i got infected with a backdoor trojan - interesting observation...

TuffGuy

Diamond Member
Jul 6, 2000
6,478
0
76
A couple of weeks ago I had to reformat my drive and I forgot to install NAV and ZoneAlarm. A few days ago my CuteFTP stopped working. So I installed ZoneAlarm and NAV today. The file C:\windows\system\winlogon.exe keeps trying to access the internet. It's destination address is 207.68.172.253:HTTP. Looking that up I get:

Whois information for 207.68.172.253


NETWORK: NETBLK-MSN-BLK [20480]
MSN (NETBLK-MSN-BLK)
One Redmond Way
Redmond, WA 98052
US

Netname: MSN-BLK
Netblock: 207.68.128.0 - 207.68.207.255
Maintainer: MSN

Coordinator:
Microsoft (ZM39-ARIN) noc@microsoft.com
425-936-4200

Domain System inverse mapping provided by:

DNS1.CP.MSFT.NET 207.46.138.20
DNS2.CP.MSFT.NET 207.46.138.21
DNS1.TK.MSFT.NET 207.46.232.37
DNS1.DC.MSFT.NET 207.68.128.151
DNS1.SJ.MSFT.NET 207.46.97.11

Record last updated on 20-Jun-2001.
Database last updated on 24-Feb-2002 19:56:16 EDT.

hmmm...
 

Maleficus

Diamond Member
May 2, 2001
7,682
0
0
you should guard your backdoor more closely! alot of um yea those type of people around.
 

bacillus

Lifer
Jan 6, 2001
14,517
0
71
I do believe wmp8 calls home at times!
other than that, have you set windows to automatically look for updates.
 

Lithium381

Lifer
May 12, 2001
12,452
2
0


<< The interesting thing is that it's trying to contact Microsoft... >>



yeah, that's strange, i think i'll go install my copy of zonealarm, which i neglected to install when i formated my HD a week and a half ago....
 

MustPost

Golden Member
May 30, 2001
1,923
0
0
Oh, good, you were talking about computers. I thought you were talking about another kind of trojan ;)
 

LiQiCE

Golden Member
Oct 9, 1999
1,911
0
0
Are you running Windows XP? As far as I know the Active Registration System (you know, the thing that you use to "Activate" your copy of Windows XP) which is partially contained in winlogon.exe checks to make sure your registration is still valid by using the Internet.

Could that be whats trying to connect to Microsoft's servers? If so, then I would think its acting normal.
 

BillGates

Diamond Member
Nov 30, 2001
7,388
2
81
You didn't mention what version of Windows you're using....but I have "heard" that with some versions of FreeWindows XP you have to replace the winlogon.exe with a cracked version.....

Is this XP - and is it trying to call home to do the lovely product activation??

(I've heard the above things, I still use Windows 3.1 - leave me alone.)
 

BillGates

Diamond Member
Nov 30, 2001
7,388
2
81
Whoops, sorry I echoed you there....I had my browser with this topic up for a while, should have refreshed before replying.
 

joohang

Lifer
Oct 22, 2000
12,340
1
0
You sure that's Microsoft?

The address is wrong. It should be One Microsoft Way. And there are no sites up at MSFT.NET.

Could be some idiot pretending to be Microsoft.
 

loup garou

Lifer
Feb 17, 2000
35,132
1
81


<< Crap, forgot to turn on the sarcasm button again. >>


Hehe...my fault...forgot to turn on my sarcasm detector. ;)
 

TuffGuy

Diamond Member
Jul 6, 2000
6,478
0
76
Well, I'm using that free version of WinXP that doesn't require activation... ;)

Anyway, I just finished doing the scan/removal in safe mode. 70,000+ files take a while to process. :( anyway, I found two viruses: backdoor.trojan and backdoor.bionet.318.

---

Take a week elsewhere to work some extra hours and buy yourself a legal copy of your OS <wink> <wink>.

AnandTech Moderator
 

GTaudiophile

Lifer
Oct 24, 2000
29,767
33
81
wmplayer.exe always tries to call home to MS whenever I run the program.

Isn't ZoneAlarm the best?
 

loup garou

Lifer
Feb 17, 2000
35,132
1
81


<< Well, I'm using that free version of WinXP that doesn't require activation... ;) >>


Well if you're using a warezed version of XP, I wouldn't doubt that it has virii installed with it.
 

Fritzo

Lifer
Jan 3, 2001
41,920
2,161
126


<< i got infected with a backdoor trojan >>



Heheheheheh....sounds like a homosexual condom :) What happened...did it break? ;)
 

Hossenfeffer

Diamond Member
Jul 16, 2000
7,462
1
0


<< Well, I'm using that free version of WinXP that doesn't require activation... >>

Hmm. That free version... wasn't aware that Microsoft had been marketing a free version.