Intrusion attempt by my own computer

In the past few days I had norton block what it classified as "Intrusion attempt" by my own computer. In view history I found the following details:

 

Risk name: HTTP Malicious Toolkit Variant Activity

Risk level: High

Attacking computer: My own.....

Destination adress: lvhook.biz ( 220.196.59.23,80)

Trafic description: TCP, 50129

 

I dont know if that's related with the page I was visiting, but the last time I was "attacked" I was just googling a review for Norton Gaming Edition. I found one in a site called pclaptopreview.com and as soon as i clicked on it I got the popup.

I already run a full scan ( Norton internet security 2009 btw ) in safe mode and in normal and found nothing in my pc. Also used ad-aware 2008 to run a full scans in both safe and normal mode and again I found nothing

 

Can someone advice me in what to do, I never been "attack" like this before and this weekend I got norton block this 3 times already so Im kinda worried.

Thanks in advance :)

 

In the past few days I had norton block what it classified as "Intrusion attempt" by my own computer. In view history I found the following details:

 

Risk name: HTTP Malicious Toolkit Variant Activity

Risk level: High

Attacking computer: My own.....

Destination adress: lvhook.biz ( 220.196.59.23,80)

Trafic description: TCP, 50129

 

I dont know if that's related with the page I was visiting, but the last time I was "attacked" I was just googling a review for Norton Gaming Edition. I found one in a site called pclaptopreview.com and as soon as i clicked on it I got the popup.

I already run a full scan ( Norton internet security 2009 btw ) in safe mode and in normal and found nothing in my pc. Also used ad-aware 2008 to run a full scans in both safe and normal mode and again I found nothing

 

Can someone advice me in what to do, I never been "attack" like this before and this weekend I got norton block this 3 times already so Im kinda worried.

Thanks in advance :)

 

First off, thank you for answering :)

Just one quick question, is that drive-by download a result from the site I was visiting at the time ? I got that the warning several times throughout the weekened in 3 diferent sites.

Ohh and one more thing I forgot to mention, whemever I got that norton warning a pop up appeared in IE saying my computer might be infected, asking me if I wanna run a scan, afriad it could be a scam from one of intrusive anti-spyaware sites i just closed the window and ran my own scans ( NIS 2009 and Ad-aware 2008 )

 

Once again, thank you for the reply, and sorry for all the questions Im just a end customer without deep knowledge in how most of this stuff works

Hopefully I wont get "attacked" again

 

Drive-By Download:

A drive-by download is computer code that takes advantage of a software bug in a Web browser to make it do something that the attacker wants—such as run malicious code, crash the browser, or read data from the computer. Software bugs that are open to browser attacks are also known as vulnerabilities.

 

I would suggest doing a Full System Scan in Safe Mode with Norton and the Ad-Aware Product; make sure you Update first before going in to Safe Mode and also make sure, once in Safe Mode, that your computer in Dis-connected from the Internet before Running any Anti-Virus Scans.  Let us know the Results.

 

And you're Welcome!  :)

 

Hi Cupp,

 

Here is a good Symantec article describing "Drive-By Downloads". You will note that these types of malicious downloads do not require any user intervention. Merely visiting a compromised site can invoke the download.

 

You were wise to close out of the pop-ups as they were obviously scams.

 

In the future, I would suggest using  the "Alt" + "F4" keys whenever you see a suspicious page or pop-up.

 

There have been instances where clicking on the "X" to close actually starts the download!  Using Alt + F4 is safer in these instances.

 

Best Wishes.

 

 

Seeing your advices on other posts I already did that. Neither NIS 2009 or As-aware 2008 found anything, later the same night i got attacked as detailed in the my first post and ran them again both in safe and normal mode, after updating them, and disconnected. Didnt found anything once again.


Cupp wrote:

 

 

Seeing your advices on other posts I already did that. Neither NIS 2009 or As-aware 2008 found anything, later the same night i got attacked as detailed in the my first post and ran them again both in safe and normal mode, after updating them, and disconnected. Didnt found anything once again.


 

You should be fine then.  Although, I would advise Scanning again in Safe Mode later this week to make sure.  Let us know the Results when you have Completed the Full Scans.