being attacked by 208.73.210.29; MBAB blocking outbound access every 5-10 minutes
#41
Posted 29 April 2012 - 03:50 PM
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#42
Posted 29 April 2012 - 08:33 PM
#43
Posted 29 April 2012 - 10:00 PM
And, I haven't seen another popup in nearly an hour.
#44
Posted 29 April 2012 - 10:02 PM
173.192.183.196
#45
Posted 30 April 2012 - 07:48 AM

Here's where that's from.
Delete your copy if ComboFix, download and run a fresh copy.......post the log.
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#46
Posted 30 April 2012 - 08:33 AM
#47
Posted 30 April 2012 - 08:54 AM
here is the new CF log:
#48
Posted 30 April 2012 - 09:01 AM
I'm running out of ideas.....let me do some more research...I'll get back to you ASAP. MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#49
Posted 30 April 2012 - 09:04 AM
I really do appreciate your time and assistance.
#50
Posted 30 April 2012 - 09:39 AM
Download and run McAfee Labs Stinger:
http://www.mcafee.co...se-stinger.aspx
-------------------------------
Then.....
Please Update and run a Full Scan with MBAM, post the report.
Make sure that everything is checked, and click Remove Selected.
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#51
Posted 30 April 2012 - 11:46 AM
#52
Posted 30 April 2012 - 11:52 AM
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#53
Posted 30 April 2012 - 01:03 PM
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org
Database version: v2012.04.30.06
Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Protection: Enabled
4/30/2012 11:45:25 AM
mbam-log-2012-04-30 (11-45-25).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 300865
Time elapsed: 43 minute(s), 57 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
#54
Posted 30 April 2012 - 01:04 PM
#55
Posted 30 April 2012 - 01:40 PM
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#56
Posted 30 April 2012 - 03:00 PM
#57
Posted 30 April 2012 - 03:06 PM
#58
Posted 30 April 2012 - 03:11 PM
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#59
Posted 30 April 2012 - 03:16 PM
Please download SystemLook from the link below and save it to your Desktop.
http://jpshortstuff....temLook_x64.exe
- Double-click SystemLook.exe to run it.
- Copy the content of the following codebox into the main textfield:
:filefind 208.73.210.29 13376694984709702142491016734454 :regfind 208.73.210.29 13376694984709702142491016734454
- Click the Look button to start the scan.
- When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#60
Posted 30 April 2012 - 03:17 PM
2012/04/30 05:46:05 -0500 MESSAGE IP Protection stopped
2012/04/30 05:46:07 -0500 MESSAGE Database refreshed successfully
2012/04/30 05:46:07 -0500 MESSAGE Starting IP protection
2012/04/30 05:46:09 -0500 MESSAGE IP Protection started successfully
2012/04/30 06:09:38 -0500 IP-BLOCK 173.192.183.195 (Type: outgoing, Port: 51064, Process: mcsvhost.exe)
2012/04/30 06:09:38 -0500 IP-BLOCK 173.192.183.195 (Type: outgoing, Port: 51071, Process: mcsvhost.exe)
2012/04/30 06:09:38 -0500 IP-BLOCK 173.192.183.195 (Type: outgoing, Port: 51087, Process: mcsvhost.exe)
2012/04/30 06:09:38 -0500 IP-BLOCK 173.192.183.195 (Type: outgoing, Port: 51094, Process: mcsvhost.exe)
2012/04/30 06:09:38 -0500 IP-BLOCK 173.192.183.195 (Type: outgoing, Port: 51098, Process: mcsvhost.exe)
2012/04/30 06:09:47 -0500 IP-BLOCK 173.192.183.195 (Type: outgoing, Port: 51109, Process: mcsvhost.exe)
2012/04/30 08:26:02 -0500 MESSAGE Starting protection
2012/04/30 08:26:05 -0500 MESSAGE Protection started successfully
2012/04/30 08:26:09 -0500 MESSAGE Starting IP protection
2012/04/30 08:26:10 -0500 MESSAGE IP Protection started successfully
2012/04/30 08:36:40 -0500 MESSAGE Stopping IP protection
2012/04/30 08:38:37 -0500 MESSAGE IP Protection stopped
2012/04/30 08:53:25 -0500 MESSAGE Starting protection
2012/04/30 08:53:28 -0500 MESSAGE Protection started successfully
2012/04/30 11:44:53 -0500 MESSAGE Starting database refresh
2012/04/30 11:44:55 -0500 MESSAGE Database refreshed successfully
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users



This topic is locked









