cabinet.dll

IP: *.tpnet.pl 26.08.07, 11:00
ZoneAlarm wykrył,że nowy program cabinet.dll chce połączyć się z internetem.To
oryginalnie jest plik microsoftu do plików spakowanych typu cab.Słyszał
ktoś,żeby to chciało połączyć się z internetem?Nic się nie dzieje,ewentualnie
małe spowolnienie,ale spodziewam się jakiegoś nowego trojana,bo były błędy
przy rozpakowaniu plików rar,albo częściowo puste pliki rar.cabinet.dll
wyszukałem w kilku miejscach na dysku,jest taki sam,ma MD,chyba,że to nie ten
się chciał połączyć.Nie jest to duża sprawa,może ktoś zna,albo wyjaśni taki
przypadek?
    • Gość: Kolobos Re: cabinet.dll IP: *.escom.net.pl 26.08.07, 11:37
      Sprawdz w logach firewall'a (o ile jakies ma) gdzie znajdowal sie plik, ktory chcial sie laczyc.
      • Gość: Ptyś Re: cabinet.dll IP: *.tpnet.pl 26.08.07, 12:42
        Poszukam,stępnie tylko podaję za firewallem rozmiar pliku file size 0 KB
        • Gość: Ptyś Re: cabinet.dll IP: *.tpnet.pl 26.08.07, 18:50
          Żadne szczegóły nie sa dostępne,tylko rozmiar 0KB.Logg ZA :
          PE,2007/08/25,22:59:54 +2:00 GMT,cabinet.dll,cabinet.dll,255.255.255.255:67,N/A
          ACCESS,2007/08/25,23:00:02 +2:00 GMT,Generic Host Process for Win32 Services was
          blocked from connecting to the Internet (255.255.255.255:DHCP).,N/A,N/A
          ACCESS,2007/08/25,23:00:02 +2:00 GMT,Generic Host Process for Win32 Services was
          blocked from connecting to the Internet (239.255.255.250:Port 1900).,N/A,N/A
          PE,2007/08/25,23:00:02 +2:00 GMT,cabinet.dll,cabinet.dll,127.0.0.1:3581,N/A
          FWIN,2007/08/25,23:00:02 +2:00 GMT,24.167.129.11:59934,200:200:200:200:5900,TCP
          (flags:S)
          FWIN,2007/08/25,23:00:04 +2:00 GMT,88.21.226.248:6881,200:200:200:200:48216,UDP
          ACCESS,2007/08/25,23:00:06 +2:00 GMT,Generic Host Process for Win32 Services was
          blocked from connecting to the local zone (127.0.0.1:Port 3581).,N/A,N/A
          ACCESS,2007/08/25,23:00:08 +2:00 GMT,Generic Host Process for Win32 Services was
          blocked from sending data to the Internet (255.255.255.255:DHCP).,N/A,N/A
          FWIN,2007/08/25,23:00:08 +2:00 GMT,83.11.178.185:4641,200:200:200:200:135,TCP
          (flags:S)
          ACCESS,2007/08/25,23:00:08 +2:00 GMT,Generic Host Process for Win32 Services was
          blocked from connecting to the local zone (127.0.0.1:Port 3582).,N/A,N/A
          FWIN,2007/08/25,23:00:08 +2:00 GMT,70.50.0.63:61621,200:200:200:200:48216,UDP
          ACCESS,2007/08/25,23:00:08 +2:00 GMT,Generic Host Process for Win32 Services was
          blocked from connecting to the local zone (127.0.0.1:Port 3583).,N/A,N/A
          FWIN,2007/08/25,23:00:08 +2:00 GMT,90.224.126.232:60955,200:200:200:200:48216,UDP
          FWIN,2007/08/25,23:00:12 +2:00 GMT,83.11.159.184:3040,200:200:200:200:135,TCP
          (flags:S)
          ACCESS,2007/08/25,23:00:20 +2:00 GMT,Generic Host Process for Win32 Services was
          blocked from connecting to the Internet (239.255.255.250:Port 1900).,N/A,N/A
          FWIN,2007/08/25,23:00:20 +2:00 GMT,217.209.88.146:63561,200:200:200:200:48216,UDP
          ACCESS,2007/08/25,23:00:24 +2:00 GMT,Generic Host Process for Win32 Services was
          blocked from sending data to the Internet (239.255.255.250:Port 1900).,N/A,N/A
          FWIN,2007/08/25,23:00:26 +2:00 GMT,83.6.77.236:3931,200:200:200:200:445,TCP
          (flags:S)
          ACCESS,2007/08/25,23:00:28 +2:00 GMT,Generic Host Process for Win32 Services was
          blocked from connecting to the local zone (127.0.0.1:Port 3600).,N/A,N/A
          ACCESS,2007/08/25,23:00:28 +2:00 GMT,Generic Host Process for Win32 Services was
          blocked from connecting to the local zone (127.0.0.1:Port 3601).,N/A,N/A
          ACCESS,2007/08/25,23:00:28 +2:00 GMT,Generic Host Process for Win32 Services was
          blocked from connecting to the local zone (127.0.0.1:Port 3602).,N/A,N/A
          ACCESS,2007/08/25,23:00:36 +2:00 GMT,Eksplorator Windows was blocked from
          connecting to the Internet (239.255.255.250:Port 1900).,N/A,N/A
          ACCESS,2007/08/25,23:00:36 +2:00 GMT,Eksplorator Windows was blocked from
          connecting to the local zone (127.0.0.1:Port 3609).,N/A,N/A
          ACCESS,2007/08/25,23:00:40 +2:00 GMT,Eksplorator Windows was blocked from
          sending data to the Internet (239.255.255.250:Port 1900).,N/A,N/A
          ACCESS,2007/08/25,23:00:46 +2:00 GMT,Eksplorator Windows was blocked from
          connecting to the local zone (127.0.0.1:Port 3586).,N/A,N/A
          ACCESS,2007/08/25,23:00:46 +2:00 GMT,Eksplorator Windows was blocked from
          connecting to the local zone (127.0.0.1:Port 3587).,N/A,N/A
          ACCESS,2007/08/25,23:00:46 +2:00 GMT,Eksplorator Windows was blocked from
          connecting to the local zone (127.0.0.1:Port 3588).,N/A,N/A
          • Gość: Kolobos Re: cabinet.dll IP: *.escom.net.pl 26.08.07, 19:55
            To tylko dwa polaczenia i nie laczyl sie on z internetem, wiec mozesz to zignorowac.
Pełna wersja