Memory Down, Firewall Showing Alarming Outgoing Traffic Level

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by AngelsWilliam, Apr 9, 2010.

Thread Status:
Not open for further replies.
  1. AngelsWilliam

    AngelsWilliam Private First Class

    Hiya.
    About a week ago, my laptop told me there was a Super Anti-spyware program update, so I did all the usual stuff it asks me to do. Thing is, when the update finished, SAS didn't restart. In fact, when I started it manually, it still showed the previous version. Oh, shit.

    So, I went to your download site to see if there actually had been an update. There had, but it had been on April 2, not April 5, like this notification I got had said. Double shit.

    Well, I downloaded the legitimate version...and while I was at it, I downloaded the XP cleaning procedure routine, too, just in case. I also checked to see if Malware Bytes had been updated since I had last gotten a program update. It hadn't.

    Anyway, I uninstalled SAS from my laptop, ran CCleaner & its registry cleaner, then reinstalled SAS and repeated what I'd done with CCleaner. Then I checked for SAS updates and ran it. It didn't find anything.

    I then went with the rest of the XP cleaning procedure. MBAM didn't find anything. I'm not sure how to read Combofix or MGTools, but RootRepeal found something this time.

    But, things seemed to be behaving after I did the routine, so I didn't turn in my logs. Then, this morning, I noticed my memory (doubled in size to 1GB at one of your staff's suggestion) was down in the yellow (monitored with FreeRAM XP Pro). I opened task manager to see if legitimate programs were using memory. It was Windows Defender, Windows Update Client, and the new Avast version...but I noticed that the Avast processes weren't the same ones I was used to...

    ...I also noticed at the same time that one side of my firewall indicator was going nuts. I don't know which side is which, so I thought I'd better open the user interface and check if there was an update coming in before I shut down the laptop to go downstairs.

    It wasn't incoming traffic. It was outgoing traffic. Lots and lots of outgoing traffic. Like, 10,000 every second.

    I told myself to remain calm; it was probably just because I'd selected to participate in the Avast community, so I opened Avast and unchecked that option. I then pulled out my wireless card and put it back in. I watched the firewall indicator for a bit. It started to flicker...and after about 2 minutes, data started pouring out of my computer again.

    He-e-e-e-e-ell, no!

    Help, please? (My apologies to Tim, whom I promised I'd stay away for a while. *wink*) My first 4 logs are attached; MGTools to follow. Thanks so much!
     

    Attached Files:

  2. AngelsWilliam

    AngelsWilliam Private First Class

    Okay, here's the MGlogs.zip. Thank you again for your help! My laptop is my life!!! Without it, I can't read myself to sleep and listen to my soothing music to help me sleep.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not having malware problems. Your logs are all clean.
     
  4. AngelsWilliam

    AngelsWilliam Private First Class

    Is there another forum I should go to, then? I've got 1G memory, and it's going down to less than 300M free. I've already set Defender so it doesn't scan its own folder, so that's not the issue.

    I'm not discrediting your assessment; I'm just saying I'm not happy with my computer's performance and thought some of it behaved like malware symptoms, particularly the heavy outgoing traffic.

    Other memory (?) issues:
    Sometimes the DVD player freezes everything, even when I have the wireless card unplugged and the firewall and Avast disabled. And, it's not because of the program or a bad drive or a bad DVD because at other times the program and drive work just fine...and I've had some bad DVDs, so I know what that looks like/sounds like.

    Whenever iTunes switches songs, I can't do anything on the computer until it gets to the next song. This is true with all computers, though, so I assume this is an iTunes issue. Love the program, hate its little quirks.

    Other concerns:
    What the hell is all that stuff leaving my computer so fast? And where the hell is it going?

    I checked the ports listed in my firewall using NeoTraceIt, and they're listed as SBCGlobal (our DSL carrier, though I thought they'd been bought out by AT&T), Network Solutions, and Microsoft. I recognize all those names, but I think I'm remembering Network Solutions was my former job's network. Do you recognize that name?

    Thanks for your help. Please let me know where to take the above concerns. At least I know I can use my laptop again. It's kinda my lifeline. Well, not really, but...now that I have it, I always feel lost without it when I don't have it. You know how it is....

    Thanks again,
     
  5. AngelsWilliam

    AngelsWilliam Private First Class

    Ooooo-kaaaaaay....when I was installing the new version of iTunes, Windows Defender came up with a warning that there were 4 unknown authors trying to access/start/whatever stuff having to do with the winsock files and whatnot. I'd give you the information, but somehow my System Restore function got turned off, and the quarantined items in Windows Defender got deleted even though Windows Defender isn't checked in CCleaner.

    Anyway, I can now no longer access the Interwebs via my laptop, even though Avast is still getting database updates, I still show "Very Good" wireless connection, and my firewall indicator is still showing lots of activity.

    But, I can't get anything to come up in Firefox, I can't update SAS or MBAM, and I'd already done the MGClean process because you said my logs were clean. So, if I can't access your site via my laptop, what do I do? I mean, I can get the SAS and MBAM updates on a flash drive and get them on my laptop that way, but Combofix needs the Internet to work....Does MGT, too?

    I know my local guy used to have this tool called Winsock Fix he'd have me click on whenever something like this happened, but I have gone through 2 Windows version updates since then.

    HAAAAAAAAAAAAAAAAAALP!

    From my desktop,
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Software Forum or Networking Forum if you want to check outgoing packets. You could use a tool likeWireshark to view/capture outgoing and incoming packets to see if you can determine the source of your traffic.

    Not based on your logs. There was only one file that I question what it is and that is the below which looked like something you added to FireFox. If you do not know what this is, perhaps you should remove it.

    2010-04-05 13:54 . 2004-08-19 02:39 36864 -c--a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\7uvxe0eo.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\IEMenu.exe

    You can run additional scans if you wish like online scanners and also some other rootkit scans given in the link below, but likely will not find anything that is a real problem:

    Alternative Scans

    Not topics for the Malware Removal Forum.


    Network Soultions is a web hosting company from what I remember.
     
    Last edited: Apr 13, 2010
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Problems caused by installing new software and then blocking the changes it needs to make are not issues for the Malware Forum. You should post in the Software Forum.

    You may want to just try using System Restore to go back to the point before you tried to install the new iTunes, but this is just a suggestion and not a topic for this forum.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds