Author Topic: Unknown connection apparently from AvastSvc.exe  (Read 3281 times)

0 Members and 1 Guest are viewing this topic.

Offline Equinox

  • Jr. Member
  • **
  • Posts: 33
Unknown connection apparently from AvastSvc.exe
« on: October 22, 2014, 06:36:42 AM »
Can someone tell me what this connection is and if it's safe?


It's in the Firewall Network connections section and it's under C:\Program Files\AVAST Software\Avast\AvastSvc.exe

I am using the new version via the 20 day trial for internet security 2015.

Thanks.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5420
  • Spartan Warrior
Re: Unknown connection apparently from AvastSvc.exe
« Reply #1 on: October 22, 2014, 07:14:11 AM »
It appears others are looking at this site too:
https://www.virustotal.com/en/url/6b2f271ce7a3261e5919b9b2f48add403c9c1ade8cb48f002c281d4f4adec44b/analysis/
Other webscanning engines report as down or benign:
http://www.herdprotect.com/ip-address-198.105.212.228.aspx
http://zulu.zscaler.com/submission/show/066c37fe0d660bd984cf62970a25f7fb-1413954102
http://sitecheck.sucuri.net/results/mark.handbookforhandymen.com
http://www.downforeveryoneorjustme.com/mark.handbookforhandymen.com
Could be a way avast! is blocking this site in the trial or paid versions, similar to a DNS filtering/lookup table, or the site is actually down at the moment.
Windows 10 Home 64-bit 20H2 Avast Premier Security version 21.3.2459 (build 21.3.6164.652) UI version 1.0.612.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9362
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Unknown connection apparently from AvastSvc.exe
« Reply #2 on: October 22, 2014, 07:16:40 AM »
It's not from avast!, avast's process just scans it, thats why it looks like avast! seems to be doing it, because all traffic goes through avastsvc.exe process.
Visit my webpage Angry Sheep Blog

Offline Equinox

  • Jr. Member
  • **
  • Posts: 33
Re: Unknown connection apparently from AvastSvc.exe
« Reply #3 on: October 22, 2014, 07:19:07 AM »
mchain, that was me.

I killed the connection and now it's back under system.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9362
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Unknown connection apparently from AvastSvc.exe
« Reply #4 on: October 22, 2014, 07:22:03 AM »
I suggest you go to Full scan menu, enable PUP detection and scan the system. There has to be something missed that is doing this. Most likely a PUP...
Visit my webpage Angry Sheep Blog

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5420
  • Spartan Warrior
Re: Unknown connection apparently from AvastSvc.exe
« Reply #5 on: October 22, 2014, 07:23:02 AM »
mchain, that was me.

I killed the connection and now it's back under system.

Are you the owner of this site?  Or did you kill the connection within avast?  See RejZoR answer.
Windows 10 Home 64-bit 20H2 Avast Premier Security version 21.3.2459 (build 21.3.6164.652) UI version 1.0.612.

Offline Equinox

  • Jr. Member
  • **
  • Posts: 33
Re: Unknown connection apparently from AvastSvc.exe
« Reply #6 on: October 22, 2014, 07:26:42 AM »
I am not the owner of the site, it just showed up - as the first picture says.
The Virustotal scan of the site was from me, that was what I meant.

I was doing a quick scan but I'll change it to fullscan and shut off the network. I also have Malwarebytes premium but that hasn't found anything on it's threat scans.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9362
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Unknown connection apparently from AvastSvc.exe
« Reply #7 on: October 22, 2014, 07:35:55 AM »
There should be one more trick to see what's doing it. Disable Web Shield shield entirely (but just this shield) and check the firewall to see which EXE is really doing it. Because when you turn off Web Shield, connections shouldn't pass through avastsvc.exe anymore and you should see the actual origin EXE. This should help us identify the real cause of it and not the wrong one (avast!'s service just scanning it).
Visit my webpage Angry Sheep Blog

Offline Equinox

  • Jr. Member
  • **
  • Posts: 33
Re: Unknown connection apparently from AvastSvc.exe
« Reply #8 on: October 22, 2014, 08:15:16 AM »
I disabled the webshield and it's still under system and the same as the second photo shows.

Offline Equinox

  • Jr. Member
  • **
  • Posts: 33
Re: Unknown connection apparently from AvastSvc.exe
« Reply #9 on: October 22, 2014, 08:47:40 AM »
I'm not going to pretend I know the possibility of what I'm about to say, but is it per chance possible?

My ISP has this thing called 'Global Mode', where my country's IP addresses don't get flagged as ours - it relies on their DNS settings - so it looks as if the user is not from my country but instead American so we can go to sites such as Hulu and Netflix etc. Now, with SecureDNS off, the issue (the connection 'mark.handbookforhandymen.com') has not come back, but instead there was another one that had the same DNS and/or ISP in the 'Get Details' thing. I currently have the secure DNS off, and it has nothing other than what I expected to be there (connection wise - Chrome extensions etc). However, when I turn the SecureDNS on, it all goes back to there being a weird connection much like the mark.handbook... but instead it's I think the IP address and the ISP and more all in the name, which reminds me of the DNS I get when I google it for my ISP (ie they're similar, IP address and ISP name in the name of it).
Is it possible this is just a conflict between my ISP's DNS and the SecureDNS?
note; if any of this makes no sense please don't hesitate to tell me to shut up - because as I said, I don't know anything about this.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9362
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Unknown connection apparently from AvastSvc.exe
« Reply #10 on: October 22, 2014, 11:20:41 AM »
Are you using ProxMate in your browser or through DNS ?
Visit my webpage Angry Sheep Blog

Offline Equinox

  • Jr. Member
  • **
  • Posts: 33
Re: Unknown connection apparently from AvastSvc.exe
« Reply #11 on: October 22, 2014, 11:29:31 AM »
No proxies of any kind. The thing I described above is all through my ISP.