Http Ms Iis Ntlm Asn1 Bo

Discussion in 'Malware Help (A Specialist Will Reply)' started by agent_keiko, Apr 28, 2006.

  1. agent_keiko

    agent_keiko Private E-2

    Norton AV has reported that the intruder HTTP MS IIS NTLM ASN1 BO has been trying to get into my system. Norton has blocked the attempts, but the threat warning is still showing up.

    I have already done hijackthis. It reports that my system is clean. According to Microsoft, I have also got all the latest updates. And yet this threat has been popping up several times a day.

    Is there anything I can do to stop this threat from appearing again? Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you read the below?

    http://www.symantec.com/avcenter/attack_sigs/s21141.html

    More than MS Windows can be a affected. Exactly what is reporting this? If it your firewall?

    You should work thru the below.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. agent_keiko

    agent_keiko Private E-2

    Hello, I have run bitdefender and hijackthis. I have placed their logs into the attachment below this message. I was not able to get Pandascan to work. Their boxes did not size correctly for me.

    Please see if you can work with what I manage to find. Thank you.

    edit: the WildTangent entry on my hijackthis log is clean. This comes from a WildTangent program I have loaded up many months before.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on what you ran, I see no malware issues.

    Is there a reason you did not run Windows Defender (or Counter Spy if Windows Defender would not run)?

    Did you run Spybot S&D? I don't see it with the SDhelper enabled.

    You did not answer my previous question on who is reporting this? Is it really only Norton AV? Or is it a firewall? Does your Symantec software have a firewall component?
     
  5. agent_keiko

    agent_keiko Private E-2

    I have finished running Windows Defender. It says that my system has no detected malware.

    To answer your question, norton antivirus (worm protection) is reporting the intruder. I have Zone Alarm as my firewall.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thought that Norton's Internet Security Suite (which it looks like you are running) had a firewall included in it?

    Did you look thru the link I gave you in message # 2?

    Are you running any of those other software components that may need updating?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds