Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 4th, 2002, 08:37 AM
pin pin is offline
Regular Poster
 
Join Date: Nov 2002
Posts: 116
Default strange connection attempts detected..

hihi..

i posted this on the lavasoft bbs, but it seems they can't find out what's wrong.. i hope you can help.

quite suddenly one day, tcpview showed me connecting out to www14.dixiesys.com, through very many connections, as if i was being flooded. it happened periodically, and was becoming annoying, so i make a Tiny firewall rule to block all connections to that site. and clicked on log when this rule is applied.

when i looked in the log, it said that iexplore.exe was the program trying to connect out, but of course was blocked.

it seems to happen from any port (and always to port 80), but there is a pattern that with each blocked attempt, iexplore tries to connect to dixiesys from a higher port until it eventually gives up... until the next time.

i ran the cleaner and TDS, but found nothing. i posted a startuplist to the lavasoft bbs, and there was nothing suspicious there.

i also run adsgone, which changes the HOSTS file, and so i thought maybe it was showing up as dixiesys because i had it blocked. but no, it wasn't there, so i added it. besides, when that happens, the IP listed is the localhost, not this other strange one.

today i decided to make a web block rule in my router also for the word dixiesys.
...
on a -possibly- unrelated issue, the log in the status window of my router often lists SYN floods and SMURF attacks. this seems to happen especially just after someone connects to the router from the LAN.

sorry for long post... but, any advice?
  #2  
Old November 4th, 2002, 08:51 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re:strange connection attempts detected..

pin,

Let's go for the pragmatic route first. As it seems, connection attempts are made to a site hosted by dixies.com.

Since you obviously do have log files, contacting the host from the site you mentioned, accompanied with an explanation and log files, asking the urgently to look into this, seems a logical first step:

www.dixiesys.com/index.php?display=contact

Keep us posted!

As for the "unrelated issue": in order to keep threads as clean as possible, please open a new thread for that one

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #3  
Old November 4th, 2002, 09:31 AM
Primrose's Avatar
Primrose Primrose is offline
Security Expert
 
Join Date: Sep 2002
Posts: 2,743
Default Re:strange connection attempts detected..

http://www14.dixiesys.com/

IS...


"This is the placeholder for domain www14.dixiesys.com. If you see this page after uploading site content you probably have not replaced the index.html file.

This page has been automatically generated by Server Administrator. "
_____________

That means either something is coming or has left.

Did you ever even go to dixe before? They are into webhosting....games and maybe IRC>
  #4  
Old November 4th, 2002, 09:43 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,717
Default Re:strange connection attempts detected..

Hi pin,

I've just gone over your thread at the Adaware forum and I must say you did the best you could to try and protect yourself.
I noticed you use Windows Washer, but have you tried cleaning out your temp files in safe mode?

Regards,

Pieter
__________________
Regards,

Pieter
It´s nice to be important, but it´s more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #5  
Old November 4th, 2002, 12:09 PM
pin pin is offline
Regular Poster
 
Join Date: Nov 2002
Posts: 116
Default Re:strange connection attempts detected..

i have not gone into safemode yet, no! thx for the idea.

there's no reason for me to go to dixiesys.

i emailed them, (thx for the contact page), and they are going to look into it for me. i will try and stay optimistic =).

apparently that router firewall rule i set up doesn't block it, which makes me think i don't know how to set up router firewall rules =P.

anyway, we'll see what happens.
  #6  
Old November 5th, 2002, 11:48 AM
pin pin is offline
Regular Poster
 
Join Date: Nov 2002
Posts: 116
Default Re:strange connection attempts detected..

problem solved. it had to do with http referrals of an avatar, or something like that. nothing dangerous!

thx for the help though =) i feel as though i wasted the time of many ppl on this one!
  #7  
Old November 6th, 2002, 10:32 AM
Detox's Avatar
Detox Detox is offline
Global Moderator
 
Join Date: Feb 2002
Location: Texas, USA
Posts: 8,507
Default Re:strange connection attempts detected..

hey BTW isn't that avatar of yours from the first Final Fantasy game on Nintendo or something??
__________________
"The price of freedom is eternal vigilance."
- Thomas Jefferson
  #8  
Old November 6th, 2002, 05:25 PM
pin pin is offline
Regular Poster
 
Join Date: Nov 2002
Posts: 116
Default Re:strange connection attempts detected..

it is from the sega genesis game, phantasy star II.
  #9  
Old November 7th, 2002, 06:12 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re:strange connection attempts detected..

Quote:
i feel as though i wasted the time of many ppl on this one!

No, you didn't: you are sure now nothing's wrong - and that's worth the effort!

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #10  
Old November 7th, 2002, 06:19 PM
pin pin is offline
Regular Poster
 
Join Date: Nov 2002
Posts: 116
Default Re:strange connection attempts detected..

thx again..

at least i can say i'm slightly more knowledgeable about normal internet activity, and that can only be a good thing. =).
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:41 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums