Announcement

Collapse
No announcement yet.

How to fix Malicious Website Blocked Alerts from Svchost.exe

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • How to fix Malicious Website Blocked Alerts from Svchost.exe

    If you are using Malwarebytes and receive a Malicious Website Blocked alert that has a corresponding process of C:\Windows\System32\Svchost.exe associated with it, there is a good chance that your computer is configured with a malicous DNS server. A computer's DNS servers are typically changed to malicious ones through two methods. The first being that you have a unwanted programs called DNS Unlocker, TopFlix, AnyFlix, Cloudscout, or DNS Keeper installed, which change your DNS settings to ones under their control. The other possibility is that your router's DNS settings have been modified.

    How to fix Malicious Website Blocked Alerts from Svchost.exe

    • Wed, 04 May 2016 15:51:12 EDT
    • Read 804 times








    Untitled DocumentIf you are using Malwarebytes and receive a Malicious Website Blocked alert that has a corresponding process of C:\Windows\System32\Svchost.exe associated with it, there is a good chance that your computer is configured with a malicous DNS server. A computer's DNS servers are typically changed to malicious ones through two methods. The first being that you have a unwanted programs called DNS Unlocker, TopFlix, AnyFlix, Cloudscout, or DNS Keeper installed, which change your DNS settings to ones under their control. The other possibility is that your router's DNS settings have been modified.
    As the DNS settings on a computer ultimately determine what actual site you go to when browsing the web, by hijacking your computer's DNS servers, malware developers can control what sites you go to. This also allows them to show sites that you think are legitimate, but are actually imposters, or to show ads on sites that normally do not have them.
    Normally, when Malwarebytes detects a process connecting to a malicious site it will display the malicious process associated with the connection. As DNS resolution is handled by legitimate Windows services, connections related to malicious DNS servers will instead be shown as coming from C:\Windows\System32\svchost.exe.
    When people see these alerts they automatically think that svchost.exe is infected or that it has been patched. In reality, there is nothing wrong with svchost.exe and it is just acting as a intermediary for the network services that are performing DNS resolution. Since this DNS resolution is using a malicious server, it causes the alert to appear.
    The table below lists the historic malicious DNS servers's IP addresses and their associated host names that Malwarebytes may detect. If you are the owner of one of these IP addresses and they are no longer involved in malicious activity, you should contact Malwarebytes regarding this. I can't help remove their detections.
    5.135.12.56 31.168.224.100
    82.163.142.155 82.163.142.159
    82.163.142.164 82.163.142.166
    82.163.142.189 82.163.142.185
    82.163.143.153 82.163.143.157
    82.163.143.164 82.163.143.185
    82.163.143.189 82.163.143.247
    This guide will walk you through removing these malicious DNS entries from your computer so that you will no longer see these alerts and can use your computer properly.
    Array



    Click here to view the article.
Working...
X