Positron Posted December 12, 2020 ID:1426891 Share Posted December 12, 2020 Earlier today I had many outbound blocks of "cds.a2w5j2z3.hwcdn.net" by premium Malware Antimalware as a potential threat. I checked the internet and "hwcdn.net" seems listed as a problem in general. Now I am not getting any outbound popups blocked, even though my premium lists nothing quarantined. Should I be worried? Thanks. Pos Link to post Share on other sites More sharing options...
kevinf80 Posted December 12, 2020 ID:1426892 Share Posted December 12, 2020 Hiya Positron and welcome to Malwarebytes, Can you post the last three block logs from Malwarebytes History... Open Malwarebytes.... Click on the Detection History tab > from main interface. Then click on "History" that will open to a historical list Double click on the RTP Detection log which shows the Date and time of the scan just performed. Click Export > From export you have two options:Copy to Clipboard - if seleted right click to your reply and select "Paste" log will be pasted to your replyText file (*.txt) - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply Please use "Text file (*.txt), then name the file and save to a place of choice, recommend "Desktop" then attach to reply Thank you, Kevin... Link to post Share on other sites More sharing options...
Positron Posted December 12, 2020 Author ID:1426894 Share Posted December 12, 2020 Hi Kevin and thanks for your reply. I counted 36 outbound attempts in about 1 1/2 hours, from ~10:40 am to ~12:22 am this morning, and then stopped. Attached are the last 3. A hwc.txt B hwc.txt C hwc.txt Link to post Share on other sites More sharing options...
kevinf80 Posted December 13, 2020 ID:1426899 Share Posted December 13, 2020 Hiya Positron, The IP`s listed in the blocks are to the same site, I`ve run them through several checkers and find nothing wrong. Lets see if the blocks return in the next 24 hours... Also run the following and post the produced logs... Download Farbar Recovery Scan Tool and save it to your desktop. Alternative download option: http://www.techspot.com/downloads/6731-farbar-recovery-scan-tool.htmlNote: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version. If your security alerts to FRST either, accept the alert or turn your security off to allow FRST to run. It is not malicious or infected in any way... Be aware FRST must be run from an account with Administrator status... Double-click to run it. When the tool opens click Yes to disclaimer.(Windows 8/10 users will be prompted about Windows SmartScreen protection - click More information and Run.) Make sure Addition.txt is checkmarked under "Optional scans" Press Scan button to run the tool.... It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply. The tool will also make a log named (Addition.txt) Please attach that log to your reply. Let me see those logs in your reply... Thank you, Kevin.... Link to post Share on other sites More sharing options...
Positron Posted December 13, 2020 Author ID:1426906 Share Posted December 13, 2020 I looked up the ip address and found all bad. Here are the Addition.txt and FRST.txt from the scan. I hope I got it right. I have to leave now, 6:40, but will be back 9:45pm or so. Addition.txt FRST.txt Link to post Share on other sites More sharing options...
kevinf80 Posted December 13, 2020 ID:1426910 Share Posted December 13, 2020 (edited) My local time 1am, off to bed shortly... https://cleantalk.org/blacklists/cds.a2w5j2z3.hwcdn.net https://cleantalk.org/blacklists/69.16.175.10 https://cleantalk.org/blacklists/69.16.175.42 https://www.virustotal.com/gui/ip-address/69.16.175.10/details https://www.virustotal.com/gui/ip-address/69.16.175.42/detection I see no concerns in your FRST logs, Edited December 13, 2020 by kevinf80 typing error Link to post Share on other sites More sharing options...
Positron Posted December 13, 2020 Author ID:1426931 Share Posted December 13, 2020 I understand Kevin, pretty late for you, and getting about that time for me as well. I am having outbound block multiple times again this evening. I cannot find a website or email to send to high winds network group. I saw this when my Malware blocked an outbound; says c:\program files\Mozilla firefox\firefox.exe Does that help or mean anything? Thanks. pos Link to post Share on other sites More sharing options...
Solution kevinf80 Posted December 13, 2020 Solution ID:1426943 Share Posted December 13, 2020 Hiya Pos, Use the instructions in the following link to reset Firefox, see if that stops the outbound calls... https://malwaretips.com/blogs/reset-firefox-settings/ I`m not saying the outbound calls to highwinds network group are not suspicious, I just cannot find any definite proof to confirm it... Lets see if the reset helps.. Thank you, Kevin Link to post Share on other sites More sharing options...
Positron Posted December 13, 2020 Author ID:1426986 Share Posted December 13, 2020 I am a little late getting on today. I just performed a "reset" of Firefox and will see how things go today. Will report again later. Thanks again Kevin. Hope you have a safe and great day today. pos Link to post Share on other sites More sharing options...
kevinf80 Posted December 13, 2020 ID:1426990 Share Posted December 13, 2020 Cheers pos, its 8:15 pm local time for me, will be online til maybe 1 am.... Thanks, Kevin.. Link to post Share on other sites More sharing options...
kevinf80 Posted December 16, 2020 ID:1427388 Share Posted December 16, 2020 Ant progress...? Link to post Share on other sites More sharing options...
Positron Posted December 21, 2020 Author ID:1428295 Share Posted December 21, 2020 Seems to be fixed, no popups anymore. That problem is solved. Thanks Kevin. Pos Link to post Share on other sites More sharing options...
kevinf80 Posted December 21, 2020 ID:1428303 Share Posted December 21, 2020 Hiya Pos, Thanks for the update, good to hear your issues have cleared.. Continue to clean up: Right click on FRST here: C:\Users\Owner\Desktop\FRST.exe and rename uninstall.exe when complete right click on uninstall.exe and select "Run as Administrator" If you do not see the .exe appended that is because file extensions are hidden, in that case just rename FRST to uninstall That action will remove FRST and all created files and folders... Next, Read the following links to fully understand PC Security and Best Practices, you may find them useful....Answers to Common Security Questions and best PracticesDo I need a Registry Cleaner? Take care and surf safe Kevin... Link to post Share on other sites More sharing options...
kevinf80 Posted December 21, 2020 ID:1428339 Share Posted December 21, 2020 Glad we could help. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Please review the following for Tips to help protect from infection Thank you Link to post Share on other sites More sharing options...
Recommended Posts