Author Topic: File reputation warning  (Read 5683 times)

0 Members and 1 Guest are viewing this topic.

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
File reputation warning
« on: July 15, 2015, 10:15:42 AM »
For Windows Update kb890830-x64-v.5.26
downloaded by c:\Windows\Sysem32\svchost.exe
from IP 80 17 2 198
seemingly an IP in my own ISP's network.



BTW, copy and paste text from Avast alert windows would help!

« Last Edit: July 15, 2015, 10:31:34 AM by 1234ava »

Offline stibi

  • Sr. Member
  • ****
  • Posts: 383
Re: File reputation warning
« Reply #1 on: July 15, 2015, 10:28:38 AM »
too small to read ...

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: File reputation warning
« Reply #2 on: July 15, 2015, 10:32:53 AM »
I've updated my post with a second screenshot. Hope it helps!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: File reputation warning
« Reply #3 on: July 15, 2015, 03:51:13 PM »
It looks as though your ISP is adding a redirect to windows updates and this does alert Avast as it expect a direct line

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: File reputation warning
« Reply #4 on: July 15, 2015, 04:20:25 PM »
OK, but why? Is it sort of a proxy?
I followed these instructions to check whether I am behind an ISP proxy, but looks like I am not, not even a transparent one.
 https://thevpn.guru/transparent-proxy-detect-expose-explain/


According to VirusTotal the file
hXXp://80.17.2.198/data/8006b0f02907687d/au.v4.download.windowsupdate.com/d/msdownload/update/software/uprl/2015/07/windows-kb890830-x64-v.5.26_9b9723c065acf885288e5f085994de2e1f75157a.exe

is clean
https://www.virustotal.com/en/url/a97d99b7637eb6ecd523e4278e66163951fe87cd9c31371ed1b84001db8108f8/analysis/1436969579/

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: File reputation warning
« Reply #5 on: July 15, 2015, 04:23:48 PM »
P.s. I don't know if it matters, but I am using OpenDNS, not my ISP's DNS.

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: File reputation warning
« Reply #6 on: July 15, 2015, 05:06:02 PM »
In other words, should I trust the connection or abort it?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: File reputation warning
« Reply #7 on: July 15, 2015, 06:47:53 PM »
Is your ISP Telecom Italia S.p.a  ?  Yes you can trust the download

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: File reputation warning
« Reply #8 on: July 15, 2015, 08:19:38 PM »
OK. Thanks!

Anyways, I don't like my ISP hijacking my windowsupdate downloads.

REDACTED

  • Guest
Re: File reputation warning
« Reply #9 on: September 02, 2015, 05:48:58 PM »
I started getting similar warnings a few days ago --- that would be late August of 2015..

I am going to provide some information and comments. However, I want to first say that, in my view, AVAST SHOULD RESPOND and let us know exactly what is going on.

1. I abort the download in every case.

2. As long as the notices remain, my browser stalls and will not access the internet. However, my Juno 4 stand-alone email still works. Once I have aborted all attempted downloads, the browser function resumes.

3. The notices come in groups of 6 (once, I got a group of 7) with the same filename and same “origin”. A group comes about 2 or 3 times daily.

The finename is different between groups or batches. The “origin” also varies, but by just one letter: for example:

http://download.windowsupdate.com/c/msdownload/update/software/defu/2015/..

and

http://download.windowsupdate.com/d/msdownload/update/software/defu/2015/ ...

My system is set to never download anything without my knowledge. Therefore, anything that IS downloaded to my system without my knowledge is malicious. In the present case, there is no question that these attempted downloads are malicious.

I have more detailed notes of my experience with that, but I think the above contains all the necessary information.

PLEASE --- AVAST --- look into this and let us know what is going on.

Thanks.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: File reputation warning
« Reply #10 on: September 02, 2015, 05:51:44 PM »
that seems to be windows update files or windows 10 files if you have said yes to the upgrade


REDACTED

  • Guest
Re: File reputation warning
« Reply #11 on: September 02, 2015, 06:20:58 PM »
This reply seems to have been lost so I'm submitting it again. Sorry if there is a duplicate:

"that seems to be windows update files or windows 10 files if you have said yes to the upgrade"

I see no evidence that this is anything but a guess. I have seen similar attempts at an explanation many times in various forums. I regard it as a poor guess because these files appear without any explanation or request for permission from the point of origin and are not digitally signed.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: File reputation warning
« Reply #12 on: September 02, 2015, 07:13:30 PM »

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: File reputation warning
« Reply #13 on: September 03, 2015, 09:59:21 AM »
@Infti, did you say Yes to getting Windows 10?