Page 2 of 4 FirstFirst 1234 LastLast
Results 11 to 20 of 36

Thread: Unknown svchost.exe DNS port 53 network activity

  1. #11
    David H. Lipman Guest

    Re: Unknown svchost.exe DNS port 53 network activity

    From: "Raffi" <thegrizzzly@yahoo.com>


    |
    | The "problem" was back overnight. I'll post more information soon.
    |
    | Raffi



    If you are using any version of Sun Java that is prior to JRE Version 6.0,
    then you are strongly urged to remove any/all versions.
    There are vulnerabilities in them and they are actively being exploited.

    It is highly suggested that you update to the latest version which is Sun Java JRE/JSE
    Version 6.0

    Simple check, look under...
    C:\Program Files\Java

    The only folder under that folder should be the latest version.

    Such as...
    C:\Program Files\Java\jre1.6.0

    http://java.sun.com/javase/downloads/index.jsp
    http://www.java.com/en/download/manual.jsp

    FYI:
    http://sunsolve.sun.com/search/docum...=1-26-102557-1
    http://sunsolve.sun.com/search/docum...=1-26-102648-1
    http://sunsolve.sun.com/search/docum...=1-26-102622-1


    For non-viral malware...

    Please download, install and update the following software...

    * Ad-aware SE v1.06
    http://www.lavasoft.de/
    http://www.lavasoftusa.com/
    http://www.lavasoft.de/ms/index.htm

    * SpyBot Search and Destroy v1.4
    http://security.kolla.de/
    http://www.safer-networking.org/microsoft.en.html

    * SuperAntiSpyware
    http://www.superantispyware.com/supe...freevspro.html

    After the software is updated, I suggest scanning the system in Safe Mode.

    I also suggest downloading, installing and updating BHODemon for any Browser Helper Objects
    that may be on the PC.

    * BHODemon

    http://www.majorgeeks.com/downloadge...4332b4b8b8442d

    For viral malware...

    * Download MULTI_AV.EXE from the URL --
    http://www.ik-cs.com/programs/virtools/Multi_AV.exe

    To use this utility, perform the following...
    Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
    Choose; Unzip
    Choose; Close

    Execute; C:\AV-CLS\StartMenu.BAT
    { or Double-click on 'Start Menu' in C:\AV-CLS }

    NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
    FireWall to allow it to download the needed AV vendor related files.

    C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
    This will bring up the initial menu of choices and should be executed in Normal Mode.
    This way all the components can be downloaded from each AV vendor's web site.
    The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

    You can choose to go to each menu item and just download the needed files or you can
    download the files and perform a scan in Normal Mode. Once you have downloaded the files
    needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
    during boot] and re-run the menu again and choose which scanner you want to run in Safe
    Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

    When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
    file. http://www.ik-cs.com/multi-av.htm

    Additional Instructions:
    http://pcdid.com/Multi_AV.htm


    * * * Please report back your results * * *


    --
    Dave
    http://www.claymania.com/removal-trojan-adware.html
    http://www.ik-cs.com/got-a-virus.htm



  2. #12
    Raffi Guest

    Re: Unknown svchost.exe DNS port 53 network activity


    David H. Lipman wrote:
    > From: "Raffi" <thegrizzzly@yahoo.com>
    >
    >
    > |
    > | The "problem" was back overnight. I'll post more information soon.
    > |
    > | Raffi
    >
    >
    >
    > If you are using any version of Sun Java that is prior to JRE Version 6.0,
    > then you are strongly urged to remove any/all versions.
    > There are vulnerabilities in them and they are actively being exploited.
    >
    > It is highly suggested that you update to the latest version which is Sun Java JRE/JSE
    > Version 6.0
    >
    > Simple check, look under...
    > C:\Program Files\Java
    >
    > The only folder under that folder should be the latest version.
    >
    > Such as...
    > C:\Program Files\Java\jre1.6.0
    >
    > http://java.sun.com/javase/downloads/index.jsp
    > http://www.java.com/en/download/manual.jsp
    >
    > FYI:
    > http://sunsolve.sun.com/search/docum...=1-26-102557-1
    > http://sunsolve.sun.com/search/docum...=1-26-102648-1
    > http://sunsolve.sun.com/search/docum...=1-26-102622-1
    >
    >
    > For non-viral malware...
    >
    > Please download, install and update the following software...
    >
    > * Ad-aware SE v1.06
    > http://www.lavasoft.de/
    > http://www.lavasoftusa.com/
    > http://www.lavasoft.de/ms/index.htm
    >
    > * SpyBot Search and Destroy v1.4
    > http://security.kolla.de/
    > http://www.safer-networking.org/microsoft.en.html
    >
    > * SuperAntiSpyware
    > http://www.superantispyware.com/supe...freevspro.html
    >
    > After the software is updated, I suggest scanning the system in Safe Mode.
    >
    > I also suggest downloading, installing and updating BHODemon for any Browser Helper Objects
    > that may be on the PC.
    >
    > * BHODemon
    >
    > http://www.majorgeeks.com/downloadge...4332b4b8b8442d
    >
    > For viral malware...
    >
    > * Download MULTI_AV.EXE from the URL --
    > http://www.ik-cs.com/programs/virtools/Multi_AV.exe
    >
    > To use this utility, perform the following...
    > Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
    > Choose; Unzip
    > Choose; Close
    >
    > Execute; C:\AV-CLS\StartMenu.BAT
    > { or Double-click on 'Start Menu' in C:\AV-CLS }
    >
    > NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
    > FireWall to allow it to download the needed AV vendor related files.
    >
    > C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
    > This will bring up the initial menu of choices and should be executed in Normal Mode.
    > This way all the components can be downloaded from each AV vendor's web site.
    > The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.
    >
    > You can choose to go to each menu item and just download the needed files or you can
    > download the files and perform a scan in Normal Mode. Once you have downloaded the files
    > needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
    > during boot] and re-run the menu again and choose which scanner you want to run in Safe
    > Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
    >
    > When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
    > file. http://www.ik-cs.com/multi-av.htm
    >
    > Additional Instructions:
    > http://pcdid.com/Multi_AV.htm
    >
    >
    > * * * Please report back your results * * *
    >
    >
    > --
    > Dave
    > http://www.claymania.com/removal-trojan-adware.html
    > http://www.ik-cs.com/got-a-virus.htm


    I have found the process responsible for the Port 53 traffic.
    Suspending this process in Process Explorer stops the network activity.
    Resuming it restarts the activity. Below are the details.

    Process: svchost.exe Pid: 944

    Type Name
    Desktop \Default
    Directory \KnownDlls
    Directory \Windows
    Directory \BaseNamedObjects
    File C:\WINDOWS\system32
    File \Device\KsecDD
    File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9
    File \Device\NamedPipe\net\NtControlPipe5
    File \Device\Tcp
    File \Device\Ip
    File \Device\Tcp
    File \Device\Ip
    File \Device\Ip
    File C:\WINDOWS\system32\drivers\etc
    File \Device\Tcp
    File \Device\Udp
    File \Device\Afd\Endpoint
    File \Device\WMIDataDevice
    File \Device\WMIDataDevice
    File \Device\NamedPipe\lsarpc
    File \Device\Afd\Endpoint
    File \Device\Udp
    File \Device\Afd\Endpoint
    File \Device\Udp
    File \Device\Afd\Endpoint
    File \Device\Udp
    File \Device\Afd\Endpoint
    File \Device\Udp
    File \Device\Afd\Endpoint
    File \Device\Udp
    File \Device\Afd\Endpoint
    File \Device\Udp
    File \Device\Afd\Endpoint
    File \Device\Udp
    File \Device\Afd\Endpoint
    File \Device\Udp
    File \Device\Afd\Endpoint
    File \Device\Udp
    Key HKLM
    Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
    Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
    Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Linkage
    Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameter s
    Key HKLM\SYSTEM\ControlSet001\Services\NetBT\Parameter s\Interfaces
    Key HKLM\SYSTEM\ControlSet001\Services\NetBT\Parameter s
    Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parame ters\Protocol_Catalog9
    Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parame ters\NameSpace_Catalog5
    KeyedEvent \KernelObjects\CritSecOutOfMemoryEvent
    Mutant \BaseNamedObjects\DCS_grd
    Port \RPC Control\DNSResolver
    Process svchost.exe(944)
    Section \BaseNamedObjects\DCS_raw
    Section \BaseNamedObjects\DCS_LOGraw
    Semaphore \BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}
    Thread svchost.exe(944): 948
    Thread svchost.exe(944): 3036
    Thread svchost.exe(944): 972
    Thread svchost.exe(944): 976
    Thread svchost.exe(944): 3036
    Thread svchost.exe(944): 460
    Thread svchost.exe(944): 460
    Thread svchost.exe(944): 1344
    Thread svchost.exe(944): 3548
    Thread svchost.exe(944): 3548
    Thread svchost.exe(944): 1392
    Thread svchost.exe(944): 1392
    Thread svchost.exe(944): 1404
    Thread svchost.exe(944): 1708
    Thread svchost.exe(944): 1404
    Thread svchost.exe(944): 1708
    WindowStation \Windows\WindowStations\Service-0x0-3e4$
    WindowStation \Windows\WindowStations\Service-0x0-3e4$


  3. #13
    Stefan Kanthak Guest

    Re: Unknown svchost.exe DNS port 53 network activity

    "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote:

    > From: "Raffi" <thegrizzzly@yahoo.com>
    >
    >
    > |
    > | The "problem" was back overnight. I'll post more information soon.
    > |
    > | Raffi
    >
    >
    >
    > If you are using any version of Sun Java that is prior to JRE Version 6.0,
    > then you are strongly urged to remove any/all versions.
    > There are vulnerabilities in them and they are actively being exploited.


    Stop spreading FUD!
    1.5.0_10 as well as 1.4.2_13 have no known vulnerabilities!

    > It is highly suggested that you update to the latest version which is Sun Java JRE/JSE
    > Version 6.0


    It's completely sufficient to have the latest version of 1.5.0 or 1.4.2
    installed and all previous versions (manually!) removed.
    There are still quite some applets and java applications out there which
    won't run with JRE6 or even JRE5!

    > Simple check, look under...
    > C:\Program Files\Java


    | dir "C:\Program Files\"
    |
    | File not found

    When will you learn to use "%ProgramFiles%"?

    > The only folder under that folder should be the latest version.
    >
    > Such as...
    > C:\Program Files\Java\jre1.6.0
    >
    > http://java.sun.com/javase/downloads/index.jsp
    > http://www.java.com/en/download/manual.jsp
    >
    > FYI:
    > http://sunsolve.sun.com/search/docum...=1-26-102557-1
    > http://sunsolve.sun.com/search/docum...=1-26-102648-1
    > http://sunsolve.sun.com/search/docum...=1-26-102622-1
    >
    >
    > For non-viral malware...
    >
    > Please download, install and update the following software...


    Alun already gave the ONLY CORRECT advice: flatten and rebuild.

    Stefan

    fup microsoft.public.security


  4. #14
    Gabriele Neukam Guest

    Re: Unknown svchost.exe DNS port 53 network activity

    On this special day, David H. Lipman wrote :

    > If you are using any version of Sun Java that is prior to JRE Version 6.0,
    > then you are strongly urged to remove any/all versions.


    You should replace the six with a nine or ten.

    http://sunsolve.sun.com/search/docum...=1-26-102729-1
    http://sunsolve.sun.com/search/docum...=1-26-102731-1
    http://sunsolve.sun.com/search/docum...=1-26-102732-1

    are the newest alerts by Sun.


    Gabriele Neukam

    Gabriele.Spamfighter.Neukam@t-online.de

    --
    Bei Windows haut man raus was man nicht braucht.
    Bei Linux haut man rein was man braucht.
    (René 'vollmi' Vollmeier in de.comp.security.misc)



  5. #15
    David H. Lipman Guest

    Re: Unknown svchost.exe DNS port 53 network activity

    From: "Gabriele Neukam" <Gabriele.Spamfighter.Neukam@t-online.de>

    | On this special day, David H. Lipman wrote :
    |
    >> If you are using any version of Sun Java that is prior to JRE Version 6.0,
    >> then you are strongly urged to remove any/all versions.

    |
    | You should replace the six with a nine or ten.
    |
    | http://sunsolve.sun.com/search/docum...=1-26-102729-1
    | http://sunsolve.sun.com/search/docum...=1-26-102731-1
    | http://sunsolve.sun.com/search/docum...=1-26-102732-1
    |
    | are the newest alerts by Sun.
    |
    | Gabriele Neukam
    |
    | Gabriele.Spamfighter.Neukam@t-online.de
    |

    I'm sorry Gabriele but Sun is f'd up and confusing.

    v6 is the latest and based upon ALL the problems with Sun not being forthcoming with
    Vulnerability statements, v6 is the suggested version. It is a complete re-write.

    In the middle of the following page...
    "Java Runtime Environment (JRE) 6"
    http://java.sun.com/javase/downloads/index.jsp

    --
    Dave
    http://www.claymania.com/removal-trojan-adware.html
    http://www.ik-cs.com/got-a-virus.htm



  6. #16
    Raffi Guest

    Re: Unknown svchost.exe DNS port 53 network activity

    David H. Lipman wrote:
    > From: "Gabriele Neukam" <Gabriele.Spamfighter.Neukam@t-online.de>
    >
    > | On this special day, David H. Lipman wrote :
    > |
    > >> If you are using any version of Sun Java that is prior to JRE Version 6.0,
    > >> then you are strongly urged to remove any/all versions.

    > |
    > | You should replace the six with a nine or ten.
    > |
    > | http://sunsolve.sun.com/search/docum...=1-26-102729-1
    > | http://sunsolve.sun.com/search/docum...=1-26-102731-1
    > | http://sunsolve.sun.com/search/docum...=1-26-102732-1
    > |
    > | are the newest alerts by Sun.
    > |
    > | Gabriele Neukam
    > |
    > | Gabriele.Spamfighter.Neukam@t-online.de
    > |
    >
    > I'm sorry Gabriele but Sun is f'd up and confusing.
    >
    > v6 is the latest and based upon ALL the problems with Sun not being forthcoming with
    > Vulnerability statements, v6 is the suggested version. It is a complete re-write.
    >
    > In the middle of the following page...
    > "Java Runtime Environment (JRE) 6"
    > http://java.sun.com/javase/downloads/index.jsp
    >
    > --
    > Dave
    > http://www.claymania.com/removal-trojan-adware.html
    > http://www.ik-cs.com/got-a-virus.htm


    I did have older versions of JRE, J2SE and J2ME SDK and uninstalled
    them as well as deleting all related folders. The problem is still
    there.

    As I mentioned before, I have run a few anivirus and antispyware
    programs both in normal and safe mode and they haven't identified any
    issues. Of course all software were properly updated before running.

    At this poing I'm starting to consider reinstalling Windows XP.

    Raffi


  7. #17
    David H. Lipman Guest

    Re: Unknown svchost.exe DNS port 53 network activity

    From: "Raffi" <thegrizzzly@yahoo.com>

    |
    | I did have older versions of JRE, J2SE and J2ME SDK and uninstalled
    | them as well as deleting all related folders. The problem is still
    | there.
    |
    | As I mentioned before, I have run a few anivirus and antispyware
    | programs both in normal and safe mode and they haven't identified any
    | issues. Of course all software were properly updated before running.
    |
    | At this poing I'm starting to consider reinstalling Windows XP.
    |
    | Raffi

    Replacing Sun Java was NOT part of the solution for you.

    Since there are so many vulnerabilities in older version, upgrading and replacing them with
    the latest version will help mitigate malware which may exploit those vulnerablities and
    help prevent future problems.

    Plaese run the anti malware scans and software I suggested.
    --
    Dave
    http://www.claymania.com/removal-trojan-adware.html
    http://www.ik-cs.com/got-a-virus.htm



  8. #18
    Raffi Guest

    Re: Unknown svchost.exe DNS port 53 network activity


    David H. Lipman wrote:
    > From: "Raffi" <thegrizzzly@yahoo.com>
    >
    > |
    > | I did have older versions of JRE, J2SE and J2ME SDK and uninstalled
    > | them as well as deleting all related folders. The problem is still
    > | there.
    > |
    > | As I mentioned before, I have run a few anivirus and antispyware
    > | programs both in normal and safe mode and they haven't identified any
    > | issues. Of course all software were properly updated before running.
    > |
    > | At this poing I'm starting to consider reinstalling Windows XP.
    > |
    > | Raffi
    >
    > Replacing Sun Java was NOT part of the solution for you.
    >
    > Since there are so many vulnerabilities in older version, upgrading and replacing them with
    > the latest version will help mitigate malware which may exploit those vulnerablities and
    > help prevent future problems.
    >
    > Plaese run the anti malware scans and software I suggested.
    > --
    > Dave
    > http://www.claymania.com/removal-trojan-adware.html
    > http://www.ik-cs.com/got-a-virus.htm


    I'll run all the scans you suggested later today and post the results.

    Raffi


  9. #19
    Raffi Guest

    Re: Unknown svchost.exe DNS port 53 network activity


    Raffi wrote:
    > David H. Lipman wrote:
    > > From: "Raffi" <thegrizzzly@yahoo.com>
    > >
    > > |
    > > | I did have older versions of JRE, J2SE and J2ME SDK and uninstalled
    > > | them as well as deleting all related folders. The problem is still
    > > | there.
    > > |
    > > | As I mentioned before, I have run a few anivirus and antispyware
    > > | programs both in normal and safe mode and they haven't identified any
    > > | issues. Of course all software were properly updated before running.
    > > |
    > > | At this poing I'm starting to consider reinstalling Windows XP.
    > > |
    > > | Raffi
    > >
    > > Replacing Sun Java was NOT part of the solution for you.
    > >
    > > Since there are so many vulnerabilities in older version, upgrading and replacing them with
    > > the latest version will help mitigate malware which may exploit those vulnerablities and
    > > help prevent future problems.
    > >
    > > Plaese run the anti malware scans and software I suggested.
    > > --
    > > Dave
    > > http://www.claymania.com/removal-trojan-adware.html
    > > http://www.ik-cs.com/got-a-virus.htm

    >
    > I'll run all the scans you suggested later today and post the results.
    >
    > Raffi


    OK, I downloaded and ran all the software. While Ad-Aware was running I
    get a warning from AntiVir that it had found a virus called
    Run_it_xxx.exe. I deleted it. Other than that, they came up with a few
    minor viruses on some files that have been on my PC for ever. I
    quarantined them. I also made sure I have all the Windows security
    updates, and I do except for a RAID driver. I also upgraded to IE 7
    just to be sure. The problem still persists.

    I installed a program called Prevx1 which seems to be a nice program.
    It tells you when an application starts ends etc. Every time I
    disconnect and reconnect the network connection, it tells me that a
    program called MOBSYNC.EXE has started. I'm not sure if this is
    related.

    Also, the network connection seems to be active only at certain times
    and inactive otherwise. When it's active it goes like crazy. I'm
    suspicious that the PC is being used for DOS attacks or SPAM etc.

    I'm still at a loss and any help will be appreciated. The only way I
    can fight this is by unplugging the network connection.

    Also, I recently configured reverse DNS lookup for my static IP address
    through my ISP. Can this be related to the network activity?

    Raffi


  10. #20
    David H. Lipman Guest

    Re: Unknown svchost.exe DNS port 53 network activity

    From: "Raffi" <thegrizzzly@yahoo.com>


    |
    | OK, I downloaded and ran all the software. While Ad-Aware was running I
    | get a warning from AntiVir that it had found a virus called
    | Run_it_xxx.exe. I deleted it. Other than that, they came up with a few
    | minor viruses on some files that have been on my PC for ever. I
    | quarantined them. I also made sure I have all the Windows security
    | updates, and I do except for a RAID driver. I also upgraded to IE 7
    | just to be sure. The problem still persists.
    |
    | I installed a program called Prevx1 which seems to be a nice program.
    | It tells you when an application starts ends etc. Every time I
    | disconnect and reconnect the network connection, it tells me that a
    | program called MOBSYNC.EXE has started. I'm not sure if this is
    | related.
    |
    | Also, the network connection seems to be active only at certain times
    | and inactive otherwise. When it's active it goes like crazy. I'm
    | suspicious that the PC is being used for DOS attacks or SPAM etc.
    |
    | I'm still at a loss and any help will be appreciated. The only way I
    | can fight this is by unplugging the network connection.
    |
    | Also, I recently configured reverse DNS lookup for my static IP address
    | through my ISP. Can this be related to the network activity?
    |
    | Raffi

    MOBSYNC.EXE is most likely legit and OK.

    This may have to do with the RDNS service.

    --
    Dave
    http://www.claymania.com/removal-trojan-adware.html
    http://www.ik-cs.com/got-a-virus.htm



Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •