Author Topic: hourly popups of Threat Secured  (Read 1220 times)

0 Members and 1 Guest are viewing this topic.

Offline C J

  • Newbie
  • *
  • Posts: 2
hourly popups of Threat Secured
« on: February 23, 2024, 08:54:14 PM »
I'm trying out Avast Free on win7 home  64bits, Avast ver. 24.1.6099, Virus defs. ver. 240221-8.

I'm getting a Threat Secured popup at 16 minutes after every hour.  The popups say a connection was aborted by svchost.exe to http://190.2.139.23/wpad.dat and that a Trojan Horse threat was involved.

The system log always shows (WinHttpAutoProxySvc) having been started at that time.

Also, the Task Scheduler shows ...\AvastBrowserUpdate.exe scheduled to run at that time, and if I run it manually from the Task Scheduler, I also get the popup.  I get another similar popup after each boot, no others.

Scans of my system by both Avast and Malwarebytes do not find any infections.  What to do?

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5719
  • Spartan Warrior
« Last Edit: February 23, 2024, 11:08:05 PM by mchain »
Windows 11 Home 23H2
Windows 11 Pro 23H2
Avast Premier Security version 24.8.6127 (build 24.8.9372.868)
UI version 1.0.814

Offline JGram

  • Newbie
  • *
  • Posts: 9
Re: hourly popups of Threat Secured
« Reply #2 on: February 24, 2024, 12:49:47 AM »
Is nuking it and doing a fresh OS install an option?

Are you sure your install is fully patched? Are you running deep/full scans or quick scans?Running anything misc. legacy on that system? Asking because win7 is pretty dated, not throwing stones.

Also, see if you can disable Avast Browser in the Avast app, and check your startup lists to make sure Avast Browser isn't on it.

Offline C J

  • Newbie
  • *
  • Posts: 2
Re: hourly popups of Threat Secured
« Reply #3 on: February 25, 2024, 04:29:57 AM »
Thanks much to JGram and mchain for your guidance.

I agree that Win7 is dated and I will have to dispense with it someday, but for now ...

The ipqualityscore site did find 2 checkers that rated the IP as Malicious, but also lots that didn't?  To the best of my awareness, the Web Proxy Auto-Discovery (WPAD) service hasn't been used on this system till installing Avast, and even then its use appears to be limited to only the Avast Browser updating itself.  I doubted the Avast Browser was looking somewhere bad to do its update, and expected that the Avast antivirus product was doing what it should.  Time to learn more of what WPAD does and why it thought the mentioned IP should be looked at.

I haven't come across any UI method of shutting down the Avast Browser.  I am almost always a Firefox user.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5719
  • Spartan Warrior
Re: hourly popups of Threat Secured
« Reply #4 on: February 27, 2024, 12:14:02 AM »
Not aware of any issues with Avast Secure Browser using WPAD to update itself here.

If you disable add-ons for  ASB do the alerts go away?  (Back up bookmarks first)  Re-enable add-ons one at a time, are all clean?  Uninstall ASB do alerts cease?

(Reason for backing up bookmarks is so as to be able to restore later if needed.)
Windows 11 Home 23H2
Windows 11 Pro 23H2
Avast Premier Security version 24.8.6127 (build 24.8.9372.868)
UI version 1.0.814