jeparham
February 12th, 2008, 06:39 PM
Background: WinXP SP2, all patches. NOD32AV 3.0.566.0, defs: 02082008. ZoneAlarm with AntiSpyware.
NOD32 is set to do full scan of all files weekly. No malware of any type has ever been found by the scans.
Now... with that said... I have no idea what is going on in the guts of my PC. I was looking at the Program Logs of ZoneAlarm today and I noticed this in the log:
Date: 2008/02/12 16:56:40-500 GMT
Program Access: ekrn.exe
Destination: 88.255.94.74:80
Direction: Outgoing
Action: Blocked
Count: 2
Destination DNS: iloveie.info
Over 2 days there were a total of 22 access attempts made by ekrn.exe to connect to iloveie.info
There were also 25 attempts to connect by UpdClient.exe, which appears to be part of ZoneAlarm itself.
There were God only knows how many attempts by Firefox. I stopped counting there were so many. FF also tried to connect to Reservaza.com 31 times over 3 days in January.
There were 10 attempts by Thunderbird, and a couple by "Svchost.exe"
ZoneAlarm indicates that it has blocked all attempts to connect to the sites, which I already know are involved in bank account hijacking.
As I already noted, NOD32 has found nothing in weekly scanning. In fact, none of the symptoms of a Trojan.SilentBanker infection have been discovered. DNS is ok. Registry appears clean.
Anybody have any idea what might be happening?
And I apologize if I have posted this in the wrong place. I am rather rattled by this and I had no idea where else to go for help.
James
NOD32 is set to do full scan of all files weekly. No malware of any type has ever been found by the scans.
Now... with that said... I have no idea what is going on in the guts of my PC. I was looking at the Program Logs of ZoneAlarm today and I noticed this in the log:
Date: 2008/02/12 16:56:40-500 GMT
Program Access: ekrn.exe
Destination: 88.255.94.74:80
Direction: Outgoing
Action: Blocked
Count: 2
Destination DNS: iloveie.info
Over 2 days there were a total of 22 access attempts made by ekrn.exe to connect to iloveie.info
There were also 25 attempts to connect by UpdClient.exe, which appears to be part of ZoneAlarm itself.
There were God only knows how many attempts by Firefox. I stopped counting there were so many. FF also tried to connect to Reservaza.com 31 times over 3 days in January.
There were 10 attempts by Thunderbird, and a couple by "Svchost.exe"
ZoneAlarm indicates that it has blocked all attempts to connect to the sites, which I already know are involved in bank account hijacking.
As I already noted, NOD32 has found nothing in weekly scanning. In fact, none of the symptoms of a Trojan.SilentBanker infection have been discovered. DNS is ok. Registry appears clean.
Anybody have any idea what might be happening?
And I apologize if I have posted this in the wrong place. I am rather rattled by this and I had no idea where else to go for help.
James