
02-11-2012
10:13 PM
- last edited on
02-12-2012
06:09 AM
by
ornahp
I have been using Trend Micro Internet Security for almost 10 years and I have never seen a contiuous Web Threat like this before. In Trend Micro Titanium Internet Security 2012, it is blocking a continuous increasing count of Web Threats from a website. The website is showing up as:
x-web.in/Y2x8MS40fGI1M2M4YmU0ZGZhZjY2YWZjZTE2NGMzZ
I exported the log report and used Excel to count the number of threats in 1 minute. It varies, but I was seeing 370 to 380 entries per minute!
The details of the log include:
Rating: Dangerous Page (49)
Response: Blocked
Detected By: Web Reputation
Of course I did a scan and TM didn't find anything. I ran ComboFix and the Web Threat is still counting. It allocates so fast, it's like a ticker counter.
Has anyone ever seen this before?
Thank you.
Solved! Go to Solution.
02-12-2012 05:16 PM
i have the same exact problem with the same website, and cant stop this from happening
02-12-2012 05:18 PM
It looks like I found the trojans that were causing it. I downloaded the free version of Malwarebytes Anti-Malware and did a quick scan. It found 2 trojan agents and several other suspect folders and files:
Memory Processes Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> 3904 -> Delete on reboot.
Files Detected:
C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot.
The other folders and files that it detected and removed were related to PUP.PlaySushi, which I have no idea what it is.
After cleaning the files, Trend Micro is no longer continuously blocking the Web Threat.
Hopefully this will benefit others who may run into this trojan.
02-12-2012
05:24 PM
- last edited on
02-12-2012
06:10 PM
by
ornahp
i found 2 trojans as well when i ran the malwarebytes scan, but once i restarted the computer, I still received these constant web threats from x-web.in
02-12-2012 07:34 PM
Yes, after re-starting the computer and waiting for a short period, the Web Threat does resume. Hmmm. I wonder if it's an actual trojan or if Trend Micro is incorrectly reporting it as a Web Threat?
The problem still persists...
02-12-2012 09:04 PM
Welcome aboard! ![]()
Please follow the below instructions to resolve your issues...
Download ComboFix from the any of the locations given in this website:


02-13-2012 06:04 PM
I attached the Combo Fix log report. I don't know how attachments work on this forum.
02-13-2012 08:57 PM - edited 02-13-2012 08:59 PM
how is your computer running now?
Please download Malwarebytes' Anti-Malware from Here
Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
02-14-2012 03:03 PM
The computer has been running fine all of this time. However, Trend Micro is just continuously blocking the same Web Threat. I don't know if it's a trojan that is on my computer or if it's just an outside threat that is trying to get into my computer.
The Malwarebytes program found the same 2 files as before (svchost.exe), however, upon reboot nothing has changed. TM is still blocking the Web Threat. Anyway, here is the Malwarebytes log:
Malwarebytes Anti-Malware 1.60.1.1000
Database version: v2012.02.13.01
Windows 7 Service Pack 1 x64 NTFS (Safe Mode)
Internet Explorer 9.0.8112.16421
2/14/2012 5:39:42 PM
mbam-log-2012-02-14 (17-39-42).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P
Objects scanned: 211032
Time elapsed: 7 minute(s), 29 second(s)
Memory Processes Detected: 1 C:\Windows\svchost.exe (Trojan.Agent) -> 956 -> Delete on reboot.
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1 C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot.
(end)
02-14-2012 09:13 PM
Then that needs investigation...
Download aswmbr.exe ( 1.8mb ) to your desktop.
http://public.avast.com/~gmerek/aswMBR.htm
Double click the aswMBR.exe to run it Click the "Scan" button to start scan.

Click the [Scan] button to start scan

On completion of the scan click [Save log], save it to your desktop and post in your next reply.
Copyright (c) 1989-2012 Trend Micro Incorporated. All rights reserved.
