I keep getting an intrusion attempt.
IPS Alert Name - System Infected Trojan Downloader Activity 2
The attack was resulted from \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\SVCHOST.EXE
Do you know what could be causing this? or how to stop it?
I keep getting an intrusion attempt.
IPS Alert Name - System Infected Trojan Downloader Activity 2
The attack was resulted from \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\SVCHOST.EXE
Do you know what could be causing this? or how to stop it?
Hi, bdsw30,
Unfortunately, it appears that your system has been infected by a trojan, a type of malware that opens a door for some form of intrusion. What you're seeing is Norton blocking that infection from opening that door.
Given that the infected file is part of your Operating System--and there are likely to be others that are not being reported, too, given that the nasty was able to worm its way into your system undetected in the first place--it is best to refer you to the recommended forums, where a real malware expert can work with you one-on-one in real time to dig these things out. Some of our best folks here have checked them out to make sure that they are capable, and competent to deal with rootkits and other nasties. Most of them handle tricky Windows problems as well.
Just sign up for one of their free accounts--where required--and go to the forums; don't click on any of the ads! Note that some of these forums (like bleepingcomputer) require that once they begin working with you, you not consult any other sources on your infection until it's resolved--and will close your case if you do. This is important, to avoid confusion (and really bad outcomes) resulting from trying to follow several people's advice at once! LOL
Good luck, and please let us know how it turns out!
Thank you!
I went to one of the links that you provided, and went to the topic:
http://support.emsisoft.com/topic/5868-trojan-downloader/
and downloaded the "TDSSKiller", since I thought it was related to some corrupt .exe file, or something attached to a .exe file. It did locate a Malware file, and removed it. Rebotted my computer, and for a couple hours now I haven't had any intrusion attempts (where I used to get an intrusion attempt like every 10 minutes). So I think it worked and I think that was it.
cool thanks!
b-rad
Glad to hear it went well! Keep a close eye out for the return of symptoms, and let us know if anything crops up.
I will thanks. Its been almost 10 hours now, and nothing. So I think it worked. But I'll let you know if anything comes out of the grave.
thanks!