firewall blocking loopback?

Discussion in 'Malware Help (A Specialist Will Reply)' started by SpecialFNK, Jul 16, 2005.

  1. SpecialFNK

    SpecialFNK Private First Class

    i have a Toshiba Techra 8000 laptop.
    i have windows 98.
    my firewall is Zone Alarm.
    my anti viris is AntiVir
    i use dial up connection.

    over the last week i think i have had something on my laptop.
    everytime i dial up and log online the first entry in my firewall log is an outgoing block. up until this past week i dont remember seeing anything ever blocked outgoing, everything has been incoming.
    now today ive noticed a few entries in my firewall log of blocking incoming of loopback.
    i did right click and more info and was givin this information.
    .
    "ZoneAlarm has successfully stopped Internet traffic from reaching your computer. No breach in your security has occurred. Your computer is safe.
    The data packet that ZoneAlarm blocked was sent from port 80 on a web server whose IP address is 127.0.0.1. This alert usually means that a previous connection between your computer and the web server was not completely or correctly shut down."

    this loopback has occured 3 times in a row within a minute without me disconnecting.

    i have done all the steps in the read me first and am still having these blocks.

    i havnt noticed any other problems with my laptop.
    would something be on my computer that is sending a message of some sort once i log online?
    is there any more information on what this loopback is and what it means?
    is there anything else i can download?
     
  2. SpecialFNK

    SpecialFNK Private First Class

    i was looking for someway to edit my post with new information but couldnt find an edit.. but now i have more information to add..

    i downloaded PestPatrol.
    i ran this and found 3 things..
    -flashget? ..i previously had flashget but have since deleted it
    -cydoor
    -CWS.GoogleMS.3

    i ran Spybot Search and Destroy again, and that removed the cydoor.
    while i was running Spybot an error message popped up that said this..
    there were problems in the include file \program files\spybot_search_destroy\include/hijackers.sbi
    see 'include errors.log' for details.

    i looked for errors.log but could not find such a name/file.

    what is CWS.GoogleMS.3 ?? i assume this is something to do with cool web search?
    i have CWShredder. i did and update and ran this, but it nothing was found.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Last edited: Jul 17, 2005
  4. SpecialFNK

    SpecialFNK Private First Class

    i downloaded the newest version of Spybot, did an upate, ran that, and everything worked fine and came up clean.

    the CWS only came up when running pest patrol.
    i did an upate of pest patrol, ran that, and everything came up clean. ill assume that was a false posative.

    i still think there must be something on my lap top that is causing an outgoing block to appear right after i connect online because it never used to do that up until this past week.
    i also sometimes still get this loopback whatever that is.

    my firewall does say these are blocked so as far as i know everything is clean. nothing is slower and my browser works normally.

    i only downloaded pest patrol recently hoping to actually find something so i could know what is causing this outgoing block and remove it.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Loopback - The IP address 127.0.0.1 is used as the loopback address. This means that it is used by the host computer to send a message back to itself. It is commonly used for troubleshooting and network testing.


    Did you setup something to ping yourself? Does anything show in your HJT log that has 127.0.0.1 in it? Have you installed any new software or hardware recently (within the last couple weeks)?
     
  6. SpecialFNK

    SpecialFNK Private First Class

    i did hijackthis again and didnt notice anything with 127.0.0.1
    couple things i did notice.. i have 2 lines that say 08 extra context menu item: download using flashget. i dont have flashget anymore so can i check mark these and fix them which will remove them?

    i havnt set up anything to ping myself, im not even sure if i would know how.
    i havnt installed anything new recently.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can fix those lines left owver from Flashget.
     
  8. SpecialFNK

    SpecialFNK Private First Class

    i removed those 2 items of flashget from the hijackthis, yet when i do pest patrol it still shows an item of this flashget.
    the item says..
    Category: Browser Helper Object
    In Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{A5366673-E8CA-11D3-9CD9-0090271D075B}
    i also have this same line in my hijackthis..
    the line is- 02 BHO: (no name) {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
    i assume with these numbers/letters matching this is also flashget, and i can remove this?

    ive also noticed something else the last few days.
    everytime i shut down my laptop or restart it, it wont shut down. it just freezes the screen on the background for my desktop without showing the icons, just the background shows. all i can do then is hit the power bar because nothing else works, not even Ctrl Alt Del
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can try having HJT fix the O2 line but it may not remove it. We have seen dozens of problems like that. Sometimes you can just delete the registry key (the one you gave) manually and that works. Other times, even doing that does not work.

    Another solution that sometime works is to reinstall the application (FlashGet) and then uninstall it properly the next time (that is assuming the uninstall was not done correctly the first time).

    The shut down problem you mentioned does not sound like malware but since it just started, have run the cleaning procedures to look for anything?
     
  10. SpecialFNK

    SpecialFNK Private First Class

    i used HJT and removed that line of flashget and it is now gone from HJT and pest patrol.

    i have restarted my laptop now a few times and no longer have the freezing problem, so ill assume this is fixed.

    i still do have this block outgoing in my firewall.
    my firewall does say this is blocked and my laptop is safe, but i would still like to find something and know what this is and have it stop.
    i guess im paranoid that this block outgoing is some type of signal trying to be sent out notifying someone else that im online.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Any number of programs could be doing it. Look in your log, it should tell you the program that is send the Outgoing message.
     
  12. SpecialFNK

    SpecialFNK Private First Class

    ive restarted/shut down my laptop a few times and ive had the freezing again.
    today ive done CCleaner and then did a shut down/restart and this time i didnt have any freezing.
    is this normal? everytime i shut down i should use CCleaner before i shut down?

    i changed one setting in my Zone Alarm firewall.
    in the section Firewall under Trusted Zone Security i changed it from medium to high.
    i connected a few times online and now ive noticed 2 different outgoing blocks.
    the first one is the same one ive been getting before.
    it doesnt give much information about it. the program space is blank, the protocol is UDP, source DNS is computer, the destination DNS is blank.
    the website information says the same as ive been getting.. "computer attempted to connect to port 137 on another computer, located at address 149.99.255.255."
    under technical info it says- "Link Layer Protocol, Ethernet, The protocol that allows two directly linked computers to share a network cable." i dont share any type of network with anyone else or any other computers that im aware of.


    i also have this other outgoing block right after iv connected a few different time now with destination DNS- ALL-ROUTERS.MCAST.NET, destination IP is always 224.0.0.2 , protocol is ICMP(type:10/subtype:0)
    i right clicked for more info and it says this..
    " ZoneAlarm prevented your computer from sending an Internet Control Message Protocol (ICMP) message. The type of this ICMP message was Router Solicitation (10). As part of its protection policy, ZoneAlarm blocked this message."
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see a current HJT log.

    Note the 224.0.0.2 address is a multicast IP address. Do use any kind of video stuff on this PC? Even if you download or video broadcasts from your ISP. This could be a IGMP join message to a video server.

    And your other message is communication with your ISP as I already told you in the previous thread you had for a similar problems. You are simply looking for problems that do not exist. These are all normal expect communications.
    Code:
     
    [url="http://samspade.org/t/whois?a=149.99.255.255;server=auto"][color=#0000ff]149.99.255.255[/color][/url] = [ ] 
     
    OrgName:	Sprint Canada Inc. 
    OrgID:	 SPCA 
    Address:	2550 Victoria Park Ave. 
    Address:	Suite 200 
    City:	 Toronto 
    StateProv: ON 
    PostalCode: M2J-5E6 
    Country:	CA 
    NetRange: [url="http://samspade.org/t/whois?a=149.99.0.0;server=auto"][color=#0000ff]149.99.0.0[/color][/url] - [url="http://samspade.org/t/whois?a=149.99.255.255;server=auto"][color=#0000ff]149.99.255.255[/color][/url] 
    CIDR:	 149.99.0.0/16 
    
     
  14. SpecialFNK

    SpecialFNK Private First Class

    i dont use any type of video stuff. i dont play movies or video games or anything like that.
    i still have the outgoing block of ALL-ROUTERS.MCAST.NET

    im including HJT log from this morning.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As suspected, your log is still clean.

    As far as I can tell you have no problems. The outgoing message is somethings that Windows sends at startup to look for multi-cast servers. This address is a valid address for any multi-cast server that may be out there. But at anyrate, since your firewall blocks it, it does not present any problems anyway.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds