Author Topic: Enhanced Privacy Virus 208.91.196.4  (Read 6388 times)

0 Members and 1 Guest are viewing this topic.

dprout69

  • Guest
Enhanced Privacy Virus 208.91.196.4
« on: March 09, 2014, 02:24:37 AM »
OK... for some reason Avast Free just started going crazy on two computers...

Windows 7 64 bit
IE11
« Last Edit: March 09, 2014, 07:00:27 PM by dprout69 »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Enhanced Privacy Virus
« Reply #1 on: March 09, 2014, 03:08:35 AM »
URL:Mal = IP is blocked, most likely because the IP is blacklisted, malicious website(s) are hosted on that IP.

If you want us to check your system for malware, please follow these instructions:
http://forum.avast.com/index.php?topic=53253.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: Enhanced Privacy Virus
« Reply #2 on: March 09, 2014, 03:10:14 AM »
That IP address (in your image) is in the British Virgin Islands, Confluence Networks, so it is a bit strange given the domain name enhancedprivacy.eu. This check on the domain returns a different IP address, http://www.urlvoid.com/scan/enhancedprivacy.eu/#report.

Do you have any privacy add-ons in IE11 ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

dprout69

  • Guest
Re: Enhanced Privacy Virus
« Reply #3 on: March 09, 2014, 03:17:21 AM »
I have all the privacy lists enabled of which enhanced privacy is one of them.  I disabled it but it still flags.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Enhanced Privacy Virus
« Reply #4 on: March 09, 2014, 03:23:44 AM »
Zulu says it is a parked domain.

dprout69

  • Guest
Re: Enhanced Privacy Virus
« Reply #5 on: March 09, 2014, 03:27:33 AM »
whats a parked domain?  Ahhh... means its just like a placeholder website.

Interesting thing about this though is it started on both computers at the same time.  I'm thinking an update to either the list or avast may be triggering this.
« Last Edit: March 09, 2014, 03:32:16 AM by dprout69 »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Enhanced Privacy Virus
« Reply #6 on: March 09, 2014, 03:42:38 AM »
Please follow the instructions in the link I gave you.

dprout69

  • Guest
Re: Enhanced Privacy Virus
« Reply #7 on: March 09, 2014, 04:13:00 AM »
Just FYI... I completed a system image earlier and allowed avast to update as normal.  Once it updated the pop ups started again.

I just completed another system image and prevented avast from updating and the pop ups are non existent.  Looks to be a false positive from avast.

Im currently deep scanning with emsisoft, malwarebytes and avast... we'll see if anything alerts,  I'll then update avast and see if it triggers again.

dprout69

  • Guest
Re: Enhanced Privacy Virus
« Reply #8 on: March 09, 2014, 04:33:06 AM »
Additional info... that IP address is normal.

The IP address in my screenshot is:
http://208.91.196.4/?dn=enhancedprivacy.eu&pid=7PO84Q7C6

If you go into the Privacy list addons in IE > Get more tracking lists > click on Enhanced Privacy List, this particular privacy list's URL is:
http://www.searchremagnified.com/?dn=enhancedprivacy.eu&pid=7PO84Q7C6

Per http://netiplist.com/domain/searchremagnified.com
searchremagnified = 208.91.196.4 in the British Virgin Islands

Still haven't had a single pop up...

Still scanning
« Last Edit: March 09, 2014, 04:37:26 AM by dprout69 »

dprout69

  • Guest
Re: Enhanced Privacy Virus
« Reply #9 on: March 09, 2014, 12:47:12 PM »
So deep scans produced nothing. 

The moment I updated Avast on one computer the pop ups started again.  Surfing on the other computer that hasn't been updated I get no pop ups...  So if indeed that is focused solely on an URL, then the URL is the same on both computers.  The only difference between them is the Avast update yesterday afternoon.

I reported as False Positive. 

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Enhanced Privacy Virus
« Reply #10 on: March 09, 2014, 02:38:38 PM »
To me it doesn't seem a false positive.
It is only logical that avast blocks it after the update.
Latest version is offering better protection.
And as David and I pointed out, there is something fishy with that website.

dprout69

  • Guest
Re: Enhanced Privacy Virus
« Reply #11 on: March 09, 2014, 03:37:09 PM »
Well... it offers different protection... not necessarily better (may be flawed).

We'll see.  Theres another thread started as well where the OP posted his logs.  Either way I dont feel it's anything on my computer.  It has to do with that website and avast. 
« Last Edit: March 09, 2014, 03:44:14 PM by dprout69 »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Enhanced Privacy Virus
« Reply #12 on: March 09, 2014, 06:36:37 PM »
Hi,

Why would your computer be contacting random sites? Moreso fishy ones? That isn't normal and I suspect you do have malware active. Please post the logs for review.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

dprout69

  • Guest
Re: Enhanced Privacy Virus
« Reply #13 on: March 09, 2014, 06:49:50 PM »
Its not a random site.  There's another thread on this where the person posted logs.  Might as well close this one out as all the info is over there.

forum.avast.com/index.php?topic=147383.0
« Last Edit: March 09, 2014, 07:02:09 PM by dprout69 »

richard804

  • Guest
Re: Enhanced Privacy Virus 208.91.196.4
« Reply #14 on: March 10, 2014, 05:38:29 PM »
I am getting enhanced privacy virus since the new ie11 got installed on March 8.