DLL changes - normal or malware driven?

  • Thread starter Thread starter Morgan Ohlson
  • Start date Start date
M

Morgan Ohlson

I raised the security level some week ago. Therefor I dn't really know whats
normal and what isn't.

When Firefox reach a new site it is sometimes recorded (warning) that a DLL
is changed. It can look like the copy below. Is that a normal DLL change or
something fixed by malware? (se below)

Morgan O.
----------------------------------------------------------

The new DLLs have been loaded:
C:\PROGRAM\JAVA\JRE1.5.0_04\BIN\NET.DLL

To disable DLL Authentication go to the security tab under the Tools,
Options menu.

File Version : 1.0.6.0
File Description : Firefox
File Path : D:\Program\Firefox\firefox.exe
Process ID : 0xFFF33335 (Heximal) 4294128437 (Decimal)

Connection origin : local initiated
Protocol : TCP
Local Address : 83.248.52.34
Local Port : 3506
Remote Name : www.comhem.se
Remote Address : 194.237.212.165
Remote Port : 80 (HTTP - World Wide Web)

Ethernet packet details:
Ethernet II (Packet Length: 56)
Destination: 00-0f-90-27-75-ce
Source: 00-50-fc-69-9d-ee
Type: IP (0x0800)
Internet Protocol
Version: 4
Header Length: 20 bytes
Flags:
.1.. = Don't fragment: Set
..0. = More fragments: Not set
Fragment offset:0
Time to live: 128
Protocol: 0x6 (TCP - Transmission Control Protocol)
Header checksum: 0x28e3 (Correct)
Source: 83.248.52.34
Destination: 194.237.212.165
Transmission Control Protocol (TCP)
Source port: 3506
Destination port: 80
Sequence number: 244993017
Acknowledgment number: 3830526872
Header length: 20
Flags:
0... .... = Congestion Window Reduce (CWR): Not set
.0.. .... = ECN-Echo: Not set
..0. .... = Urgent: Not set
...1 .... = Acknowledgment: Set
.... 0... = Push: Not set
.... .0.. = Reset: Not set
.... ..0. = Syn: Not set
.... ...1 = Fin: Set
Checksum: 0x3eef (Correct)
Data (0 Bytes)

Binary dump of the packet:
0000: 00 0F 90 27 75 CE 00 50 : FC 69 9D EE 08 00 45 00 | ...'u..P.i....E.
0010: 00 28 F7 F9 40 00 80 06 : E3 28 53 F8 34 22 C2 ED | .(..@....(S.4"..
0020: D4 A5 0D B2 00 50 0E 9A : 4B F9 E4 51 33 98 50 11 | .....P..K..Q3.P.
0030: 20 68 EF 3E 00 00 69 76 : | h.>..iv
---------------------------------------------- end
 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Morgan said:
I raised the security level some week ago. Therefor I dn't really know whats
normal and what isn't.

When Firefox reach a new site it is sometimes recorded (warning) that a DLL
is changed. It can look like the copy below. Is that a normal DLL change or
something fixed by malware? (se below)

In this case it may be that the Java VM has been updated; I believe 1.5.0
04 is the latest.

I have net.dll in my Java VM bin directory. It is 77,926 bytes long and was
last modified on 6th March 2005. It's SHA1 checksum is:

ec0b4e06255c3a28de42e72abc7bb0cbfa06a2ab

Cheers
- --
Adam Piggott, Proprietor, Proactive Services (Computing).
http://www.proactiveservices.co.uk/

Please replace dot invalid with dot uk to email me.
Apply personally for PGP public key.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (MingW32)

iD8DBQFDLVx87uRVdtPsXDkRAsIZAJ0U4bgpGD+d5RKu3BT6jGykstvUaQCfUuww
6UZQYm8TjAGTZaCwd/5Atl4=
=StVV
-----END PGP SIGNATURE-----
 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1



In this case it may be that the Java VM has been updated; I believe 1.5.0
04 is the latest.

I have net.dll in my Java VM bin directory. It is 77,926 bytes long and was
last modified on 6th March 2005. It's SHA1 checksum is:

ec0b4e06255c3a28de42e72abc7bb0cbfa06a2ab

Cheers
- --
Adam Piggott, Proprietor, Proactive Services (Computing).
http://www.proactiveservices.co.uk/

Please replace dot invalid with dot uk to email me.
Apply personally for PGP public key.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (MingW32)

iD8DBQFDLVx87uRVdtPsXDkRAsIZAJ0U4bgpGD+d5RKu3BT6jGykstvUaQCfUuww
6UZQYm8TjAGTZaCwd/5Atl4=
=StVV
-----END PGP SIGNATURE-----

To rais the security level and see whats happening in the PC may be
something more people should do. Just to learn more about processes inside
the computer.


Thanks!


Morgan O.
 
From: "Morgan Ohlson" <[email protected]>


|
| To rais the security level and see whats happening in the PC may be
| something more people should do. Just to learn more about processes inside
| the computer.
|
| Thanks!
|
| Morgan O.

Are you suggesting an a Redundant Arrary of Inexpensive Systems (RAIS) ?

Or is it to increase the security as in - raise
Or is it to decrease the security as in - raze
 
From: "Morgan Ohlson" <[email protected]>


|
| To rais the security level and see whats happening in the PC may be
| something more people should do. Just to learn more about processes inside
| the computer.
|
| Thanks!
|
| Morgan O.

Are you suggesting an a Redundant Arrary of Inexpensive Systems (RAIS) ?

X > Or is it to increase the security as in - raise
Or is it to decrease the security as in - raze

/m
 
Back
Top