Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Am I infected?


  • Please log in to reply
2 replies to this topic

#1 dyoung009

dyoung009

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:05:38 PM

Posted 10 February 2015 - 10:45 AM

Hi everyone, new guy here,

 

I've been searching through the forums lately in an attempt to find a solution to my problem, but nothing has come up. I'm running Norton 360 and a daily intrusion alert comes up during web browsing in IE stating "suspicious.cloud.7.ep." The file details reports the following: "c:\windows\syswow64\colormedia.dll",requiring a system restart. Not sure if this is related, but I am also getting an "unauthorized access blocked" from c:\windows\system32\conhost.exe. Are these serious threats or just false-positives from Norton?

 

(EDITED) I'm running Windows 7 (64), and some of the steps I have tried to correct this is scans by Norton, MBAM, and MBAR. Some threats did come up for the former two, however, the problem still persists. Also, just to add a side note, my computer is acting relatively stable.

 

Thanks ahead of time to anyone who can help.


Edited by dyoung009, 10 February 2015 - 10:56 AM.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,040 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:38 PM

Posted 10 February 2015 - 11:08 AM

Hello dyoung, Suspicious.Cloud.7.EP is a kernel-mode rootkit. These need to be prioperly removed.

Please follow this Preparation Guide and post in a new topic.
Let me know if all went well.


How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 dyoung009

dyoung009
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:05:38 PM

Posted 10 February 2015 - 11:10 AM

Will do. Thanks again.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users