svchost connecting to various websites

Status
Not open for further replies.
Hello,

I'm on W2K SP4 and recently I noticed that my firewall constantly blocks svchost trying to access different websites (www.yourfreeworld.com, www.TheGoldClick.Com, getpaideventoday.com and many others) in about 1-5 minute intervals. It's command line is "svchost -k rpcss". It survived repairing (not reinstalling) windows. AVG Rootkit and Virus scanners, Ad-Aware, SpyBot-S&D, SUPERAntiSpyware nor any other scanner reports anything. I'm stuck. Any help would be appreciated.

(ComboFix log was over 100kb so it's in two parts.)

EDIT:
killing one of KERNEL sub-threads under svchost stops the malware untill reboot. But it's not a solution.
Help please.

Thanks in advance,
Peter.
 
Taranis - don't be so impatient. Three posts at hourly intervals is not the way to treat voluntary technical support and it is not a surprise that you have been ignored.
1 - svchost is not necessarily malware unless it is outside the windows/system 32 folder and is misspelt.
2 - there is a thread here about this - I suggest you go and look for it - and while you are about it, be a good boy (no girl would be so arrogant) and read the thread about newbie postings.
 
AlbertLionheart said:
Taranis - don't be so impatient. Three posts at hourly intervals is not the way to treat voluntary technical support and it is not a surprise that you have been ignored.
1 - svchost is not necessarily malware unless it is outside the windows/system 32 folder and is misspelt.
2 - there is a thread here about this - I suggest you go and look for it - and while you are about it, be a good boy (no girl would be so arrogant) and read the thread about newbie postings.

You might want to read my posts again, concentrating on the dates:
1st : 09-03-2007, 05:03 PM
2nd : 09-04-2007 06:52 AM (14 hours later)
3rd : 09-05-2007 07:47 PM (another 37 hours later)
If you call that "hourly" than sorry for being impatient.
 
Even 3 days in a holiday week isn't too much! Some of us who volunteer our help took a bit of time out for family barbecues and other similar activities. Everyone who posts here about a problem is convinced their problem is the worst there is and wants help "now". We do our best. Consider also that we are also dealing with many different time zones.
 
Status
Not open for further replies.
Back