Author Topic: alerts related with C:\Windows\System32\svchost.exe  (Read 3063 times)

0 Members and 2 Guests are viewing this topic.

REDACTED

  • Guest
alerts related with C:\Windows\System32\svchost.exe
« on: July 17, 2015, 09:57:17 AM »
Hi, this is my first time here. I usually try to solve my problems reading other people entries, but this one seems hard to me.
I have beginning to see in my computer what seems a problem many users have: the alerts (about 12), starting the computer, related to the svchost.exe. Avast tells me its blocking webpages, different ones I dont even try to open (opticguardzip.net, and about 4 more...).
I have run avast, malwarebytes and adwcleaner, and I have deleted all the threats, but i still have the alerts of avast.
I would really appreaciate if someone could help me in the process to clean whatever I have. For what i have seen in other forum entries, it is a problem must be particulary solved for every computer? is that so?
(sorry for my mistakes of language, I normally speak in spanish)
Thx as lot in advance.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: alerts related with C:\Windows\System32\svchost.exe
« Reply #1 on: July 17, 2015, 09:58:40 AM »
Attach your basic diagnostic logs. (MBAM, FRST and aswMBR)
Instructions: https://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: alerts related with C:\Windows\System32\svchost.exe
« Reply #2 on: July 17, 2015, 10:16:53 AM »
Hi and thx for your fast answer.
Here I attach 2 of the 3 archives you ask. But I have a problem with FRST. When I click on the link to download it, avast pop ups and blocks it:

URL: http://download.bleepingcomputer.com/dl/4391ee916e6c574c1a312584847009b9/55a8b8f4/windows/security/security-utilities/f/farbar-recovery-scan-tool/64/FRST64.exe
Infección: Win64:Evo-gen [Susp]
Proceso: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

Thx a lot


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: alerts related with C:\Windows\System32\svchost.exe
« Reply #3 on: July 17, 2015, 10:18:40 AM »
But I have a problem with FRST. When I click on the link to download it, avast pop ups and blocks it:
It's a FP, you can safely allow the download.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: alerts related with C:\Windows\System32\svchost.exe
« Reply #4 on: July 17, 2015, 10:25:00 AM »
how do I allow it? It says "error de red" (net error). And I dont see any option :(

REDACTED

  • Guest
Re: alerts related with C:\Windows\System32\svchost.exe
« Reply #5 on: July 17, 2015, 10:26:23 AM »
should I try to disconnect avast while downloading?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: alerts related with C:\Windows\System32\svchost.exe
« Reply #6 on: July 17, 2015, 10:27:59 AM »
how do I allow it? It says "error de red" (net error). And I dont see any option :(
Easiest, disable Avast for 10 minutes.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: alerts related with C:\Windows\System32\svchost.exe
« Reply #7 on: July 17, 2015, 10:36:33 AM »
ok, here it is. I had to disable avast not only to download the archive, but also to run FRST, is that normal? (first time I run it, avast block it and sent it to the chest)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: alerts related with C:\Windows\System32\svchost.exe
« Reply #8 on: July 17, 2015, 10:38:27 AM »
Good job, now you've to wait a bit...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: alerts related with C:\Windows\System32\svchost.exe
« Reply #9 on: July 17, 2015, 10:43:54 AM »
yeah, no problem. Thx for the effort.
I would really appreciate, I dont know if it is possible, that if you see where is the problem, you could explain me what is happenning, and not only give me the steps to solve it. I mean, i dont know much about computers, so probably i will understand nothing if you give me some code lines to copy and execute, but it would really be great for me to try to understand the origin of the problem and the way your solution works.
Really thx a lot.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: alerts related with C:\Windows\System32\svchost.exe
« Reply #10 on: July 17, 2015, 02:50:09 PM »
The bad boys are hiding in the BITs portion of windows   http://ss64.com/nt/bitsadmin.html

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
2015-06-19 18:49 - 2015-06-19 19:57 - 00000000 __SHD C:\Users\PcCom\AppData\Local\EmieUserList
2015-06-19 18:49 - 2015-06-19 19:57 - 00000000 __SHD C:\Users\PcCom\AppData\Local\EmieSiteList
2015-06-19 18:49 - 2015-06-19 19:57 - 00000000 __SHD C:\Users\PcCom\AppData\Local\EmieBrowserModeList

RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: alerts related with C:\Windows\System32\svchost.exe
« Reply #11 on: July 17, 2015, 04:24:41 PM »
Is it done?
May I ask, please, where in those files I sent, have you find the source of the problem? (its really intriguing for me, I have no idea how you did it)
What should I do if the problem shows again in the future?
What should I do to prevent possible situations like this one?
Thx a lot, really!