Avast community forum
Home
Help
Search
Login
Register
Avast WEBforum
»
Consumer Products
»
Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier)
(Moderators:
hectic-mmv
,
LudekS
,
chytil2
) »
URL Blocked by webshield
« previous
next »
Print
Pages: [
1
]
Go Down
Author
Topic: URL Blocked by webshield (Read 2213 times)
0 Members and 1 Guest are viewing this topic.
neorosis
Newbie
Posts: 2
URL Blocked by webshield
«
on:
December 01, 2019, 12:54:23 PM »
From today I am getting Popups saying URL blocked by Avast. The process is svchost.exe
The URL is to the domain
http://referently.club
The exact full URL is:
http://referently.club:8080/?tr=tNVOV1rk5ydiaEu13_PF8B--aW5ilgWxnFISE1x5BQyC3aqNhxyAt9gQd9BhNjLHX4z27xeBnN1kwL9BcYJEyDp7O3x5VF2s-hWBoSDQmQbAU-X_8esQE2A4olPcC_KEOuex7OlkUryd5ilUOsBlTPQxuzG5KkG2vKGuAlfaveTN0TwkDbkzm4jzf6QFC84j8TxV99zTXCnSuXnp7OVoqg0sdzVR1W0cU3r
Now I have tried to look for some process piggy banking on svchost.exe but not found any suspicious program or service. Boot time scan is clean. Malwarebytes scan is clean. Nothing suspicious at autorun or services list.
I disabled Avast for a few seconds and pasted this URL in browser which downloads a file named file.dat which Avast detects as generic malware. Virustotal analysis:
https://www.virustotal.com/gui/file/87cc748c326a03e6bbacbe486409d2964113fb33a410692b30465207bee8baba/detection
Google doesn't throw up any similar domain.
Will be glad to know where to look to eliminate what I suspect is well hidden trojan downloader.
Logged
Asyn
Avast Überevangelist
Certainly Bot
Posts: 76036
Re: URL Blocked by webshield
«
Reply #1 on:
December 01, 2019, 01:08:55 PM »
Start a topic in V&W and post your logs there:
https://forum.avast.com/index.php?action=post;board=4
Instructions (basic diagnostic logs):
https://forum.avast.com/index.php?topic=194892.0
Logged
W8.1
[x64]
-
Avast Free AV 23.3.8047.BC
[UI.757]
- Firefox ESR 102.9
[NS/uBO/PB]
- Thunderbird 102.9.1
Avast-Tools:
Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos):
https://forum.avast.com/index.php?topic=60523.0
neorosis
Newbie
Posts: 2
Re: URL Blocked by webshield
«
Reply #2 on:
December 01, 2019, 01:38:18 PM »
OK Doing that shortly thanks.
Logged
Print
Pages: [
1
]
Go Up
« previous
next »
Avast WEBforum
»
Consumer Products
»
Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier)
(Moderators:
hectic-mmv
,
LudekS
,
chytil2
) »
URL Blocked by webshield