Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

svchost URL:Mal [Solved]


  • This topic is locked This topic is locked

#1
maxetnies

maxetnies

    New Member

  • Member
  • Pip
  • 7 posts

Hello, Lately avast keeps popping up alerts saying that web shield has blocked certain web page or files. whenever I would connect into any internet source or wifi connection, the pop up would keep going but without an internet connection there are no pop-ups coming up.

it says:
Object: https://getmuzicas.info/?....(long url?) 
Infection: URL:Mal
Process: C:\windows\system32\svchost.exe

 

I have read solution such problem in topic 

Avast URL:Mal

by Essexboy

 

In attach files you can find my FRST.txt and Addition.txt from FRST64

Please send me fixlist.txt

Attached Files


  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
As you may have noticed on the Avast forum, this either goes quietly or fights us all the way. We do not yet have a good handle on this

After the reboot could you let me know if the alerts are still present

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
CMD: ipconfig /release
CMD: netsh int ip reset
CMD: ipconfig /renew
CMD: DEL %TEMP%\*.* /F /S /Q
CMD: RD /S /Q %TEMP%
REBOOT:
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
  • 0

#3
maxetnies

maxetnies

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts

Good day, Essexboy! Thanks for replay!

 

 

 

But it still keeps popping up such alerts:

1)

avast! Web Shield has blocked a harmful webpage or file.
Object: http://getusaaall.info/?e=pcho....
Infection: URL:Mal
Process: C:\Windows\System32\svchost.exe

2)

"avast! Web Shield has blocked a harmful webpage or file.

Object: https://getmuzicas.info/?....(long url?) 

Infection: URL:Mal
Process: C:\windows\system32\svchost.exe"

 

Please see in attchment my Fixlog.txt

Attached Files


  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK phase two...

The FRST fix works in about 30% of the cases so far, we believe that the malware is changing with time


Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here NSIS_extraction.png
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.
  • Notes:
    1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

    3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


    Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

  • 0

#5
maxetnies

maxetnies

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts

Thanks! 

Done.

There is  my  ComboFix.txt in attacment


  • 0

#6
maxetnies

maxetnies

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts

file

Attached Files


  • 0

#7
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

Are you still getting the alerts ?


  • 0

#8
maxetnies

maxetnies

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts

I will answer for a half hour for sure.

But at that moment i am not annoing by avast alerts.


  • 0

#9
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

OK keep me informed please, also could you zip the following folder and attach it to your next post :

 

C:\Qoobox


  • 0

#10
maxetnies

maxetnies

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts

No more alert!!! Thanks a lot.

I try to zip Qoobox, but system dosn't allow me to do it - writes: "access denied"


  • 0

#11
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

OK I am sure I will get more of these :)

 

Any further problems before I remove my bits and bobs ?


  • 0

#12
maxetnies

maxetnies

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts

Ok.

No...  thanks. I hope that there is no crime in my laptop anymore =))


  • 0

#13
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

No, apart from that your log looks clean :)

 

 

Subject to no further problems   :)

 

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

 

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

 

Download and run Delfix

 

delfix.JPG

 

: Keep Java Updated :

WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article

I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser)

 

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

 

CryptoPrevent install this programme to lock down and prevent crypto ransome ware

 

CryptoPrevent.JPG

 

Malwarebytes.

 

Update and run weekly to keep your system clean

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

 

To learn more about how to protect yourself while on the internet read this little guide  Best security practices Keep safe  :wave:


  • 0

#14
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP