Avast threat warning on local IP file

Pacheko17

Controversial opinions guy.
OP
Member
Joined
Jan 31, 2015
Messages
1,495
Trophies
1
Location
República Juliana
XP
1,848
Country
Brazil
There is this file called wpad.dat that keeps getting Avast crazy. It is running on svchost.exe and comes from the Local IP.

I'm currently connected to my dad's office and I don't think there's much to worry about since it's blocked, but every time I come here and connect to the WiFi, the alert shows up.

Doesn't happen at home or literally anywhere else, quite obvious that it's a server-side infection.

Avast warning:
13530481_1784802798472691_626692200_n.png

JS:Banker is a apparently a password stealing trojan. Shit makes me scared as all hell lol.
But everything is fine, I connected to this WiFi for the first time months ago and got this, nothing happened whatsoever so I guess it really is blocked.

Dad said he'll warn the operator. But any input on this would be greatly appreciated.
 
Last edited by Pacheko17,

Cyan

GBATemp's lurking knight
Former Staff
Joined
Oct 27, 2002
Messages
23,746
Trophies
4
Age
45
Location
Engine room, learning
XP
15,563
Country
France
Does your dad have a file named "wpad.dat" on his server's root? if he does, he probably know what this file is.
if that file is not on his local server (or if he doesn't even have a server) maybe he should scan his computer for threats, check why svchost is sending this.

that filename is funny as "wpad" is used in wii homebrew for "Wii pad" functions, but not used as a .dat file.
 
  • Like
Reactions: Pacheko17

Pacheko17

Controversial opinions guy.
OP
Member
Joined
Jan 31, 2015
Messages
1,495
Trophies
1
Location
República Juliana
XP
1,848
Country
Brazil
Does your dad have a file named "wpad.dat" on his server's root? if he does, he probably know what this file is.
if that file is not on his local server (or if he doesn't even have a server) maybe he should scan his computer for threats, check why svchost is sending this.

that filename is funny as "wpad" is used in wii homebrew for "Wii pad" functiond, but not used as a .dat file.

He doesn't know, he doesn't operate the server. I could go check it out but I don't know the password for the server computer. And yeah, I laughed when that popped up xD


According to wikipedia, this is a wpad file:
"The Web Proxy Auto-Discovery Protocol (WPAD) is a method used by clients to locate the URL of a configuration file using DHCP and/or DNS discovery methods. Once detection and download of the configuration file is complete, it can be executed to determine the proxy for a specified URL."

I guess it's used to download the configuration files probably to block websites. Because weird thing is, his computer couldn't acess Facebook, Youtube or other websites that are blocked by the company's firewall, but after he formatted it, installed Avast and connected to the internet, the warning showed up too and now he can use stuff normally.
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,026
Trophies
1
Location
US
Website
mogbox.net
XP
5,988
Country
United States
Something is using a RunPE code to inject itself into svchost, and the DAT file is most likely a database of dumped passwords that is decrypted by the malware itself and sent to a remote server. Many stealers and keyloggers do this since storing the dump in plaintext would allow the victim to happen across it and wonder why all their passwords are being stored in a file.
 
Last edited by Joom,

Pacheko17

Controversial opinions guy.
OP
Member
Joined
Jan 31, 2015
Messages
1,495
Trophies
1
Location
República Juliana
XP
1,848
Country
Brazil
Something is using a RunPE code to inject itself into svchost, and the DAT file is most likely a database of dumped passwords that is decrypted by the malware itself and sent to a remote server. Many stealers and keyloggers do this since storing the dump in plaintext would allow the victim to happen across it and wonder while all their passwords are being stored in a file.

So does that mean my PC got infected or nope?

Already ran multiple scans with Avast and MalwareBytes, they caught nothing.
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,026
Trophies
1
Location
US
Website
mogbox.net
XP
5,988
Country
United States
So does that mean my PC got infected or nope?

Already ran multiple scans with Avast and MalwareBytes, they caught nothing.
Don't ever assume your system is clean just because an AV doesn't detect anything. Attackers use what's known as a crypter to encrypt malware in order to bypass detections. Use CCleaner to check your startup entries for anything suspicious, and check AppData as malware is typically dropped there in order to bypass the UAC prompt. Also, your dad's company should do the same for the server you connect to.
 

Pacheko17

Controversial opinions guy.
OP
Member
Joined
Jan 31, 2015
Messages
1,495
Trophies
1
Location
República Juliana
XP
1,848
Country
Brazil
Don't ever assume your system is clean just because an AV doesn't detect anything. Attackers use what's known as a crypter to encrypt malware in order to bypass detections. Use CCleaner to check your startup entries for anything suspicious, and check AppData as malware is typically dropped there in order to bypass the UAC prompt. Also, your dad's company should do the same for the server you connect to.

Dad already warned the system operator, I'll check out AppData and then download CCleaner to have a look. Thanks ^^
 

Pacheko17

Controversial opinions guy.
OP
Member
Joined
Jan 31, 2015
Messages
1,495
Trophies
1
Location
República Juliana
XP
1,848
Country
Brazil
Don't ever assume your system is clean just because an AV doesn't detect anything. Attackers use what's known as a crypter to encrypt malware in order to bypass detections. Use CCleaner to check your startup entries for anything suspicious, and check AppData as malware is typically dropped there in order to bypass the UAC prompt. Also, your dad's company should do the same for the server you connect to.

AppData is fine, nothing out of the ordinary and nothing weird on CCleaner too. Guess I'm good to go.

Sorry for double post
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,026
Trophies
1
Location
US
Website
mogbox.net
XP
5,988
Country
United States
That's good. Do you happen to have a firewall installed that prints out detailed network activity? Like, what connections are being made amongst processes? It'd be a good idea to see if svchost is calling home to somewhere weird. If you don't have one, Comodo is decent and free.
 
  • Like
Reactions: Pacheko17

0x40

Well-Known Member
Member
Joined
Apr 20, 2013
Messages
282
Trophies
0
Location
/
XP
772
Country
United States
AppData is fine, nothing out of the ordinary and nothing weird on CCleaner too. Guess I'm good to go.

Sorry for double post
Malware can hide itself from the filesystem, so not finding anything doesn't necessarily mean it's clean. I would back up everything of value and format/reinstall if I were you.
 

Pacheko17

Controversial opinions guy.
OP
Member
Joined
Jan 31, 2015
Messages
1,495
Trophies
1
Location
República Juliana
XP
1,848
Country
Brazil
That's good. Do you happen to have a firewall installed that prints out detailed network activity? Like, what connections are being made amongst processes? It'd be a good idea to see if svchost is calling home to somewhere weird. If you don't have one, Comodo is decent and free.

Checked. svchost is calling only to local ip addresses and to my default gateway.
 
General chit-chat
Help Users
  • K3N1 @ K3N1:
    Ask @x65943 he's trained for that stuff
  • JuanMena @ JuanMena:
    Kissing random dudes choking in celery? Really? Need to study for that?
  • K3N1 @ K3N1:
    Yes it requires a degree
  • K3N1 @ K3N1:
    I could also yank out the rest of my teeth but theirs professionals for that
  • x65943 @ x65943:
    If your throat closes, putting oxygen in your mouth will not solve anything - as you will be introducing oxygen prior to the area of obstruction
  • JuanMena @ JuanMena:
    Just kiss me Kyle.
  • x65943 @ x65943:
    You either need to be intubated to bypass obstruction or create a stoma inferior to the the area of obstruction to survive
  • x65943 @ x65943:
    "Just kiss me Kyle." And I thought all the godreborn gay stuff was a smear campaign
  • JuanMena @ JuanMena:
    If I die, tell my momma I won't be carrying Baby Jesus this christmas :sad::cry:
  • K3N1 @ K3N1:
    Smear campaigns are in The political section now?
  • JuanMena @ JuanMena:
    Chary! Chary! Chary, Chary, Chary!
  • Sonic Angel Knight @ Sonic Angel Knight:
    Pork Provolone :P
  • Psionic Roshambo @ Psionic Roshambo:
    Sounds yummy
  • K3N1 @ K3N1:
    Sweet found my Wii u PSU right after I ordered a new one :tpi:
  • JuanMena @ JuanMena:
    It was waiting for you to order another one.
    Seems like, your PSU was waiting for a partner.
  • JuanMena @ JuanMena:
    Keep them both
    separated or you'll have more PSUs each year.
  • K3N1 @ K3N1:
    Well one you insert one PSU into the other one you get power
  • JuanMena @ JuanMena:
    It literally turns it on.
  • K3N1 @ K3N1:
    Yeah power supplies are filthy perverts
  • K3N1 @ K3N1:
    @Psionic Roshambo has a new friend
    +1
  • JuanMena @ JuanMena:
    It's Kyle, the guy that went to school to be a Certified man Kisser.
  • Psionic Roshambo @ Psionic Roshambo:
    Cartmans hand has taco flavored kisses
  • A @ abraarukuk:
    hi guys
  • Iron_Masuku @ Iron_Masuku:
    Hello
    Iron_Masuku @ Iron_Masuku: Hello