Trojan.Backdoor Activity 797

While in Chrome, I'm constantly receiving popups saying "We blocked an attack from System Infected: Trojan.Backdoor Activity 797". The details state it is a HIGH severity, and the Activity stats that "An intrusion attempt by Ahazko.com has blocked". This occurs every few minutes. The question I have is has anyone seen this before, and if so, is there anything I can do to stop this? Note that I know how to stop receiving the popups, but this just masks the issue? Appreciate any information you can provide on this! 

Note that I'm running Windows 10 with the latest version of Norton 360, with the latest version of LiveUpdate installed

https://www.virustotal.com/gui/file/2d99d3170530577cafc7392d708d8d

related:
https://community.norton.com/en/forums/module-cuserssquashierdll-failed-load




Malwarebytes offers free one-on-one malware removal assistance.
Malwarebytes staff & experts help all.  Malwarebytes subscription is not required. 
Malwarebytes Malware Removal Help will gather & analyze logs and run custom scripts & tools.  

Note: were my machine
I'd ask Malwarebytes Malware Removal Help Forums to check my machine.  

bjm_:

John Ben:
File Attachment: 
Trojan.Backdoor Activity 797.zip


https://www.virustotal.com/gui/ip-address/194.67.193.206/relations

10/73 security vendors and 1 sandbox flagged this file as malicious
Squashier.dll

https://www.virustotal.com/gui/file/2d....65301047b0e/relations

 

https://www.virustotal.com/gui/file/2d99d3170530577cafc7392d708d8d8c66c 

John Ben:

Note that I already ran Malwarebytes and it did not find anything.

 

John Ben:

Category: Intrusion Prevention
Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description
06/11/24 04:16:09 PM,High,An intrusion attempt by ahazko.com was blocked.,Blocked,No Action Required,System Infected: Trojan.Backdoor Activity 797,No Action Required,No Action Required,"ahazko.com (194.67.193.206, 59619)",http://ahazko.com/blogs/skinny/bleat/index.php,"MY-HP-PAVILION (192.168.1.252, 60127)",ahazko.com (194.67.193.206),"TCP, Port 59619"
Network traffic from <b>http://ahazko.com/blogs/skinny/bleat/index.php</b> matches the signature of a known attack.  The attack was resulted from \DEVICE\HARDDISKVOLUME4\WINDOWS\SYSWOW64\REGSVR32.EXE.  To stop being notified for this type of traffic, in the <b>Actions</b> panel, click <b>Stop Notifying Me</b>. 

Website blocked due to trojan

Website Blocked: ahazko.com
v2.6.27 | Trojan: 2.0.202406271105
Malwarebytes Browser Guard blocked this page because it may contain malicious activity.


ahazko.com
URL Analysed: http://ahazko.com/blogs/skinny/bleat/index.php
NORTON RATING  Warning
CURRENT CATEGORY  Malicious Sources/Malnets

https://safeweb.norton.com/report?url=http://ahazko.com/blogs/skinny/bleat/index.php


15/95 security vendors flagged this URL as malicious
http://ahazko.com/blogs/skinny/bleat/index.php
​​​​​​​ahazko.com

png_19464.png

https://www.virustotal.com/gui/url/e69e2b7c9ac4fd4 


ahazko.com/blogs/skinny/bleat/index.php
Scan failed
Host not found
Site is not Blacklisted
Scan Failed
http://ahazko.com/blogs/skinny/bleat/index.php (More Details)
Unable to scan your site. Host not found

https://sitecheck.sucuri.net/results/ahazko.com/blogs/skinny/bleat/index.php


We can't resolve the domain ahazko.com
194.67.193.206 was not found in our database
ISP	Dzardanov Artur Kazbekovich
Usage Type	Data Center/Web Hosting/Transit
Domain Name	ihor-hosting.ru
Country	 Russian Federation
City	Digora, Severnaya Osetiya, Respublika

https://www.abuseipdb.com/check/194.67.193.206

Hello @John Ben
Did you recently update/install any program / browser extension?
Did you recently allow browser push notification? 
Do you run Chrome sync?

Did you ask for help over on Malwarebytes Forums? 

Please tell us what Norton is telling you regarding this event.
For information regarding this event > from Norton pop-up > View Details > Copy to Clipboard &or from Norton history > More Options > Copy to Clipboard > paste here.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

John Ben:
File Attachment: 
Squashier Issue 2024-06-24.zip


 AMD64 Family 23 Model 1 Stepping 1 AuthenticAMD is a 16 thread processor configuration. 

https://openbenchmarking.org/s/AMD64%20Family%2023%20Model%201%20Stepping%201%20AuthenticAMD

 

Ok, a recent Norton update looks to have fixed the issue I was having by removing the "Squashier.dll" file from my system (see attachment). Note however that I am now receiving many popups saying that the Squashier.dll file "failed to load" (see attachment). Yes, I'm happy to have this trojan virus removed and Norton popups stopped, but now I have this other annoying popup. Does anyone know how I can get this "failed to load" popup to stop?

Thanks in advance for any ones help on this

@John Ben
Um, did you ask for help over on Malwarebytes Forums? 

Thanks

Did you recently update/install any program / browser extension?
Did you recently allow browser push notification? 
Do you run Chrome sync?

Um, did you ask for help over on Malwarebytes Forums? 


user 3rdRock was helped over on Malwarebytes Forums
https://forums.malwarebytes.com/topic/305412-i-think-im-infected-systemtrojan-backdoor-activity-756/


John Ben:
Appreciate it if anyone could give me some guidance on what I could to to get this thing removed

~ ask Malwarebytes Malware Removal Help Forums to check your machine ~

Malwarebytes Malware Removal Help Forums
Malwarebytes offers free one-on-one malware removal assistance.
Malwarebytes staff & experts help all.  Malwarebytes subscription is not required. 
https://forums.malwarebytes.com/forum/108-malware-removal-help/

Yes, I am still getting those popups. Note that I've tried Malwarebytes, Norton 360 (Full-Scan) and Power Eraser, running using Norton VPN, and I'm still getting them. I take it that Norton is blocking it, but I'd feel more comfortable if it could be totally removed (without having to reinstall the OS). Appreciate it if anyone could give me some guidance on what I could to to get this thing removed

Thanks!

~ are you still receiving popups saying "We blocked an attack from System Infected: Trojan.Backdoor Activity 797" ..?

Did you recently update/install any program / browser extension?
Did you recently allow browser push notification? 

Note: were my machine
I'd ask Malwarebytes Malware Removal Help Forums to check my machine.  

BJM_ ... I'm not exactly sure what I'm suppose to do with the information you provided. Could you give some Help on what I need to do with it? Thanks in advance for your help!

John Ben:
File Attachment: 
Trojan.Backdoor Activity 797.zip


 

https://www.virustotal.com/gui/ip-address/194.67.193.206/relations

10/73 security vendors and 1 sandbox flagged this file as malicious
Squashier.dll

png_19281_1.png

https://www.virustotal.com/gui/file/2d....65301047b0e/relations

John Ben: 
While in Chrome, I'm constantly receiving popups saying "We blocked an attack from System Infected: Trojan.Backdoor Activity 797".

Browser-related remediation (especially concerning preference/configuration files) can be particularly troublesome given the safeguards built into the browsers, along with syncing mechanisms and other complications associated with Internet browsers. The issue you're experiencing is likely caused by the syncing mechanism associated with your Google account. 

https://forums.malwarebytes.com/topic/258886-chrome-secure-preferences-detection-always-returns/ 22-Apr-2020

https://forums.malwarebytes.com/topic/258938-resetting-google-chrome-to-clear-unexpected-issues/ 23-Apr-2020

`````````````````````````````````````````````

Browser push notifications: a feature asking to be abused
https://www.malwarebytes.com/blog/news/2019/01/browser-push-notifications-feature-asking-abused

Adware and PUPs families add push notifications as an attack vector
https://www.malwarebytes.com/blog/news/2019/06/adware-and-pups-families-add-push-notifications-as-an-attack-vector

`````````````````````````````````````````````````

John Ben: 
Note that I already ran Malwarebytes and it did not find anything.

Malwarebytes offers free one-on-one malware removal assistance.
Malwarebytes staff & experts help all.  Malwarebytes subscription is not required. 
Malwarebytes Malware Removal Help will gather & analyze logs and run custom scripts & tools.  

Note: were my machine
I'd ask Malwarebytes Malware Removal Help Forums to check my machine.  

user 3rdRock helped over on Malwarebytes Forums
https://forums.malwarebytes.com/topic/305412-i-think-im-infected-systemtrojan-backdoor-activity-756/

~ ask Malwarebytes Malware Removal Help Forums to check your machine ~

Hello! Note that I already ran Malwarebytes and it did not find anything. I will checkout the other guides and forums to see if they might be able to help. Attached you will find a zip file containing snipits of the Norton Threat Block Alert, along with a copy of the Advanced Details for the alert. Let me know if you require any further information on this. 

Thanks!

p.s. Just in case, below is a clipboard copy of the details:

Category: Intrusion Prevention
Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description
06/11/24 04:16:09 PM,High,An intrusion attempt by ahazko.com was blocked.,Blocked,No Action Required,System Infected: Trojan.Backdoor Activity 797,No Action Required,No Action Required,"ahazko.com (194.67.193.206, 59619)",http://ahazko.com/blogs/skinny/bleat/index.php,"MY-HP-PAVILION (192.168.1.252, 60127)",ahazko.com (194.67.193.206),"TCP, Port 59619"
Network traffic from <b>http://ahazko.com/blogs/skinny/bleat/index.php</b> matches the signature of a known attack.  The attack was resulted from \DEVICE\HARDDISKVOLUME4\WINDOWS\SYSWOW64\REGSVR32.EXE.  To stop being notified for this type of traffic, in the <b>Actions</b> panel, click <b>Stop Notifying Me</b>. 

Hello @John Ben

Please tell us what Norton is telling you regarding this event.
For information regarding this event > from Norton pop-up > View Details > Copy to Clipboard &or from Norton history > More Options > Copy to Clipboard > paste here.

```````````````````````````````````````````````````````
Please share popup snip regarding this event. 
How to post an image in the forums
https://community.norton.com/en/forums/how-post-image-forums-0

```````````````````````````````````````````````````````

System Infected: Trojan.Backdoor Activity 797
https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=34569

==================================================

Were my machine.
I'd ask Malwarebytes Malware Removal Help Forums to check my machine.  

Malwarebytes offers free second opinion on-demand scanner. 
Malwarebytes offers free self-help guides. 
Malwarebytes offers free one-on-one malware removal assistance.
Malwarebytes staff & experts help all.  Malwarebytes subscription is not required. 

Malware Removal Help Forums dedicated to cleaning infected devices. Get personalized help removing adware, malware, spyware, ransomware, trojans, viruses and more from tech experts. Follow the instructions in the pinned topics first. All assistance here is used at your own risk and we take no responsibility should there be damage to the system in question.

================================================

What is Norton Virus Protection Promise?
https://support.norton.com/sp/en/us/home/current/solutions/v62458994 03-Jun-2024

Virus Protection Promise is a virus removal service provided by Norton experts.

https://us.norton.com/virus-protection-promise