Author Topic: unblocked maleware/virus/?  (Read 1940 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
unblocked maleware/virus/?
« on: December 05, 2015, 07:23:46 PM »
I started using openDNS.com as my DNS service to block inappropriate sites from my home network.  When I review the log of blocked sites, I see that every day, my computer is trying to hit 45 adult sites twice a day.  There is no indication of anything happening on my machine (no pop-ups or error messages).  I ran a full scan with AVAST and it didn't find anything. First of all, I don't know what this is called.  Is maleware, virus, trojen, browser hacker, etc.  Second, any ideas how to track this down on my PC?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: unblocked maleware/virus/?
« Reply #1 on: December 05, 2015, 07:27:03 PM »
are there other computers connected on your network?
are there other users of your computer?


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: unblocked maleware/virus/?
« Reply #2 on: December 05, 2015, 07:30:55 PM »
for a computer check ......

follow instructions here  https://forum.avast.com/index.php?topic=53253.0
attach Malwarebytes and Farabar Recovery Scan Tool logs ... 3 logs total

see below the box you write in ... Attachments and other options

when done a expert will check logs


REDACTED

  • Guest
Re: unblocked maleware/virus/?
« Reply #3 on: December 05, 2015, 08:04:45 PM »
Thanks for your help.  There are other computers/users.  I took computers/devices off the network for one day each to determine which computer is the source.  The scan software did not find anything either.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89052
  • No support PMs thanks
Re: unblocked maleware/virus/?
« Reply #4 on: December 05, 2015, 08:19:25 PM »
I suspect that might be avast doing a DNS poisoning check - it doesn't actually visit the sites - which checks some common and or heavily used sites to see what (that the correct) IP address is returned.

DNS Servers can get hacked and returns an incorrect IP address, so if you had issues on the DNS server (less likely with OpenDNS) you could get directed to a malicious site.

By doing this kind of check against known popular domains/ip addresses, it can check your DNS server isn't poisoned.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security