This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"a recent attempt to attack your computer was blocked"

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

have used utorrent recently and after use, i keep on getting the pop out by norton that "a recent attempt to attack your computer was blocked" ( i believe utorrrent is the cause as it only happened after i downloaded songs from there) The message keeps on popping out every few minutes for tem minutes then pops out periodically. Today, my mozilla also suddenly crash. I tried doing a fulll norton scan is both normal and SAFE mode but this message still keeps on popping out. Can anyone here advise what is this and anyway that i can remove it using Norton so that this will not happen again. Below are the details( i left the "destination address" blank as i think it is refering to my computer address and i do not want to post it online): "an instrusion attempt by 194.60.205.232 was blocked" Risk Name : HTP Tidserv Request Attacking Computer : 194.60.205.232, 80 Attacking URL: switcho81.com/uv544k8x6t6M70c5dmVyPTMuOTYmYmlkP5vbmFtZSZhaWQ9MzAwNDQmc2lkPTAmcmQ9MCZlbmc9d3d3L mdvb2dsZS5jb20uc2cmcT1pbnRydXNpb24rYXR0ZW1wdCt3YXMrYmxvY2tlZA==16k Destination address: USER-FDxxxxx (xxx.xxx.xxx.) - (im leaving this field blank as i think this is the address of my computer) Souce address : [removed] Traffic description : TCP, www-http work traffic from 194.60.205.232 matches the signature of a knowm attack. The attack was resulted from \DEVICE\HARDDISK\VOLUME1\PROGRAM FILES\MOZILLA FIREFOX\FIRSFOX.EXE. To stop being notified for this type of traffic. in the Actions panel, click "stop notifying me". Network traffic from switcho81.com/uv544k8x6t6M70c5dmVyPTMuOTYmYmlkP5vbmFtZSZhaWQ9MzAwNDQmc2lkPTAmcmQ9MCZlbmc9d3d3L mdvb2dsZS5jb20uc2cmcT1pbnRydXNpb24rYXR0ZW1wdCt3YXMrYmxvY2tlZA==16k matches the signatire of a known attack. The attack was resulted from \DEVICE\HARDDISK\VOLUME1\PROGRAM FILES\MOZILLA FIREFOX\FIRSFOX.EXE. To stop being notified for this type of traffic. in the Actions panel, click "stop notifying me" is my com already infected? would appreciate any advise that i can get. thank you attached are the results from scans using OTL as per the guidelines Aprreiciate if you can kindly advise.. Thanks!!
Hello speedz76 and welcome to WhatTheTech. Please follow these guidelines while we work on your PC:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until Iโ€™ve given you the โ€œAll clear.โ€ Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Any underlined text in my posts indicates a clickable link.
  • If you have any questions at all, please stop and ask before proceeding.
๐Ÿ–ผClick to load external image (Posted Image) Download GMER Rootkit Scanner from here to your desktop.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scanโ€ฆclick on NO.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Uncheck the following โ€ฆ
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<โ€” ROOKIT" entries


If you have trouble running GEMR:
  • Make sure that your security software is disabled
  • Uncheck the box next to "Files" this time also
  • If you still can't run it, try in the Safe Mode
Please include the following in your next post:
  • GMER log
speedz76:

๐Ÿ–ผClick to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
    O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe File not found
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
    O33 - MountPoints2\{04370170-41a3-11db-8e4f-a13f75696004}\Shell\Auto\command - "" = RavMonE.exe e
    O33 - MountPoints2\{04370170-41a3-11db-8e4f-a13f75696004}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{ee387012-2451-11df-999d-0013f77cdd5d}\Shell\AutoRun\command - "" = F:\Setup.exe โ€“ File not found
    :Commands
    [EmptyFlash]
    [EmptyTemp]
    [Purity]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
๐Ÿ–ผClick to load external image (Posted Image) Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please include the following in your next post:
  • OTL Fix log
  • ComboFix log
thanks ran the 2 programs and the log files as per attached during the Combo fix runโ€ฆ it said like some rootkit is detected and reboot my PC and then restart the program Before that, i disabled my Norton Anitvirus until the next restart, so i'm not sure if they the reboot affects the Combo fix scan After running and finishing combo fix, i need to reboot my PC another time to enable my wireless USB adaptor Theres an icon at the bottom of the right hand screen saying "windows firewall not anabled". should i enable it? Pls take a look at my log and advice Thanks!
speedz76:

๐Ÿ–ผClick to load external image (Posted Image) Download TDSSKiller.zip and extract TDSSKiller.exe to your desktop
  • Execute TDSSKiller.exe by doubleclicking on it.
  • Press Start Scan
  • If Malicious objects are found then ensure Cure is selected. Important - If there is no option to "Cure" it is critical that you select "Skip"
  • Then click Continue > Reboot now
  • Once complete, a log will be produced at root. It will be named for example, TDSSKiller.2.4.0.0_24.07.2010_13.10.52_log.txt
  • Attach that log, please.
Please include the following in your next post:
  • TDSSKiller log
Hi sorry, my fingers was a bit too fast. When i ran the program, it detected some "rootkit" and i select "cure" for 2 items, but i pressed the "reboot now" before i can click open and saved the log. Can i run the program again and then post the log? or anyway to retreive the past log?
speedz76:

That was it! How is it running now? Please do this next:

๐Ÿ–ผClick to load external image (Posted Image) Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
  • Go to this page.
  • Scroll down to where it says "Java Platform, Standard Edition."
  • Click the "Download JRE" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Javaโ„ข 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH Checked
      Applications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
๐Ÿ–ผClick to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

๐Ÿ–ผClick to load external image (Posted Image) Please run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Please include the following in your next post:
  • MBAM log
  • ESET log
Hi Thank you for your patience and your clear instructions. I have not recieved the message of "a recent attempt to attack your computer was blocked" for today, since I followed your earlier thread instructions 1) Just to check, i use mozilla and IE interchangably. In your thread, you ask to remove all Java on our "add/remove" programs on computer panel. I found out that for mozilla, the Java is still availble under the "tools", "add ons" โ€“ Java Deployment toolkit 6.0.230.5 was in the mozilla all the while despite going to control panel and add remove programs for Java. Just wanted to make sure this will not affect the scanning in any way 2) The Malwarebytes program remove my "Funshion" program. Is it safe to reinstall it later ( as was planning to use it watch shows). I assumed it was safe as I have been using it all this while but only got the virus attack when immediately after using utorrent 3) Everytime i restart my PC, the messages "Windows firewall not turned on". If i turn it on, will it affect the "disinfectant process" that we are going through now or I'll just hold on first. 4) Somehow, when I was running the Malware scanner, this message suddenly pops pit from my Norton Antivrus >> "file insight" window TRD6_Webstart.sex.part Origin Source file - firefox.exe file created - trf6_webstart.exe.part I have the screenshot if you need it (but i cant upload it here) 5) I ran the ESET Online Scanner and when it scan sfinish, it said no virus found. But i cant find any "details" tab when i click "finish". Let me know if you need me to rerun again Thanks!
speedz76:

I only wanted you to remove the older, insecure versions of Java, then install the latest version (Java 6 Update 23). If you did that, it makes sense that you would still have Java entries on board, but now they are up to date.

Malwarebytes detects your Funshion application as adware. McAfee Site Advisor agrees (see here. I'd look for a different app if I were you.

I'm not sure what that Noton message is about. Is there any more details in Norton's history logs?

Let me know if you have any other questions or concerns - if not, I'll give you some cleanup instructions.
Hi RPMcMurphy Thank you for your advice. Looking at what you posted, I will to search for other sites instead of using Funshion :) Anyway, I just tried to rerun EsetOnline Scanner and i still can't locate the "details" tab and the log file, although the result of the scan is that it is virus free. As such, the only log i have is the MBAM_log.txt which i posted earlier. Before we go on to the next step, my windows firewall is currently disabled. If i enable my windows firewall, will it affect the upcoming "disinfectant" process? Please advise me on the next steps to be taken Thank you
speedz76:

You can go ahead and enable your firewall. I have another update and some important cleanup for you to take care of now:

๐Ÿ–ผClick to load external image (Posted Image) Uninstall ComboFix
  • Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens and press OK:
    Combofix /Uninstall
๐Ÿ–ผClick to load external image (Posted Image)

๐Ÿ–ผClick to load external image (Posted Image) Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
  • Manually delete any remaining logs or tools.
๐Ÿ–ผClick to load external image (Posted Image) Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
  • Restart any anti-malware programs that we disabled while we were cleaning your machine.
  • Keep your antivirus application current and updated. Also, hang on to MBAM. Scan with them at least weekly.
  • Consider running in a limited user account. See this post for more information.
  • Please carefully review the information in the Security - Best Practices and Prevention forum located HERE
Please post once more so I know you are all set and I can close this thread. Good luck and stay safe!
Thank you so much RPMcMurphy! Have followed your instructions and removed the combofix and OTL Before you close the thread, i would like to check two more thing 1) After following your instructions and rebooting my PC, i launched my Norton Anti Virus to look at the history and this is what i found: "Security History - Advanced Details (severity) - Medium, (Acitivty) - Unauthorized access blocked (Duplicate Object. (Date & Time) - Tuesday, December 21, 2010, 8:31pm. (Status)- Blocked. (Recommeded Action) - No Action required Advanced Details Date : Tuesday, December 21, 2010 8:31 PM Actor : C:\WINDOWS\SYSTEM32\SERVICES.EXE Actor PID : 680 Target : \Device\HarddiskVolume1\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe Target PID : 2412 Action: Duplicate Object Reaction : Unauthorized access blocked" I scrolled down the history and found that i have the same message logged everytime when my PC has just booted up. Is my PC still infected? I do not have any pop up or warnings from Norton about this though, and only see this on my Norton's history log 2) Just curious, how do you guys earn as this is a free site? I mean the service rendered is fantastic! But i'm just wondering what do you guys get from this? Thanks Please advise on (1) Thank you!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI