Author Topic: Threat blocked, how to find out what program or browser is trying to access web  (Read 7138 times)

0 Members and 1 Guest are viewing this topic.

Offline joesampson69

  • Newbie
  • *
  • Posts: 9
Over the last 3 days I keep getting notifications every 3 hours or so that Avast blocked a threat. "We've safely aborted connection on ..... because it was infected with Other:Malware-gen"
How can i find out what program or browser is trying to access this connection? I have looked in the history and is shows all the threats blocked but it does not show who or what was trying to make the connection. I have closed all programs, restarted, scanned with Avast and Malwarebytes and no problems found. I haven't noticed anything strange with my computer or its performance. 15+ years on the internet and never had a virus or any issues.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37526
  • Not a avast user
Quote
How can i find out what program or browser is trying to access this connection?
That info is usually on the popup message

Screenshots hjelp


Offline joesampson69

  • Newbie
  • *
  • Posts: 9
This is all the information I can see.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37526
  • Not a avast user
I dont use avast anymore but it used to have a popup that said process

See screenshot here.   https://forum.avast.com/index.php?topic=218384.msg1492541#msg1492541
Here you can see that crome is the process connecting

Have you tried to clear your browser surf history or turning of browser extensions?


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89014
  • No support PMs thanks
I dont use avast anymore but it used to have a popup that said process

See screenshot here.   https://forum.avast.com/index.php?topic=218384.msg1492541#msg1492541
Here you can see that crome is the process connecting
<snip>

The pop up that gives the process (used, browser in this case and location details of the the malware) is the Avast Alert window (with the more details option selected).  Once you have closed that alert window, the notification area gives only basic information.

@ joesampson69
Try checking the Web Shield log file it may give more information than the Notification area.
Location: C:\ProgramData\AVAST Software\Avast\report\WebShield.txt new entries are appended to the bottom of that report file.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline joesampson69

  • Newbie
  • *
  • Posts: 9
I dont use avast anymore but it used to have a popup that said process

See screenshot here.   https://forum.avast.com/index.php?topic=218384.msg1492541#msg1492541
Here you can see that crome is the process connecting
<snip>

The pop up that gives the process (used, browser in this case and location details of the the malware) is the Avast Alert window (with the more details option selected).  Once you have closed that alert window, the notification area gives only basic information.

@ joesampson69
Try checking the Web Shield log file it may give more information than the Notification area.
Location: C:\ProgramData\AVAST Software\Avast\report\WebShield.txt new entries are appended to the bottom of that report file.
Thanks for the help. I checked out the location you pointed out and found the webshield.txt file. It lists the same information that in listed in the image i posted (the same info that is in the main program -notifications/history. )
I cant seem to find where (was it a browser or program and which one) the information is logged , if it is logged at all.

As far as the alerts and the balloon that would pop up, there isnt one anymore. I work at my computer for hours on end and sometimes the icon for the AVAST program (lower right hand side with all other running programs) that is orange will have a blue dot on it and that is what lets you know something is blocked. When i click on it, it only shows the basic info that i shared an image of.



Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89014
  • No support PMs thanks
Thanks for the help. I checked out the location you pointed out and found the webshield.txt file. It lists the same information that in listed in the image i posted (the same info that is in the main program -notifications/history. )
I cant seem to find where (was it a browser or program and which one) the information is logged , if it is logged at all.

As far as the alerts and the balloon that would pop up, there isnt one anymore. I work at my computer for hours on end and sometimes the icon for the AVAST program (lower right hand side with all other running programs) that is orange will have a blue dot on it and that is what lets you know something is blocked. When i click on it, it only shows the basic info that i shared an image of.

1.  I was hoping it would have given additional information.

2.  The Avast Alert window is a one shot deal, unfortunately once closed it can't be viewed again.  So don't panic (avast has essentially frozen time) and immediately delete the alert window, click the more details option and take a screenshot.  That helps and there is also a unique identifier at the bottom that could help Avast.

Were you actually trying to connect to inkestyle.net  ?  (edit typo in domain)

Were you browsing at the time and if so that is the browser ?
If so, have you added any new (or update any) add-ons ?
If not it could be a redirection from a site you are visiting
« Last Edit: November 04, 2021, 08:19:26 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline joesampson69

  • Newbie
  • *
  • Posts: 9
I was not trying to connect to the website. Something is trying to connect with to it and I dont know what it is.
I will get a blue dot over the Avast icon located lower right hand side (system tray) next to time.  There is no popup or sound. When I click on the icon Avast opens up and it shows 3 tabs, alerts, history and ignored issues.

There is not a link or button to press to show more details.

Since I first started this thread there have been 21 alerts and all have been to the inkestyle website.
No other alerts for any other websites.

Is there anywhere in Avast that is lists in detail what program/webpage/extension/ is trying to access the internet.

A few times I noticed the error popup when I was doing work for work in paint and excel. Meaning, I wasn't surfing the web.

The alert doesn't pop up everyday there was 4 attempts on 11/13 and then 1 today 11/17. I use my computer everyday 6 to 14 hours a day.

Is there a program to monitor my computer to see what is trying to access the internet?

Thanks for the help


Thanks for the help. I checked out the location you pointed out and found the webshield.txt file. It lists the same information that in listed in the image i posted (the same info that is in the main program -notifications/history. )
I cant seem to find where (was it a browser or program and which one) the information is logged , if it is logged at all.

As far as the alerts and the balloon that would pop up, there isnt one anymore. I work at my computer for hours on end and sometimes the icon for the AVAST program (lower right hand side with all other running programs) that is orange will have a blue dot on it and that is what lets you know something is blocked. When i click on it, it only shows the basic info that i shared an image of.

1.  I was hoping it would have given additional information.

2.  The Avast Alert window is a one shot deal, unfortunately once closed it can't be viewed again.  So don't panic (avast has essentially frozen time) and immediately delete the alert window, click the more details option and take a screenshot.  That helps and there is also a unique identifier at the bottom that could help Avast.

Were you actually trying to connect to inkestyle.net  ?  (edit typo in domain)

Were you browsing at the time and if so that is the browser ?
If so, have you added any new (or update any) add-ons ?
If not it could be a redirection from a site you are visiting

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89014
  • No support PMs thanks
Unfortunately there is no other area that would have any more details outside of the actual Avast Alert, More Details and there is a unique number in the alert window that Avast may be able to interpret.

So it is crucial that you gather as much information at the time of the alert, e.g. what you were doing at the time and make a screenshot of the Avast Alert or Error message/window.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline joesampson69

  • Newbie
  • *
  • Posts: 9
Unfortunately there is no other area that would have any more details outside of the actual Avast Alert, More Details and there is a unique number in the alert window that Avast may be able to interpret.

So it is crucial that you gather as much information at the time of the alert, e.g. what you were doing at the time and make a screenshot of the Avast Alert or Error message/window.

There is no alert window that pops up anymore. I remember on older versions of Avast it would beep 2 or 3 times and an alert window would pop up. That doesnt happen anymore. The only reason I know it blocked something is because of a blue dot over the Avast icon in the system tray. pic posted. when I click on the avast icon it opens a window. pic posted.

I checked the settings in avast , pic posted, and I think I have it set up so it should show any alert window popups.

Maybe Ill try a different anti virus and see if it picks up the same things

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89014
  • No support PMs thanks
Unfortunately I haven't experienced this Blue dot over the avast tray icon, so I don't know if this is just an indication of 'you have a notification' or something different.

Have you got avast set to Silent Mode ?
If so that could account for no Alert window.
If so 2 - I would suggest taking Avast out of silent mode in the hope of getting the popup again, click the more details option and do a screenshot.

That said I don't know how that would play out given your comment in the first post.
Quote from: joesampson69
Over the last 3 days I keep getting notifications every 3 hours or so that Avast blocked a threat. "We've safely aborted connection on ..... because it was infected with Other:Malware-gen"
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline joesampson69

  • Newbie
  • *
  • Posts: 9
I am the OG poster. I have seen this topic come up in a few other forums and people reference this thread. So I thought I should do a update. I still get the "Threat secured" "aborted connection" about every 3 months or so. When it does happen, I will get anywhere from 3 to 15 alerts usually all in a 48 hour period and then nothing happens for months.
It did it again today, so far 3 times in about 2 hours.
  Avast says the process is in c:\program files(x86)\Google\Chrome\Application\chrome.exe

Is there a program or way to find out what is using chrome to try and access this website? I have chrome open all day while I am working and today I was writing (using pen and paper) not touching my computer and the ding ding of avast goes off. "Threat Secured"... I dont get it.
https://sitecheck.sucuri.net/results/https/inkestyle.net/23567dbd647db71d0a.js

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89014
  • No support PMs thanks
Well it isn't unusual for the browser to be named as that is what is actually doing the connecting.
Your screenshot indicates there were more detections 3 / 3 probably more scripts

However if you aren't having the browser make that connection something else is.  This may be an extension/add-on that has been recently added or updated.  When the connection is made it is then running that javascript code and that is what avast is alerting on.

There are many others that also consider inkestyle.net malicious - https://www.virustotal.com/gui/url/6055b8e041cbd253a4b93b8f882623cbdc4d6732c26dd7529964073f94f06b53?nocache=1

I don't use chrome, but you should look at the extensions/add-ons that you have installed and remove any that you didn't install or might be suspect or you don't use frequently.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline joesampson69

  • Newbie
  • *
  • Posts: 9
Well it isn't unusual for the browser to be named as that is what is actually doing the connecting.
Your screenshot indicates there were more detections 3 / 3 probably more scripts

However if you aren't having the browser make that connection something else is.  This may be an extension/add-on that has been recently added or updated.  When the connection is made it is then running that javascript code and that is what avast is alerting on.

There are many others that also consider inkestyle.net malicious - https://www.virustotal.com/gui/url/6055b8e041cbd253a4b93b8f882623cbdc4d6732c26dd7529964073f94f06b53?nocache=1

I don't use chrome, but you should look at the extensions/add-ons that you have installed and remove any that you didn't install or might be suspect or you don't use frequently.

Thanks for the reply. Now a few hours later there are a total of 5 detections total all the same script / url

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89014
  • No support PMs thanks
Yes but that doesn't tell me anything new.

You need to investigate the browsers extensions as I mentioned, if you aren't physically connecting to that site something is and the most likely culprit are browser extensions.

You could also try a browser reset and see if that stops the connection/s.
As I mentioned I don't use chrome so I have no practical experience of doing this.

Browser Reset - https://support.google.com/chrome/answer/3296214?hl=en
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security