|
|||||||
|
If it's only happening in Firefox, that sounds suspicious - it's possible for malware to install addons that are hidden from Firefox's list.
![]() |
| 10-05-2012, 11:20 AM | |
|
|
|
Today was different - a more serious threat that Norton Anti Virus caught and squashed. My NAV history log is not easy to post (screen capture difficulties) but my clipboard version is readable with some patience. This came from the slickdeals window in FF..... Category: Intrusion Prevention Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description 2012-10-05 10:21:07,High,An intrusion attempt by localhost was blocked.,Blocked,No Action Required,Web Attack: FakeAV Download 2,No Action Required,No Action Required,"localhost (xxx.0.0.1, 8254)" ,dqrdrezet.ftp1.biz/index.php?c=RaENOjEayDF925cOxP3ACC60zajgAjCTlcK0liAaKtvKheVQzm+YhzfWz1MPnw1S6zBdyf5LKZPwyvIgCwX04PyFyoM=,"localhost (xxx.0.0.1, xxxx)",xxx.0.0.1 (xxx.0.0.1),"TCP, Port 8254" Network traffic from <b>dqrdrezet.ftp1.biz/index.php?c=RaENOjEayDF925cOxP3ACC60zajgAjCTlcK0liAaKtvKheVQzm+YhzfWz1MPnw1S6zBdyf5LKZPwyvIgCwX04PyFyoM=</b> matches the signature of a known attack. The attack was resulted from \DEVICE\HARDDISKVOLUME1\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE. To stop being notified for this type of traffic, in the <b>Actions</b> panel, click <b>Stop Notifying Me</b>. x'd out my IP addrs -- HTH |
|
|
Category: Intrusion Prevention Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description 2012-10-06 22:47:41,High,An intrusion attempt by localhost was blocked.,Blocked,No Action Required,Web Attack: FakeAV Download 2,No Action Required,No Action Required,"localhost (xxx.0.0.1, 8254)",pbfmjkcza.ftp1.biz/index.php?c=RaENOjEayDF925cOxP3ACC60zajgAjCTlcK0liAaKtvKheVQzm+YhzfWz1MPnw1S6zBdyf4YKpSizaJzWwSg5fuFyoM=,"localhost (xxx.0.0.1, 2300)",xxx.0.0.1 (xxx.0.0.1),"TCP, Port 8254" Network traffic from <b>pbfmjkcza.ftp1.biz/index.php?c=RaENOjEayDF925cOxP3ACC60zajgAjCTlcK0liAaKtvKheVQzm+YhzfWz1MPnw1S6zBdyf4YKpSizaJzWwSg5fuFyoM=</b> matches the signature of a known attack. The attack was resulted from \DEVICE\HARDDISKVOLUME1\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE. To stop being notified for this type of traffic, in the <b>Actions</b> panel, click <b>Stop Notifying Me</b>. Although I appreciate the smiley, I worked I/T support for >30 years and yeah, some issues were at the user point (minimal) and some of the information provided was so minimal it was hopeless. But for me to tell YOU what YOUR problems are costs me a post with no REPS ever - that is why I rarely venture an incident .. in the past, not much concern was apparent and I feel well protected so ... Last edited by alwenz; 10-07-2012 at 10:50 AM.. |
|
|
Download RevoUninstaller, and uninstall FF using advanced mode, and make sure to check/delete all registry entries and folders. All, when going through the first step of the uninstall process, make sure not to save any browser customization, history, etc. If you do have a lot of bookmarks etc that you need to keep, open Chrome or IE and import them...then you can import them back into FF once you reinstall it. I believe I've found the solution to obesity in America. Hemispherectomy....no one uses it anyway.
|
||
|
||
|
This has been happening to me the past few weeks as well.
I have SD bookmarked,click it and I go to the home page but am almost immediately redirected. It doesn't happen every time,but it does only happen when I come here. I've run antivirus,etc. Everything comes out okay. These are the ones from tonight. http://favozek.info/in.php?q=G/CD...p9UkfZww== http://testables.net/d/juicyru.com http://testables.net/go/2296_1822...2C8 This also popped up from Norton. Category: Intrusion Prevention 2012-10-28 2:05:30,High,An intrusion attempt by blog.onlineshopschemes.com was blocked.,Blocked,No Action Required,Web Attack: Facebook Fake Survey 6 I use Firefox and haven't tested to see if it happens with another browser. Last edited by TXhippiechick; 10-27-2012 at 11:32 PM.. |
|
I appreciate the reports guys, we believe you but we're having a really hard time tracking down what's causing this.
This is not allowed, not intentional, and we're gonna get rid of it as soon as we can. The more data you can give us the better. The personal views and opinions expressed in this post are exactly that and do not necessarily represent an official opinion or stance of Slickdeals and this is a disclaimer in case I say something stupid. In fact, anything I say should not be taken seriously.
Got a suggestion or having problems? Let us know how we're doing in the Site Issues and Suggestions forum. Links: The Official Slickdeals Blog - My Flickr - My LinkedIn [linkedin.com] - Follow me on Twitter: SlickdealsCEO [twitter.com] |
| Thread Tools | Search this Thread |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| sc.slickdealz.net ? | PiratePenguin | Site Questions, Issues or Suggestions | 2 | 11-08-2011 08:34 AM |
| Can't go to 'full site' when comming in from Twitter | johnrb85 | Site Questions, Issues or Suggestions | 2 | 03-08-2011 07:29 AM |
| keep getting me to this site www.clickserver.cc.dt ...when i click on a link. | therock_80 | Site Questions, Issues or Suggestions | 17 | 09-29-2009 10:33 PM |
| Can't get to mobile site | Gregory | Site Questions, Issues or Suggestions | 14 | 05-07-2008 08:27 PM |
| Anyone else getting this? | Gray. | Site Questions, Issues or Suggestions | 18 | 08-21-2007 11:17 AM |