David H. Lipman wrote:
> From: "Raffi" <thegrizzzly@yahoo.com>
>
>
> |
> | OK, I downloaded and ran all the software. While Ad-Aware was running I
> | get a warning from AntiVir that it had found a virus called
> | Run_it_xxx.exe. I deleted it. Other than that, they came up with a few
> | minor viruses on some files that have been on my PC for ever. I
> | quarantined them. I also made sure I have all the Windows security
> | updates, and I do except for a RAID driver. I also upgraded to IE 7
> | just to be sure. The problem still persists.
> |
> | I installed a program called Prevx1 which seems to be a nice program.
> | It tells you when an application starts ends etc. Every time I
> | disconnect and reconnect the network connection, it tells me that a
> | program called MOBSYNC.EXE has started. I'm not sure if this is
> | related.
> |
> | Also, the network connection seems to be active only at certain times
> | and inactive otherwise. When it's active it goes like crazy. I'm
> | suspicious that the PC is being used for DOS attacks or SPAM etc.
> |
> | I'm still at a loss and any help will be appreciated. The only way I
> | can fight this is by unplugging the network connection.
> |
> | Also, I recently configured reverse DNS lookup for my static IP address
> | through my ISP. Can this be related to the network activity?
> |
> | Raffi
>
> MOBSYNC.EXE is most likely legit and OK.
>
> This may have to do with the RDNS service.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
I had some time to do packet analysis using Etherial and most of the
conenctions were DNS queries and SMTP connections.
I went ahead and blocked all traffic from the PC to the ISP DNS servers
in my firewall (Comodo). The DNS server for my PC is statically defined
as the gateway router. Since the ISP DNS was no longer accessible it
rerouted the DNS queries (and/or query responses) to the gateway
router. These were a bunch of MX queries for mostly .ru domains.
Next I blocked all inbound and outbound UDP connections for svchost.exe
and services.exe. This stopped most of the traffic. After a while I
started seeing traffic to a couple of specific ip addresses
(208.66.195.78 and 62.189.194.215) which don't resolve to anything with
nslookup. I blocked these IP addresses in the firewall as well. Next
the PC started sending out a bunch of broadcasts (.255). So I blocked
outbound broadcast connections.
Next it started sending broadcast to 0.255 using the ZIP (Zone
Information Protocol) protocol. I don't think I've seen this one
before. I haven't been able to block these yet.
My guess is the PC is somehow being used as a DNS/SMTP relay. Another
guess is my svchost.exe and/or services.exe have been compromized.
As usual, any help in getting to the bottom of this would be welcome.
Raffi


Reply With Quote