Author Topic: Need help removing URL:Mal svchost.exe  (Read 9003 times)

0 Members and 2 Guests are viewing this topic.

REDACTED

  • Guest
Need help removing URL:Mal svchost.exe
« on: July 10, 2016, 01:49:07 PM »
Avast alerted me to an infection / malicious website, and I'm seeking help locating and removing it.
Object = sso.anbtr.com/domain/wpad.work
Infection = Url:Mal
Process = C:\windows\system32svchost.exe
I am running Windows 10 Pro 64bit
Thanks in advance

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Need help removing URL:Mal svchost.exe
« Reply #1 on: July 10, 2016, 02:02:30 PM »
Attach your basic diagnostic logs. (MBAM, FRST and aswMBR)
Instructions: https://forum.avast.com/index.php?topic=53253
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Need help removing URL:Mal svchost.exe
« Reply #2 on: July 10, 2016, 03:51:01 PM »
ok hrere is the scan logs you requested .

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help removing URL:Mal svchost.exe
« Reply #3 on: July 10, 2016, 03:58:48 PM »
Open FRST and in the search box copy/paste the following :

sso.anbtr.com;wpad.work

Then press search registry
On completion a text pad will be produced
Please attach that

Also do you use this computer for work ?

REDACTED

  • Guest
Re: Need help removing URL:Mal svchost.exe
« Reply #4 on: July 10, 2016, 04:09:49 PM »
no my wife does accounts for a friend on it

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help removing URL:Mal svchost.exe
« Reply #5 on: July 10, 2016, 05:51:03 PM »
Hmm not seeing it in the registry

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool
  • Click the Scan button and wait for the process to complete.
  • Click the logfile button and the log will open in Notepad
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished and the PC has rebooted
  • Please post the content of that log file with your next answer.
  • The report will be saved in the C:\AdwCleaner folder.

REDACTED

  • Guest
Re: Need help removing URL:Mal svchost.exe
« Reply #6 on: July 10, 2016, 06:27:10 PM »
ok here it is

REDACTED

  • Guest
Re: Need help removing URL:Mal svchost.exe
« Reply #7 on: July 10, 2016, 07:35:37 PM »
ok after I press clean the progran freezes and stops responding = Not Responding
but here is the log file

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help removing URL:Mal svchost.exe
« Reply #8 on: July 10, 2016, 08:01:24 PM »
Hmm could you reboot and then run AdwCleaner again please.  Is Avast still alerting

REDACTED

  • Guest
Re: Need help removing URL:Mal svchost.exe
« Reply #9 on: July 10, 2016, 08:28:53 PM »
ok i rebooted twice ans same thing happens program lock up when i click on clean
but i attached the logfile and its still alearting

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help removing URL:Mal svchost.exe
« Reply #10 on: July 10, 2016, 10:17:18 PM »
OK lets now try this

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
Tcpip\Parameters: [DhcpNameServer] 216.131.91.251 216.131.91.252 208.67.222.222
Tcpip\..\Interfaces\{cfc12fb4-2711-4ae6-ba2e-e3bf02891a74}: [DhcpNameServer] 216.131.91.251 216.131.91.252 208.67.222.222
S2 ClanoyplkulyCoreberweckfadeck.exe; "C:\Program Files (x86)\Wuzokrermupy\ClanoyplkulyCoreberweckfadeck.exe" {C25DA384-2010-45A4-A1ED-BFA540D4789B} {9DC74CD5-24EA-4ADE-9C42-608A8CE17116} [X]
C:\Program Files (x86)\Wuzokrermupy
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: Need help removing URL:Mal svchost.exe
« Reply #11 on: July 11, 2016, 12:06:46 AM »
heres the fixlog and avast is alearting me even more often now every few seconds
Process = c:\windows\system32\dllhost.exe
also got the clean function to work in safe mode and here are the results
« Last Edit: July 11, 2016, 01:08:59 AM by walwynd »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Need help removing URL:Mal svchost.exe
« Reply #12 on: July 11, 2016, 12:16:59 AM »
Essexboy will be back online tomorrow, usually after 15:00 european time


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help removing URL:Mal svchost.exe
« Reply #13 on: July 11, 2016, 03:38:09 PM »
Could I have a fresh FRST scan please and a screenshot of the Avast alert

REDACTED

  • Guest
Re: Need help removing URL:Mal svchost.exe
« Reply #14 on: July 11, 2016, 04:46:41 PM »
here is the results
pics wont upload say there are to big,  1= 4.mb is there anyway to reduce them first??
« Last Edit: July 11, 2016, 05:19:54 PM by wallyd »