BleepingComputer.com: Return of the attempts to "dial out"

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Return of the attempts to "dial out"

#1 User is offline   okiewild 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 64
  • Joined: 30-March 09

Posted 07 April 2011 - 09:29 AM

I've posted on this topic once before. I'm back because the previous suggestion that I examine the log for an unauthorized process didn't yield any results, and my configuration has changed since then.

For security, I use Malwarebyte's Anti-Malware and ESET Smart Security. And the Windows firewall.

Here's the problem. I sporadically use BitTorrent. Whenever it's active, MBAM keeps popping up messages that it blocked attempts by something on my system to connect to a hazardous website. The IP address varies. (If I'm not imagining things, I seem to remember that the attempts to "dial out" once in the past continued even after I had fully exited BitTorrent.)

When this happened recently, I ran in-depth scans of both drives with MBAM and ESET. Didn't find anything. I re-installed SuperAntispyware Professional (ESET's installer had told me not to have another similar product installed) and ran a full scan. All it found was more than 200 tracking cookies (ESET didn't catch that!) and a remnant (in the registry) of a piece of malicious software that had been removed by another product.

There are still outgoing attempts. One popped up just as I was typing this. I'm stumped.

This post has been edited by hamluis: 07 April 2011 - 11:19 AM
Reason for edit: Moved from XP to Am I infected.


#2 User is online   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,381
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 07 April 2011 - 09:36 AM

Can you post the exact error messages and maybe screenshots?

When I hear the terms "dial out" I think of a 56K dial Up Modem and IE being improperly configured.

This post has been edited by cryptodan: 07 April 2011 - 09:36 AM


My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#3 User is offline   okiewild 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 64
  • Joined: 30-March 09

Posted 07 April 2011 - 09:52 AM

Sorry for the misleading verbage. There's no modem in my setup. I'm attaching a small screen capture.

Attached File  outgoing.gif (7.28K)
Number of downloads: 3

YIPES, I just realized I posted in the Windows XP section. I thought my BleepingComputer bookmark defaulted to the spyware section. Is there some way I can move my thread or is that up to the moderators?

EDIT: Moved to Am I Infected forum ~ Hamluis.

This post has been edited by hamluis: 07 April 2011 - 11:20 AM


#4 User is online   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,381
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 07 April 2011 - 01:14 PM

How do you exit Bit Torrent?

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#5 User is offline   okiewild 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 64
  • Joined: 30-March 09

Posted 07 April 2011 - 06:14 PM

By going to the top left drop down menu named "File" and choosing the lower-most option "Exit." I just tested this, launching and exiting BitTorrent, then opening the Task Manager to see if there were any possible BitTorrent processes running. Of course process names can vary, but nothing there seemed related.

#6 User is online   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,381
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 07 April 2011 - 06:52 PM

Can you take a screenshot of your task manager, and post it here?

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#7 User is offline   okiewild 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 64
  • Joined: 30-March 09

Posted 07 April 2011 - 10:03 PM

Actually, I was just thinking about going into the ProcessExplorer utility, because I thought I saw some new items there I couldn't identify. But I'll hold off until you all take a look at this first. Your sharp eyes may spot something right away that would take me an hour to figure out. This is actually two screen captures pasted together so you can see everything revealed after I scroll down through the manager.

Posted Image

#8 User is online   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,381
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 07 April 2011 - 11:22 PM

Can you show all processes from all users?

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#9 User is offline   okiewild 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 64
  • Joined: 30-March 09

Posted 08 April 2011 - 01:28 PM

Not sure how to answer that. I'm the only user on this PC, and I run from the administrator account. Of course, there's a guest account. Also an unused account using just my first name, that I created after being told it might not be such a good idea to always work from the admin account. If you need to see those two process lists, do I assume correctly that I just log into them and do a screen capture there?

#10 User is online   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,381
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 08 April 2011 - 02:09 PM

Do you see the box at the very bottom that says show processes from all users? You check that box.

Also what Bit Torrent client do you use?

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#11 User is offline   okiewild 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 64
  • Joined: 30-March 09

Posted 08 April 2011 - 06:04 PM

BitTorrent 7.2 (build 232926)
note: the instant I launched BitTorrent to get this information, there was an attempt to reach a dangerous website, blocked by MBAM.

Posted Image

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users