Author Topic: Blocked Threads (HTML:RedirME-inf, URL:Blacklist)  (Read 1689 times)

0 Members and 1 Guest are viewing this topic.

Offline Ashielf

  • Newbie
  • *
  • Posts: 4
Blocked Threads (HTML:RedirME-inf, URL:Blacklist)
« on: October 24, 2019, 05:05:05 PM »
Hi all!

I get infrequent and irregular (3-4 times while working on my PC for multiple hours) warnings from Avast and Malwarebytes while having my browsers (primary an up-to-date Opera) open. The URL's vary but it's always about "HTML:RedirMe-inf [Trj]" and "URL:Blacklist".

I have already installed and run Malwarebytes but it doesn't find anything except when I ran it the first time (see last block in the Malwarebytes attachment).

I was not able to pin the cause. I don't have the same sites open when it happens and it also occurred once when opening Chrome.
I attached the FRST readings.

Could anyone help me?

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Blocked Threads (HTML:RedirME-inf, URL:Blacklist)
« Reply #1 on: October 24, 2019, 05:26:26 PM »
Darkweb surfing are we? :P >> D:\Tor Browser\Browser\TorBrowser\Tor\tor.exe

I'll bring Sass Drake around to have a look for you.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Ashielf

  • Newbie
  • *
  • Posts: 4
Re: Blocked Threads (HTML:RedirME-inf, URL:Blacklist)
« Reply #2 on: October 24, 2019, 05:29:42 PM »
Darkweb surfing are we? :P >> D:\Tor Browser\Browser\TorBrowser\Tor\tor.exe

I'll bring Sass Drake around to have a look for you.

Damn, I thought wearing a hoody and balaklava would be enough to stop detection. Now you have me.
In all seriousness though, I have only used it on common sites to stop annoying trackers and the like or to get an unfiltered view. Shouldn't have gotten anything via Tor.

Thanks for helping.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: Blocked Threads (HTML:RedirME-inf, URL:Blacklist)
« Reply #3 on: October 24, 2019, 05:52:49 PM »
Have you tried to clear your browsers cache / surf history ?


Offline Ashielf

  • Newbie
  • *
  • Posts: 4
Re: Blocked Threads (HTML:RedirME-inf, URL:Blacklist)
« Reply #4 on: October 24, 2019, 06:44:48 PM »
Have you tried to clear your browsers cache / surf history ?
To be honest, this slipped my mind. I have done it now and will keep an eye on the prompts.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Blocked Threads (HTML:RedirME-inf, URL:Blacklist)
« Reply #5 on: October 24, 2019, 07:39:56 PM »
Have you tried to clear your browsers cache / surf history ?
To be honest, this slipped my mind. I have done it now and will keep an eye on the prompts.

I was joking around about Tor. I wasn't trying to insinuate you were doing anything bad. I have a dark sense of humour, so my apologies. (Tone doesn't translate very well over text either.)
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Ashielf

  • Newbie
  • *
  • Posts: 4
Re: Blocked Threads (HTML:RedirME-inf, URL:Blacklist)
« Reply #6 on: October 24, 2019, 07:46:40 PM »
No offence taken.  8)

Unfortunately, the alarms still persist, even after clearing the cache/history. Here is the newest one:

Malwarebytes
www.malwarebytes.com

-Log Details-
Protection Event Date: 24/10/2019
Protection Event Time: 19:44
Log File: f814386c-f685-11e9-b636-5404a66bc052.json

-Software Information-
Version: 3.8.3.2965
Components Version: 1.0.629
Update Package Version: 1.0.13053
Licence: Trial

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: System

-Blocked Website Details-
Malicious Website: 1
, , Blocked, [-1], [-1],0.0.0

-Website Data-
Category: PUP
Domain: usa.godabert-nap.com
IP Address: 52.207.141.11
Port: [52313]
Type: Outbound
File: C:\Program Files (x86)\Opera\64.0.3417.61\opera.exe

(end)