Avast WEBforum
Other => Viruses and worms => Topic started by: Avaster654457 on November 14, 2018, 11:47:44 AM
-
I booted up yesterday and got this message, what worries me is that i had no browser windows open and it seems to be a web-based warning which could indicate something malicious already on/in my PC
I know all manor of programs are always contacting the internet for updates or whatever but i have never gotten this type of message unless browsing the internet
As i was writing this post and in the process of doing a smart scan i got another popup
Hear are the warning popups, my updates, scan settings and results
I am now running full system scans with Avast, Malwerebytes and Super anti spyware
-
...
-
You can report a suspected FP (File/Website) here: https://www.avast.com/false-positive-file-form.php
-
What exactly am i supposed to upload because there is no actual file infected (i think)?
The avast popup said the process was ...system32\svchost.exe but that's not actually a file and there are multiple versions of this process name running
The URL is http://crl4.DigiCert.com/DigiCertAssuredIDRootCA.crl but again that doesnt help me upload anything because it could be or is the file/process that is malicious
-
What exactly am i supposed to upload because there is no actual file infected (i think)?
your screenshot say URL:Phising, so you submit blocked URL as possible FP
The avast popup said the process was ...system32\svchost.exe but that's not actually a file and there are multiple versions of this process name running
process = What is trying to contact that URL
If you think you are infected and want assistanse from a expert, follow instructions >> https://forum.avast.com/index.php?topic=194892.0
-
I scanned the URL via virus total and it came back clean
I have done full scans with Avast, Malwerebytes and super anti spyware and they came back clean
I do not believe my system is infected
However i would like to know the reasoning for getting the messages
Was it a false positive of the URL or a false positive of svchost.exe, was it a windows based program etc
-
bump
-
Do you still get the warning..?
-
I scanned the URL via virus total and it came back clean
So possible False Positive ... submit it to avast lab
You may already know. VT does not scan the website for infections it check it against a number of blocklists
However i would like to know the reasoning for getting the messages
Was it a false positive of the URL or a false positive of svchost.exe, was it a windows based program etc
If you send it to avast lab and give them the info then you find out when they reply