Author Topic: svchost tries to access malicious urls  (Read 3738 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
svchost tries to access malicious urls
« on: May 31, 2015, 01:23:07 AM »
Hi, Avast have also detected such threat on my laptop:

URL: http://opticguardzip.net/......
Infection: URL:Mal
Process: C:\Windows\System32\svchost.exe

Scan logs will follow

thanks

REDACTED

  • Guest
Re: svchost tries to access malicious urls
« Reply #1 on: May 31, 2015, 01:45:03 AM »
Here they are...
Thanks a lot
« Last Edit: May 31, 2015, 01:46:37 AM by bj5 »

REDACTED

  • Guest
Re: svchost tries to access malicious urls
« Reply #2 on: May 31, 2015, 08:01:16 AM »
Hello,



Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on icon and select Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
Code: [Select]
createsrpoint;
autoclean;
emptyalltemp;
bitsadmin /reset /allusers;b
ipconfig /flushdns;b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Post its content into your next reply.

REDACTED

  • Guest
Re: svchost tries to access malicious urls
« Reply #3 on: May 31, 2015, 11:47:48 AM »
Hello,

here it is.

thanks for your help

REDACTED

  • Guest
Re: svchost tries to access malicious urls
« Reply #4 on: May 31, 2015, 12:40:57 PM »
Re-run zoek and run this script:

Code: [Select]
createsrpoint;
autoclean;
C:\Users\samsung\AppData\Local\Google\Chrome\User Data\Default\Preferences;f
emptyalltemp;


Post its content into your next reply.

REDACTED

  • Guest
Re: svchost tries to access malicious urls
« Reply #5 on: May 31, 2015, 01:35:26 PM »
Ok, done

REDACTED

  • Guest
Re: svchost tries to access malicious urls
« Reply #6 on: May 31, 2015, 01:49:18 PM »

How's your computer behaving now?

REDACTED

  • Guest
Re: svchost tries to access malicious urls
« Reply #7 on: May 31, 2015, 02:00:24 PM »
Well, the threat was detected 2 times this morning, (it happens around 1 time every 2 hours).
Since the first scan of ZOEK, it hasn't been reproduced.

I cross my fingers, thanks.
I let you know if it's ok

REDACTED

  • Guest
Re: svchost tries to access malicious urls
« Reply #8 on: May 31, 2015, 02:03:10 PM »
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.

REDACTED

  • Guest
Re: svchost tries to access malicious urls
« Reply #9 on: May 31, 2015, 02:32:24 PM »
the results in attachment

REDACTED

  • Guest
Re: svchost tries to access malicious urls
« Reply #10 on: May 31, 2015, 02:35:22 PM »
Excellent, any problems?

REDACTED

  • Guest
Re: svchost tries to access malicious urls
« Reply #11 on: May 31, 2015, 03:40:48 PM »
No more!

big big thanks, no gonna need to educate a little bit my parents in web surfing...

REDACTED

  • Guest
Re: svchost tries to access malicious urls
« Reply #12 on: May 31, 2015, 03:42:16 PM »
The following will implement some post-cleanup procedures:


Download DelFix by Xplode and save it to your desktop.
  • Run the tool by right click on the icon and Run as administrator option.
  • Make sure that these ones are checked:
    • Remove disinfection tools
    • Purge system restore
    • Reset system settings
  • Push Run and wait until the tool completes his work.
  • All tools we used should be gone. Tool will create an report for you (C:\DelFix.txt)
The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.