I kept getting repeated warnings of Epictory, Redled, Reduled, Blacklight etc that my svchost file was being hijacked in Avast after restart or when browsing.
After running boot time scans and up to date anti malware tools nothing was found so I did some investigating.
Turns out all this comes from some site in the Netherlands, I looked it up and they have two IP addresses:
37.48.117.5 https://www.virustotal.com/en/ip-address/37.48.117.5/information/
37.48.117.50 https://www.virustotal.com/en/ip-address/37.48.117.50/information/
So I went into Windows Firewall and created a new rule to block both these IP’s and voila no more warnings, hope this helps someone else.
Go to Control Panel / Security Settings / Windows Firewall then click on Advanced Settings. Click on Inbound Rules then New Rule under the Actions Tab on the Right.
Now click on Custom then Scope, select Remote IP Addresses then These IP Addresses and Add, then copy 37.48.117.5 in the This IP Address or Subnet box, and then click Okay, repeat for 37.48.117.50 and then click next and Block Connection, click next again, give the rule a name, I called mine Reduled and click on finish.
Close Windows Firewall and your done.
Now both those IP addresses will be blocked from accessing your computer.