Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: Kekurikekaka on March 13, 2010, 12:18:41 AM

Title: I get Exploit Blocked message all the time
Post by: Kekurikekaka on March 13, 2010, 12:18:41 AM
Hello!  :)

I get a exploit blocked message all the time. Maybe once every 5-20 minutes, and its very annoying. Never got this with the old avast. I now run version 100312.

The content of message:
Quote
EXPLOIT BLOCKED

avast! Network Shield has blocked a threat.
No further action is required.

Object: 88.111.44.247:135/tcp
Infection: DCOM Exploit
Action: Blocked

The threat was detected and blocked just before the attack.

This is almost a clean install of Windows 7, with all valid and bought software. All the installed software is the same i had installed before i reformatted the harddrive. The difference is avast.

I have also searched for viruses, with 0 infected files. I've run a open port scanner, and i get full scores with no open ports.

Please, help me stop this message! I like avast, but this popup is killing me..
Title: Re: I get Exploit Blocked message all the time
Post by: disPlay on March 13, 2010, 12:42:17 AM
The IP Address 88.111.44.247 goes for United Kingdom with the ISP Tiscali UK Limited.And here is the desciption of the 135 port.
Microsoft's DCOM (Distributed, i.e. networked, COM) Service Control Manager (also known as the RPC Endpoint Mapper) uses this port in a manner similar to SUN's UNIX use of port 111. The SCM server running on the user's computer opens port 135 and listens for incoming requests from clients wishing to locate the ports where DCOM services can be found on that machine.
Title: Re: I get Exploit Blocked message all the time
Post by: Kekurikekaka on March 13, 2010, 12:45:22 AM
So what you are saying is that my IP adress is listed som where and people try to attack me by it?

And will it stop if i get my ISP to change my IP?
Title: Re: I get Exploit Blocked message all the time
Post by: Pondus on March 13, 2010, 01:06:49 AM
http://forum.avast.com/index.php?topic=54444.0
Title: Re: I get Exploit Blocked message all the time
Post by: DavidR on March 13, 2010, 01:25:49 AM
It is a DCOM Exploit, which is both random and speculative:
Random in that it is not targeted to your but uses a randomly generated IP address (which has hit upon your IP), your IP address is generated dynamically by your ISP so it is changing so that is why it is random and not targeted.
Speculative in the fact that if your OS is up to date and everything after XP SP2 (and a bit) isn't vulnerable to the exploit, but the speculate that at some point they will hit an IP with an out of date OS.

So this is more of a pain in the rear and avast's network shield has stopped it getting on to your system, why you didn't find anything.

Under normal circumstances your firewall should intercept these exploit attempts and just block them, for whatever reason avast is either loading before the windows 7 firewall (or your firewall) or your firewall is letting it through (possibly file and printer sharing is enabled).

What is your firewall ?
Title: Re: I get Exploit Blocked message all the time
Post by: Kekurikekaka on March 13, 2010, 01:29:44 AM
Thanks.

I actually got the very same infected registry item.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.


After searching in Google, i have found out that this is a file in Windows 7, and is not a infected files. All x64 Windiws 7 have this "infection".
I dont want to remove it either, as the guy in the topic you gave me link to had to take a system restore.

Any more ideas? If i cant figure this out soon, i have to change AV  :(

EDIT
I use Windows 7 64 bit with default firewall.
Title: Re: I get Exploit Blocked message all the time
Post by: DavidR on March 13, 2010, 01:37:01 AM
The registry hit in MBAM is I believe flawed as some people actually make this change not to allow changes to the active desktop if they use it.

I wouldn't remove it either - So I would either report it as a false positive or flag it as Ignore or just take no action on it.

What is a file, what you have posted is a registry entry not a file.
Title: Re: I get Exploit Blocked message all the time
Post by: Pondus on March 13, 2010, 01:38:14 AM
quote: http://groups.google.com/group/alt.privacy.spyware/browse_thread/thread/009ef8cc0c7cf3ae

The HKLM\...\NoActiveDesktopChanges registry key above determines
whether or not the users of the machine have the ability to change
their active desktop configuration. There are a large number of
trojans and malware that change that registry entry to "1" in order to
prevent users from removing the displayed content within the active
desktop.  You can also set this to 1 to prevent users from changing
their wallpaper, for instance.  It is not necessarily an indication
that you are compromised, but by default users are allowed to change
their active desktop settings.  The Malwarebytes program flagged the
registry entry because it is more often than not an indication that
malware may be present.  If you are comfortable with the appearance
and functioning of your Windows desktop, and don't plan on allowing
other users to change the desktop settings, then leave the registry
entry set to 1, otherwise set it to zero or allow Malwarebytes to do
it for you.

and DavidR is spot on.....