Link to home
Start Free TrialLog in
Avatar of HMCS
HMCSFlag for United States of America

asked on

Avast Free Blocks Something

For the last few days Avast has been blocking something that I don't understand but I highly suspect that it is malware or something else that should not be here in the first place.

I've run scans with:

IO Bit Malware Fighter
Avast Free Antivirus
Avira
Spy bot S & D
Malwarebytes

None of these programs have turned up anything odd in numerous scans.

I am enclosing print screens of the last 10 instances I have had blocking notices. I hope that in showing these that someone can get a handle on what it going on.
Avast-1.jpg
Avast-2.jpg
Avast-3.jpg
Avast-4.jpg
Avast-5.jpg
Avast-6.jpg
Avast-7.jpg
Avast-8.jpg
Avast-10.jpg
Avatar of jhyiesla
jhyiesla
Flag of United States of America image

It appears that you have a program or process running that is trying to access certain web sites.  This assumes that you don't have any legitimate processes trying to do this.

You've run most of what I would have run to determine any buried malware on the computer.  You might also want to try combo fix from bleepingcomputer.dom or TDSSKiller from the Kaspersky site.  The latter is a root kit scanner and remover.
Avatar of HMCS

ASKER

I've downloaded TDSS Killer and the combofix - also the Kaspersky Virus Removal Tool. I'll post the results as soon as I can. thanks for the advice. I am very sure this is something on my computer that does not need to be there and more than likely is malware of some sort.
It could also be a botnet of some kind, but Malwarebytes should find and remove them.
Avatar of HMCS

ASKER

I hope the two things you mentioned will identify it and eliminate it - STAT! Things like this make me very nervous! I am happy tho that Avast at least blocked it but the program will not identify and eliminate it however.
Avatar of HMCS

ASKER

I did run TDSS, Combofix and Kaspersky Virus Removal Tool - which the latter I found while getting the TDSS tool.

The virus removal took did find two things but it was not what I was looking for. Once I got back online I had the same popup from Avast about it blocking a harmful webpage or file.

I am still concerned however that I have this happen in the first place and it (svchost.exe) is attempting to send me to a malicious web page.

That to me sends a message that still something is not right, as I should not be having this activity and then having Avast blocking the attempt(s) which are to more than one URL according to what I have seen in these reported attempts.

At this point in time I don't know what it would take to unearth the "root" cause of this behavior. I would appreciate your comments.

I have enclosed the actual report generated on what Kaspersky found.
Avatar of HMCS

ASKER

For some reason the file did not go through - I'll try one more time!User generated image
SOLUTION
Avatar of jhyiesla
jhyiesla
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of HMCS

ASKER

I rarely use IE but I am sure some programs use it. Mostly I use Firefox and occasionally chrome.  I always use CCCleaner which in theory should clean all of my browsers.

Also what about svchost.exe? It is always listed in my popups as the process involved? Actually at this moment svchost is not even running according to task mgr.

I've actually thought of somewhat ditching my present install of Win 7 64 bit and dual booting it with an OEM copy of Win 7 64 bit. I'd toyed around with doing this and i even have a lengthy question pertaining to doing just that but I never have gotten around to doing it since I had several simultaneous medical problems pop up that demanded my immediate attention. Presently I am still somewhat dealing with those diagnoses and its effect on my present health.

I'd certainly like to fix this problem first rather than diving into a dual boot situation since at this point in time my head is not exactly screwed on straight.

I'll do what you suggested and get back to you, hopefully today! :-) Thanks !
I agree about CCCleaner.  However, the error messages you reported did point to some of the temp files in your profile, although not ones typically used, at least by IE.

Dual boot can be OK, but, unless you can really successfully clean your problem, the most prudent thing to do is completely nuke your present setup and start over - obviously saving off important data you will need for the new install.

Assuming you have a desktop that will support multiple drives, you might also consider installing a new drive or putting a new drive in and keeping your old one in an external enclosure if you don' want to do dual-boot. Then you could install a fresh copy and more easily copy back your data from the second drive. Unfortunately with Windows there's no good way to copy programs - you have to reinstall them.
Hi HMCS,

Please run AdwCleaner on your system and post the logs for the same, it might ask you to reboot the system to do the cleanup as well, so reboot and post the logs.

https://toolslib.net/downloads/finish/1/

Sudeep
Avatar of HMCS

ASKER

Here is a download of the scan using the ADWcleaner:

Some of what is reported I do need to delete and others I have no real clue what it is and this is the type of thing I can't touch unless someone with more knowledge tells me it is ok to mess with.
AdwCleaner-R0-.txt
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of HMCS

ASKER

From what I've seen in this report it looks like alot of "fragments" of different things which I've deleted in the past and/or didn't know existed on my computer. in the first place.

I think I'll be busy deleting alot of things I consider potential problems or safe enough to delete without occurring any potential harmful effects.

After this is done I'll post a scan and also see if I get those Avast messages again. They seem to happen mostly when I first connect to the net but I've also seen "random" connection attempts also.

Hopefully this could solve this problem and is for sure worth a try.
Avatar of HMCS

ASKER

Sorry I've been late in getting the scan back to you but Real Life" got in the way!!!

Here is the most recent scan - I did delete alot of stuff that I could recognize as ok to delete.

The sad part is that when I reconnected to the internet I had the same popup again as before.

A few days ago I created another user account which is mostly "bare bones" and so far i don't have any of these popups from Avast.

So far what do you think ?
AdwCleaner-S0-05-29-15.txt
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of HMCS

ASKER

I am going to try and correct the profile and whatever else comes later!

I've had two messages that this question is inactive and so I am going to just close it out and work on it on my own!

I appreciate the help and assistance that you have given me,

Thanks again and it may be a long time before I ever submit another question at EE! I've been a member since about 1999 and before the even since it was free then.