Ugly Hedgehog - Photography Forum
Home Active Topics Newest Pictures Search Login Register
Main Photography Discussion
Have you received this warning?
Oct 19, 2014 16:04:55   #
cgchief Loc: Jarrettsville
 
Last night while in the 'ugly hedgehog' I received an ALERT
from AVAST (my security program) stating that it had prevented a virus from entering.
URL
hxxp://debrovorda.com/aa/
infection: URL:Mal

I ran a scan with my Anti-Malware program hoping that would take care of the situation.

However, today I received the same ALERT
URL
hxxp://romolottra.com/aa/
infection: URL:Mal

Please comment and suggest action.

Reply
Oct 19, 2014 16:10:14   #
CHG_CANON Loc: the Windy City
 
I used the 'report issue' and forwarded your post to ADMIN. I've seen somewhat the same issue a few times over the past few years. ADMIN is a user and a PM to their attention is the best way to alert them of an IT type problem on the website. In addtion to the details you provided, include the date and time too.

Reply
Oct 19, 2014 16:10:26   #
Mr PC Loc: Austin, TX
 
cgchief wrote:
Last night while in the 'ugly hedgehog' I received an ALERT
from AVAST (my security program) stating that it had prevented a virus from entering.
URL
hxxp://debrovorda.com/aa/
infection: URL:Mal

I ran a scan with my Anti-Malware program hoping that would take care of the situation.

However, today I received the same ALERT
URL
hxxp://romolottra.com/aa/
infection: URL:Mal

Please comment and suggest action.


Computer guy here. Which antimalware do you have? We like Malwarebytes (the free version is fine), Superantispyware and Spybot. None of them is perfect. I would run one after the other to see if one of them picks it up. Let us know how it turns out. There are more extreme measures to try after this, including doing a System Restore to take the computer back to the way it was before this started. Hope this helps.

Reply
 
 
Oct 19, 2014 16:15:37   #
FRENCHY Loc: Stone Mountain , Ga
 
cgchief wrote:
Last night while in the 'ugly hedgehog' I received an ALERT
from AVAST (my security program) stating that it had prevented a virus from entering.
URL
hxxp://debrovorda.com/aa/
infection: URL:Mal

I ran a scan with my Anti-Malware program hoping that would take care of the situation.

However, today I received the same ALERT
URL
hxxp://romolottra.com/aa/
infection: URL:Mal

Please comment and suggest action.


A time or two during the past days , I had a big Red warning telling me that this site is not safe .At that point I shot everything off, and run a scan that last almost 2 hours . Nothing as been detected . So far so good

Reply
Oct 19, 2014 16:20:42   #
Erik_H Loc: Denham Springs, Louisiana
 
Mr PC wrote:
Computer guy here. Which antimalware do you have? We like Malwarebytes (the free version is fine), Superantispyware and Spybot. None of them is perfect. I would run one after the other to see if one of them picks it up. Let us know how it turns out. There are more extreme measures to try after this, including doing a System Restore to take the computer back to the way it was before this started. Hope this helps.

Does Malwarebytes put a big drain on your system's resources?

Reply
Oct 19, 2014 16:21:07   #
cgchief Loc: Jarrettsville
 
CHG_CANON wrote:
I used the 'report issue' and forwarded your post to ADMIN. I've seen somewhat the same issue a few times over the past few years. ADMIN is a user and a PM to their attention is the best way to alert them of an IT type problem on the website. In addtion to the details you provided, include the date and time too.


Date 10-18-2014 time about 10 pm
10-19-2014 time 4pm again 4:20pm

Reply
Oct 19, 2014 16:23:14   #
picpiper Loc: California
 
cgchief wrote:
Last night while in the 'ugly hedgehog' I received an ALERT
from AVAST (my security program) stating that it had prevented a virus from entering.
URL
hxxp://debrovorda.com/aa/
infection: URL:Mal

I ran a scan with my Anti-Malware program hoping that would take care of the situation.

However, today I received the same ALERT
URL
hxxp://romolottra.com/aa/
infection: URL:Mal

Please comment and suggest action.


In all likelihood these AVAST alerts have nothing to do with UHH. However, it does sound like you may be dealing with a rootkit that periodically tries to download additional nastiness which AVAST is blocking. I did a search for "AVAST infection: URL:Mal" and found these informative threads (among several others):

http://forum.avast.com/index.php?topic=110393.0
http://forums.malwarebytes.org/index.php?/topic/131309-urlmal-infection/

You will probably have to create a thread on the forum at malwarebytes.org to get some help in cleaning out the infection. They maintain specialized tools and will guide you through the clean up.

Good luck.

Reply
 
 
Oct 19, 2014 16:23:29   #
Swamp Gator Loc: Coastal South Carolina
 
I run ESET in conjunction with Malwarebytes Premium live protection on my desktop PC and have never had an alert pop up from this site.
Also never had a problem using an ipad or a Chromebook to view this site.

Reply
Oct 19, 2014 16:26:40   #
cgchief Loc: Jarrettsville
 
CHG_CANON wrote:
I used the 'report issue' and forwarded your post to ADMIN. I've seen somewhat the same issue a few times over the past few years. ADMIN is a user and a PM to their attention is the best way to alert them of an IT type problem on the website. In addtion to the details you provided, include the date and time too.


I received some further info
WINDOWS/SYSwow64/svchost.exe
Should I open this?

Reply
Oct 19, 2014 16:28:51   #
juicesqueezer Loc: Okeechobee, Florida
 
I have AVAST as well and got the same alerts as soon as I logged on to UHH yesterday and today. No problems so far, but don't like seeing those boxes!

Reply
Oct 19, 2014 16:33:27   #
picpiper Loc: California
 
One other thought: Look into your AVAST logs to find out more about what was happening when those warnings popped up.
Read this entire thread to find the log files:
http://www.sevenforums.com/software/107859-where-logs-avast.html

Reply
 
 
Oct 19, 2014 16:41:08   #
picpiper Loc: California
 
cgchief wrote:
I received some further info
WINDOWS/SYSwow64/svchost.exe
Should I open this?


svchost.exe is part of the Windows operating system. Basically it is a wrapper for many varied running services and processes. If AVAST mentioned it in an alert there may be something viral running inside one specific instance of svchost.exe. See here for more info:

http://www.howtogeek.com/howto/windows-vista/what-is-svchostexe-and-why-is-it-running/

Reply
Oct 19, 2014 17:12:41   #
cgchief Loc: Jarrettsville
 
Mr PC wrote:
Computer guy here. Which antimalware do you have? We like Malwarebytes (the free version is fine), Superantispyware and Spybot. None of them is perfect. I would run one after the other to see if one of them picks it up. Let us know how it turns out. There are more extreme measures to try after this, including doing a System Restore to take the computer back to the way it was before this started. Hope this helps.


I have and used both
SuperAntiSpyware and Malwarebytes Anti-Malware.

Further info from message
Process: Windows/SYSwow64/svchost.exe.

I am afraid to active it. Any knowledge of it?

Reply
Oct 19, 2014 17:41:28   #
joe west Loc: Taylor, Michigan
 
cgchief wrote:
Last night while in the 'ugly hedgehog' I received an ALERT
from AVAST (my security program) stating that it had prevented a virus from entering.
URL
hxxp://debrovorda.com/aa/
infection: URL:Mal

I ran a scan with my Anti-Malware program hoping that would take care of the situation.

However, today I received the same ALERT
URL
hxxp://romolottra.com/aa/
infection: URL:Mal

Please comment and suggest action.


i use AVG program...there's 2 version Free & pay....the free one has all the goodies, full blown free version

Reply
Oct 19, 2014 20:13:31   #
picpiper Loc: California
 
cgchief wrote:

Further info from message
Process: Windows/SYSwow64/svchost.exe.

I am afraid to active it. Any knowledge of it?


Did you miss my brief explanation (and link to complete explanation) that I posted above?

Reply
If you want to reply, then register here. Registration is free and your account is created instantly, so you can post right away.
Main Photography Discussion
UglyHedgehog.com - Forum
Copyright 2011-2024 Ugly Hedgehog, Inc.