URL: Blacklist notification

Hi,

Trust you are doing well.
Just curious to know abt the URL: Blacklist notification, cud’nt find any documentation
… is it some virus script codenamed “Blacklist”?

The msg popped when I was trying to access
https://www.locusinn.com/games/divinity/guides/DivinityQuestGuideV2.pdf
… and it automatically terminates the connection.
Am using Avast Secure Browser latest version on a fully updated Win 7 HP x64.

I also checked the website profile on VirusTotal … came out clean (snap attached)

Am getting similar messages frequently for 1st page results on Google… anything wrong with my settings?

Thanks.

Just curious to know abt the URL: Blacklist notification, cud'nt find any documentation .. is it some virus script codenamed "Blacklist"?

Blacklist (computing)
https://en.wikipedia.org/wiki/Blacklist_(computing)
https://en.wikipedia.org/wiki/Wikipedia:Spam_blacklist
https://en.wikipedia.org/wiki/Template:Blacklisted-links

You dont give any info / screenshot about what avast say so we have to guess …

Thanks for the revert.
It says “infected with URL:Blacklist”
Will soon update the full string of notification.
I dont have access to this specific computer right now…

It says "infected with URL:Blacklist"
OK it seems avast may have changed a detection name? as i have not seen that before

It used to be:
URL:Mal = Blacklisted URL or IP
PDF:UrlMal-inf [Trj] = pdf.doc that containe link to a blacklisted URL

The infected with is just a general text that is on top of all messages even if it is not a infection

Hi,
Heres the full string:
“Weve safely aborted connection on www.locusinn.com because it was infected with URL:Blacklist”

I am merely posing this as an example … this kind of intervention has become somewhat frequent.
I have attached my web shield settings… for soliciting recommendations.

Thanks.

you can check suspicious URLs here:

File and URL (blacklist) check https://www.virustotal.com/
Website check https://sitecheck.sucuri.net/

If you suscpect false positives then see my post here on how to report
https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438

VirusTotal isn’t very good for URL checking as it doesn’t actually do a scan, but refers to blacklists.

It is possible that the “infected with URL:Blacklist” could also be caused by an attempt to access a 3rd party URL from that site.

Sucuri also does blacklist checks but also checks for other things: https://sitecheck.sucuri.net/results/https/www.locusinn.com

Seems [h]ttps://www.locusinn.com not configured correctly. http://urlquery.net/report/74c504ba-1673-48d5-9732-b7def7da2389, i.e. insecure connection.

Hello, I’ve had the same problem for a long time, around half a year.
But, My url is not the same. My url is bbtbfr.pw
"We’ve safely abortd connection on bbtbfr.pw because it was infected with URL:Blackist.

Report a false positive (select file or website)
https://www.avast.com/false-positive-file-form.php

https://sitecheck.sucuri.net/results/bbtbfr.pw

Detection was removed in 26.02.2020 at 06:21 AM

Our virus specialists have now cleared its reputation in our database.

With URLs this change should be instant, but it might take up to 24 hours with files.

It is not a false positive.

Our virus specialists have been working on this problem and they informed me that this detection is correct. This is most likely caused by a browser hijacker.

It is nice that this isn’t a false positive, but avast isn’t removing the threat completely, it just keeps jumping and then reappearing. I’ve had it pop up about 30-35 times today (at least) even though I get the “threat secured” message, it will just reappear 5-10 minutes later. I don’t have my web browser open, it just pops back up.

I’d love to just kill it and not worry about it, rather than have the harsh warning dings every 10 minutes warning me about the threat - even when I’m not using the machine, it’s just sitting idle.

Well it looks like you could have an underlying problem (but without details, tough to suggest anything), something is trying to connect to something considered a blacklisted URL and avast is preventing the connection to that URL. What the problem is finding what is trying to make that connection.

Attaching a screenshot of the avast alert window might help and opening the See Details option may indicate what was trying to make that connection.

Without details we just can’t say what the cause is.
It may well be best to start your own new topic on this (possibly in the viruses and worms sub-forum) and we will try to help.

Hello, Having similar problem.

I ran;
Avast Scan
MalwareBytes
Hitman Pro

Did a general registry search I cannot find the issue. Looked at ‘Program and Features’ in Win CP. I attached my screen shot.

Thanks in Advance for any help.

MAC

Report a false positive (select file or website)

Click this link >> https://www.avast.com/false-positive-file-form.php

How to report stuff to avast lab >> https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438

If this is something that pops up when you dont do anything, try clear your browsers surf history and/or run Malwarebytes Adwcleaner (not the same as malwarebytes antimalware)

Running localised scans on your system is unlikely to find anything if the source in web locations.

Had you clicked the See details option it would have given us (and you) more information on what originated it, e.g. your browser or a local computer file/source.

However haven run multiple local anti-malware scans and no detections would tend to indicate it is something that you were browsing or a link from a site that you were browsing.

EDIT: Further search for this returns many hits - https://www.google.co.uk/search?q=personal-video.live+virus