Author Topic: Threat Detected appearing all the time - svchost.exe  (Read 3877 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Threat Detected appearing all the time - svchost.exe
« on: June 12, 2015, 10:11:37 PM »
I'm getting VERY frequent pop-up boxes reporting that a threat has been detected.
It is centred on the svchost.exe with ortiguard, any-Chicago

Attached are the basic scan log files, I will perform a Zoek scan now.

many thanks
Andy (UK)

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Threat Detected appearing all the time - svchost.exe
« Reply #1 on: June 12, 2015, 10:12:33 PM »
Hello,

Please follow this topic and attach required reports

https://forum.avast.com/index.php?topic=53253.0
« Last Edit: June 12, 2015, 10:14:52 PM by TwinHeadedEagle »
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Threat Detected appearing all the time - svchost.exe
« Reply #2 on: June 12, 2015, 10:35:19 PM »
Logs attached

malware_log
FRST
Addition
aswMBR

REDACTED

  • Guest
Re: Threat Detected appearing all the time - svchost.exe
« Reply #3 on: June 12, 2015, 10:37:22 PM »
Also I ran rhe zoek.exe programme.

I used one of your scripts, but changed the user to MYNAME

Attached is the log produced.

NB: the zoek.exe programme keeps restarting event though I close it,

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Threat Detected appearing all the time - svchost.exe
« Reply #4 on: June 12, 2015, 10:50:01 PM »
Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on icon and select Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
Code: [Select]
createsrpoint;
autoclean;
emptyalltemp;
ipconfig /flushdns;b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)
Post its content into your next reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Threat Detected appearing all the time - svchost.exe
« Reply #5 on: June 13, 2015, 01:36:34 AM »
Here is the log file from zoek.exe

Appreciate your help to all members of this forum  ;D

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Threat Detected appearing all the time - svchost.exe
« Reply #6 on: June 13, 2015, 05:47:14 PM »
Fix with ZOEK

This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.

Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on icon and select Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
Code: [Select]
createsrpoint;
C:\Users\andy\AppData\Local\Google\Chrome\User Data\Default\Preferences;f
chrdefaults;
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)
Post its content into your next reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Threat Detected appearing all the time - svchost.exe
« Reply #7 on: June 13, 2015, 09:37:24 PM »

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by andy on 13/06/2015 at 18:13:52.94.
Microsoft Windows 7 Professional  6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\andy\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2015-06-12-201918.log   4862 bytes
C:\zoek-results2015-06-12-232357.log   24737 bytes

==== System Restore Info ======================

13/06/2015 18:18:22 Zoek.exe System Restore Point Created Successfully.

==== Deleting Files \ Folders ======================

"C:\Users\andy\AppData\Local\Google\Chrome\User Data\Default\Preferences" deleted

==== Reset Google Chrome ======================

C:\Users\andy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Default User\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\andy\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\andy\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\Default User\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Default User\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=3099 folders=519 759811266 bytes)

==== EOF on 13/06/2015 at 18:19:05.88 ======================

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Threat Detected appearing all the time - svchost.exe
« Reply #8 on: June 13, 2015, 10:43:32 PM »
Very good. How is your PC behaving now?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Threat Detected appearing all the time - svchost.exe
« Reply #9 on: June 13, 2015, 11:23:54 PM »
The popup warnings have disappeared.
many thanks
Andy

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Threat Detected appearing all the time - svchost.exe
« Reply #10 on: June 14, 2015, 12:05:18 AM »
Cheers :)

The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
Remove disinfection tools
Create registry backup
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE