05-26-2009 11:31 AM
Encountered this on a pc running up to date NIS2009. Full system scan finds nothing. Should NIS2009 defs find/fix this? It continually tries to connect to this site on port 8653. See ThreatExpert report.
http://www.threatexpert.com/report.aspx?uid=a215e3
How can I remove this garbage?
05-26-2009 11:45 AM - edited 05-26-2009 12:06 PM
Hi i7 -
Weird! It should, judging by the older date of this.
Download, Install and Update - Malwarebyte's AntiMalware - www.malwarebytes.org - disconnect from the Internet and run a complete system scan.
Let's see if MBAM picks it up and throws it into Quarantine. If so, then delete it.
Did *you* submit this to ThreatExpert? Additionally, If you can get to the actual file also submit it at:
https://submit.symantec.com/websubmit/retail.cgi
Let us know what the result is.
![]()
Compumind
NIS 2009, XP-SP3, Vista-SP2, IE 8
05-26-2009 12:08 PM
05-26-2009 12:11 PM - edited 05-26-2009 12:12 PM
Hi i7 -
Ok. Let's then try this:
http://www.emsisoft.com/en/software/stick/
We will evaluate from there.
TIA ![]()
Compumind
NIS 2009, XP-SP3, Vista-SP2, IE 8
05-26-2009 12:13 PM - edited 05-26-2009 12:14 PM
Try a Hijackthis log to see if there is anything it was attached to that might still be there. When you ran the MBAM did you disable system restore?
http://www.trendsecure.com/portal/en-US/tools/secu
You could paste it here for one of the pros to have a look at.
05-26-2009 12:19 PM - edited 05-26-2009 12:24 PM
Hi i7 -
The 8653 port is a valid TCP, UDP number.
How do you *know* that it is trying to connect, if NIS 2009 (and others) do not detect it?
Please also visit this site and run all the Port tests - https://www.grc.com/x/ne.dll?bh0bkyd2 - are these in "stealth" mode?
Again, let us know. We will check the System Restore Points, after this is complete.
Thanks.
![]()
Compumind
NIS 2009, XP-SP3, Vista-SP2, IE 8
05-26-2009 12:49 PM
Firewall logs show the connection occurs every 2min. Netstat also shows the outgoing connection on port 8653. Have captured the IP it is going to (in China). Connection is through a router. NIS firewall is not blocking it.
Will not have access to the infected computer until later today.
05-26-2009 12:51 PM
Hi i7 -
OK. Please let us know.
BTW - What operating system are you using?
![]()
Compumind
NIS 2009, XP-SP3, Vista-SP2, IE 8
05-26-2009 12:53 PM
05-26-2009 12:56 PM - edited 05-26-2009 01:00 PM
Hi I7 -
Good - so please follow the steps in order (that you have not done yet) so we could isolate and eradicate.
Look forward to hearing from you.
TIA
![]()
BTW - has any "weird" software been installed on this computer, lately?
Compumind
NIS 2009, XP-SP3, Vista-SP2, IE 8
