For the past two days I've been getting numerous alerts of blocked intrusion events from gurusafe.net. This has never happened on such a regular basis. Details:
Attacking computer: gurusafe.net (185.17/184.6, 80)
Attacker url: gurusafe.net/55/restore.dat
Traffic description: TCP, www-http
Network traffic from gurusafe.ne/55/restore.dat matches the signature of a known attack. the attack was resulted from \device\harddiskvolume2\windows\system32\svchost.exe.
Should I just stop the notification or is this something I should be concerned about?