Sandurz wrote:Oh, it was a java-driveby. Those things suck. As soon as you give them permission to do anything you're screwed. It usually is because you're using Firefox or IE (the two most used browsers). Anyways, that sucks. Do you remember what was asking for updates?
Yeah, I've done a lot of research on malware. I'm doing a report on malware for my networking class =D
I usually use Opera, might I've used Firefox occassionally.
Java and DivX updaters were running. Avast! found a rootkit from the Java update file. Nothing from the DivX files. I've ran two full scans of my computer now, with no more viruses or malware found, but I've only used Avast!.
I've been thinking of getting an Ubuntu live cd and a linux antivir program, and checking for rootkits that way. Even if they can hide from the Window programs, the Linux checker might be able to find them.
However, I think I'll first run through some other tests or a MalwareBytes check or something similar. Perhaps run a Highjack This! test, but I can't make head or tales out of the log file so I'd need help in understanding what it tells.
My svchost.exe is listening on ports 9423, 9422, 9421 and 1670. It also has UDP out connections to two different IP addresses to their port 3478. One of those seems to be related to having installed Photoshop trial once (but why would the Akamai downloader still be around?).