Re: Unknown svchost.exe DNS port 53 network activity

Re: Unknown svchost.exe DNS port 53 network activity

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Re: Unknown svchost.exe DNS port 53 network activity David H. Lipman 12-20-2006
Posted by David H. Lipman on December 24, 2006, 9:05 am
If you were  Registered and logged in, you could reply and use other advanced thread options


|
| OK, I downloaded and ran all the software. While Ad-Aware was running I
| get a warning from AntiVir that it had found a virus called
| Run_it_xxx.exe. I deleted it. Other than that, they came up with a few
| minor viruses on some files that have been on my PC for ever. I
| quarantined them. I also made sure I have all the Windows security
| updates, and I do except for a RAID driver. I also upgraded to IE 7
| just to be sure. The problem still persists.
|
| I installed a program called Prevx1 which seems to be a nice program.
| It tells you when an application starts ends etc. Every time I
| disconnect and reconnect the network connection, it tells me that a
| program called MOBSYNC.EXE has started. I'm not sure if this is
| related.
|
| Also, the network connection seems to be active only at certain times
| and inactive otherwise. When it's active it goes like crazy. I'm
| suspicious that the PC is being used for DOS attacks or SPAM etc.
|
| I'm still at a loss and any help will be appreciated. The only way I
| can fight this is by unplugging the network connection.
|
| Also, I recently configured reverse DNS lookup for my static IP address
| through my ISP. Can this be related to the network activity?
|
| Raffi

MOBSYNC.EXE is most likely legit and OK.

This may have to do with the RDNS service.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Raffi on December 26, 2006, 4:26 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

David H. Lipman wrote:
>
>
> |
> | OK, I downloaded and ran all the software. While Ad-Aware was running I
> | get a warning from AntiVir that it had found a virus called
> | Run_it_xxx.exe. I deleted it. Other than that, they came up with a few
> | minor viruses on some files that have been on my PC for ever. I
> | quarantined them. I also made sure I have all the Windows security
> | updates, and I do except for a RAID driver. I also upgraded to IE 7
> | just to be sure. The problem still persists.
> |
> | I installed a program called Prevx1 which seems to be a nice program.
> | It tells you when an application starts ends etc. Every time I
> | disconnect and reconnect the network connection, it tells me that a
> | program called MOBSYNC.EXE has started. I'm not sure if this is
> | related.
> |
> | Also, the network connection seems to be active only at certain times
> | and inactive otherwise. When it's active it goes like crazy. I'm
> | suspicious that the PC is being used for DOS attacks or SPAM etc.
> |
> | I'm still at a loss and any help will be appreciated. The only way I
> | can fight this is by unplugging the network connection.
> |
> | Also, I recently configured reverse DNS lookup for my static IP address
> | through my ISP. Can this be related to the network activity?
> |
> | Raffi
>
> MOBSYNC.EXE is most likely legit and OK.
>
> This may have to do with the RDNS service.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm

I had some time to do packet analysis using Etherial and most of the
conenctions were DNS queries and SMTP connections.

I went ahead and blocked all traffic from the PC to the ISP DNS servers
in my firewall (Comodo). The DNS server for my PC is statically defined
as the gateway router. Since the ISP DNS was no longer accessible it
rerouted the DNS queries (and/or query responses) to the gateway
router. These were a bunch of MX queries for mostly .ru domains.

Next I blocked all inbound and outbound UDP connections for svchost.exe
and services.exe. This stopped most of the traffic. After a while I
started seeing traffic to a couple of specific ip addresses
(208.66.195.78 and 62.189.194.215) which don't resolve to anything with
nslookup. I blocked these IP addresses in the firewall as well. Next
the PC started sending out a bunch of broadcasts (.255). So I blocked
outbound broadcast connections.

Next it started sending broadcast to 0.255 using the ZIP (Zone
Information Protocol) protocol. I don't think I've seen this one
before. I haven't been able to block these yet.

My guess is the PC is somehow being used as a DNS/SMTP relay. Another
guess is my svchost.exe and/or services.exe have been compromized.

As usual, any help in getting to the bottom of this would be welcome.

Raffi


Posted by David H. Lipman on December 26, 2006, 4:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options



| I had some time to do packet analysis using Etherial and most of the
| conenctions were DNS queries and SMTP connections.

| I went ahead and blocked all traffic from the PC to the ISP DNS servers
| in my firewall (Comodo). The DNS server for my PC is statically defined
| as the gateway router. Since the ISP DNS was no longer accessible it
| rerouted the DNS queries (and/or query responses) to the gateway
| router. These were a bunch of MX queries for mostly .ru domains.

| Next I blocked all inbound and outbound UDP connections for svchost.exe
| and services.exe. This stopped most of the traffic. After a while I
| started seeing traffic to a couple of specific ip addresses
| (208.66.195.78 and 62.189.194.215) which don't resolve to anything with
| nslookup. I blocked these IP addresses in the firewall as well. Next
| the PC started sending out a bunch of broadcasts (.255). So I blocked
| outbound broadcast connections.

| Next it started sending broadcast to 0.255 using the ZIP (Zone
| Information Protocol) protocol. I don't think I've seen this one
| before. I haven't been able to block these yet.

| My guess is the PC is somehow being used as a DNS/SMTP relay. Another
| guess is my svchost.exe and/or services.exe have been compromized.

| As usual, any help in getting to the bottom of this would be welcome.

| Raffi

http://www.dnsstuff.com/tools/whois.ch?ip=!NET-208-66-195-64-1&server=whois.arin.net

http://www.dnsstuff.com/tools/whois.ch?ip=62.189.194.215&email=on


This is suspicious.

You may have to backup the PC, wipe it and then reinstall the OS from scratch if
all the
csnas have come up negative.

The only other option is to use anti RootKit software such as Gmer and
BlackLight to find
the malware. Otherwise, wipe the system.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Grzegorz Wiktorowski on December 26, 2006, 6:11 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>
> The only other option is to use anti RootKit software such as Gmer and
> BlackLight to find
> the malware. Otherwise, wipe the system.
>

Try Sysinternals RootkitRevealer. Also I suggest to visit Sysinternals -
Malware forum at:

http://forum.sysinternals.com/forum_topics.asp?FID=18

--
Grzegorz Wiktorowski




Posted by Raffi on December 27, 2006, 1:21 am
If you were  Registered and logged in, you could reply and use other advanced thread options
David H. Lipman wrote:
>
>
>
> | I had some time to do packet analysis using Etherial and most of the
> | conenctions were DNS queries and SMTP connections.
>
> | I went ahead and blocked all traffic from the PC to the ISP DNS servers
> | in my firewall (Comodo). The DNS server for my PC is statically defined
> | as the gateway router. Since the ISP DNS was no longer accessible it
> | rerouted the DNS queries (and/or query responses) to the gateway
> | router. These were a bunch of MX queries for mostly .ru domains.
>
> | Next I blocked all inbound and outbound UDP connections for svchost.exe
> | and services.exe. This stopped most of the traffic. After a while I
> | started seeing traffic to a couple of specific ip addresses
> | (208.66.195.78 and 62.189.194.215) which don't resolve to anything with
> | nslookup. I blocked these IP addresses in the firewall as well. Next
> | the PC started sending out a bunch of broadcasts (.255). So I blocked
> | outbound broadcast connections.
>
> | Next it started sending broadcast to 0.255 using the ZIP (Zone
> | Information Protocol) protocol. I don't think I've seen this one
> | before. I haven't been able to block these yet.
>
> | My guess is the PC is somehow being used as a DNS/SMTP relay. Another
> | guess is my svchost.exe and/or services.exe have been compromized.
>
> | As usual, any help in getting to the bottom of this would be welcome.
>
> | Raffi
>
>
http://www.dnsstuff.com/tools/whois.ch?ip=!NET-208-66-195-64-1&server=whois.arin.net
>
> http://www.dnsstuff.com/tools/whois.ch?ip=62.189.194.215&email=on
>
>
> This is suspicious.
>
> You may have to backup the PC, wipe it and then reinstall the OS from scratch
if all the
> csnas have come up negative.
>
> The only other option is to use anti RootKit software such as Gmer and
BlackLight to find
> the malware. Otherwise, wipe the system.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm

Update - I had tried a couple of rootkit detection software without
success and had given up. But gmer finally found it. Turns out it is a
rootkit. It's called Backdoor.Rustock.B. It uses the following hidden
data stream c:\windows\system32:lzx32.sys (c:\windows\system32:18467).
This Symantec website has more information:
http://www.symantec.com/security_response/writeup.jsp?docid=2006-070513-1305-99&tabid=3

The syptoms for the rootkit are similar to what I'm experiencing. From
what I've read so far it might be tricky to get rid of. It seems to be
active in safe mode as well. I'll be searching for a way to get rid of
it. If there are any ideas out there, please let me know.

Thanks for all the help.
Raffi


Similar ThreadsPosted
Unknown download activity in background - how to determine what it is? July 28, 2007, 3:51 am
my network server has a virus and i can not conect to the network. November 1, 2008, 6:19 pm
svchost.exe virus? January 16, 2007, 5:19 pm
Strange svchost.exe April 23, 2008, 8:54 am
Modified svchost.exe November 9, 2008, 5:46 am
C:\WINDOWS\SYSTEM32\SVCHOST.EXE August 7, 2006, 6:00 pm
Help! Fake svchost.exe on my computer October 6, 2006, 7:27 am
What is C:\WINDOWS\system32\svchost.exe December 8, 2006, 10:03 pm
SMTP Trojan uses SVCHOST on W2K Pro November 4, 2008, 1:23 pm
Port log April 22, 2008, 2:54 am

The site map in XML format XML site map

Contact Us | Privacy Policy