Announcement

Collapse
No announcement yet.

Malicious websites attacking our home?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #16
    If you want to see what it is doing d/l - http://technet.microsoft.com/en-us/s...rnals/bb897437 tcpview will tell you what process is being envoked and by what IP address.


    Originally posted by Tx Redneck View Post
    Joey, you run whois on the ip?
    Yes sir, it is from Czech... Definetly bad. These guys get paid for email working email addresses, bank info, SSN, etc.. its a business to them. Some do it to gain notoriety in the space and that is how they prove themselves to join an organized crime unit of h4ckz0rz. (like being jumped into a gang)



    Trying RIPE lookup...
    % This is the RIPE Database query service.
    % The objects are in RPSL format.
    %
    % The RIPE Database is subject to Terms and Conditions.
    % See http://www.ripe.net/db/support/db-terms-conditions.pdf

    % Note: this output has been filtered.
    % To receive output for a database update, use the "-B" flag.

    % Information related to '31.31.73.0 - 31.31.73.255'

    inetnum: 31.31.73.0 - 31.31.73.255
    netname: WEDOS-HOSTING
    descr: WEDOS hosting services
    country: CZ
    admin-c: PS10635-RIPE
    tech-c: PS10635-RIPE
    status: ASSIGNED PA
    mnt-by: WEDOS-MNT
    mnt-lower: WEDOS-MNT
    mnt-routes: WEDOS-MNT
    remarks: INFRA-AW
    source: RIPE # Filtered

    person: Petr Stastny
    address: WEDOS Internet, a.s.
    address: Masarykova 1230
    address: Hluboka nad Vltavou
    address: 37341
    phone: +420 380999775
    abuse-mailbox: abuse@wedos.com
    nic-hdl: PS10635-RIPE
    mnt-by: WEDOS-MNT
    source: RIPE # Filtered

    % Information related to '31.31.72.0/21AS197019'

    route: 31.31.72.0/21
    descr: WEDOS Internet, a.s.
    origin: AS197019
    mnt-by: WEDOS-MNT
    source: RIPE # Filtered
    WRX

    Comment


    • #17
      Originally posted by Tx Redneck View Post
      Run a full scan from Safemode w/networking. Post the txt file upon completion.
      I'm on my phone now. I had started a full scan in malwarebytes before i saw this.
      I'm working on the scan from safemode.

      Comment


      • #18
        This is taking a while. I still don't understand why it only happens here, though. Pretty retarded to see what my log in for here is.

        Comment


        • #19
          Are you using ABP and no-script in ff?

          Comment


          • #20
            Here is what I wound up with.

            Malwarebytes' Anti-Malware 1.51.2.1300
            Malwarebytes offers real-time antivirus, advanced anti-malware and privacy protection for all your devices. Launched in 2004 as a free virus scan, we still offer a free basic version 20 years later. Learn more.


            Database version: 8146

            Windows 5.1.2600 Service Pack 2 (Safe Mode)
            Internet Explorer 6.0.2900.2180

            11/18/2011 10:55:39 AM
            mbam-log-2011-11-18 (10-55-39).txt

            Scan type: Full scan (C:\|Z:\|)
            Objects scanned: 165110
            Time elapsed: 18 minute(s), 7 second(s)

            Memory Processes Infected: 0
            Memory Modules Infected: 0
            Registry Keys Infected: 0
            Registry Values Infected: 0
            Registry Data Items Infected: 0
            Folders Infected: 0
            Files Infected: 0

            Memory Processes Infected:
            (No malicious items detected)

            Memory Modules Infected:
            (No malicious items detected)

            Registry Keys Infected:
            (No malicious items detected)

            Registry Values Infected:
            (No malicious items detected)

            I also didn't get the notice that malwarebytes blocked anything upon opening DFWM this time. I am still in safemodew/ networking, though. We'll see what happens when I reboot.

            Comment


            • #21
              Can someone submit that ip to virustotal.com to be scanned?

              Comment


              • #22
                I'm not getting the notice anymore.

                Why did my scan have Internet explorer listed as my browser? I use firefox.

                Comment


                • #23
                  I looked through my malwarebytes logs and on 11-16-11 I got these two IP addresses. 31.31.75.215 & 31.31.75.216 hit me 9 times.

                  Then on 11-17-11 I got 31.31.75.215 again for 5 hits.

                  Today I got hit with the one above 16 times.

                  All were blocked.

                  Comment


                  • #24
                    Originally posted by Muffrazr View Post
                    I looked through my malwarebytes logs and on 11-16-11 I got these two IP addresses. 31.31.75.215 & 31.31.75.216 hit me 9 times.

                    Then on 11-17-11 I got 31.31.75.215 again for 5 hits.

                    Today I got hit with the one above 16 times.

                    All were blocked.
                    VirusTotal is a free virus, malware and URL online scanning service. File checking is done with more than 40 antivirus solutions. Files and URLs can be sent via web interface upload, email API or making use of VirusTotal's browser extensions and desktop applications.


                    VirusTotal is a free virus, malware and URL online scanning service. File checking is done with more than 40 antivirus solutions. Files and URLs can be sent via web interface upload, email API or making use of VirusTotal's browser extensions and desktop applications.


                    VirusTotal is a free virus, malware and URL online scanning service. File checking is done with more than 40 antivirus solutions. Files and URLs can be sent via web interface upload, email API or making use of VirusTotal's browser extensions and desktop applications.


                    Code:
                    index.html
                    Submission date:
                    2011-11-18 17:11:48 (UTC)
                    Current status:
                    finished
                    Result:
                    0/ 42 (0.0%)
                    	
                    Antivirus 	Version 	Last Update 	Result
                    AhnLab-V3	2011.11.18.00	2011.11.18	-
                    AntiVir	7.11.17.231	2011.11.18	-
                    Antiy-AVL	2.0.3.7	2011.11.18	-
                    Avast	6.0.1289.0	2011.11.18	-
                    AVG	10.0.0.1190	2011.11.18	-
                    BitDefender	7.2	2011.11.18	-
                    ByteHero	1.0.0.1	2011.11.14	-
                    ClamAV	0.97.3.0	2011.11.18	-
                    Commtouch	5.3.2.6	2011.11.18	-
                    Comodo	10780	2011.11.18	-
                    DrWeb	5.0.2.03300	2011.11.18	-
                    Emsisoft	5.1.0.11	2011.11.18	-
                    eSafe	7.0.17.0	2011.11.18	-
                    eTrust-Vet	37.0.9574	2011.11.18	-
                    F-Prot	4.6.5.141	2011.11.18	-
                    F-Secure	9.0.16440.0	2011.11.18	-
                    Fortinet	4.3.370.0	2011.11.18	-
                    GData	22	2011.11.18	-
                    Ikarus	T3.1.1.109.0	2011.11.18	-
                    Jiangmin	13.0.900	2011.11.16	-
                    K7AntiVirus	9.119.5493	2011.11.18	-
                    Kaspersky	9.0.0.837	2011.11.18	-
                    McAfee	5.400.0.1158	2011.11.18	-
                    McAfee-GW-Edition	2010.1D	2011.11.18	-
                    Microsoft	1.7801	2011.11.18	-
                    NOD32	6641	2011.11.18	-
                    Norman	6.07.13	2011.11.18	-
                    nProtect	2011-11-18.01	2011.11.18	-
                    Panda	10.0.3.5	2011.11.18	-
                    PCTools	8.0.0.5	2011.11.18	-
                    Prevx	3.0	2011.11.18	-
                    Rising	23.84.04.02	2011.11.18	-
                    Sophos	4.71.0	2011.11.18	-
                    SUPERAntiSpyware	4.40.0.1006	2011.11.18	-
                    Symantec	20111.2.0.82	2011.11.18	-
                    TheHacker	6.7.0.1.344	2011.11.18	-
                    TrendMicro	9.500.0.1008	2011.11.18	-
                    TrendMicro-HouseCall	9.500.0.1008	2011.11.18	-
                    VBA32	3.12.16.4	2011.11.18	-
                    VIPRE	11078	2011.11.18	-
                    ViRobot	2011.11.18.4780	2011.11.18	-
                    VirusBuster	14.1.71.0	2011.11.18	-
                    Additional information
                    MD5   : 89417c06cfb071fd3220d18f8b56e4ef
                    SHA1  : da1871119bff09fc9fca71c8d34559a21dbfdd8f
                    SHA256: 7adc881a6c7e0d49840dc1c37d5d34612183fb0cb96efabdc07d01b94b8d337e
                    I'm gonna say it's a false positive.

                    Comment


                    • #25
                      So, what does it all meeeaaaaaannn Basil?

                      Comment


                      • #26
                        Since you're a paid MBAM user, submit a request to them w/a link to this thread. Are there any funky symptoms w/your puter aside from what's been stated?

                        Comment


                        • #27
                          No. It's a really old laptop that I use here at work. The processor would overheat when I gave it too much to do, so I used the thermal compound that I regularly use for trolling motors and have never had a heat issue since. However, it's still too weak to handle a whole lot. I keep my programs on the thin side. It will lock up if I've got too many websites open that have streaming information, but that has been normal.

                          Comment


                          • #28
                            Sent the request. Hopefully it's not something too terribly bad.

                            Maybe it's just Stanleytweedle fishing for some new identity.

                            Comment


                            • #29
                              Is the ram maxed out? Specs of said turd?

                              Comment


                              • #30
                                Originally posted by Tx Redneck View Post
                                Is the ram maxed out? Specs of said turd?
                                Presario 2100
                                Mobile Intel Celeron 1.6 GHz
                                1.59 GHz, 704MB RAM

                                Comment

                                Working...
                                X