have used utorrent recently and after use, i keep on getting the pop out by norton that "a recent attempt to attack your computer was blocked" ( i believe utorrrent is the cause as it only happened after i downloaded songs from there)
The message keeps on popping out every few minutes for tem minutes then pops out periodically. Today, my mozilla also suddenly crash.
I tried doing a fulll norton scan is both normal and SAFE mode but this message still keeps on popping out. Can anyone here advise what is this and anyway that i can remove it using Norton so that this will not happen again. Below are the details( i left the "destination address" blank as i think it is refering to my computer address and i do not want to post it online):
"an instrusion attempt by 194.60.205.232 was blocked"
Risk Name : HTP Tidserv Request
Attacking Computer : 194.60.205.232, 80
Attacking URL: switcho81.com/uv544k8x6t6M70c5dmVyPTMuOTYmYmlkP5vbmFtZSZhaWQ9MzAwNDQmc2lkPTAmcmQ9MCZlbmc9d3d3L
mdvb2dsZS5jb20uc2cmcT1pbnRydXNpb24rYXR0ZW1wdCt3YXMrYmxvY2tlZA==16k
Destination address: USER-FDxxxxx (xxx.xxx.xxx.) - (im leaving this field blank as i think this is the address of my computer)
Souce address : [removed]
Traffic description : TCP, www-http
work traffic from 194.60.205.232 matches the signature of a knowm attack. The attack was resulted from \DEVICE\HARDDISK\VOLUME1\PROGRAM FILES\MOZILLA FIREFOX\FIRSFOX.EXE. To stop being notified for this type of traffic. in the Actions panel, click "stop notifying me". Network traffic from switcho81.com/uv544k8x6t6M70c5dmVyPTMuOTYmYmlkP5vbmFtZSZhaWQ9MzAwNDQmc2lkPTAmcmQ9MCZlbmc9d3d3L
mdvb2dsZS5jb20uc2cmcT1pbnRydXNpb24rYXR0ZW1wdCt3YXMrYmxvY2tlZA==16k
matches the signatire of a known attack. The attack was resulted from \DEVICE\HARDDISK\VOLUME1\PROGRAM FILES\MOZILLA FIREFOX\FIRSFOX.EXE. To stop being notified for this type of traffic. in the Actions panel, click "stop notifying me"
is my com already infected? would appreciate any advise that i can get.
thank you
attached are the results from scans using OTL as per the guidelines
Aprreiciate if you can kindly advise.. Thanks!!
Hello speedz76 and welcome to WhatTheTech. Please follow these guidelines while we work on your PC:
Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until Iโve given you the โAll clear.โ Absence of symptoms does not mean your machine is clean!
Please do not run any scans or install/uninstall any applications without being directed to do so.
Any underlined text in my posts indicates a clickable link.
If you have any questions at all, please stop and ask before proceeding.
Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
If it gives you a warning about rootkit activity and asks if you want to run scanโฆclick on NO.
[external image: Posted Image] Click the image to enlarge it
In the right panel, you will see several boxes that have been checked. Uncheck the following โฆ
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and post it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<โ ROOKIT" entries
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
thanks
ran the 2 programs and the log files as per attached
during the Combo fix runโฆ it said like some rootkit is detected and reboot my PC and then restart the program
Before that, i disabled my Norton Anitvirus until the next restart, so i'm not sure if they the reboot affects the Combo fix scan
After running and finishing combo fix, i need to reboot my PC another time to enable my wireless USB adaptor
Theres an icon at the bottom of the right hand screen saying "windows firewall not anabled". should i enable it?
Pls take a look at my log and advice
Thanks!
Hi
sorry, my fingers was a bit too fast. When i ran the program, it detected some "rootkit" and i select "cure" for 2 items, but i pressed the "reboot now" before i can click open and saved the log.
Can i run the program again and then post the log? or anyway to retreive the past log?
That was it! How is it running now? Please do this next:
๐ผClick to load external image (Posted Image)Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
Go to this page.
Scroll down to where it says "Java Platform, Standard Edition."
Click the "Download JRE" button to the right.
Select the Windows platform from the dropdown menu.
Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
Click on the link to download Windows Offline Installation and save the file to your desktop.
Close any programs you may have running - especially your web browser.
Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Javaโข 6) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java version.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u21-windows-i586-p.exe to install the newest version.
After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
On the General tab, under Temporary Internet Files, click the Settings button.
Next, click on the Delete Files button
There are two options in the window to clear the cache - Leave BOTH Checked Applications and AppletsTrace and Log Files
Click OK on Delete Temporary Files Window Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
If an update is found, it will download and install the latest version.
The program will close to update and reopen.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
Hi
Thank you for your patience and your clear instructions. I have not recieved the message of "a recent attempt to attack your computer was blocked" for today, since I followed your earlier thread instructions
1) Just to check, i use mozilla and IE interchangably. In your thread, you ask to remove all Java on our "add/remove" programs on computer panel.
I found out that for mozilla, the Java is still availble under the "tools", "add ons" โ Java Deployment toolkit 6.0.230.5 was in the mozilla all the while despite going to control panel and add remove programs for Java. Just wanted to make sure this will not affect the scanning in any way
2) The Malwarebytes program remove my "Funshion" program. Is it safe to reinstall it later ( as was planning to use it watch shows). I assumed it was safe as I have been using it all this while but only got the virus attack when immediately after using utorrent
3) Everytime i restart my PC, the messages "Windows firewall not turned on". If i turn it on, will it affect the "disinfectant process" that we are going through now or I'll just hold on first.
4) Somehow, when I was running the Malware scanner, this message suddenly pops pit from my Norton Antivrus >> "file insight" window
TRD6_Webstart.sex.part
Origin
Source file - firefox.exe
file created - trf6_webstart.exe.part
I have the screenshot if you need it (but i cant upload it here)
5) I ran the ESET Online Scanner and when it scan sfinish, it said no virus found. But i cant find any "details" tab when i click "finish". Let me know if you need me to rerun again
Thanks!
I only wanted you to remove the older, insecure versions of Java, then install the latest version (Java 6 Update 23). If you did that, it makes sense that you would still have Java entries on board, but now they are up to date.
Malwarebytes detects your Funshion application as adware. McAfee Site Advisor agrees (see here. I'd look for a different app if I were you.
I'm not sure what that Noton message is about. Is there any more details in Norton's history logs?
Let me know if you have any other questions or concerns - if not, I'll give you some cleanup instructions.
Hi RPMcMurphy
Thank you for your advice. Looking at what you posted, I will to search for other sites instead of using Funshion
Anyway, I just tried to rerun EsetOnline Scanner and i still can't locate the "details" tab and the log file, although the result of the scan is that it is virus free. As such, the only log i have is the MBAM_log.txt which i posted earlier.
Before we go on to the next step, my windows firewall is currently disabled. If i enable my windows firewall, will it affect the upcoming "disinfectant" process?
Please advise me on the next steps to be taken
Thank you
Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens and press OK: Combofix /Uninstall
Thank you so much RPMcMurphy!
Have followed your instructions and removed the combofix and OTL
Before you close the thread, i would like to check two more thing
1) After following your instructions and rebooting my PC, i launched my Norton Anti Virus to look at the history and this is what i found:
"Security History - Advanced Details
(severity) - Medium, (Acitivty) - Unauthorized access blocked (Duplicate Object. (Date & Time) - Tuesday, December 21, 2010, 8:31pm. (Status)- Blocked. (Recommeded Action) - No Action required
Advanced Details
Date : Tuesday, December 21, 2010 8:31 PM
Actor : C:\WINDOWS\SYSTEM32\SERVICES.EXE
Actor PID : 680
Target : \Device\HarddiskVolume1\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe
Target PID : 2412
Action: Duplicate Object
Reaction : Unauthorized access blocked"
I scrolled down the history and found that i have the same message logged everytime when my PC has just booted up. Is my PC still infected? I do not have any pop up or warnings from Norton about this though, and only see this on my Norton's history log
2) Just curious, how do you guys earn as this is a free site? I mean the service rendered is fantastic! But i'm just wondering what do you guys get from this?
Thanks
Please advise on (1)
Thank you!!
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI