| | |
Help with hijack this log..I think I still have a virus
Thread Solved |
•
•
Join Date: Apr 2009
Posts: 16
Reputation:
Solved Threads: 0
I checked spywareblaster again and everything is protected. I have seen these changes before with the same site listed (just before I realized I had a virus...I thought then that the firewall was blocking these sites), I allowed the changes (the trend firewall thing popped up with suspicious changes to IE), and then I started having the "free spyware scan" thing on my internet explorer pages. I have tried to do an attachment because I took a screen shot of my running processes, but I can't seem to get the attachment to work (the button does not want to give me options...again things are running slow, so that could be part of the problem). I am running a MBA-M full scan right now with the iPod plugged in to make sure there is nothing there. The computer is running VERY slow, so I am going to let it run and call it a night. I was able to get the logs from trend from my firewall and virus or spyware scan, but again, I couldn't get the attachment to work. I looked in my regedit files and even though I have denied the changes the sites are listed under My Computer\HKEY_Local_Machine\Software\Microsoft\windows\currentversion\internet settings\zonemap\domains\007guard.com
•
•
Join Date: Apr 2009
Posts: 16
Reputation:
Solved Threads: 0
The MBA-M log was clean. Here is a copy:
Malwarebytes' Anti-Malware 1.36
Database version: 1992
Windows 5.1.2600 Service Pack 3
4/17/2009 5:02:09 AM
mbam-log-2009-04-17 (05-02-09).txt
Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 145065
Time elapsed: 3 hour(s), 20 minute(s), 13 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Here is the HJT I just ran:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:20:23 AM, on 4/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~4\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~4\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~4\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~4\tmproxy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\TRENDM~1\INTERN~4\PcScnSrv.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Jill\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {67B50696-04BA-48ea-A697-28AA0EAA9C26} - C:\WINDOWS\System32\shdocvw.dll (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1183932664531
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~4\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~4\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~4\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~4\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~4\tmproxy.exe
--
End of file - 6794 bytes
It looks clean to me...The first two items on the Trend IE changes are the following (I am unable to cut and past, so I am just retyping what it says:
We have detected the following suspicious changes in your system. Mark the checkboxes beside items you want cleaned or added to your blocked or safe list, then click the appropriate button.
Internet Explorer settings (6056 changes detected)
(Arrow down)http://red.clientapps.yahoo.com/cust...tp://www/yahoo.... (I can't see the rest, the window won't let me make it into a full screen and I can't drag the window open any more)
When I hilite the item, the screen below says:
System Change, Risk Level: Low
Description: The search feature in Internet Explorer has changed. The correct page may no longer open when you click the search button or type the address of a web site in the address bar.
Details: Value: (Lists the web address above with .com after yahoo.)
Since my logs appear to be coming up clean is it possible that Trend is picking this up from one of the old log files? Do I need to delete everything from all my log files (virus logs, etc) and quarantined files and restart?
Malwarebytes' Anti-Malware 1.36
Database version: 1992
Windows 5.1.2600 Service Pack 3
4/17/2009 5:02:09 AM
mbam-log-2009-04-17 (05-02-09).txt
Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 145065
Time elapsed: 3 hour(s), 20 minute(s), 13 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Here is the HJT I just ran:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:20:23 AM, on 4/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~4\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~4\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~4\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~4\tmproxy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\TRENDM~1\INTERN~4\PcScnSrv.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Jill\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {67B50696-04BA-48ea-A697-28AA0EAA9C26} - C:\WINDOWS\System32\shdocvw.dll (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1183932664531
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~4\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~4\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~4\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~4\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~4\tmproxy.exe
--
End of file - 6794 bytes
It looks clean to me...The first two items on the Trend IE changes are the following (I am unable to cut and past, so I am just retyping what it says:
We have detected the following suspicious changes in your system. Mark the checkboxes beside items you want cleaned or added to your blocked or safe list, then click the appropriate button.
Internet Explorer settings (6056 changes detected)
(Arrow down)http://red.clientapps.yahoo.com/cust...tp://www/yahoo.... (I can't see the rest, the window won't let me make it into a full screen and I can't drag the window open any more)
When I hilite the item, the screen below says:
System Change, Risk Level: Low
Description: The search feature in Internet Explorer has changed. The correct page may no longer open when you click the search button or type the address of a web site in the address bar.
Details: Value: (Lists the web address above with .com after yahoo.)
Since my logs appear to be coming up clean is it possible that Trend is picking this up from one of the old log files? Do I need to delete everything from all my log files (virus logs, etc) and quarantined files and restart?
•
•
•
•
Since my logs appear to be coming up clean is it possible that Trend is picking this up from one of the old log files? Do I need to delete everything from all my log files (virus logs, etc) and quarantined files and restart?
•
•
•
•
Internet Explorer settings (6056 changes detected)
(Arrow down)http://red.clientapps.yahoo.com/cust...tp://www/yahoo....
•
•
•
•
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
I really believe that there is NOTHING on the computer, at least these latest logs are clean. I believe that Trend Micro was notifying you of changes made...it will do this whether the changes are good or bad, it really doesn't know if they are good or bad, just that changes were made.
Now I was concerned because you said this earlier:
•
•
•
•
I tried to dis-allow, but I got something from Trend that said that it could not make the changes (back to the original).
I firmly believe that your system is clean, especially with the scan results. You were very wise to heed these warnings but I want to caution you, when you DO receive these warnings, investigate them thoroughly BEFORE reverting back. But don't ignore them either. If you can and if it would be easier, print them out. Do a google search for items noted to investigate whether the changes should be allowed. But I do believe now these changes noted were the removals we did here.
Last edited by jholland1964; Apr 17th, 2009 at 12:48 pm.
•
•
Join Date: Apr 2009
Posts: 16
Reputation:
Solved Threads: 0
One last question Judy. I have shut down and restarted at least once and the 6K+ changes are still in trend and I think it's the trend that is causing my system to be so slow. My trend firewall is showing 3 unknown computers connecting to my network plus one offline (I think that's the router...we switched from DSL to FIOS yesterday, so now we have wireless internet access, but even before we made the switch, I was getting these firewall popups.) Here are the logs from today and yesterday, can you tell me if there is anything suspicious, if I should block anything, or if I am once again just being paranoid? Thanks!
"Personal Firewall Logs","2009/04/18","BOTTOFFICE"
"Type","Time","Protocol","Source IP Address","Source Port","Destination IP Address","Destination Port","Application Path","Application Description","Description"
"Firewall","07:53:48","ICMP","192.168.1.3","n/a","192.168.1.1","n/a","---","---","Destination Unreachable"
"Firewall","08:16:16","ICMP","192.168.1.3","n/a","192.168.1.1","n/a","---","---","Destination Unreachable"
"Exception List Rule","08:38:45","TCP","---","n/a","192.168.1.3","139","SYSTEM","---","NetBIOS (Incoming, Fixed)"
"Firewall","08:38:45","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","08:38:45","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","08:38:46","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","08:48:22","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:23","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:25","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:26","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:28","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:29","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:31","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:32","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:34","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:11","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:12","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:14","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:17","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:17","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:19","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:20","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:22","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:23","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:15","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:16","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:18","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:19","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:21","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:22","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:24","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:25","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:27","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:55:12","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:55:13","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:55:15","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:55:16","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:55:18","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:55:19","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:25:51","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:25:52","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:25:54","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:25:55","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:25:57","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:25:58","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:26:00","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:26:01","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:26:03","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","16:30:55","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","16:30:56","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","16:30:57","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","16:30:59","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","16:31:01","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","16:31:02","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:41","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:42","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:44","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:46","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:47","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:49","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:50","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:52","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:53","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Personal Firewall Logs","2009/04/17","BOTTOFFICE"
"Type","Time","Protocol","Source IP Address","Source Port","Destination IP Address","Destination Port","Application Path","Application Description","Description"
"Exception List Rule","00:20:13","TCP","BOTTOFFICE","1037","17.149.160.45","80","C:\PROGRAM FILES\ITUNES\ITUNES.EXE","iTunes","iTunes"
"Exception List Rule","00:20:13","TCP","BOTTOFFICE","1038","17.251.200.74","80","C:\PROGRAM FILES\ITUNES\ITUNES.EXE","iTunes","iTunes"
"Exception List Rule","12:50:31","TCP","BOTTOFFICE","1037","17.149.160.45","80","C:\PROGRAM FILES\ITUNES\ITUNES.EXE","iTunes","iTunes"
"Exception List Rule","12:50:31","TCP","BOTTOFFICE","1038","17.251.200.74","80","C:\PROGRAM FILES\ITUNES\ITUNES.EXE","iTunes","iTunes"
"Firewall","19:27:37","ICMP","192.168.1.3","n/a","192.168.1.1","n/a","---","---","Destination Unreachable"
"Firewall","19:27:37","ICMP","192.168.1.3","n/a","192.168.1.1","n/a","---","---","Destination Unreachable"
"Exception List Rule","19:27:39","TCP","---","n/a","192.168.1.3","139","SYSTEM","---","NetBIOS (Incoming, Fixed)"
"Firewall","19:27:39","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","19:27:40","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","19:27:41","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","19:28:21","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:28:23","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:28:24","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:11","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:12","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:14","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:15","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:17","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:18","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:20","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:21","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:23","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:22:08","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","20:22:08","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","20:22:09","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","20:30:01","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:02","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:04","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:05","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:07","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:08","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:10","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:11","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:13","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:14","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:16","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:17","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:01","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:02","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:04","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:05","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:07","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:08","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:10","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:11","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:13","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","22:31:41","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","22:31:42","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","22:31:44","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","22:31:45","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","22:31:47","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","22:31:48","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
Trend is showing that the 192..1 is trusted (but no computer name shows up) and that unknown computer .1.130 and unknown computer .1.212 are both connected to my network. If these are indeed my components, is there any way that I can name them, so I know that they are mine or is there anything I should block access to? Thanks!
"Personal Firewall Logs","2009/04/18","BOTTOFFICE"
"Type","Time","Protocol","Source IP Address","Source Port","Destination IP Address","Destination Port","Application Path","Application Description","Description"
"Firewall","07:53:48","ICMP","192.168.1.3","n/a","192.168.1.1","n/a","---","---","Destination Unreachable"
"Firewall","08:16:16","ICMP","192.168.1.3","n/a","192.168.1.1","n/a","---","---","Destination Unreachable"
"Exception List Rule","08:38:45","TCP","---","n/a","192.168.1.3","139","SYSTEM","---","NetBIOS (Incoming, Fixed)"
"Firewall","08:38:45","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","08:38:45","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","08:38:46","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","08:48:22","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:23","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:25","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:26","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:28","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:29","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:31","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:32","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","08:48:34","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:11","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:12","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:14","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:17","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:17","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:19","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:20","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:22","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","09:19:23","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:15","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:16","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:18","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:19","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:21","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:22","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:24","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:25","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:24:27","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:55:12","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:55:13","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:55:15","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:55:16","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:55:18","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","12:55:19","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:25:51","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:25:52","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:25:54","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:25:55","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:25:57","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:25:58","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:26:00","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:26:01","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","13:26:03","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","16:30:55","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","16:30:56","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","16:30:57","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","16:30:59","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","16:31:01","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","16:31:02","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:41","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:42","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:44","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:46","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:47","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:49","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:50","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:52","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","17:01:53","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Personal Firewall Logs","2009/04/17","BOTTOFFICE"
"Type","Time","Protocol","Source IP Address","Source Port","Destination IP Address","Destination Port","Application Path","Application Description","Description"
"Exception List Rule","00:20:13","TCP","BOTTOFFICE","1037","17.149.160.45","80","C:\PROGRAM FILES\ITUNES\ITUNES.EXE","iTunes","iTunes"
"Exception List Rule","00:20:13","TCP","BOTTOFFICE","1038","17.251.200.74","80","C:\PROGRAM FILES\ITUNES\ITUNES.EXE","iTunes","iTunes"
"Exception List Rule","12:50:31","TCP","BOTTOFFICE","1037","17.149.160.45","80","C:\PROGRAM FILES\ITUNES\ITUNES.EXE","iTunes","iTunes"
"Exception List Rule","12:50:31","TCP","BOTTOFFICE","1038","17.251.200.74","80","C:\PROGRAM FILES\ITUNES\ITUNES.EXE","iTunes","iTunes"
"Firewall","19:27:37","ICMP","192.168.1.3","n/a","192.168.1.1","n/a","---","---","Destination Unreachable"
"Firewall","19:27:37","ICMP","192.168.1.3","n/a","192.168.1.1","n/a","---","---","Destination Unreachable"
"Exception List Rule","19:27:39","TCP","---","n/a","192.168.1.3","139","SYSTEM","---","NetBIOS (Incoming, Fixed)"
"Firewall","19:27:39","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","19:27:40","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","19:27:41","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","19:28:21","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:28:23","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:28:24","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:11","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:12","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:14","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:15","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:17","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:18","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:20","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:21","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","19:59:23","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:22:08","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","20:22:08","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","20:22:09","IGMP","192.168.1.3","n/a","224.0.0.22","n/a","---","---","Security Rule Matched"
"Firewall","20:30:01","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:02","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:04","ICMP","192.168.1.1","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:05","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:07","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:08","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:10","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:11","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:13","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:14","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:16","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","20:30:17","ICMP","192.168.1.101","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:01","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:02","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:04","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:05","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:07","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:08","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:10","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:11","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","21:00:13","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","22:31:41","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","22:31:42","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","22:31:44","ICMP","192.168.1.102","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","22:31:45","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","22:31:47","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
"Firewall","22:31:48","ICMP","192.168.1.100","n/a","192.168.1.3","n/a","---","---","Destination Unreachable"
Trend is showing that the 192..1 is trusted (but no computer name shows up) and that unknown computer .1.130 and unknown computer .1.212 are both connected to my network. If these are indeed my components, is there any way that I can name them, so I know that they are mine or is there anything I should block access to? Thanks!
It appears to me the firewall is doing it's job. Those ISP numbers are unknown. Can you connect to the internet without difficulty?
Frankly if you feel Trend Micro is slowing the system you might try another set of security programs, both FREE.
Online Armor Firewall is Excellent. Avira Free antivirus is also excellent. Neither one is overwhelming with excessive activity or usage amounts either. I use both, or have used both (right now I am using the Windows Firewall and am also very pleased with it) and have been quite pleased with the results.
Frankly if you feel Trend Micro is slowing the system you might try another set of security programs, both FREE.
Online Armor Firewall is Excellent. Avira Free antivirus is also excellent. Neither one is overwhelming with excessive activity or usage amounts either. I use both, or have used both (right now I am using the Windows Firewall and am also very pleased with it) and have been quite pleased with the results.
![]() |
Similar Threads
- Hijack this log please look at (Viruses, Spyware and other Nasties)
- Error #317 popup (Hijack This Log (Viruses, Spyware and other Nasties)
- Need Help bad, here is my hijack this log. (Viruses, Spyware and other Nasties)
- hijack this log- i found a trojan (Viruses, Spyware and other Nasties)
- Computer has severe problems; HIJACK log (Viruses, Spyware and other Nasties)
- Re: Hijack log-WMP Internal application error ha occured (Viruses, Spyware and other Nasties)
- Hijack This log (Viruses, Spyware and other Nasties)
- Possible ISTbar problem - Hijack This log. (Viruses, Spyware and other Nasties)
- Virus/Spyware on computer, Hijack This log file (Viruses, Spyware and other Nasties)
- Computer is very slow Hijack log (Viruses, Spyware and other Nasties)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: Google being redirected to ad sites
- Next Thread: I have a Trojan ( I think) that won't let me connect to the internet.
| Thread Tools | Search this Thread |
Tag cloud for Viruses, Spyware and other Nasties
adware anti-malware anti-virussitesaccessissue antivirus apple attack audio avg backtoschoolspeech bar blackhat botnet botnets censorship china commercial conficker connect control cyber cybercrime cyberwarfare ddos domains education email europe exam exploit facebook fake fancheckvirus gaming gtaiv halloween herss.exe hijack hosting internet iphone kaspersky legal logfiles malware mcafee mega-d messagelabs microsoft mobile msn nazi news obama onlinethreats paedophile panel parents patch phishing police policeprovirusmba-mblockedinternetaccess president privacy pro redirect redirecting report research rogueantivirus samhain sans scareware search security seopoisoning sites software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec system teen translate trojan unabletoaccessanti-virussites unwanted update usa virus viruses vista volume war warning windows worm yahoo zeroday






