Jump to content

Romanian Connection not Being Detected


Recommended Posts

Every so often I will receive a popup balloon telling me that Malwarebytes has successfully blocked a connection to a potentially malicious website, listing an IP as 46.108.226.93, which I believe is in Romania. It lists it as either being incoming or outgoing, as it changes every other time. It lists the process it is coming from as pmb.exe, but when I end that process it lists the process as coming from svchost.exe with the same IP address. I have run several scans with both Malwarebytes and the default Windows Defender, and it has detected nothing. It is to be noted that yesterday I was infected with FBI randsomeware, but somehow managed to stop it from locking out my computer without removing the virus. Again, several scans have detected nothing at all.

Link to post
Share on other sites

Hello Sandstorms and welcome to MalwareBytes forum.

Let me suggest, if you're an MBAM PRO customer, you contact the consumer help desk here.

If you are in an organization or a corporate customer, contact Corporate Support for assistance.

If you wish to continue on the forum, then please start with the following.

Disregarding title & name of the infection in the article, but doing the steps outlined..... do this

Please see this article by Grinler

http://www.bleepingcomputer.com/virus-removal/remove-police-central-e-crime-unit-reveton-ransomware

Go down to the section titled "Automated Removal Instructions for Police Central e-crime Unit Ransomware using the Emsisoft Emergency Kit:"

Do only bullet points 1 thru 12

Then report back with the results.

If you have questions please stop & ask.

Please do not do any other fixes or changes, without checking with me first.

NEXT:

Download DDS and save it to your desktop from http://download.bleepingcomputer.com/sUBs/dds.com here

or http://download.bleepingcomputer.com/sUBs/dds.scr or

http://www.infospyware.net/sUBs/dds

Disable any script blocker if your antivirus/antimalware has it.

For directions on how, see How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Do NOT turn off the firewall

Double click dds to run the tool.

DDS will run in a command prompt window and will take 3 to 4 minutes or so.

Follow and answer the prompts as appropriate.

  • When done, DDS will open two (2) logs:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.

Please Copy & Paste contents of the following logs in your next reply:
DDS.txt
Attach.txt
Use NOTEPAD to Copy all contents of each log, then Paste directly into main-body of reply box.
Do -not- use the attach option unless a single log is way-too-large & won't fit.
Download Security Check by screen317 from >>here<<.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.