DNS calls to Ukraine destinations

DNS calls to Ukraine destinations

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
DNS calls to Ukraine destinations Gary S. Terhune 09-24-2006
Posted by Gary S. Terhune on September 28, 2006, 11:29 am
If you were  Registered and logged in, you could reply and use other advanced thread options
It's a 017 item in HJT, Steve, (actually, three or four nearly identical
items)involving some entries that include the rogue IPs, in
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces.

But I can't get to the machine until later today or this evening. Don't seem
to have saved a copy of the HJT report anywhere else. I figure I'm also
close to or past the line where I won't be able to do much on it simply
because I'm working on it remotely. David's Multi_AV was plenty fun already.
It came up with a few things, but not what I'm looking for. This one is
still trying to ping those DNS servers about once per second, each IP.

--

Gary S. Terhune
MS-MVP Shell/User

> Dan,
>
> Still haven't heard from Gary yet. If the malware is not a RootKit then
> we'll get that link posted here. If it is an RK, then we'll have to take
> this to a private thread to block RK writers from observing which tool and
> version is used to remove it. That's what it's come down to lately.
> But if Gary ever contacts us, we'll have him provide you with any info you
> need.
> Hope you understand ;)
>
> MowGreen [MVP 2003-2006]
> ===============
> *-343-* FDNY
> Never Forgotten
> ===============
>
>
> Dan wrote:
>> MowGreen wrote:
>>>>> the ISA logs show this machine making repeated calls on DNS protocol,
>>>>> port 53, to two different IPs that belong to a web hosting company in
>>>>> the Ukraine. I can't help but think that this is malware in action,
>>>>> but can't determine what is doing it.
>>>
>>> Gary,
>>>
>>> As long as you can keep the malware blocked, post the log to the
>>> HijackThis Forum at AumHa:
>>> http://aumha.net/viewforum.php?f=30
>>>
>>> We'll call in the "Experts" if need be and at least identify the
>>> malware, the risk from it, and who's hosting it.
>>>
>>> I'll BCC this. Email me when you post the HJT log and please, provide us
>>> with the IPs, too.
>>>
>>>
>>> MowGreen [MVP 2003-2006]
>>> ===============
>>> *-343-* FDNY
>>> Never Forgotten
>>> ===============
>>>
>>>
>>> Gary S. Terhune wrote:
>>>> I have an XP Pro box on an SBS network (one SBS Premium server w/ ISA
>>>> 2004,
>>>> two XP Pro clients.) The box was heavily infected by numerous viruses
>>>> and
>>>> other malware on 9/11. Issues with antivirus installation resulted in
>>>> its
>>>> not updating for some time, but I'm not certain just how it all got
>>>> started.
>>>> Far as I can tell, none of it got to any of the other machines on the
>>>> network,
>>>>
>>>> I cleaned up using various AV and anti-spyware tools (AdAware, Spybot,
>>>> Trend-Micro AV) and it seems to be healthy now, but the ISA logs show
>>>> this
>>>> machine making repeated calls on DNS protocol, port 53, to two
>>>> different IPs
>>>> that belong to a web hosting company in the Ukraine. I can't help but
>>>> think
>>>> that this is malware in action, but can't determine what is doing it.
>>>> The
>>>> ISA firewall is blocking the requests, but I'd like to know what's
>>>> going on.
>>>> Any ideas on how to trace this? I can't find anything in running
>>>> processes
>>>> that isn't supposed to be there. Note that these calls are being made
>>>> even
>>>> when nobody is logged on to the machine. They're averaging one per
>>>> second.
>>>>
>>
>> Well, I hope Gary will provide the link to the HiJack This website in
>> this newsgroup so that other users like me can see what potential malware
>> is in the HiJack This log. Gary, if you do not want to post here then
>> you know my email and please email me where you posted the Hijack This
>> log and thanks in advance because I appreciate all you do for these
>> newsgroups.



Posted by MowGreen on September 28, 2006, 1:21 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Email the HJT log, Gary. There are several malwares that will show the
017 entry connections to DNS'.
Please include the IP addys, too.


MowGreen [MVP 2003-2006]
===============
*-343-* FDNY
Never Forgotten
===============


Gary S. Terhune wrote:
> It's a 017 item in HJT, Steve, (actually, three or four nearly identical
> items)involving some entries that include the rogue IPs, in
>
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces.
>
> But I can't get to the machine until later today or this evening. Don't seem
> to have saved a copy of the HJT report anywhere else. I figure I'm also
> close to or past the line where I won't be able to do much on it simply
> because I'm working on it remotely. David's Multi_AV was plenty fun already.
> It came up with a few things, but not what I'm looking for. This one is
> still trying to ping those DNS servers about once per second, each IP.
>

Posted by Gary S. Terhune on September 29, 2006, 1:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Sorry, Steve. Had a bad day yesterday. I'll see if I can complete even this
simple task today. Other machine on the network is also going to need major
cleaning up, judging by the wife's mumbling this morning. Headed to Aumha
now...

--

Gary S. Terhune
MS-MVP Shell/User

> Email the HJT log, Gary. There are several malwares that will show the 017
> entry connections to DNS'.
> Please include the IP addys, too.
>
>
> MowGreen [MVP 2003-2006]
> ===============
> *-343-* FDNY
> Never Forgotten
> ===============
>
>
> Gary S. Terhune wrote:
>> It's a 017 item in HJT, Steve, (actually, three or four nearly identical
>> items)involving some entries that include the rogue IPs, in
>>
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces.
>>
>> But I can't get to the machine until later today or this evening. Don't
>> seem to have saved a copy of the HJT report anywhere else. I figure I'm
>> also close to or past the line where I won't be able to do much on it
>> simply because I'm working on it remotely. David's Multi_AV was plenty
>> fun already. It came up with a few things, but not what I'm looking for.
>> This one is still trying to ping those DNS servers about once per second,
>> each IP.
>>



Posted by MowGreen on September 29, 2006, 4:37 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
NP. Ping me when you post. I haven't seen it yet.

MG

Gary S. Terhune wrote:
> Sorry, Steve. Had a bad day yesterday. I'll see if I can complete even this
> simple task today. Other machine on the network is also going to need major
> cleaning up, judging by the wife's mumbling this morning. Headed to Aumha
> now...
>

Posted by Gary S. Terhune on October 4, 2006, 8:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Just to bring this up to date, I used HJT to remove the entries and have yet
to see any evidence further activity, nor any return of the Registry
entries. Gonna check again tonight to be sure. I'll also try to post update
to Aumha.org, though I can't seem to log on there.

--
Gary S. Terhune
MS MVP Shell/User

> NP. Ping me when you post. I haven't seen it yet.
>
> MG
>
> Gary S. Terhune wrote:
> > Sorry, Steve. Had a bad day yesterday. I'll see if I can complete even
this
> > simple task today. Other machine on the network is also going to need
major
> > cleaning up, judging by the wife's mumbling this morning. Headed to
Aumha
> > now...
> >




The site map in XML format XML site map

Contact Us | Privacy Policy