Please explain what a Network Shield Popup means by Process listed

I’ve had a search and can’t work out what the process part of the message means.

For example, there are a few IP bulletin boards that are infected with the url4short redirect, which can be read about on Google and has a posted solution:

https://www.google.co.uk/search?q=url4short
http://peter.upfold.org.uk/blog/2013/01/15/cleaning-up-the-ip-board-url4short-mess/

Avast detects this redirect to the url4short website from infected servers, and pops up a message from Network Shield:

Malicious URL Blocked
Object: url4short web address
Infection URL:Mal
Process: C:WINDOWS/system32/winlogon.exe

So what does it mean by Process? Is that the process the URL:Mal targets?

Just curious how the message should be read, as all it’s doing is blocking blacklisted sites so why the “process” message? It makes me paranoid the process itself is infected!

“Process:” shows what process was trying to access malicious URLs.

If you want to confirm your system is clean, you can request virus removal assistance on “Virus and Worms” section.
http://forum.avast.com/index.php?board=4.0

If you do so, please follow this guide before you post:
http://forum.avast.com/index.php?topic=53253.0

Thanks for the reponse.

It’s ok, I know the system is clean as it’s a server side redirect as confirmed by those links above.

I think it’s a bug in Avast, as:

On a Windows XP machine the process is Winlogon.exe
On a Windows 7 machine the process is correctly listed as Firefox.exe

So it seems like a bug in how Avast identifies the correct process in XP.