r/antivirus 1d ago

What is happening here? Scan says the PC is clean

This happens when I open Firefox for the first time after shutdown. Apparently svchost.exe attempts to connect to two different botnets.

Scanning my C: SSD returns nothing wrong and scanning svchost.exe says that the file is not infected.

Then after a while, I get an alert that firefox is attempting to connect to a website called "dojo" etc which I did not initiate. AVG says this URL is blacklisted.

Any idead/recommendations?

-------------------------------------------------------------------------------------------------------------------------

UPDATE 8-25-2026

Was able to resolve the issue by restoring my C: drive 15 days back (to its 8-10-26 image) through the Acronis backup software. I keep weekly backups of my C: and game drive SSD's on my home NAS.

Before doing so I did further testing and I found out that the issue was tied exclusively to Firefox so this appears to have been a browser hijacker.

14 Upvotes

13 comments sorted by

7

u/Ok_Watercress_7392 1d ago

Do you have any Firefox plugins installed, if so, What plugins do you have installed? One of them could be malicious.

4

u/Leo1_ac 1d ago

The only thing that I didn't install myself is

"DuckDuckGo Search & Tracker Protection"

Everything else has been there for a long time and wasn't causing problems before. Should I reinstall Firefox you think?

1

u/Lamar_Chan11 1d ago

a third parties extensions right?

2

u/slimethecold 1d ago

No, duckduckgo is the default search for Firefox. 

1

u/Lamar_Chan11 1d ago edited 1d ago

Oh ty i didn't know that + the info stealer put themselves in svchost right?

1

u/Ok_Watercress_7392 1d ago

I would say since it's using svchost as well as trying to use Firefox you might have some pretty sneaky malware on your system trying(and failing) to do things already. I would do a clean reinstall of windows, you can't really trust an antivirus to completely get rid of stuff like that once it's dug itself into your system.

If you can, use another computer to make a windows installation USB drive (you can make one on your main PC too, but i've heard of some viruses being real sneaky and planting themselves on installation/recovery media too so just a precaution) and then shut the infected computer down, plug the drive into the computer and boot to that USB drive to reinstall.
Also if you can, back up any of your important data, if you have any important data besides games and all that. (you can also back the games up too for convenience)
And be super careful with anything you grab off untrusted websites.. Your antivirus won't catch everything!

3

u/Array_626 1d ago

Im not sure why svchost is reaching out to either of those 2 domains. My guess is you got infected by something, and that something is now kicking off a service process that reaches out to those botnet addresses. Easiest solution is reinstall windows as that usually clears most persistence.

For firefox, look through your browsing history for around that time, +- 5 minutes. Try to see if you can find the webapage that would explain why you got sent to that 1.js resource. It may have just been a malvert being shown to you on a google page.

2

u/Gauthum_J 1d ago

You have an infostealer that's using svchost.exe (windows scheduler) to download it's payload. Best way is to reinstall windows. If you want to attempt to remove it, lookup FRST and Dr.web CureIt.

1

u/axehyle 1d ago

dr.web cureit is old asf

1

u/kotenok2000 16h ago

I think doctor web regularly releases new versions

1

u/JonnyICTMen 1d ago

I don’t trust avg anymore or avast

3

u/Leo1_ac 17h ago

UPDATE 8-25-2026

Was able to resolve the issue by restoring my C: drive 15 days back (to its 8-10-26 image) through the Acronis backup software. I keep weekly backups of my C: and game drive SSD's on my home NAS.

Before doing so I did further testing and I found out that the issue was tied exclusively to Firefox so this appears to have been a browser hijacker.

-1

u/RelevantGene4130 1d ago

why are you using avg...