Hi everyone
I'm new here so forgive me if I haven't gone through the proper intro channels (if any). I'm a little close to panicking about my PC security and I really need some help.
6 times in February, Norton blocked an intrusion attack from the Fake AV crap trying to install. This is what's listed:
High,An intrusion attempt by xxx.xx.68.66 was blocked.,Blocked,No Action Required,HTTP Fake Antivirus Install Request 4,"xxx.xx.68.66, 80","my computer name (192.xxx.x.xx, xxxxx)",xx.xx.68.66,"TCP, www-http",,xxx.xx.68.66/hitin.php?land=20&affid=93101. The attacking ip varied by one or two numbers, but all came from virtually the same place.
Then, I got notice from NIS that another intrusion attack was blocked...this time from my computer! I'm worried. This is what's listed:
2/25/2010 12:38 AM, High, An intrusion attempt by "MY COMPUTER NAME" was blocked., Blocked,No Action Required,HTTP Fake Antivirus Webpage Request ,"MY COMPUTER NAME (my computer static IP and port listed here)","xx.xx.xxx.x32, 80","my ip" (my ip),"TCP, Port xxxx",,webcantivirus.com/psx1/?vih=pnT45TDuNzUuOTMuOTkmcGlkPTQwczImdGltZT0xMjY1MckOPAhN. It also says that "the the attack was resulted from \device\harddiskvolume2\program files (x86)\internet explorer\iexplore.exe"
OK, if I'm reading this correctly, it seems that my computer tried to attack another computer. How can this be?? Did something slip by Norton? Could one of my programs be infected even though I scan everything before and after I dl & install? And I'm not sure what hard disk volume 2 is unless something has gotten into my recovery partition. Shortly after I got this computer I realized that sys restore was turned on for my recovery drive so I turned it off b/c with my old computer, I never had it on.
I've done full scans with NIS & MWB in full Windows mode and in safe mode. Both said I was clean. Even fired up the ol' Windows Defender just to make it feel useful, and of course it said I was clean. I'm stumped and worried and could really use some help.
Win7 64 bit
NIS 2010 17.5 0.127
Thanks
Sasha