Author Topic: help with c:\\windows\system32\svchost.exe Virus  (Read 29564 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #60 on: March 04, 2015, 02:49:34 PM »
I -- dunno...
web shield is the part of avast that scans websites and blocks malicious code, right?

if I know I have a virus trying to contact websites to run malicious codes and I disable the one program on my computer keeping it from doing exactly that... how would that help me and not just be really dangerous to my computer?

I mean, obviously you're trying to help and there seems to be a plan that entails disabling web shields and it all makes sense. I just don't know that plan.

so, no, I am not happy disabling web shields. I'll totally do it if it's necessary to get rid of this virus.

could you maybe give me an idea how risky this is? like, what's the worst case scenario? should I make sure to save all my data? (I haven't backed up my files yet because I didn't want to risk infecting my external hard drive. is this a danger? or can I use a memory stick without risk of infection?) then I'll be happy to go ahead with this.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #61 on: March 04, 2015, 03:07:43 PM »
The intent is to allow one outbound transmission so that Glasswire can capture the responsible file, however there are inherent risks.  At this stage it may be preferable to restore the computer to a time before this appeared

REDACTED

  • Guest
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #62 on: March 04, 2015, 05:46:25 PM »
okay, yes. it does sound like it might be back to restore from a backup.

I can't really gage what kind of virus this is and how it operates, so I am not certain of the risks. is this virus known? is there a way for me to know / find out what it does? I mean, regarding questions like backing up my files, how far back the restoration point should be, etc.?

the virus just appeared the day I contacted you first. would it suffice to go back a month or two? or could the virus have been on my computer for a longer time? and do you think it would be safe to back up my files on an external hard drive or should I just let it be?

thank you very much for all your help!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #63 on: March 04, 2015, 06:25:59 PM »
A few days before the first appearance should suffice, the web site it is trying to go to has some malware on there varying from Sality (nasty) to Poweliks easy

I do not believe that this is a dormant virus on a trigger as it would require a specific task or file.  I have seen no evidence to date of anything not kosher, plus the tools we use would have at least highlighted anomalies

REDACTED

  • Guest
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #64 on: March 05, 2015, 09:36:48 AM »
okay, I will get right on it.

thank you so much for all your help!

best*