things I reinstalled on it were AVG and Google Chrome. As soon as I had both, and only the default Chrome extensions, AVG popped up with a URL:Mal notification. I had nothing else but base Windows programs then installed.

And yes, Chrome is my default browser. This happens no matter what I'm doing on my computer, as explained in the MWB link.
« Last Edit: November 16, 2017, 02:43:19 AM by Twobees »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: URL:Mal & Other Popups
« Reply #5 on: November 16, 2017, 05:30:15 AM »
Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: URL:Mal & Other Popups
« Reply #6 on: November 16, 2017, 10:05:55 AM »
« Last Edit: November 16, 2017, 10:14:19 AM by Pondus »

REDACTED

  • Guest
Re: URL:Mal & Other Popups
« Reply #7 on: November 22, 2017, 11:27:40 PM »
Here are the requested text files. The scan with MWB was not with the trial version of the program, only the free, basic version.

What do you mean when you're asking "do I use other devices with Chrome"? Like a phone, laptop, or tablet? I use Chrome on my mobile phones but I do not have a data plan, I only use WiFi.

I have not tried this link's help yet ( https://forums.malwarebytes.com/topic/214325-chrome-secure-preferences-detection-always-comes-back/ ) that you provided because the same one was posted to me on the MWB forums. I'm waiting for them to open the thread back up so I can ask more questions about it.

I'm not sure if that second link provided for me ( https://blog.malwarebytes.com/malwarebytes-news/2013/05/oh-the-sites-you-will-never-see/ ) can help or not, because I do not have the premium version of MWB anymore, and it is not an active protection program, it is only a scanner. It's not detecting anything anymore, but Avast still is, despite being a free version of it and not the paid service.


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: URL:Mal & Other Popups
« Reply #8 on: November 23, 2017, 07:13:39 AM »
Quote
I'm waiting for them to open the thread back up so I can ask more questions about it.
Only ask for help in one forum or it will be chaos


REDACTED

  • Guest
Re: URL:Mal & Other Popups
« Reply #9 on: December 01, 2017, 08:04:58 AM »
I think I'll stick with this one then since the other one seemingly isn't being re-opened for me again.

REDACTED

  • Guest
Re: URL:Mal & Other Popups
« Reply #10 on: December 04, 2017, 11:11:07 AM »
Had another popup about two hours ago. I wasn't even browsing, just watching YouTube in one window while playing a game. I do have a lot of other windows open, however, and I haven't gotten any alerts in a very long time, probably about a week or two.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user

REDACTED

  • Guest
Re: URL:Mal & Other Popups
« Reply #12 on: December 04, 2017, 08:44:18 PM »
I get a virus message every time I open a page on this web site.  Can you fix?
theboot@townsquarenewsletters.com

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: URL:Mal & Other Popups
« Reply #13 on: December 04, 2017, 08:53:20 PM »
I get a virus message every time I open a page on this web site.  Can you fix?
theboot@townsquarenewsletters.com
It is not a website, it is a e-mail adress ... note the > @


attach screenshot of avast message ....


Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: URL:Mal & Other Popups
« Reply #14 on: December 05, 2017, 05:19:55 PM »
hic.6125878[.]com
This is CoinHive In-Browser Miner Malware.Keep in mind this is a JS infection (malware is on this webpage that's why avast is blocking it) not a binary one.I and some other researchers on twitter have been seeing a steady uptick in miner malware.

Might have come from one those crap extension/infected webpage things that user's often install into their browsers by accident.Be wary of what you install and click on.There is a js:redirector somewhere in your system which is causing these connections to such sites (probably in your browser from what i can see in the logs)..Try flushing chrome cache and completely resetting it from the settings in chrome.

While you may have uninstalled it from the browser it may still have messed with chrome's pref file causing redirections to these places.
« Last Edit: December 05, 2017, 05:32:20 PM by TrueIndian »