Author Topic: Web Shield False Positives  (Read 2302 times)

0 Members and 1 Guest are viewing this topic.

Offline flyboy_2

  • Newbie
  • *
  • Posts: 2
  • I'm a llama!
Web Shield False Positives
« on: October 24, 2016, 06:00:34 AM »
Back in June I posted something about the Avast Web shield in Mac setting off multiple false positives.

It claims to have blocked threats (always seems to be 3 in a row, and always random URL's). See image below.

If I put the laptop to sleep with Chrome open, then I get six alerts.

I tried creating a new blank account on Mac, logged in and started Chrome, and I still get 3 alerts, so I know it's nothing I've picked up in my account, it's not a Chrome extension, cookies, or anything like that.

It's not me or my data, so I thought it might be the Google Chrome web browser itself. One “expert” said he or she thought it might have something to do with “Chrome startup random DNS queries”. I didn’t get very far with that.

I was never able to figure out this problem. However, I now have some new information:

This issue ONLY happens on my laptop, and it ONLY happens when I am connected to the internet at my cottage. The cottage has a combo modem/router provided by my ISP, and it picks up the Internet feed from a cell phone tower.

Just today I heard from a friend, and they are having exactly the same problem. And how about this, their home is in a remote area, and like my cottage they also have a modem/router that picks up the Internet feed from a cell phone tower.

I am not sure whether we have the same ISP and/or model of modem/router, but I think I have narrowed it down to how we pick up the Internet.

Why exactly this would trigger the Avast Web shield to give false positives I still don’t know.

Anyone have any ideas?

Network+ / Linux +

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Web Shield False Positives
« Reply #1 on: October 24, 2016, 01:37:34 PM »
“Chrome startup random DNS queries” is indeed it.

Can you turn off your shield, then ping one of the random strings in printscreen? {win}+{R}, cmd {enter}, ping efhlkenfafp {enter}. Then copy all text and paste it here.

Thanks!

REDACTED

  • Guest
Re: Web Shield False Positives
« Reply #2 on: October 27, 2016, 08:08:15 PM »
Dianes-iMac:~ DianeMcKinzey$ ping http://efsulozjlcvreg/
PING http://efsulozjlcvreg/ (184.151.127.26): 56 data bytes
Request timeout for icmp_seq 0
Request timeout for icmp_seq 1
Request timeout for icmp_seq 2
Request timeout for icmp_seq 3
Request timeout for icmp_seq 4
Request timeout for icmp_seq 5
Request timeout for icmp_seq 6
Request timeout for icmp_seq 7
Request timeout for icmp_seq 8
Request timeout for icmp_seq 9
Request timeout for icmp_seq 10
Request timeout for icmp_seq 11
^C
--- http://efsulozjlcvreg/ ping statistics ---
13 packets transmitted, 0 packets received, 100.0% packet loss
Dianes-iMac:~ DianeMcKinzey$

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Web Shield False Positives
« Reply #3 on: October 28, 2016, 10:29:04 AM »
Thanks, I have unblocked 184.151.127.26 ;) If you run into a similar issue in the future, just post the IP that is causing this here.