Author Topic: Redirect search malware in svchost.exe  (Read 3578 times)

0 Members and 1 Guest are viewing this topic.

fcanitrot

  • Guest
Redirect search malware in svchost.exe
« on: November 24, 2010, 10:08:23 PM »
Hi. Here fcanitrot from Chile.

I am new to the forum. Been having problems for a while so decided to to install avast. works well in blocking but soesn't sem to be able to stop the redirecting.

Installed Mbam and it found some stuff avast did not but the problem still persists. Evry while I get a mesage from avast saying it blocked some malicious URL so far every time it is in WIN32/ mainly svchost but I also got Wscript.exe

Any idea how to deal with this.

Thanks
« Last Edit: November 24, 2010, 10:16:48 PM by fcanitrot »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Redirect search malware in svchost.exe
« Reply #1 on: November 24, 2010, 11:49:58 PM »
Quote
Been having problems for a while so decided to to install avast.
you did remove the antivirus you had before you installed avast ? as it is not smart to run more then one AV


can you post the malwarebytes scan log ?

try this

Kaspersky TDSSKiller
http://support.kaspersky.com/viruses/solutions?qid=208280684


did it work ?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Redirect search malware in svchost.exe
« Reply #2 on: November 24, 2010, 11:51:05 PM »
If you are on a 32bit system, run a boot time scan with avast.
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

fcanitrot

  • Guest
Re: Redirect search malware in svchost.exe
« Reply #3 on: December 02, 2010, 09:52:14 PM »
I did run a boot time scan but it did not fix the problem.

The situation is as follows.

Computer boots correctly.

Works fine and fast for a while.

I get a Malicious url in svchost.exe message.

After that the browser starts redirecting weirdly.

After a short while now I get another avast warning from svchost.

At some point I also get a windows error message saying that svchost,exe was unable to write to memory.

Computer gets progressivly slow until it completely crashes.

Heres my last mbam log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5184

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

11/30/2010 3:32:18 PM
mbam-log-2010-11-30 (15-32-18).txt

Scan type: Quick scan
Objects scanned: 189583
Time elapsed: 35 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Redirect search malware in svchost.exe
« Reply #4 on: December 03, 2010, 07:37:58 AM »
Heres my last mbam log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5184

The latest version of Mbam is 1.50. Please update to it.
Then update the database and run a full scan.
Post the log here.
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0