Jump to content

Crowbait

Members
  • Posts

    7
  • Joined

  • Last visited

Everything posted by Crowbait

  1. our network was setup way before my time on 123.123.123.xxx ipconfig.txt
  2. this is the infect computer sending the riskware on our network MB scans do not detect anything FRST.txt Addition.txt mb-check-results.zip
  3. info from one of several getting riskware alerts Addition.txtcoFRST.txtmputers mb-check-results.zip i will scan infected machine and send info next upload
  4. this is the log from one of the many computers receiving the event -Log Details- Protection Event Date: 4/17/18 Protection Event Time: 2:06 PM Log File: 0028d4c6-426a-11e8-804a-b86b23c9d7c6.json Administrator: Yes -Software Information- Version: 3.4.5.2467 Components Version: 1.0.342 Update Package Version: 1.0.4768 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: System -Blocked Website Details- Malicious Website: 1 , , Blocked, [-1], [-1],0.0.0 -Website Data- Category: RiskWare Domain: IP Address: 123.123.123.123 Port: [161] Type: Inbound File: C:\Windows\System32\svchost.exe (end)
  5. Where is the log you wish. also, all the machines scan clean. the sender and receiving that is.
  6. are you refering to the machines receiving the message or the one sending? David
  7. I am getting a repeating message "website blocked due to riskware" on several computers. i get this with and without any browsers running. It is from a local computer on our network xxx.xxx.xxx.123 port 5355 or port 1900 or port 3702 or port 161 or port 2869 Type is "inbound" file is"C:\windows\system32\svchost.exe I have ran scans on all computers in question. without any positive results. any suggestions? David
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.