Tech Support Forum banner
Status
Not open for further replies.

HTTP phoenix java class activity intrusian attempts

2.4K views 1 reply 2 participants last post by  sjpritch25  
#1 ·
I have been having hell with intrusion attempts showing up on my norton, first by a company called galovit.com i checked theyre ip and it belonged to gigibits.com, now this morning from a company called jovartos.com tried to download a http phoenix toolkit exectuble download, when this happens my media player opens but then norton blocks it. Also my internet explorer was constantly running in the background with clicking galore, i thought i sought that yesterday with spyware doctor, it found a number of infections and removed them but now they are back. I am looking in my security activity in norton and it says intrusion prevention signature autoblock has blocked ip 188.72.198.211 for a period of 30 minutes and firewall rules were automatically created for java tm web start launcher and ips statistical submission. Also now my wireless button no longer works and i cant find my norton down the bottom right of my screen. also im having unortharised access blocked, open process token and unortharised access logged (access process data). I would love to hang these people who do this!!!!!! here is my hijak this log, and im really sorry for the long post.
 
#2 ·
Welcome to TSF :)

Download Combofix from this webpage: http://www.bleepingcomputer.com/combofix/how-to-use-combofix

**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" .
Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall




===================================================



Scan with RKUnHooker
  • Please download Rootkit Unhooker Save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers, Stealth. Uncheck the rest, then Click Ok.
  • Wait till the scanner has finished then click File, Save Report.
  • Save the report to your Desktop. Click Close.

In your next reply, copy and paste the contents of the log.

Note*** you may get this warning it is ok, just ignore

"Rootkit Unhooker has detected a parasite inside itself!!
 
Save
Status
Not open for further replies.
You have insufficient privileges to reply here.