Author Topic: How to view history of blocked threats so that I know what has been blocked?  (Read 8686 times)

0 Members and 1 Guest are viewing this topic.

paulcola

  • Guest
Running Avast Free 5.0.677 on Windows XP SP3
Avast said it blocked something, but I still got infected. I was able to clean it with Process Explorer and Malwarebytes, but I have no idea what Avast attempted to block, or which site it derived from.

How can I run a history? Or is there a log file I need to view?

The file that showed up as a new process was hotfix.exe. But I have no idea what Avast called it when it attempted to block it. I have a feeling this particular baddie is showing up in ads in my Hotmail account (not in emails, the actual side ads on the Hotmail page).

Thanks!
Paul

PS: The search engine on this forum is, with all due respect, difficult to use. Searching for 'history of blocked sites" brings up everything but what I'm looking for (it even finds the word 'of' in 'software' and 'often', etc). Makes it a challenge to look for previously discussed issues.

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Based on my research of the file, hotfix.exe can eather be Microsoft's file to remove other Hotfixes or a virus trying to act like hotfix.exe. You could of uploaded it to VirusTotal...
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
The MS hotfixes don't have a hotfix.exe file name they usually have the format of the hotfix number, like the two in my image.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

paulcola

  • Guest
It'd be great to know the site it derived from so I could add it to my blocked list. I know for a fact that this hotfix.exe was malware pretending to be something else.

I've since installed a registry monitor on my computer so I can verify any and all changes to the registry as they occur. If something like this attempts to happens again, I will have another level of prevention.