unauthorized remote http connections

Discussion in 'Malware Help (A Specialist Will Reply)' started by JBSCH, Feb 21, 2013.

  1. JBSCH

    JBSCH Private E-2

    I have recently been experiencing occasions where my MCPC (W7 64bit) was not being as responsive as it had in the past. I did some checking with MBAM and several of the McAfee tools but they did not report anything.

    However, I did find multiple unauthorized live http connections to my machine (with netstat - a) so I ran the Win Removal steps 1 thru 3. The first program, RogueKiller had some hits. It looks like a well hidden piece of maleware that I will need some help in clearing it up. Would really appreciate a review the attached results. I have not made any changes to the machine per instructions.

    I also have two other W7 64 machines on the same home LAN and a Vista 32. All of these are showing the same unauthorized connections. Could this malware be propagating to other machines via the LAN?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm sorry but you are not having malware problems. Your logs are clean.

    It is possible that McAfee is the source of your performance issues.
     
  3. JBSCH

    JBSCH Private E-2

    Thank you for the review. I appreciate that very much!
    I am still left with a puzzle as to why & where http connections like these are showing up on my machines:

    C:\Windows\system32>netstat -a
    Active Connections
    Proto Local Address Foreign Address State
    TCP 192.168.1.187:54027 107.14.45.56:http ESTABLISHED
    TCP 192.168.1.187:54165 107.14.45.43:http ESTABLISHED

    I see the 'Foreign Addresses' are assigned to Road Runner & we therefore share the same ISP but we are not geographically close to each other.
    Any suggestions on where I could start looking for a source?

    Once again thank you for volunteering your time to help the community.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Road Runner is providng your Internet Access. The below is what you IP maps to and I X out only your IP to keep it from being seen.

    cpe-xx-xxx-xxx-xxx.nycap.res.rr.com

    Notice the rr.com ;)
     
  5. JBSCH

    JBSCH Private E-2

    Today I fired up my XP laptop and found that it was also establishing connections to 107.14.xx.xx locations. I used the system restore to go back to December of last year. The MS automatic updates (36 of them) and McAfee took a chunck of time but after this I see no more of the 107.14.xx.xx connections.
    So I now know that some time after December I acquired a back door. Problem is how do I find It? I've run the 5 programs to scan this machine. Since this is the same problem that started this thread. should I start a new thread or not?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could just be a coincidence that these connections have gone away after the system restore. They could have been due to some software you had installed which is now no longer really in effect due to the system restore. Based on everything in your logs, there does not seem to be any infection to find. There were no indications of any problems and for the most part, we would have seen something.

    If it really bothers you have those connections, block that IP addess range with your firewall and see what happens. If it is for some software or for your ISP to get something to work, you should find out pretty soon after blocking them.
     
  7. JBSCH

    JBSCH Private E-2

    Still working on it. I'll keep an eye on the laptop and let you know if the issue on that machine is solved. McAfee doesn't appear to have a way of blocking a range of IP addresses like 107.14.xx.xx and as far as I can see my model of Netgear router (N600 WNDR3700V3) does not have this ability either. It gives me a way of putting individual URLs but not ranges of IPs. If you see a way of blocking using my equipment I'll give it a try.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't know as I don't use McAfee. See the manual somewhere ?;) Also can you just block a few individual addresses to see what happens. I'm still not convinced there are really any problems here.

    The manual is online.

    http://documentation.netgear.com/wndr3700v3/enu/202-10985-01/usermanual.pdf

    I would say maybe something around page 37 - may be helpful.
     
  9. JBSCH

    JBSCH Private E-2

    I have looked at the manual, in that section. From what I could see there does not appear to be any straight forward method of preventing outgoing and incoming traffic to & from a specific IP range. Any references to write ups would be appreciated.
    As a temporary fix i may have to go to each machine and try a PersistentRoute setup (ROUTE ADD).
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But what about what I suggested.... blocking specific IP addresses not ranges? And what about this>> https://www.mcafeeasap.com/Sc/Help/PageLevelHelp/Help/en-US/index.html#GUID-804BF10F-4ADB-4B53-89C2-163021CEB2F8.html

    Note as I stated earlier, I still do not see any problems in your logs and the MGlogs.zip file you attached had the output from netstat -a in the runkeys.txt log. There were no problems.
     
  11. JBSCH

    JBSCH Private E-2

    Unfortunately I am not using The SaaS Endpoint, just the McAfee products for home use. Since you have been able to confirm that my problem is not malware related, am going forward to look for other reasons why I these unwanted connections are established to my machines. Be happy to update you if we find the explanation.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay thanks! I suggest you talk with your ISP to find out if any of them are really due to them. As noted, they do show to be from RR.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds