Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Jun 14 2009, 09:58 PM
Post
#1
|
|
|
Member ![]() ![]() Group: Members Posts: 27 Joined: 14-June 09 Member No.: 342,058 |
Recently, attacks have been unceasing. It happens every 10 minutes or so. I've scanned a couple of times in the past few days, but scans have only turned up tracking cookies. Below are copies of security log entries. (only dates and my name have been left out) Severity: Medium Activity: Unauthorized access blocked (send terminate message to window) Status: Blocked Reccomended action: No action required Actor: c:\windows\explorer.exe Actor PID: * Target: C:\Program Files\Norton Antivirus\Norton Antivirus\Engine\16.5.0.134\ccSvcHst.exe Target PID: ** Action: Send Terminate Message to Window Reaction: Unauthorized access blocked Recommended action: No Action Required *1240, 1556, 812, 1264, 184, 816, 164, 180, 184 **1864, 1176, 1312, 1480, 2020, 640, 2212, 2724, 3448, 604, 3308, 3476, 3912, 3428, 2812, 3956, 2608, 2088, 200, 2372, 2308, 3428, 2568, 2904, 3040, 4084, 3608, 1120, 1004, 2132, 724, 2252, 3904, 3356 Happened 34 times (although certainly more by the time someone reads this) since June 9 Severity: Medium Activity: Unauthorized access logged (Access Process Data) Status: Logged Actor: c:\windows\system32\mrt.exe Actor PID: 2420 Target: C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA908}\PIFSvc.exe Target PID: 1948 Action: Access Process Data Reaction: Unauthorized access logged Recommended action: No Action Required Happened once on June 9 Severity: High Activity: Auto-Protect has detected Bloodhound.Exploit.196 Status: Blocked Risk category: Heuristic Virus Definitions Version: 2009.06.12.021 Component: Auto-Protect File Name: c:\documents and settings\MY NAME REMOVED\local settings\temporary internet files\content.ie5\ljt680e1\357[1].pdf Recommended action: Resolved - no action Happened three times from June 12 to June 13 Severity: High Activity: An intrusion attempt by 84.16.228.90 was blocked. Application path \ DEVICE \ HARDDISKVOLUME1 \ PROGRAM FILES \ ADOBE \ ACROBAT 7.0 \ ACRORD32.EXE Status: Blocked Risk name: HTTP Acrobat Suspicious Executable File Download Attacking computer: 84.16.228.90, 80 Attacker URL: recklitu.com/img\ouet.php Destination address: MY NAME REMOVED-CF5F22DA5 (76.91.104.108, 1259*) Source address: 84.16.228.90 Traffic Description: TCP, www-http Recommended action: No Action Required *Another log entry said 1470 Happened twice on June 12 Some additional info: One June 12th, my computer kept freezing up, but it hasn't happened since. I do not go to any shady websites, certainly none recently. I'm sorry if this is vague; I'm not too familiar with computers! |
|
|
|
Jun 14 2009, 10:16 PM
Post
#2
|
|
![]() Bleepin' Peaceful ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 3,077 Joined: 9-December 08 Member No.: 267,653 |
Hi and welcome to BC!
Please do this...... Please download Malwarebytes Anti-Malware alternate download link 1 alternate download link 2 NOTE: Before saving MBAM please rename it to thcbytes.exe then save it to your desktop. MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
If MBAM will not install, try renaming it this way.
********** * Go to start > Run copy/paste the contents of the code box excluding "code" in the run box and click OK. CODE cmd /c (ipconfig /all&nslookup google.com&ping -n 2 google.com&route print) >log.txt&log.txt&del log.txt A command window opens. Wait until a log.txt file opens. * Please copy/paste the log file in your reply. ********** With your next post please provide: * MBAM log * Internet connection logfile Kind regards, t This post has been edited by thcbytes: Jun 14 2009, 10:18 PM -------------------- Proud member - Unified Network of Instructors and Trained Eliminators
![]() If I'm helping you and I don't reply within 48 hours please feel free to send me a PM. Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored! |
|
|
|
Jun 15 2009, 04:42 PM
Post
#3
|
|
|
Member ![]() ![]() Group: Members Posts: 27 Joined: 14-June 09 Member No.: 342,058 |
Hi, thanks for replying! Before I download MBAM, I just want to make sure of a few things:
*What are "changes to my registry?" *Can I uninstall it later? Thank you! |
|
|
|
Jun 15 2009, 05:39 PM
Post
#4
|
|
![]() Bleepin' Peaceful ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 3,077 Joined: 9-December 08 Member No.: 267,653 |
Hello again,
In order for the tool to run it will make changes in the database that stores settings in your OS ie "registry changes". These changes are not malicious. They are required for the tool to be effective. Many antivirus and antispyware software will globally block registry changes good or bad so this is why we ask you to temporarily disable your active protection. Our tools will be ineffective otherwise. All the tools we utilize can be simply uninstalled via the add/remove function in your computer. MBAM is a freeware utility that you might want to make part of your regular safety routine though. Most of the helpers here share their expertize out of the goodness of their hearts and because of an interest in computer security. Me included. Proceed if you desire, I will be here, Kind regards, t -------------------- Proud member - Unified Network of Instructors and Trained Eliminators
![]() If I'm helping you and I don't reply within 48 hours please feel free to send me a PM. Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored! |
|
|
|
Jun 16 2009, 08:34 PM
Post
#5
|
|
|
Member ![]() ![]() Group: Members Posts: 27 Joined: 14-June 09 Member No.: 342,058 |
Hello again, In order for the tool to run it will make changes in the database that stores settings in your OS ie "registry changes". These changes are not malicious. They are required for the tool to be effective. Many antivirus and antispyware software will globally block registry changes good or bad so this is why we ask you to temporarily disable your active protection. Our tools will be ineffective otherwise. All the tools we utilize can be simply uninstalled via the add/remove function in your computer. MBAM is a freeware utility that you might want to make part of your regular safety routine though. Most of the helpers here share their expertize out of the goodness of their hearts and because of an interest in computer security. Me included. Proceed if you desire, I will be here, Kind regards, t Is there any other option? If I have to turn off my antivirus, that would be really chancing it. |
|
|
|
Jun 16 2009, 09:05 PM
Post
#6
|
|
![]() Bleepin' Peaceful ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 3,077 Joined: 9-December 08 Member No.: 267,653 |
You could try to give it a run without disabling anything. If you get warnings from your antivirus software then allow the changes temporarily
I understand your apprehensions but we are the good guy's. We are here to help not hurt you. Kind regards, t -------------------- Proud member - Unified Network of Instructors and Trained Eliminators
![]() If I'm helping you and I don't reply within 48 hours please feel free to send me a PM. Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored! |
|
|
|
Jun 16 2009, 09:08 PM
Post
#7
|
|
![]() Just Hoping To Help ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,208 Joined: 30-December 08 From: Utah Member No.: 275,768 |
I run that program with my antivirus on and do not have any problems. My firewall has an operating system firewall that blocks access and changes to my system files unless I give permission for the program to access and make changes to those files so I just give Malwarebytes full permission. Malwarebytes cannot scan or clean up your system unless it has access to it, neither can any other program.
If you find that you need to turn off your antivirus in order for the program to operate correctly you can do that safely just by disconnecting from the internet before running the scan. |
|
|
|
Jun 16 2009, 09:54 PM
Post
#8
|
|
|
Member ![]() ![]() Group: Members Posts: 27 Joined: 14-June 09 Member No.: 342,058 |
Thanks for helping me out! The program installed perfectly. Here are the scan results:
Malwarebytes' Anti-Malware 1.37 Database version: 2291 Windows 5.1.2600 Service Pack 3 6/16/2009 7:43:31 PM mbam-log-2009-06-16 (19-43-31).txt Scan type: Quick Scan Objects scanned: 102905 Time elapsed: 17 minute(s), 49 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f919fbd3-a96b-4679-af26-f551439bb5fd} (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) And here's my internet connection logfile: Windows IP Configuration Host Name . . . . . . . . . . . . : burch-cf5f22da5 Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : socal.rr.com Ethernet adapter Local Area Connection 2: Connection-specific DNS Suffix . : socal.rr.com Description . . . . . . . . . . . : NVIDIA nForce Networking Controller #2 Physical Address. . . . . . . . . : 00-11-09-B9-83-C6 Dhcp Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes IP Address. . . . . . . . . . . . : 76.91.105.79 Subnet Mask . . . . . . . . . . . : 255.255.240.0 Default Gateway . . . . . . . . . : 76.91.96.1 DHCP Server . . . . . . . . . . . : 76.85.238.49 DNS Servers . . . . . . . . . . . : 66.75.160.63 66.75.160.64 Lease Obtained. . . . . . . . . . : Tuesday, June 16, 2009 7:46:28 PM Lease Expires . . . . . . . . . . : Wednesday, June 17, 2009 7:46:28 PM Server: rdns-lb-01.orange.rr.com Address: 66.75.160.63 Name: google.com Addresses: 74.125.45.100, 74.125.67.100, 74.125.127.100 Pinging google.com [74.125.45.100] with 32 bytes of data: Reply from 74.125.45.100: bytes=32 time=85ms TTL=49 Reply from 74.125.45.100: bytes=32 time=85ms TTL=49 Ping statistics for 74.125.45.100: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 85ms, Maximum = 85ms, Average = 85ms =========================================================================== Interface List 0x1 ........................... MS TCP Loopback interface 0x2 ...00 11 09 b9 83 c6 ...... Realtek RTL8139/810x Family Fast Ethernet NIC #2 - Packet Scheduler Miniport =========================================================================== =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 76.91.96.1 76.91.105.79 20 76.91.96.0 255.255.240.0 76.91.105.79 76.91.105.79 20 76.91.105.79 255.255.255.255 127.0.0.1 127.0.0.1 20 76.255.255.255 255.255.255.255 76.91.105.79 76.91.105.79 20 127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1 224.0.0.0 240.0.0.0 76.91.105.79 76.91.105.79 20 255.255.255.255 255.255.255.255 76.91.105.79 76.91.105.79 1 Default Gateway: 76.91.96.1 =========================================================================== Persistent Routes: None BTW, after I restarted after the scan, Windows alerted me that my Firewall had been turned off. Might that have been a virus? |
|
|
|
Jun 16 2009, 10:17 PM
Post
#9
|
|
![]() Bleepin' Peaceful ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 3,077 Joined: 9-December 08 Member No.: 267,653 |
Well done
Yes. The malware disabled your firewall and your antivirus software from updating. Is this your server? CODE Server: rdns-lb-01.orange.rr.com ********** Let's proceed, Please do this...... * Clean your Cache and Cookies in IE:
********** Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page. Please download DrWeb-CureIt and save it to your desktop. DO NOT perform a scan yet. Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode". Scan with Dr.Web CureIt as follows:
********** Please run a BitDefender Online Scan
********** With your next post please provide: * Answer question * DrWeb log * Bitdefender log Kind regards, t -------------------- Proud member - Unified Network of Instructors and Trained Eliminators
![]() If I'm helping you and I don't reply within 48 hours please feel free to send me a PM. Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored! |
|
|
|
Jun 17 2009, 01:14 AM
Post
#10
|
|
|
Member ![]() ![]() Group: Members Posts: 27 Joined: 14-June 09 Member No.: 342,058 |
Well done Yes. The malware disabled your firewall and your antivirus software from updating. Is this your server? CODE Server: rdns-lb-01.orange.rr.com ********** Let's proceed, Please do this...... * Clean your Cache and Cookies in IE:
Thanks for replying! Unfortunately, I'm not sure how to determine what my server is. Before I follow your instructions, I'm a bit confused on two things: When I click "delete all offline content", what will be deleted? I don't have Firefox, so should I ignore step #2? Thanks again for helping! |
|
|
|
Jun 17 2009, 01:23 AM
Post
#11
|
|
![]() Just Hoping To Help ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,208 Joined: 30-December 08 From: Utah Member No.: 275,768 |
Checking that box won't delete anything you really need. It just deletes the files that were saved to your computer if you have ever marked any webpages to be viewed offline. At this point, even if you have done that, I would go ahead and have that content deleted as you can always go back to that webpage and set for offline viewing again.
I believe your server is your ISP, are you using RoadRunner to connect to the internet? I do not know what the orange stands for (maybe Orange County?) but the rr is most likely for RoadRunner Yes, if you do not have Firefox then there is no need to clear the cache or cookies for it. Did you turn your firewall and antivirus programs back on? If not, you should. If they are on and just being reported by Windows Security Center as off, say so. Sometimes Windows Security Center does not report them accurately and Malwarebytes did change the setting for the Windows Security Center notifications. Also, are you able to update your antivirus program? This post has been edited by Stang777: Jun 17 2009, 01:35 AM |
|
|
|
Jun 17 2009, 06:14 AM
Post
#12
|
|
![]() Bleepin' Peaceful ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 3,077 Joined: 9-December 08 Member No.: 267,653 |
Agreed.
Thanks Stang You may proceed when ready, t -------------------- Proud member - Unified Network of Instructors and Trained Eliminators
![]() If I'm helping you and I don't reply within 48 hours please feel free to send me a PM. Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored! |
|
|
|
Jun 17 2009, 06:55 AM
Post
#13
|
|
![]() Just Hoping To Help ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,208 Joined: 30-December 08 From: Utah Member No.: 275,768 |
You are so very welcome Thcbytes
|
|
|
|
Jun 17 2009, 10:12 PM
Post
#14
|
|
|
Member ![]() ![]() Group: Members Posts: 27 Joined: 14-June 09 Member No.: 342,058 |
OK! The BitDefender scan didn't turn up anything. My ISP is Time Warner Cable.
QUOTE Did you turn your firewall and antivirus programs back on? If not, you should. If they are on and just being reported by Windows Security Center as off, say so. Sometimes Windows Security Center does not report them accurately and Malwarebytes did change the setting for the Windows Security Center notifications. Also, are you able to update your antivirus program? Windows Security Center reported that the firewall had been turned off, so I turned it back on. And I think my Antivirus updates itself. Here is the DrWeb CureIt scan result: 000000BB;C:\WINDOWS\temp;Trojan.Swizzor.based;Deleted.; pifCrawl.exe;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08};Trojan.Swizzor.based;Deleted.; pv.exe;C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\Uninstall-hpLJ_101x;Program.PrcView.3741;Moved.; A0245384.exe;C:\System Volume Information\_restore{36964EE1-EB8F-4509-9797-1EE4E979EB5C}\RP458;Trojan.Swizzor.based;Deleted.; |
|
|
|
Jun 17 2009, 10:38 PM
Post
#15
|
|
![]() Bleepin' Peaceful ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 3,077 Joined: 9-December 08 Member No.: 267,653 |
Hello,
CODE OK! The BitDefender scan didn't turn up anything. My ISP is Time Warner Cable. Were just about there... Do this.... Update and rerun MBAM ========== Please download and scan with SUPERAntiSpyware Free
Scan with SUPERAntiSpyware as follows:
========== Please run the F-Secure Online Scanner Note: This Scanner is for Internet Explorer Only! Follow the Instruction here for installation. Accept the License Agreement. Once the ActiveX installs,Click Full System Scan Once the download completes, the scan will begin automatically. The scan will take some time to finish, so please be patient. When the scan completes, click the Automatic cleaning (recommended) button. Click the Show Report button and Copy&Paste the entire report in your next reply. ========== With your next post please provide: * Hows it running? * MBAM log * F-Secure log Thanks, t -------------------- Proud member - Unified Network of Instructors and Trained Eliminators
![]() If I'm helping you and I don't reply within 48 hours please feel free to send me a PM. Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored! |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 8th November 2009 - 11:19 AM |