Author Topic: Multiple Avast Alerts Daily - Every Day For Months  (Read 4655 times)

Multiple Avast Alerts Daily - Every Day For Months
« on: December 24, 2007, 05:04:04 PM »
Hello All!

For about the last two months I have been receiving the following Avast alerts daily [with multiple alerts during the day]:

Malware Was Found!
A Trojan Horse Was Found!

It usually involves the following.

I then clicked on the "Abort Connection" Button to stop the Malware/Trojan Horse from downloading to the computer.

[1] Can anyone explain why these alerts are happening several times a day and every single day for over two months now?
[2] Is there something on the computer calling these files?
[3] How can I find out where they are coming from and stop them?
[4] How can I get this to stop [Very Annoying] and still use the computer safely?

Any and all responses appreciated.


Re: Multiple Avast Alerts Daily - Every Day For Months
« Reply #1 on: December 24, 2007, 05:11:54 PM »
1. it may be that there is something undetected or hidden (possibly browser hijack) that is connecting to those sites, assuming you aren't actually connecting to those sites.

2. see 1. above.

3. If you haven't already got this software try one in order (freeware), download, install, update and run it, preferably in safe mode.
If using win2k, winXP or Vista. SUPERantispyware On-Demand only in free version. Or AVG anti-spyware (formerly Ewido) Resident scanner during trial On-Demand after trial ends. Or Spyware Terminator Resident scanner.

Program & Tutorial - Also useful as a diagnostic tool - FileHippo Download - HiJackThis - HJT Information HiJackThis Tutorial.

Download and run HJT and post the contents of the log file (cut and paste) into this topic, you may need to split it over two or more posts depending on how large it is.

4. Providing avast keeps intercepting them you are relatively safe, however, that is only god for those that avast detects, so you need to get on to the SAS scan (report the results, log) followed up by HJT and post the contents of the log file, we can have a look at them.
Re: Multiple Avast Alerts Daily - Every Day For Months
« Reply #2 on: December 24, 2007, 05:16:38 PM »
I suggest:

1. Disable System Restore and reenable it after step 3.
2. Clean your temporary files.
3. Schedule a boot time scanning with avast with archive scanning turned on.
4. Use the tools posted by David: AVG Antispyware; SUPERantispyware and/or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.
5. Test your machine with anti-rootkit applications. I suggest AVG or Trend Micro RootkitBuster.
6. Make a HijackThis log to post here or, better, submit the RunScanner log to to on-line analysis.
7. Immunize your system with SpywareBlaster or Windows Advanced Care.
8. Check if you have insecure applications with Secunia Software Inspector.
Re: Multiple Avast Alerts Daily - Every Day For Months
« Reply #3 on: December 24, 2007, 05:18:41 PM »
You may well have an undetected downloader. I'd suggest an on line scan at

It will identify any malware it finds but won't remove it so you can deal with it later.


which will give you the option to rmove what it finds.

Just pause/stop avast's standard shield during the online scan.


Re: Multiple Avast Alerts Daily - Every Day For Months
« Reply #4 on: December 31, 2007, 04:33:40 PM »
Hello All!

Thanks for your advice oldman, Tech and DavidR.

I ran an online scan at  Nothing was found.

This morning after the computer booted up, I got a Window with a message that I was going to be redirected to a page and that any information I gave would be transmitted to another page.  I was given a choice to agree or cancel.  I canceled.

I never ever saw a window like that before.  I only have IE7 and FF 2.x on the computer.  No browser had been opened yet.

I will try to run an Avast Boot Scan later this evening.

I ran HijackThis this morning.  The results are below.

Again, thanks for all your help with this.


HijackThis Log File
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:13:47 AM, on 12/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\IDriveE\IDriveE Service.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common

O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)
O2 - BHO: Skype add-on (mastermind) -

{22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program

Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection -

{53707962-6F74-2D53-2644-206D7942484F} -

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -

C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO -

{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program

O2 - BHO: ZoneAlarm Spy Blocker BHO -

{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program

O3 - Toolbar: ZoneAlarm Spy Blocker -

{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program

Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program

O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows

Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"

O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting]

"C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting]

"C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: 2.3.lnk = C:\Program Files\

O8 - Extra context menu item: Add to Google Photos Screensa&ver -

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} -

C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine

Advantage Validation Tool) -
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash

Object) -
O17 -


: NameServer =
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software

- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program

Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program

Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program

Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Desktop Manager 5.5.709.30344

(GoogleDesktopManager-093007-112848) - Google - C:\Program

Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program

Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IDriveE Service - Pro Softnet Corporation - C:\Program

Files\IDriveE\IDriveE Service.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program

O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC -


End of file - 6792 bytes

Re: Multiple Avast Alerts Daily - Every Day For Months
« Reply #5 on: December 31, 2007, 08:07:43 PM »
Here is the analysis for your HijackThis log.
Sorry, I'm not an expert on cleaning.
Re: Multiple Avast Alerts Daily - Every Day For Months
« Reply #6 on: December 31, 2007, 08:21:31 PM »
The two lines flagged in the analysis would appear to be legitamate.

Re: Multiple Avast Alerts Daily - Every Day For Months
« Reply #7 on: December 31, 2007, 08:24:39 PM »
Concur with Oldman looks clean


Re: Multiple Avast Alerts Daily - Every Day For Months
« Reply #8 on: January 01, 2008, 12:42:36 AM »
Yaa i also think it looks clean... ::)