Author Topic: powershell url blacklist  (Read 1786 times)

0 Members and 1 Guest are viewing this topic.

Offline jamierayf

  • Newbie
  • *
  • Posts: 2
powershell url blacklist
« on: May 18, 2022, 12:36:26 PM »
Hi I have been getting this popup recently and am struggling to find the source/fix it.

"aborted connection to api.privatechatting.com because it was infected with url blacklist. "

URL - -http://api.privatechatting.com/connect-

process - C:/Windows/System32/WindowsPowerShell/v1.0/powershell.exe

I'm not very computer literate, so please explain it simply for me :)

I saw some forums online that prompted me to install autorun and sysinspector. I'm not too familiar with either program but I couldn't see anything obvious when using them, as to what the cause may be. Any help is appreciated :)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: powershell url blacklist
« Reply #1 on: May 18, 2022, 01:20:58 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline jamierayf

  • Newbie
  • *
  • Posts: 2
Re: powershell url blacklist
« Reply #2 on: May 18, 2022, 02:03:05 PM »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: powershell url blacklist
« Reply #3 on: May 18, 2022, 03:36:50 PM »
You're welcome.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: powershell url blacklist
« Reply #4 on: May 19, 2022, 01:31:37 PM »
Any link starting with http should make you twice shy to click it without checking it's security in advance.

The link you presented us with landed you at: -https://www.afternic.com/forsale/api.privatechatting.com?utm_source=TDFS_DASLNC&utm_medium=DASLNC&utm_campaign=TDFS_DASLNC&traffic_type=TDFS_DASLNC&traffic_id=daslnc&utm_source=TDFS_DASLNC&utm_medium=DAS

The word 'forsale' in that link may say enough i.m.h.o.

Therefore Asyn's advice is a valid one, as you will find some trained malware removal expert's advice there, tailored to your specific malware situation.

Anyway the link above was given clean: https://www.virustotal.com/gui/url/534a35411f212abb3d349ca8e0a13a81ceb200e888fa731d6db1c1f0584691ce?nocache=1  But wait for the opinion of the malware cleansers at bleepingcomputer dot com.

polonus
« Last Edit: May 19, 2022, 01:34:58 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!