martinz0000
Members-
Posts
6 -
Joined
-
Last visited
Reputation
0 Neutral-
Okay thanks for you help , Will check my backup for malware. Will be still using p2p , can't really stop using that right now when its the only way to watch some tv shows that are not aviable in my country.
- 10 replies
-
- svchost.exe
- Malicious
-
(and 2 more)
Tagged with:
-
Are you sure ? I never had those detections before and i was using lots of p2p software. Could it be new malware database version or something ?
- 10 replies
-
- svchost.exe
- Malicious
-
(and 2 more)
Tagged with:
-
Okay , here we go. TDSS did not detect anything this time so. MBAM.txt TDSSKiller.3.0.0.41_02.11.2014_22.32.25_log.txt
- 10 replies
-
- svchost.exe
- Malicious
-
(and 2 more)
Tagged with:
-
So i did a os reinstall. After a hour or something the problem appeared again , just a bit different. First it detected something in qTorrent , so i closed it (Only downloaded some songs and stuff) After a while it blocked outbound connection of skype.exe. So far looks like svchost.exe is okay. I can do the tdskiller and mbam logs thingy again so we could find what's the cause of this. (OS is a clean one from ms page.) Anyway check the first detection in protection log , its some kind of temporary file in appdata folder. This is the protection log : Malwarebytes Anti-Malware www.malwarebytes.org Error, 02.11.2014. 19:15:59, SYSTEM, HOME, Protection, IsLicensed, 13, Protection, 02.11.2014. 19:15:59, SYSTEM, HOME, Protection, Malware Protection, Stopping, Protection, 02.11.2014. 19:15:59, SYSTEM, HOME, Protection, Malware Protection, Stopped, Protection, 02.11.2014. 19:16:05, SYSTEM, HOME, Protection, Malware Protection, Starting, Protection, 02.11.2014. 19:16:05, SYSTEM, HOME, Protection, Malware Protection, Started, Protection, 02.11.2014. 19:16:05, SYSTEM, HOME, Protection, Malicious Website Protection, Starting, Protection, 02.11.2014. 19:16:06, SYSTEM, HOME, Protection, Malicious Website Protection, Started, Update, 02.11.2014. 19:16:09, SYSTEM, HOME, Manual, Rootkit Database, 2014.9.18.1, 2014.11.1.2, Update, 02.11.2014. 19:16:23, SYSTEM, HOME, Manual, Malware Database, 2014.9.19.5, 2014.11.2.5, Protection, 02.11.2014. 19:16:23, SYSTEM, HOME, Protection, Refresh, Starting, Protection, 02.11.2014. 19:16:23, SYSTEM, HOME, Protection, Malicious Website Protection, Stopping, Protection, 02.11.2014. 19:16:23, SYSTEM, HOME, Protection, Malicious Website Protection, Stopped, Protection, 02.11.2014. 19:16:27, SYSTEM, HOME, Protection, Refresh, Success, Protection, 02.11.2014. 19:16:27, SYSTEM, HOME, Protection, Malicious Website Protection, Starting, Protection, 02.11.2014. 19:16:27, SYSTEM, HOME, Protection, Malicious Website Protection, Started, Detection, 02.11.2014. 19:59:30, MÄrtiÅÅ¡, HOME, Protection, Malware Protection, File, PUP.Optional.OpenCandy, C:\Users\MÄrtiÅÅ¡\AppData\Local\Temp\uttCB7F.tmp, Quarantine, [c03dcd69ed8f7cbaed9d4f0e11f427d9] Detection, 02.11.2014. 20:02:05, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 109.163.226.236, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe, Detection, 02.11.2014. 20:02:05, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 109.163.226.236, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe, Detection, 02.11.2014. 20:02:34, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.212.124.13, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe, Detection, 02.11.2014. 20:02:34, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.212.124.13, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe, Detection, 02.11.2014. 20:03:36, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 217.23.187.159, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe, Detection, 02.11.2014. 20:03:36, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 217.23.187.159, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe, Detection, 02.11.2014. 20:03:40, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 188.65.50.47, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe, Detection, 02.11.2014. 20:03:41, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 188.65.50.47, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe, Detection, 02.11.2014. 20:05:08, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 5.150.195.167, 0427d7.se, 63633, Outbound, C:\Program Files (x86)\Mozilla Firefox\firefox.exe, Detection, 02.11.2014. 20:05:08, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 5.150.195.167, 0427d7.se, 63633, Outbound, C:\Program Files (x86)\Mozilla Firefox\firefox.exe, Protection, 02.11.2014. 20:17:43, SYSTEM, HOME, Protection, Malware Protection, Starting, Protection, 02.11.2014. 20:17:43, SYSTEM, HOME, Protection, Malware Protection, Started, Protection, 02.11.2014. 20:17:43, SYSTEM, HOME, Protection, Malicious Website Protection, Starting, Protection, 02.11.2014. 20:18:23, SYSTEM, HOME, Protection, Malicious Website Protection, Started, Detection, 02.11.2014. 20:20:26, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.212.124.13, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe, Detection, 02.11.2014. 20:20:27, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.212.124.13, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe, Scan, 02.11.2014. 20:38:01, SYSTEM, HOME, Manual, Start:02.11.2014. 20:20:26, Duration:17 min 34 sec, Threat Scan, Completed, 0 Malware Detections, 0 Non-Malware Detections, Detection, 02.11.2014. 20:59:24, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60171, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 20:59:25, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60171, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 20:59:26, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60176, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 20:59:26, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60180, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 20:59:26, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60181, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 20:59:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 60200, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 20:59:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 60200, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 20:59:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 60204, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 20:59:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 60205, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 20:59:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 60206, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:00:22, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60307, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:00:22, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60308, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:00:22, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60309, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:00:22, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60310, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:00:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.188.57.152, 60329, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:00:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.188.57.152, 60330, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:00:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.188.57.152, 60331, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:00:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.188.57.152, 60332, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:00:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.188.57.152, 60329, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Protection, 02.11.2014. 21:14:19, SYSTEM, HOME, Protection, Malware Protection, Starting, Protection, 02.11.2014. 21:14:19, SYSTEM, HOME, Protection, Malware Protection, Started, Protection, 02.11.2014. 21:14:19, SYSTEM, HOME, Protection, Malicious Website Protection, Starting, Protection, 02.11.2014. 21:14:52, SYSTEM, HOME, Protection, Malicious Website Protection, Started, Detection, 02.11.2014. 21:17:44, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.212.124.13, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe, Detection, 02.11.2014. 21:17:44, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.212.124.13, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe, Update, 02.11.2014. 21:26:15, SYSTEM, HOME, Manual, Malware Database, 2014.11.2.5, 2014.11.2.6, Protection, 02.11.2014. 21:26:15, SYSTEM, HOME, Protection, Refresh, Starting, Protection, 02.11.2014. 21:26:15, SYSTEM, HOME, Protection, Malicious Website Protection, Stopping, Protection, 02.11.2014. 21:26:15, SYSTEM, HOME, Protection, Malicious Website Protection, Stopped, Protection, 02.11.2014. 21:26:20, SYSTEM, HOME, Protection, Refresh, Success, Protection, 02.11.2014. 21:26:20, SYSTEM, HOME, Protection, Malicious Website Protection, Starting, Protection, 02.11.2014. 21:26:20, SYSTEM, HOME, Protection, Malicious Website Protection, Started, Detection, 02.11.2014. 21:29:06, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 50336, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:29:06, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 50336, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 50338, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 50339, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 50340, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 50341, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 50338, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 50343, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 50344, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 50345, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:42:42, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 52562, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:42:42, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 52564, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:42:42, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 52565, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Detection, 02.11.2014. 21:42:42, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 52566, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe, Scan, 02.11.2014. 21:55:00, SYSTEM, HOME, Manual, Start:02.11.2014. 21:26:15, Duration:28 min 44 sec, Threat Scan, Cancelled, 0 Malware Detections, 0 Non-Malware Detections, (end)
- 10 replies
-
- svchost.exe
- Malicious
-
(and 2 more)
Tagged with:
-
Did all the scans and stuff. Also attached extra protection log of MBAM. MBAM.txt Protectionlog.txt TDSSKiller.txt
- 10 replies
-
- svchost.exe
- Malicious
-
(and 2 more)
Tagged with:
-
Hello yesterday those popups began to appear out of nowhere. MB keeps blocking inbound/outbound connections of svchost.exe. Already checked what information you guys need. Disabled all p2p things and i havent pirated any software so that should be okay. Will post Malwarebytes and TDSSKiller logs asap.
- 10 replies
-
- svchost.exe
- Malicious
-
(and 2 more)
Tagged with: