Author Topic: Avast blocking URL svchost.exe  (Read 14123 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Re: Avast blocking URL svchost.exe
« Reply #30 on: March 04, 2015, 03:18:41 PM »
Here you go, see attached.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast blocking URL svchost.exe
« Reply #31 on: March 04, 2015, 04:24:22 PM »
Are the alerts still appearing ?

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3777026070-661087563-4202175341-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-21-3777026070-661087563-4202175341-1002 -> {350D3A74-F259-4AD7-BAC1-2CFC9E2AF85F} URL = http://www.baidu.com/baidu?tn=dealio_dg&wd={searchTerms}
FF Plugin-x32: @baidu.com/npxbdsetup -> C:\Windows\Downloaded Program Files\345867055\npxbdsetup.dll No File
FF Plugin-x32: @cmbchina.com/npcmbedit -> C:\Windows\system32\NPCMBEdit.dll No File
2015-03-01 09:32 - 2015-03-01 09:32 - 0000020 _____ () C:\Users\Ronan\AppData\Roaming\004D5649544E41696E66
Task: {E45BAFAD-A369-4FBB-AECF-7319610EA8F2} - \{202A373B-6B5D-4314-8BDA-D6D28EA4C4B5} No Task File <==== ATTENTION
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: Avast blocking URL svchost.exe
« Reply #32 on: March 09, 2015, 12:57:23 AM »
Here you go.

Thanks,
Hed.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast blocking URL svchost.exe
« Reply #33 on: March 09, 2015, 04:01:57 PM »
Are the alerts still there ?

REDACTED

  • Guest
Re: Avast blocking URL svchost.exe
« Reply #34 on: March 10, 2015, 12:37:21 AM »
Yes, still there

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast blocking URL svchost.exe
« Reply #35 on: March 10, 2015, 04:12:44 PM »
Could you confirm that they disappear when chrome is uninstalled from the system

REDACTED

  • Guest
Re: Avast blocking URL svchost.exe
« Reply #36 on: March 14, 2015, 10:16:18 AM »
No, they don't disappear. And their number have considerably increased.

At the beginning it was once every hour.
Now it is around 60 warnings per hour minimum.

Starting to be really impacting my activities ;/

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast blocking URL svchost.exe
« Reply #37 on: March 14, 2015, 12:34:42 PM »
Could you attach a screenshot of the Avast alert please

REDACTED

  • Guest
Re: Avast blocking URL svchost.exe
« Reply #38 on: March 15, 2015, 02:24:28 AM »
Here you go

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast blocking URL svchost.exe
« Reply #39 on: March 15, 2015, 12:32:04 PM »
That IP is in China are you there perchance ?  Beijing Teletron Telecom Engineering Co., Ltd.





REDACTED

  • Guest
Re: Avast blocking URL svchost.exe
« Reply #40 on: March 16, 2015, 12:49:55 PM »
Yes, I am living in Beijing.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast blocking URL svchost.exe
« Reply #41 on: March 16, 2015, 05:49:26 PM »
It appears that all the main external sites.. MBAM, Windows and a few others are being routed first through their server rather than going direct to   the proper site. 

The only way around that would be to use a proxy as I believe Avast is alerting on the fact that the routing to windows updates is being directed through another server


REDACTED

  • Guest
Re: Avast blocking URL svchost.exe
« Reply #42 on: March 17, 2015, 12:32:17 AM »
I have difficulties to understand how this could happen.
I moved in into a new place, and started to use a new ISP around Mid December.
However, the warnings came around mid February.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast blocking URL svchost.exe
« Reply #43 on: March 17, 2015, 04:16:00 PM »
I have forwarded this to Avast for them to check out

Offline Tondah

  • Avast team
  • Jr. Member
  • *
  • Posts: 52
Re: Avast blocking URL svchost.exe
« Reply #44 on: March 18, 2015, 10:29:43 AM »
Hello, i checked the IP and it appears to be one of the download proxy servers from www.datadragon.net.
Server on this IP no longer exists, but it served various .exe, .xap and .apk files in unconventional way including files like "install_flash_player.exe"
I am sorry for your trouble, it will be unblocked within a while.

Tondah