virus or what: many DNS calls

virus or what: many DNS calls

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
virus or what: many DNS calls Berra 11-19-2005
Posted by Berra on November 19, 2005, 9:52 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi, I have been trying to find out why my Pentium
1100MHz/1500MBram/40+120GBHDD is booting up sloooow 60 minutes.
This is only when I am online to the (freeSCO firewall and ADSL-modem). When
I disconnect or shut down the ADSL-modem, it starts up ok.

Checking the freeSCO:s message-log tells me something, like this:

Nov 19 09:08:59 - dnsmasq[1251]: query jupitersatellites.biz from
192.168.1.1
Nov 19 09:08:59 - dnsmasq[1251]: forwarded jupitersatellites.biz to
195.67.199.21
Nov 19 09:09:00 - dnsmasq[1251]: query jupitersatellites.biz from
192.168.1.1
Nov 19 09:09:00 - dnsmasq[1251]: forwarded jupitersatellites.biz to
195.67.199.22
Nov 19 09:09:01 - dnsmasq[1251]: query jupitersatellites.biz from
192.168.1.1
Nov 19 09:09:01 - dnsmasq[1251]: forwarded jupitersatellites.biz to
195.67.199.23
Nov 19 09:09:01 - dnsmasq[1251]: reply jupitersatellites.biz is
69.50.190.163
Nov 19 09:10:12 - dnsmasq[1251]: query www.hprofit.com from 192.168.1.1
Nov 19 09:10:12 - dnsmasq[1251]: forwarded www.hprofit.com to 195.67.199.23
Nov 19 09:10:12 - dnsmasq[1251]: reply www.hprofit.com is 200.60.37.206
Nov 19 09:10:12 - dnsmasq[1251]: reply hprofit.com is 200.60.37.206
Nov 19 09:10:49 - dnsmasq[1251]: query profitcluballiance.com from
192.168.1.1
Nov 19 09:10:49 - dnsmasq[1251]: forwarded profitcluballiance.com to
195.67.199.23
Nov 19 09:10:49 - dnsmasq[1251]: reply profitcluballiance.com is 69.64.40.55

And so on....

Sometimes I can log in on the computer, and the taskmonitor tells me that
"winlogon.exe" is using 99-100% CPU!





Posted by Duane Arnold on November 19, 2005, 10:15 am
If you were  Registered and logged in, you could reply and use other advanced thread options

> Hi, I have been trying to find out why my Pentium
> 1100MHz/1500MBram/40+120GBHDD is booting up sloooow 60 minutes.
> This is only when I am online to the (freeSCO firewall and
> ADSL-modem). When I disconnect or shut down the ADSL-modem, it starts
> up ok.

Then obviously the modem is shut down and whatever is running cannot make a
connection out and send data.

The modem online connected to the Internet, the computer is on and whatever
is doing it can make an outbound connection.

>
> Sometimes I can log in on the computer, and the taskmonitor tells me
> that "winlogon.exe" is using 99-100% CPU!
>

And winlogon.exe may not be the culprit and malware can use it on its
behalf.

You may have to go look for yourself with the proper tools like PE and look
inside a running process and see what's running with it.

http://www.pcworld.com/downloads/file_description/0,fid,23780,00.asp

Menu option Show Lower Pane and Show all DLL(s) will show all hidden
processes that are running with a process when you click on the process in
the Upper Pane. You can also right-click/Properties on a line in the Upper
and Lower Panes to get even more information with PE.

The link below talks about PE and other free tools that can be used to
track something down.

Long

http://www.windowsecurity.com/articles/Hidden_Backdoors_Trojan_Horses_and_R
ootkit_Tools_in_a_Windows_Environment.html

Short

http://tinyurl.com/klw1

Duane :)

Posted by David H. Lipman on November 19, 2005, 10:25 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hi, I have been trying to find out why my Pentium
| 1100MHz/1500MBram/40+120GBHDD is booting up sloooow 60 minutes.
| This is only when I am online to the (freeSCO firewall and ADSL-modem). When
| I disconnect or shut down the ADSL-modem, it starts up ok.
|
| Checking the freeSCO:s message-log tells me something, like this:

< snip >


For non-viral malware...

Please download, install and update the following software...

* Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/

* SpyBot Search and Destroy v1.4
http://security.kolla.de/

After the software is updated, I suggest scanning the system in Safe Mode.

I also suggest downloading, installing and updating BHODemon for any Browser
Helper Objects
that may be on the PC.

* BHODemon
http://www.definitivesolutions.com/bhodemon.htm

For viral malware...

* Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file.


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Berra on November 20, 2005, 11:20 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi!
Now, I am done!
It was the file "msupdate32.dll" that was responsible.
Checking around a little in the net, I saw that there is a virus/trojan
using the "msupdate32.exe" version. I just killed the process, and all was
ok. Checking inside the file with Notepad, I could read the first url,
probably the master in the DDoS atack.
There also was the file "mspostsp.exe" with the samd date and timestamp:
also renamed. Also, I found it in the registery at the key:
[......\Winlogon\Notify\msupdate] "Dllname"="msupdate32.dll"...........
deleted!

I installed the ProcessExplorer in autostart. the I restarted with the
network connected. Whe I saw the first dns call from the computer in the
freeSCO firewall, I disconnected the LAN cable and let the machine work by
it self.
I took more that six hours before it was up and running!!! Then I could
easyli see wich process that was taking all the cpu!

Thanks for the help, David

/Bertil



>
> | Hi, I have been trying to find out why my Pentium
> | 1100MHz/1500MBram/40+120GBHDD is booting up sloooow 60 minutes.
> | This is only when I am online to the (freeSCO firewall and ADSL-modem).
When
> | I disconnect or shut down the ADSL-modem, it starts up ok.
> |
> | Checking the freeSCO:s message-log tells me something, like this:
>
> < snip >
>
>
> For non-viral malware...
>
> Please download, install and update the following software...
>
> * Ad-aware SE v1.06
> http://www.lavasoft.de/
> http://www.lavasoftusa.com/
>
> * SpyBot Search and Destroy v1.4
> http://security.kolla.de/
>
> After the software is updated, I suggest scanning the system in Safe Mode.
>
> I also suggest downloading, installing and updating BHODemon for any
Browser Helper Objects
> that may be on the PC.
>
> * BHODemon
> http://www.definitivesolutions.com/bhodemon.htm
>
> For viral malware...
>
> * Download MULTI_AV.EXE from the URL --
> http://www.ik-cs.com/programs/virtools/Multi_AV.exe
>
> To use this utility, perform the following...
> Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
> Choose; Unzip
> Choose; Close
>
> Execute; C:\AV-CLS\StartMenu.BAT
> { or Double-click on 'Start Menu' in C:\AV-CLS }
>
> NOTE: You may have to disable your software FireWall or allow WGET.EXE to
go through your
> FireWall to allow it to download the needed AV vendor related files.
>
> C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
> This will bring up the initial menu of choices and should be executed in
Normal Mode.
> This way all the components can be downloaded from each AV vendor's web
site.
> The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and
Reboot the PC.
>
> You can choose to go to each menu item and just download the needed files
or you can
> download the files and perform a scan in Normal Mode. Once you have
downloaded the files
> needed for each scanner you want to use, you should reboot the PC into
Safe Mode [F8 key
> during boot] and re-run the menu again and choose which scanner you want
to run in Safe
> Mode. It is suggested to run the scanners in both Safe Mode and Normal
Mode.
>
> When the menu is displayed hitting 'H' or 'h' will bring up a more
comprehensive PDF help
> file.
>
>
> * * * Please report back your results * * *
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



Posted by Duane Arnold on November 20, 2005, 3:59 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> Hi!
> Now, I am done!
> It was the file "msupdate32.dll" that was responsible.
> Checking around a little in the net, I saw that there is a
> virus/trojan using the "msupdate32.exe" version. I just killed the
> process, and all was ok. Checking inside the file with Notepad, I
> could read the first url, probably the master in the DDoS atack.
> There also was the file "mspostsp.exe" with the samd date and
> timestamp: also renamed. Also, I found it in the registery at the key:
> [......\Winlogon\Notify\msupdate]
> "Dllname"="msupdate32.dll"........... deleted!
>
> I installed the ProcessExplorer in autostart. the I restarted with the
> network connected. Whe I saw the first dns call from the computer in
> the freeSCO firewall, I disconnected the LAN cable and let the machine
> work by it self.
> I took more that six hours before it was up and running!!! Then I
> could easyli see wich process that was taking all the cpu!
>
> Thanks for the help, David
>

I tell him about PE and I don't get any thanks.

LOL

Duane :)

Similar ThreadsPosted
SuperAntiSpyware calls Burn4Free file a Trojan April 14, 2008, 4:38 pm
New virus (price.cpl - Bagle varient) and current Virus-Total results September 12, 2005, 10:47 pm
Weird problem on Flash Drive seems like a virus but no virus detected August 28, 2007, 12:04 pm
Why the PC Virus cannot attack my XP? I am the administrator, I run ActiveX, No Firewall, No Virus Scanner..... January 14, 2008, 4:45 pm
List of the Virus makers's IP, there is one Virus maker in Bend Oregon with multiple IPs, scanning people computers for information. December 28, 2007, 6:36 am
KAV message "riskware not-a-virus:PSWTool.Win32.RAS.a", not a virus ? September 28, 2005, 10:52 am
How to create a simulated virus with a virus signature June 14, 2005, 1:14 am
Virus that closes anti-virus softwares January 11, 2007, 6:35 am
Mail Anti-Virus,alt.comp.virus January 16, 2008, 4:33 am
A virus that "AntiVir(tm) dosen`t want to delete..(in Mozilla.)/Ein Virus das Anti-Vir(tm) nicht löschen will..(unter Mozilla.) July 22, 2005, 12:03 pm

The site map in XML format XML site map

Contact Us | Privacy Policy