Author Topic: SVCHOST.EXE process with URL:MAL infection  (Read 2491 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
SVCHOST.EXE process with URL:MAL infection
« on: July 05, 2015, 06:55:07 AM »
Hi

Built a new pc 2 or 3 weeks ago, have had avast installed the entire time.

In the last week or two, I have been getting occasional viruses blocked in my svhost.exe file.

They are the usual suspects as below:

URL:http://simplesitescan.net/4141/LighterInit_142669556111830.dll
Infection: URL:Mal
Process: C:\Windows\System32\svchost.exe

URL:http://alwaysisobar.com/4141/CutterGeneration_142669028208336.dll
Infection: URL:Mal
Process: C:\Windows\System32\svchost.exe

URL:http://bestdriverstar.net/4141/CutterSystem_142669222915982.dll
Infection: URL:Mal
Process: C:\Windows\System32\svchost.exe

Malware bytes didn't find anything major and i noticed that anytime this question is brought up there is a big warning not to follow the advice in it due to it being tailored to the individual's machine.

So can someone help me clear this up?

Edit:
It seems that it may have something to do with Nord VPN, as it happens a lot more frequently if I am connected to the vpn.
« Last Edit: July 05, 2015, 07:01:55 AM by james.sunderland »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SVCHOST.EXE process with URL:MAL infection
« Reply #1 on: July 05, 2015, 07:21:34 AM »
Attach your basic diagnostic logs. (MBAM, FRST and aswMBR)
Instructions: https://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: SVCHOST.EXE process with URL:MAL infection
« Reply #2 on: July 05, 2015, 07:55:36 AM »
Hi Asyn,

Attached as requested.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SVCHOST.EXE process with URL:MAL infection
« Reply #3 on: July 05, 2015, 08:04:46 AM »
OK, now you've to wait a bit...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: SVCHOST.EXE process with URL:MAL infection
« Reply #4 on: July 05, 2015, 08:46:50 AM »
Fix with Farbar Recovery Scan Tool

This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: SVCHOST.EXE process with URL:MAL infection
« Reply #5 on: July 05, 2015, 09:31:05 AM »
Hi Eagle,

Attached as requested.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: SVCHOST.EXE process with URL:MAL infection
« Reply #6 on: July 05, 2015, 12:26:18 PM »
Good. How is your PC behaving now?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: SVCHOST.EXE process with URL:MAL infection
« Reply #7 on: July 06, 2015, 12:41:41 PM »
Ni Issues so far, thanks for the help.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: SVCHOST.EXE process with URL:MAL infection
« Reply #8 on: July 06, 2015, 12:59:58 PM »

Post-cleanup procedures:


Download DelFix by Xplode and save it to your desktop.
  • Run the tool by right click on the icon and Run as administrator option.
  • Make sure that these ones are checked:
    • Remove disinfection tools
    • Purge system restore
    • Reset system settings
  • Push Run and wait until the tool completes his work.
  • All tools we used should be gone. Tool will create an report for you (C:\DelFix.txt)
The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE