wpad.meshforcewifi.com/wpad.dat repeated connections blacklisted

Hello,

My PC keeps displaying alerts from Avast notifying me that a threat has been secured, and a connection has been aborted because it was infected with URL:Blacklist.
The URL is http://wpad.meshforcewifi.com/wpad.dat
The Process is C:\Windows\System32\svchost.exe
it seems to happen right away after startup, twice. and then periodically every few minutes. It’s driving me crazy.

I have run Avast several times, including during Boot, and it found nothing. Malwarebytes also found nothing, I think FRST found nothing. I’ve got no idea what to try next to keep this from continuing to happen.

I am attaching the mbam, FRST, and Addition log files as instructed at https://forum.avast.com/index.php?topic=194892.0

Any thoughts on how I can find what is persistently trying to establish this connection? I haven’t installed anything new very recently.

I think FRST found nothing.
FRST does not detect. It is a diagnostic tool and you need to know how to read that log
I am attaching the mbam, FRST, and Addition log files as instructed at
That wont help since all the qualified malware removers that was here has left the forum

So i suggest you Ask for help in Malwarebytes forum

You get Expert help and computer checked with diagnostic tools in Malwarebytes forum
https://forums.malwarebytes.com/forum/7-windows-malware-removal-help-support/

Additional to what Pondus advised you to do:

Now 8 to flag this as malicious: https://www.virustotal.com/gui/url/ea75ed6c49209d6f9ec74c1af052f02e926a16e5bbd6c81cffc321ef7ec63afe?nocache=1
IP involved: https://www.shodan.io/host/204.11.56.48
Read: https://answers.microsoft.com/en-us/windows/forum/all/are-these-files-a-virus-or-malware-wpsettingsdat/7f817d52-d96f-4672-8658-ba0c6bd023f3

polonus