Know your ISP.

User #11332   15558 posts
Whirlpool Forums Addict
http://whrl.pl/RxIQ8
posted 2005-Jan-26, 1:20 pm
O.P.

I had a program called spoolcll.exe try to open up port 14054 today.

Investigation showed that although it lived in c:\winnt\system32 it wasn't tagged as a microsoft program. It had a file datestamp of 26 Jan 5 12:57pm. The internet access happened at 12:58.

It showed up in the registry as a service 'evmon'.

The running .exe could not be killed in Task Manager. Nor could the service be paused or stopped.

After telling Norton to block all access, it tried to send a message to: 212.105.105.214, port 5003, which I also blocked.

I set the service to disabled and changed the filename it was looking for. Rebooted. It wasn't running, so I changed the name of the .exe.

So, my question is: is spoolcll.exe legitimate or is it a new virus?

I have Norton AV and firewall, up to date. But I am a little behind in my W2K updates.

User #11332   15558 posts
Whirlpool Forums Addict
http://whrl.pl/RxIRE
posted 2005-Jan-26, 1:26 pm
edited 2005-Jan-26, 1:58 pm
O.P.
this post was edited

www.zoneedit.com/lookup....verse=Look+it+up

I think it is a virus of some sort, as there should be no reason I'm trying to connect to a site in Sweden.

Reverse DNS gets me:

Reverse Lookup Results
Host Type Value
105.105.212.in-addr.arpa NS ns.utfors.se
105.105.212.in-addr.arpa NS ns2.utfors.se
105.105.212.in-addr.arpa NS ns.utfors.se
105.105.212.in-addr.arpa NS ns2.utfors.se
ns.utfors.se A 195.58.103.124
ns2.utfors.se A 195.58.103.18

User #39086   3106 posts
Whirlpool Forums Addict
http://whrl.pl/RxIRH
posted 2005-Jan-26, 1:27 pm

im surprised, google returns nothing :O

User #11332   15558 posts
Whirlpool Forums Addict
http://whrl.pl/RxITG
posted 2005-Jan-26, 1:37 pm
O.P.

-CO^STY- writes...

im surprised, google returns nothing :O

Neither does Microsoft, Symantec, Kaspersky or McAffe.

User #47671   3528 posts
Whirlpool Forums Addict
http://whrl.pl/RxIVn
posted 2005-Jan-26, 1:43 pm

Evan writes...

im surprised, google returns nothing :O

Neither does Microsoft, Symantec, Kaspersky or McAffe.


just wondering, did you spell the file name correctly

User #11332   15558 posts
Whirlpool Forums Addict
http://whrl.pl/RxIWl
posted 2005-Jan-26, 1:53 pm
O.P.

ruberto writes...

just wondering, did you spell the file name correctly

Yes. SPOOLCLL.EXE

User #11332   15558 posts
Whirlpool Forums Addict
http://whrl.pl/RxIWp
posted 2005-Jan-26, 1:54 pm
O.P.

And, how do you go about reporting this to the virus companies?

I can't find an obvious link on either the Symantec, McAfee or Kaspersky sites.

User #43220   7355 posts
In the penalty box
http://whrl.pl/RxIW0
posted 2005-Jan-26, 2:03 pm
edited soon afterwards

Ever consider it may not be a virus, but SPYWARE? At the risk of suggesting something you've already done, have you tried scanning your system for spyware (using adaware, spybot s&d, etc)

edit: fiksed mina speling mestake

User #11332   15558 posts
Whirlpool Forums Addict
http://whrl.pl/RxI27
posted 2005-Jan-26, 3:16 pm
O.P.

Johnny Bravo writes...

Ever consider it may not be a virus, but SPYWARE?

No.

I wasn't into any websites at that time that I hadn't already been to. And the only sites that I had been to today were commercial sites that couldn't afford to be associated with spyware.

At the risk of suggesting something you've already done, have you tried scanning your system for spyware (using adaware, spybot s&d, etc)

Ad-Aware comes up clean.

User #43220   7355 posts
In the penalty box
http://whrl.pl/RxI51
posted 2005-Jan-26, 3:48 pm

Evan writes...

were commercial sites that couldn't afford to be associated with spyware.

not always obvious who can and who can't be associated with spyware.

I had a piece of paid for software I've run for months. It was only after I installed the latest AVG free edition that I noticed this program was trying to make an SMTP connection to somewhere in europe ... because of AVG's popup status indicator just sat there until it timed out - it's always failed in the past anyway, because iiNet block external SMTP connections (i.e, from me to any other SMTP other than their own)

User #59014   12664 posts
Whirlpool Forums Addict
http://whrl.pl/RxI7K
posted 2005-Jan-26, 4:03 pm

Evan writes...

Ad-Aware comes up clean.

What browser are you using? Ad-Aware works good on EI but not so good on Firefox etc. You should always use at least 2 spyware programmes, Spybot works well with Firefox and EI.

User #68404   2494 posts
Whirlpool Forums Addict
http://whrl.pl/RxI7M
posted 2005-Jan-26, 4:03 pm

Evan writes...

program called spoolcll.exe try to open up port 14054 today

Trend Micro Virus Encyclopedia does not list it as a virus or spy-ware 0 results found.

User #6741   3574 posts
Whirlpool Forums Addict
http://whrl.pl/RxI8a
posted 2005-Jan-26, 4:08 pm

What sort of printer do you have? I have read reports of some printer software phoning home, for the collection of printing stats.

User #43220   7355 posts
In the penalty box
http://whrl.pl/RxJaB
posted 2005-Jan-26, 4:33 pm
edited soon afterwards

alaxus writes...

What sort of printer do you have? I have read reports of some printer software phoning home, for the collection of printing stats.

I was going to mention that myself - my newly acquired Epson tried that!!!

edit: however, the OP does state that the file was created at 12;57 today ... I think he would've remembered installing something like a printer today ;-)

User #11332   15558 posts
Whirlpool Forums Addict
http://whrl.pl/RxJdk
posted 2005-Jan-26, 5:04 pm
edited 2005-Jan-26, 5:14 pm
O.P.
this post was edited

I have an HP 4100N, which wouldn't be sending to Sweden.

I'm using IE 6.

I didn't install anything at the time.

Port 5003 is a registered port number, used by Filemaker Server and Filemaker Pro, neither of which I have.

Interestingly, a google search of port 5003 brings up lintilla.df.lth.se/html/5003.html , which is associated with a Lintilla Multiple Worlds, which looks like some online game.

User #2070 41791 posts
Whirlpool Forums Addict
http://whrl.pl/RxJer
posted 2005-Jan-26, 5:14 pm
User #11332   15558 posts
Whirlpool Forums Addict
http://whrl.pl/RxJev
posted 2005-Jan-26, 5:15 pm
O.P.

Muad' Dib writes...

Do you mean spoolsv.exe?

No.

User #2070 41791 posts
Whirlpool Forums Addict
http://whrl.pl/RxJe2
posted 2005-Jan-26, 5:20 pm
edited 2005-Jan-26, 5:26 pm
this post was edited

What program picked it up?

Spool.exe is a virus, so maybe this is a new strain. Renaming itself maybe.

Utfors is a Swedish Telephony carrier.

www.rad.com/Article/0,6583,10123,00.html

User #43220   7355 posts
In the penalty box
http://whrl.pl/RxJfo
posted 2005-Jan-26, 5:24 pm

do you still have the offending file?
How big was it?
Rename it to ".txt" and look at it for any readable text that may give a clue to it's origins/purpose

User #11332   15558 posts
Whirlpool Forums Addict
http://whrl.pl/RxJhr
posted 2005-Jan-26, 5:44 pm
O.P.

Muad' Dib writes...

What program picked it up?

Norton Firewall.

And it keeps coming back. I got a new copy at 4:11 and one at 6:25. I had a connection at 6:24/6:25 from 211-74-63-39.adsl.dynamic.seed.net­ .tw(211.74.63.39): 3406 , which sent me about 300k, which is approx twice the size of the exe (at 163 K).

    Sign in
    Sign in
    Forgot your password?
    Hosted by
    Bulletproof Managed Hosting
    Local time
    2012-May-17  2:09 PM  aest
    Membership
    497,527 registered members
    18,773 visited in past 24 hrs
    1,623 members are online now
    1,686 guests are visiting
    Big numbers
    1,717,470 threads
    34,191,375 posts
    3,480,057 whims sent
    4,063 wiki topics
    195 ISPs listed
    10,110 broadband plans
    1,330 modems & routers
    60,760 features filled