Avast WEBforum

Other => Viruses and worms => Topic started by: lexy191919 on August 04, 2020, 11:41:35 AM

Title: wpad.itotolink.com Threat blocked alert keeps coming up
Post by: lexy191919 on August 04, 2020, 11:41:35 AM
Hi there

Have a laptop running Avast Free antivirus that has been consistently blocking wpad threats
(please see screenshot of Avast message with details).

Have tried a couple of things to try to assist but to no avail.

Tried scanning & quarantining found items with Malwarebytes & AdwCleaner then rebooting
Resetting resetting Chrome sync, removing all stored browser data & resetting Chrome sync. (It seems to happen when using Chrome, although not necessarily exclusive to Chrome)

Have attached scan logs from Malwarebytes, & Farbar but could not get a scan done with aswMBR.exe as laptop kept crashing during scan.

Any assistance is very much appreciated, thank you in advance.
Title: Re: wpad.itotolink.com Threat blocked alert keeps coming up
Post by: Pondus on August 04, 2020, 04:41:05 PM
Quote
but could not get a scan done with aswMBR.exe as laptop kept crashing during scan.
aswMBR has not been updated for a long time and dont support Win10


wpad.itotolink.com = Blacklisted
https://www.virustotal.com/gui/url/28fd0d3401ffc64fabeb816882a44bd121f0449f7ad940aa59ebabfe8e45601c/detection


Title: Re: wpad.itotolink.com Threat blocked alert keeps coming up
Post by: goremarcos on August 04, 2020, 05:58:43 PM
Could you please help us with what we have to do resolve this? I see the problem with the url in the link you gave us but how does that help us to stop this? What do we have to do?

I´m having thew same problem.

Thank you!!
Title: Re: wpad.itotolink.com Threat blocked alert keeps coming up
Post by: Pondus on August 04, 2020, 08:08:58 PM
Could you please help us with what we have to do resolve this? I see the problem with the url in the link you gave us but how does that help us to stop this? What do we have to do?

I´m having thew same problem.

Thank you!!
Instructions  >>  https://forum.avast.com/index.php?topic=194892.0


Title: Re: wpad.itotolink.com Threat blocked alert keeps coming up
Post by: lexy191919 on August 05, 2020, 08:22:45 AM
Quote
but could not get a scan done with aswMBR.exe as laptop kept crashing during scan.
aswMBR has not been updated for a long time and dont support Win10


wpad.itotolink.com = Blacklisted
https://www.virustotal.com/gui/url/28fd0d3401ffc64fabeb816882a44bd121f0449f7ad940aa59ebabfe8e45601c/detection

Thank you Pondus

Hopefully someone can assist with the threat blocked warning that keeps coming up all the time. (We are not accessing the blacklisted site manually at all, something in the background seems to be doing so, and I can't pinpoint what it is).

I've seen other folks with a similar wpad gremlin have been assisted with a fixlist file that superheros on this forum have sent to them to apply with Farbar. Holding thumbs here so that I don't have to do a last resort clean install of Windows 10.
Title: Re: wpad.itotolink.com Threat blocked alert keeps coming up
Post by: Pondus on August 05, 2020, 05:26:49 PM
see this  >>  https://forum.avast.com/index.php?topic=236869.msg1556902#msg1556902

Title: Re: wpad.itotolink.com Threat blocked alert keeps coming up
Post by: lexy191919 on August 05, 2020, 05:31:48 PM
see this  >>  https://forum.avast.com/index.php?topic=236869.msg1556902#msg1556902

Thank you Pondus

I will try and report back :)
Title: Re: wpad.itotolink.com Threat blocked alert keeps coming up
Post by: polonus on August 05, 2020, 07:39:54 PM
Link i infested
Quote
Checking: http://ww9.itotolink.com/
File size: 3864 bytes
File MD5: ba1cf847ad51aa5b810c6ff71600ca98

-http://ww9.itotolink.com/ - archive JS-HTML
>-http://ww9.itotolink.com//JSTAG_1[158][19b] - Ok
>-http://ww9.itotolink.com//JSTAG_2[3a8][fb] - Ok
>-http://ww9.itotolink.com//JSTAG_3[4e5][8f4] - Ok
>-http://ww9.itotolink.com//JSTAG_4[e1b][e3] - Ok
-http://ww9.itotolink.com/ - Ok

Checking: -http://wpad.itotolink.com
Engine version: 7.0.46.3050
Total virus-finding records: 9101533
File size: 640 bytes
File MD5: 1681044b0b070391553283c974894c78

-http://wpad.itotolink.com infected with Trojan.DownLoader27.22565

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)
Title: Re: wpad.itotolink.com Threat blocked alert keeps coming up
Post by: Sass Drake on August 06, 2020, 11:42:18 PM
Code: [Select]
cmd: reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" /v SearchList /d "" /f
Reboot: