Author Topic: avast traps Deloton hijacking attempt but how to stop attacks completely?  (Read 3835 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Hi there.  My copy of Avast successfully interrupts repeated attempts to take over my browser etc in Chrome on Win 10  - seems to be every time I open Chrome. 

But my question is, why does the attempt keep being tried?  Is it something that is resident on my PC or does Deloton just have my ip address and somehow externally detects when I run Chrome or what?

Obviously I am pleased and relieved that Avast detects it, but concerned that the attempted attacks keep on happening.

I have run a few malware removal tools like adwcleaner and malwarebytes itself but none detect the presence of Deloton on my machine.

Any help appreciated.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Apologies - the malwarebytes scan was negative,  so I did not attach the log. Now appreciate that there might be info you still wanted to see - so now attached.  I also ran a Farbar  scan and both files now attached.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
OK, now you've to wait for one of the malware experts...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Sure - appreciate that

REDACTED

  • Guest
** Bump**

Sorry - not sure how long it takes to get a reply. Perhaps I'll should just keep waiting?

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Hi,

I'm surprised Sass hasn't visited you yet. I'll send them a reminder immediately.

I'm so sorry
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Sorry for late response.

Can you make screenshot of Avast message/popup?

REDACTED

  • Guest
I would if I could, but I think Avast only pops up for 20 seconds as the default.  I might well have missed recent examples.  I have changed the alert to 120 seconds to increase the chances of my seeing it (I have a three monitor setup so not always working on the relevant screen).

It there an activity log that might help

Richard

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
I don't see anything in FRST logs.



Please attach following file to your post.

C:\ProgramData\AVAST Software\Avast\report\WebShield.txt

REDACTED

  • Guest
OK here is the webshield.txt report.  You can see the relevant deloton attempts on 15 and 20 march.

Appreciate your continued support.

Richard

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Which websites you keep always opened in your browser?

REDACTED

  • Guest
I use Chrome and I normally have Gmail, Calendar, Contacts permanently pinned open. Otherwise I might pin a site or two because I am awaiting answers - like this site, maybe Amazon or a couple of forums like Lotus Cars or whatever.  I will close these as and when I have got what I was expecting.

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Report your findings please because Avast probably blocks some ad domain used by websites you use.

REDACTED

  • Guest
Er.. sorry report what findings?