Author Topic: svchost.exe malware  (Read 7340 times)

0 Members and 1 Guest are viewing this topic.

aunthattie

  • Guest
svchost.exe malware
« on: June 26, 2012, 03:25:55 PM »
Hello All!
I have a windows xp machine and receive the following error about every 2 minutes from Avast:

Infection Details
URL: "hxtp://ololoshaface.com/x/"
Process: "C:\WINDOWS\System32\svchost.exe"
Infection: "URL:Mal"

Any clue on how to remove/edit/fix this? Your time is very much appreciated.
« Last Edit: June 26, 2012, 04:25:19 PM by Milos »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: svchost.exe malware
« Reply #1 on: June 26, 2012, 03:28:42 PM »
This needs further analysis by a malware removal specialist:
Go to this topic http://forum.avast.com/index.php?topic=53253.0 for information on Logs to assist in cleaning malware.
Use the information about getting and using the tools and attach the logs here, not in the LOGS topic.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: svchost.exe malware
« Reply #2 on: June 26, 2012, 03:42:37 PM »
I have a windows xp machine and receive the following error about every 2 minutes from Avast:

Infection Details
URL: "hXXp://ololoshaface.com/x/"
Process: "C:\WINDOWS\System32\svchost.exe"
Infection: "URL:Mal"

Please 'modify' your post change the URL from http to hXXp, as in the quoted text above to break the link and avoid accidental exposure to suspect sites, thanks.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

aunthattie

  • Guest
Re: svchost.exe malware
« Reply #3 on: June 27, 2012, 02:50:39 PM »
Thanks for the help. I followed the instructions on http://forum.avast.com/index.php?topic=53253.0 and attached are 3 log files. One from MBAM and the other 2 from OTC.
I look forward to hearing from you.  :)

Baldylocks13

  • Guest
Re: svchost.exe malware
« Reply #4 on: June 27, 2012, 03:14:23 PM »
Several sites have been getting malware blocks from Avast!, I had a local real estate site blocked and several of us Avast! users were locked out. The Tech team at the site confirmed that Avast! had recently upgraded their files and included that site on the blacklist (erroneously). The site is working with Avast! to fix the problem, meanwhile to go to the  site I have to disable my web and network shields when going to that site. Hope this helps!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: svchost.exe malware
« Reply #5 on: June 27, 2012, 04:25:02 PM »
@ Baldylocks13
I'm not sure the purpose of your post (to try to help or seek help) as it appears unrelated to this topic.

There is a problem on aunthattie's system that is using/misusing svchost.exe to connect to what avast considers a malicious site. So in essence it matters not so much what the site (but what is on her system misusing svchost.exe), but I somehow doubt the site you are talking about is the same as this one.

So if you are seeking help about another site then please start your own new topic.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: svchost.exe malware
« Reply #6 on: June 27, 2012, 04:47:32 PM »
Hi lets stop the alerts and tidy you up

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
THEN

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks
  • Allow the installation of the recovery console




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

aunthattie

  • Guest
Re: svchost.exe malware
« Reply #7 on: June 29, 2012, 03:48:42 AM »
Thanks for all your help! 
I ran OTL then Combofix as instructed. Attached are the logs.
After I ran Combofix I tried to shut down my computer via the windows start > turn off computer option. My computer "hung" (I waited a few minutes) and it wouldn't shut down. Holding the power button on the front of my Dell didn't work either so I was forced to unplug the computer from the back. I waited 1 minute then turned the computer back on. Windows started loading normally then I got the Blue Screen of Death. It said,
"Plug and Play detected an error most likely caused by a faulty driver" Tech. Info
STOP: 0x000000CA (Ox000000d,0x8A9A5030, 0x0000000, 0x00000000)
I am now in Safe Mode so I can post this forum post.
Any suggestions would be greatly appreciated. :-)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: svchost.exe malware
« Reply #8 on: June 29, 2012, 03:04:08 PM »
Combofix created a restore point prior to running so from safe mode select that restore point and restore the system

Combofix usually shuts down the system when it has finished...  Did combofix finish up to stage 0 ?

Once done could you run a fresh OTL scan please