What you are seeing is an alert by Avast telling you that it detected something harmful on a site, and it blocked the action to protect you (“action blocked”). Avast was doing its job to protect you.
You can submit the url to Virus Total if you like for analysis: Virus Total: http://www.virustotal.com/, then if you like report back the results in this thread (cut and paste the report).
There is something hidden/undetected on your system mis-using svchost.exe to connect. The only time the svchost.exe usually connects is for windows updates and this isn’t the case here.
So whilst avast is blocking access to the malicious site we need to find the cause.
If you haven’t already got this software (freeware), download, install, update and run it and report the findings (it should product a log file).
MalwareBytes Anti-Malware (MBAM), On-Demand only in free version http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe, right click on the link and select Save As or Save File (As depending on your browser), save it to a location where you can find it easily later. - 2. SUPERantispyware (SAS). On-Demand only in free version.
Don’t worry about reported tracking cookies they are a minor issue and not one of security, allow SAS to deal with them though. - See http://en.wikipedia.org/wiki/HTTP_cookie.
MBAM is a simple diagnostic tool that many of us here use, and in your situation can help us identify problems.
Check your computer for malware with Malwarebytes’ Anti-Malware (MBAM).
· Download freehttp://www.malwarebytes.org/ for an on-demand scanner.
· Double Click mbam-setup.exe to install the application.
· After install, click update so you have latest database before scanning.
· Under Settings:
o General: Automatically Save File After Scan Completes is checked off
o Scanner Settings: Check all boxes
o Updater: Download and install update if available is checked off
· Once the program has loaded, select “Perform FULL Scan”, then click Scan.
· The scan may take some time to finish, so please be patient.
· When the disinfection scan is complete, a log will appear in Notepad and you may be prompted to Restart. (See Extra Note).
· Click the “remove selected” button to quarantine anything found. You will find the infection details under the Quarantine tab.
· The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
· Copy & Paste the entire report in your next reply.
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts – Click OK to either and let MBAM proceed with the disinfection process; If asked to restart the computer, please do so immediately.
Please let us know if you have any questions. Thank you.
I take it that you have now rebooted to allow MBAM to remove this file C:\WINDOWS\sapstri.dll ?
This is the cause of the attempted downloads as the Trojan.Hiloti is a trojan downloader which is trying to access malicious sites to download more malware.
If you haven’t yet done that you could add it to the avast chest and send to avast for analysis (see below) to have it added to the avast signatures.
Send the sample to avast as a Undetected Malware:
Open the chest and right click in the Chest and select Add, navigate to where you have the sample and add it to the chest (see image). Once in the chest, right click on the file and select ‘Submit to virus lab…’ complete the form and submit, the file will be uploaded during the next update.
Thank you so much for helping me. I found post that said I could use a tool from Microsoft to get rid of the Trojan.
It is gone know because I can use windows update, where I could not get into it earlier.
Always nice if you can send a sample to avast when found to improve detections. Though I know when you are up to your as* in alligators the last thing on your mind is draining the swamp.
I’m glad things are working well now. To help prevent infections in the future:
Keep your Avast definitions up to date.
Quick scans with MBAM on-demand as a back up but remember to update prior to scanning .
Keep your MS Updates current.
Use safe browsing practices (see my, David’s, and other’s Signatures as examples to add to your browsers).
Make sure your software is current. Check out free Secunia Sofware Inspector http://secunia.com/vulnerability_scanning/personal/. Many of us here scan our system weekly since software is changing so rapidly and this site offers the vendor’s direct download for patches to make it easy to fix.
You will find other helpful suggestions in our Avast Support forum section as well.
If you feel that your issue is now resolved/fixed, please go back to the first open post in this topic, click the modify button in that Post and change the title/subject, add [Resolved] to the beginning of the title so this thread can be closed.
Feel free to come back any time you need help, to learn something new, or just to ask questions. We are here 24/7 for your convenience. Thank you.