Recently, attacks have been unceasing. It happens every 10 minutes or so. I've scanned a couple of times in the past few days, but scans have only turned up tracking cookies. Below are copies of security log entries. (only dates and my name have been left out)
Severity: Medium
Activity: Unauthorized access blocked (send terminate message to window)
Status: Blocked
Reccomended action: No action required
Actor: c:\windows\explorer.exe
Actor PID: *
Target: C:\Program Files\Norton Antivirus\Norton Antivirus\Engine\16.5.0.134\ccSvcHst.exe
Target PID: **
Action: Send Terminate Message to Window
Reaction: Unauthorized access blocked
Recommended action: No Action Required
*1240, 1556, 812, 1264, 184, 816, 164, 180, 184
**1864, 1176, 1312, 1480, 2020, 640, 2212, 2724, 3448, 604, 3308, 3476, 3912, 3428, 2812, 3956, 2608, 2088, 200, 2372, 2308, 3428, 2568, 2904, 3040, 4084, 3608, 1120, 1004, 2132, 724, 2252, 3904, 3356
Happened 34 times (although certainly more by the time someone reads this) since June 9
Severity: Medium
Activity: Unauthorized access logged (Access Process Data)
Status: Logged
Actor: c:\windows\system32\mrt.exe
Actor PID: 2420
Target: C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA908}\PIFSvc.exe
Target PID: 1948
Action: Access Process Data
Reaction: Unauthorized access logged
Recommended action: No Action Required
Happened once on June 9
Severity: High
Activity: Auto-Protect has detected Bloodhound.Exploit.196
Status: Blocked
Risk category: Heuristic Virus
Definitions Version: 2009.06.12.021
Component: Auto-Protect
File Name: c:\documents and settings\MY NAME REMOVED\local settings\temporary internet files\content.ie5\ljt680e1\357[1].pdf
Recommended action: Resolved - no action
Happened three times from June 12 to June 13
Severity: High
Activity: An intrusion attempt by 84.16.228.90 was blocked. Application path \ DEVICE \ HARDDISKVOLUME1 \ PROGRAM FILES \ ADOBE \ ACROBAT 7.0 \ ACRORD32.EXE
Status: Blocked
Risk name: HTTP Acrobat Suspicious Executable File Download
Attacking computer: 84.16.228.90, 80
Attacker URL: recklitu.com/img\ouet.php
Destination address: MY NAME REMOVED-CF5F22DA5 (76.91.104.108, 1259*)
Source address: 84.16.228.90
Traffic Description: TCP, www-http
Recommended action: No Action Required
*Another log entry said 1470
Happened twice on June 12
Some additional info: One June 12th, my computer kept freezing up, but it hasn't happened since. I do not go to any shady websites, certainly none recently.
I'm sorry if this is vague; I'm not too familiar with computers!

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Back to top












