Author Topic: Is my system compromised? Should I be worried?  (Read 1441 times)

0 Members and 1 Guest are viewing this topic.

Offline Sevestra Sin

  • Newbie
  • *
  • Posts: 4
Is my system compromised? Should I be worried?
« on: February 24, 2024, 05:57:22 AM »
I've been occasionally receiving this URL:Blacklist pop-up notification from Avast Free for about two weeks now. But judging from the URL, it seems to be coming from windows' update server or something, I don't know how to investigate deeper. Is this a false positive? Is my system compromised?

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5625
  • Spartan Warrior
Re: Is my system compromised? Should I be worried?
« Reply #1 on: February 24, 2024, 08:53:27 AM »
Cannot say there are no issues with your system, but Avast did block an internet connection it considered to be malicious.  This block should have prevented an infection from starting in the first place.

All depends on what you were doing or viewing at the moment.  Did you click a link, or view an ad?
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline Sevestra Sin

  • Newbie
  • *
  • Posts: 4
Re: Is my system compromised? Should I be worried?
« Reply #2 on: February 24, 2024, 09:28:17 AM »
Cannot say there are no issues with your system, but Avast did block an internet connection it considered to be malicious.  This block should have prevented an infection from starting in the first place.

All depends on what you were doing or viewing at the moment.  Did you click a link, or view an ad?
It appeared when I left my PC idle and no program were running at the time, not even in the background. I went back and the notification is already sitting on the screen. Surprisingly, I found someone else with the same issue posted theirs on this forum too. Their blacklisted URL has different domain and path, but the same query parameters as mine (cacheHostorigin=dl.delivery.mp.microsoft.com). https://forum.avast.com/index.php?topic=326222.0

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5625
  • Spartan Warrior
Re: Is my system compromised? Should I be worried?
« Reply #3 on: February 27, 2024, 01:43:58 AM »
Are you using Google Chrome as your browser?

Input this address in Chrome's address bar and press enter:  chrome://settings/content/notifications  Note:  This setting should work for all Chrome-based browsers.  Will not work for Firefox.

See this topic:  https://forum.avast.com/index.php?topic=326243.0

Go here within topic:  https://forum.avast.com/index.php?topic=326243.msg1715208#msg1715208
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline Sevestra Sin

  • Newbie
  • *
  • Posts: 4
Re: Is my system compromised? Should I be worried?
« Reply #4 on: February 27, 2024, 03:18:15 AM »
Are you using Google Chrome as your browser?

Input this address in Chrome's address bar and press enter:  chrome://settings/content/notifications  Note:  This setting should work for all Chrome-based browsers.  Will not work for Firefox.

See this topic:  https://forum.avast.com/index.php?topic=326243.0

Go here within topic:  https://forum.avast.com/index.php?topic=326243.msg1715208#msg1715208
I'm using Firefox as my browser, Google Chrome isn't installed on my system. Oh and I just finished doing a clean install of my windows 11 and it seems that the notification is coming from Microsoft Store because it popped-up 3 times consecutively when all the apps were auto updating themselves, the 3 blocked URLs shows the same IP as the one I originally posted here. The system was still in a pretty clean state where I only have the drivers installed using the CDs that came with the hardware, And Avast free. All of my external drives were also unplugged at the moment, and Firefox was installed much later on.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5625
  • Spartan Warrior
Re: Is my system compromised? Should I be worried?
« Reply #5 on: February 28, 2024, 04:31:39 AM »
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline Sevestra Sin

  • Newbie
  • *
  • Posts: 4
Re: Is my system compromised? Should I be worried?
« Reply #6 on: February 28, 2024, 08:57:13 AM »
See:  re:  151.139.180.7

Google lists your IP as located in the United States.
ip-tracker says Singapore (Asia)

Reset your modem?
Alright, I'll try resetting the modem tonight after work and wait a few days (leaving the PC on) to see if the web shield is still picking it up.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Is my system compromised? Should I be worried?
« Reply #7 on: March 02, 2024, 12:43:04 PM »
Also consider: https://www.reddit.com/r/techsupport/comments/18meugn/suspicious_microsoft_updates_from_stackpath_ips/

Wait for a final verdict from avast's.

Also: Set GPOS to not configured per above. Reboot system Windows 10 and Netgate running pfSense. You must remove all Squidguard URL blocks for anything that is "azureedge. net", example fp-as-azureedge. net. Set Windows in two places one with "netsh http set proxy" to use with Http Updates.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!