Know your ISP.

breath-hyenas
User #11332   15558 posts
Whirlpool Forums Addict
O.P.

I had a program called spoolcll.exe try to open up port 14054 today.

Investigation showed that although it lived in c:\winnt\system32 it wasn't tagged as a microsoft program. It had a file datestamp of 26 Jan 5 12:57pm. The internet access happened at 12:58.

It showed up in the registry as a service 'evmon'.

The running .exe could not be killed in Task Manager. Nor could the service be paused or stopped.

After telling Norton to block all access, it tried to send a message to: 212.105.105.214, port 5003, which I also blocked.

I set the service to disabled and changed the filename it was looking for. Rebooted. It wasn't running, so I changed the name of the .exe.

So, my question is: is spoolcll.exe legitimate or is it a new virus?

I have Norton AV and firewall, up to date. But I am a little behind in my W2K updates.

http://whrl.pl/RxIQ8
posted 2005-Jan-26, 2:20 pm
User #11332   15558 posts
Whirlpool Forums Addict
O.P.
this post was edited

www.zoneedit.com/lookup....verse=Look+it+up

I think it is a virus of some sort, as there should be no reason I'm trying to connect to a site in Sweden.

Reverse DNS gets me:

Reverse Lookup Results
Host Type Value
105.105.212.in-addr.arpa NS ns.utfors.se
105.105.212.in-addr.arpa NS ns2.utfors.se
105.105.212.in-addr.arpa NS ns.utfors.se
105.105.212.in-addr.arpa NS ns2.utfors.se
ns.utfors.se A 195.58.103.124
ns2.utfors.se A 195.58.103.18

http://whrl.pl/RxIRE
posted 2005-Jan-26, 2:26 pm
edited 2005-Jan-26, 2:58 pm
User #39086   3105 posts
Whirlpool Forums Addict

im surprised, google returns nothing :O

http://whrl.pl/RxIRH
posted 2005-Jan-26, 2:27 pm
User #11332   15558 posts
Whirlpool Forums Addict
O.P.

-CO^STY- writes...

im surprised, google returns nothing :O

Neither does Microsoft, Symantec, Kaspersky or McAffe.

http://whrl.pl/RxITG
posted 2005-Jan-26, 2:37 pm
User #47671   3517 posts
Whirlpool Forums Addict

Evan writes...

im surprised, google returns nothing :O

Neither does Microsoft, Symantec, Kaspersky or McAffe.


just wondering, did you spell the file name correctly

http://whrl.pl/RxIVn
posted 2005-Jan-26, 2:43 pm
User #11332   15558 posts
Whirlpool Forums Addict
O.P.

ruberto writes...

just wondering, did you spell the file name correctly

Yes. SPOOLCLL.EXE

http://whrl.pl/RxIWl
posted 2005-Jan-26, 2:53 pm
User #11332   15558 posts
Whirlpool Forums Addict
O.P.

And, how do you go about reporting this to the virus companies?

I can't find an obvious link on either the Symantec, McAfee or Kaspersky sites.

http://whrl.pl/RxIWp
posted 2005-Jan-26, 2:54 pm
User #43220   7355 posts
In the penalty box

Ever consider it may not be a virus, but SPYWARE? At the risk of suggesting something you've already done, have you tried scanning your system for spyware (using adaware, spybot s&d, etc)

edit: fiksed mina speling mestake

http://whrl.pl/RxIW0
posted 2005-Jan-26, 3:03 pm
edited soon afterwards
User #11332   15558 posts
Whirlpool Forums Addict
O.P.

Johnny Bravo writes...

Ever consider it may not be a virus, but SPYWARE?

No.

I wasn't into any websites at that time that I hadn't already been to. And the only sites that I had been to today were commercial sites that couldn't afford to be associated with spyware.

At the risk of suggesting something you've already done, have you tried scanning your system for spyware (using adaware, spybot s&d, etc)

Ad-Aware comes up clean.

http://whrl.pl/RxI27
posted 2005-Jan-26, 4:16 pm
User #43220   7355 posts
In the penalty box

Evan writes...

were commercial sites that couldn't afford to be associated with spyware.

not always obvious who can and who can't be associated with spyware.

I had a piece of paid for software I've run for months. It was only after I installed the latest AVG free edition that I noticed this program was trying to make an SMTP connection to somewhere in europe ... because of AVG's popup status indicator just sat there until it timed out - it's always failed in the past anyway, because iiNet block external SMTP connections (i.e, from me to any other SMTP other than their own)

http://whrl.pl/RxI51
posted 2005-Jan-26, 4:48 pm
User #59014   12157 posts
Whirlpool Forums Addict

Evan writes...

Ad-Aware comes up clean.

What browser are you using? Ad-Aware works good on EI but not so good on Firefox etc. You should always use at least 2 spyware programmes, Spybot works well with Firefox and EI.

http://whrl.pl/RxI7K
posted 2005-Jan-26, 5:03 pm
User #68404   2483 posts
Whirlpool Forums Addict

Evan writes...

program called spoolcll.exe try to open up port 14054 today

Trend Micro Virus Encyclopedia does not list it as a virus or spy-ware 0 results found.

http://whrl.pl/RxI7M
posted 2005-Jan-26, 5:03 pm
User #6741   3536 posts
Whirlpool Forums Addict

What sort of printer do you have? I have read reports of some printer software phoning home, for the collection of printing stats.

http://whrl.pl/RxI8a
posted 2005-Jan-26, 5:08 pm
User #43220   7355 posts
In the penalty box

alaxus writes...

What sort of printer do you have? I have read reports of some printer software phoning home, for the collection of printing stats.

I was going to mention that myself - my newly acquired Epson tried that!!!

edit: however, the OP does state that the file was created at 12;57 today ... I think he would've remembered installing something like a printer today ;-)

http://whrl.pl/RxJaB
posted 2005-Jan-26, 5:33 pm
edited soon afterwards
User #11332   15558 posts
Whirlpool Forums Addict
O.P.
this post was edited

I have an HP 4100N, which wouldn't be sending to Sweden.

I'm using IE 6.

I didn't install anything at the time.

Port 5003 is a registered port number, used by Filemaker Server and Filemaker Pro, neither of which I have.

Interestingly, a google search of port 5003 brings up lintilla.df.lth.se/html/5003.html , which is associated with a Lintilla Multiple Worlds, which looks like some online game.

http://whrl.pl/RxJdk
posted 2005-Jan-26, 6:04 pm
edited 2005-Jan-26, 6:14 pm
User #2070   41221 posts
Whirlpool Forums Addict

Do you mean spoolsv.exe?

www.neuber.com/taskmanag...spoolsv.exe.html

http://whrl.pl/RxJer
posted 2005-Jan-26, 6:14 pm
User #11332   15558 posts
Whirlpool Forums Addict
O.P.

Muad' Dib writes...

Do you mean spoolsv.exe?

No.

http://whrl.pl/RxJev
posted 2005-Jan-26, 6:15 pm
User #2070   41221 posts
Whirlpool Forums Addict
this post was edited

What program picked it up?

Spool.exe is a virus, so maybe this is a new strain. Renaming itself maybe.

Utfors is a Swedish Telephony carrier.

www.rad.com/Article/0,6583,10123,00.html

http://whrl.pl/RxJe2
posted 2005-Jan-26, 6:20 pm
edited 2005-Jan-26, 6:26 pm
User #43220   7355 posts
In the penalty box

do you still have the offending file?
How big was it?
Rename it to ".txt" and look at it for any readable text that may give a clue to it's origins/purpose

http://whrl.pl/RxJfo
posted 2005-Jan-26, 6:24 pm
User #11332   15558 posts
Whirlpool Forums Addict
O.P.

Muad' Dib writes...

What program picked it up?

Norton Firewall.

And it keeps coming back. I got a new copy at 4:11 and one at 6:25. I had a connection at 6:24/6:25 from 211-74-63-39.adsl.dynamic.seed.net­ .tw(211.74.63.39): 3406 , which sent me about 300k, which is approx twice the size of the exe (at 163 K).

http://whrl.pl/RxJhr
posted 2005-Jan-26, 6:44 pm
    Sign in
    Sign in
    Forgot your password?
    Hosted by
    Bulletproof Managed Hosting
    Local time
    2012-Feb-10  2:24 AM  aedt
    Membership
    478,284 registered members
    18,885 visited in past 24 hrs
    387 members are online now
    533 guests are visiting
    Big numbers
    1,668,891 threads
    32,921,465 posts
    3,365,324 whims sent
    3,986 wiki topics
    195 ISPs listed
    10,178 broadband plans
    1,268 modems & routers
    59,837 features filled