Question

Troubleshoot suspicious traffic from workstation to AD over 1025

Asked by: terradmin

I'm at my wits end on this one & am hoping the EE community could lend a helping hand!

We started receiving intrusion prevention alerts on our SonicWall E5500 NSA after a recent firmware update.  Of ~10 workstations, only two were triggering the alert: "IPS Prevention Alert: P2P eMule -- Obfuscated Protocol, SID: 4, Priority: Low"  Source: workstation, random port; Dest: either of our DCs, port 1025

I took one of the machines offline & built a new machine for the user using a custom winXP image on different hardware.  We kept the default machine name & have not had any alerts from the device, so the user is up and running for the time being.

The odd part  here is that I wiped the user's old machine, reimage using the same image as above & flashed the BIOS.  I removed the object from AD, renamed the machine to its original, and joined the domain.  The alerts started again.  The only commonality here (that i can think of ) is the machine name.  I haven't even attempted to work on the second machine in question.  (Malware & rootkit scans have come up clean)

I have since reimaged the machine from a base XP image, with no bells and/or whistles.  Installed/updated A/V, ran all appropriate Win Updates, etc.  The alerts started again as soon as I joined the domain - inbound to the AD server(s) over 1025.

Any thoughts/help would be appreciated.  Our ultimate goal is to eradicate this & apply the same fix to the second device.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-07-16 at 21:31:37ID24577993
Tags

active directory

,

winXP Pro

,

port 1025

,

intrusion prevention

,

emule

,

obfuscated protocol

Topic

Windows XP Operating System

Participating Experts
3
Points
0
Comments
27

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. rootkit suspect
    I've a pc (not mine) that I'm trying to clean up. It had at least two rootkit (lzx32.sys, pe386), several trojans (igfxtray, hkcmd, mstds, mswsck32.dll) and other malware. I used Rootkit Unhooker to detect lzx32 and pe386 (removed from the fs and registry using a linux livecd...
  2. Rootkit and/or Trojan
    I've been working on this PC for several days and thought I had it clean. Installed AVG which is showing C:|windows\system32\drivers\ndis.sys infected with Trojan Horse Rootkit-Agent.DI. ndis.sys is a legit Windows file and part of the OS (part of network driver). I tried sub...
  3. rootkit
    I have a rootkit that I can't remove. I ran sdfix, combofix and gmer. I ran gmer and ran a scan but it disappears before finishing. If I stop it when I see typing in red I can delete or disable the service. Here's a log file from gmer. See line with " \\?\globalroo...
  4. Anti-Rootkit
    Hello, I need anti-rootkit source in delphi? Anyone can help me. Good presentation appreciate. prasid
  5. rootkit found in one file in system 32 drivers
    I never heard of a rootkit before. I seem to have one cause by an infected drive I was looking at. That drive has since been reformatted but on my main system everytime I do a scan with Hitman Pro I get a message telling me I have a Rootkit in C:\WINDOWS\system32\drivers\dmio...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: terradminPosted on 2009-07-17 at 05:14:02ID: 24877850

I'm willing to work through "stabs in the dark" here - if you need more info, have questions, or even some wild guesses, I'd be happy to start a dialogue.

Anyone??

 

by: johnb6767Posted on 2009-07-17 at 13:41:04ID: 24882674

Not familiar with nSonicwalls, but Ill take a guess... Maybe the NIC is failing and sending out corrupted packets?

 

by: terradminPosted on 2009-07-17 at 20:45:00ID: 24884692

Thanks for responding, John.  The packets are definitley coming from the two workstations.  If we rename the workstation (ie: from WS1 to WS_1), the packets stop - almost as if they are sending the packets after receiving an instruction from elsewhere; however, we have been unable to find anything that would indicate that.  If I leave both WS1 and WS_1 in DNS w/the same IP, the alerts continue, so it appears that the 'ghost' instructions may be resolving via DNS...

 

by: johnb6767Posted on 2009-07-18 at 14:08:13ID: 24887365


Any chance they are trying to force browser elections?

Description of the Microsoft Computer Browser Service
http://support.microsoft.com/kb/188001
 

 

by: terradminPosted on 2009-07-18 at 14:35:38ID: 24887432

John -

What brings you to this train of thought?  Why would port 1025 be involved?

Looking at my fw logs, there may be some weight to you hypothesis - but I'd like to try to hone in on your thoughts.  We've been chasing so many possibilities, I don't want to start barking up yet another tree w/out just cause. :)

Feed me some more!

 

by: johnb6767Posted on 2009-07-18 at 22:44:24ID: 24888438

I think I was just throwing it out there, more than anything..... It really boggles me to not have a clkue as to why it having a specific name does this......

Have you isolated what proces is making the connection/. Lets go a different approach....

TCPView for Windows
http://technet.microsoft.com/en-us/sysinternals/bb897437.aspx

This is a little less of a stab in the dark......

 

by: terradminPosted on 2009-07-20 at 15:33:03ID: 24899728

John -

Thanks for responding.  Sorry it took so long to get back to you.

I'm afraid I don't have the machine readily available, so I can't run TCPView on it at the moment.  From what I remember, it was svchost that was making the connection to port 1025.  I looked in the system event log & saw an error regarding the master browser (although I don't recall the exact error right now), which is why I thought you might be on the right track.

As soon as I have the machine in my hands, I'll run TCPView and see what we find

 

by: johnb6767Posted on 2009-07-20 at 21:36:54ID: 24901317

Ok. If it is a SVCHost, we need to get more specific.

Process Explorer
http://live.sysinternals.com/procexp.exe

Double click the SVCHost.exe in question, and list the services it is hosting....

 

by: terradminPosted on 2009-07-23 at 19:49:27ID: 24932004

John -

Sorry about the delay in getting back to you.  I got in touch with Microsoft's security team and have had them poking around in our logs, packet captures, etc. for the past few days.  I just got word back of some suspicious activity on the following ports:

1335 tcp/udp
 digital-notary
 Digital Notary Protocol
 
1336 tcp/udp
 ischat
 Instant Service Chat
 (ischat.exe??)
 
1337 tcp/udp
 menandmice-dns
 menandmice DNS
 
Know anything about these?

 

by: johnb6767Posted on 2009-07-23 at 21:03:41ID: 24932193

Unfortunately no......

 

by: terradminPosted on 2009-07-25 at 09:13:10ID: 24942098

John -

I'm going to keep the thread open until I get a resolution from Microsoft (or other source) so we can add this to the paq.  If your input is in any way related to the resolution, I'll be sure to award point accordingly.

If you can think of anything else in the meantime, please feel free to add to the thread.

Thx

 

by: terradminPosted on 2009-07-31 at 06:25:19ID: 24988527

Just to keep the thread open - Microsoft PSS is taking a closer look at the systems via their forensics tool, WOLF.  Meanwhile, SonicWall Support is taking a closer look at packet captures across the firewall.  I'll update as we get closer to a resolution... hopefully soon.

 

by: JimInKSPosted on 2009-08-03 at 09:36:35ID: 25006033

I found this tread because I was getting the same log entries for one particular computer.

The only thing in the log for that computer were multiple attempts to contact 'ardownload.adobe.com', but 0 bytes downloaded in every case.

This occurred Friday afternoon 7-31 from noon till 4:00 PM CDT.  I ended up with over 250 warnings logged for this particular computer.

From log:
07/31/2009 15:56:14.704 - Alert - Intrusion Prevention -       IPS Prevention Alert: P2P eMule -- Obfuscated Protocol, SID: 4, Priority: Low -       192.168.2.2, 3479, X0 -       208.19.38.73, 80, X1 -       

This computer in question is Windows 2000 and has Adobe 9.1 installed.  There is apparently a more recent update from Adobe that we are installing now.

Is it possible that the Adobe downloader looks like eMule to the Sonicwall?

 

by: JimInKSPosted on 2009-08-03 at 09:44:51ID: 25006112

Sorry I didn't specify Adobe READER above.  I'm sure you knew what I meant!

Additional info:

We tried running the update from Adobe Reader and are getting the same eMule errors from the Sonicwall and the Adobe updater is reporting that it can't connect.

Will now uninstall the current version and download the latest version of Reader direct from Adobes website.

 

by: JimInKSPosted on 2009-08-03 at 10:55:24ID: 25006724

Well, downloaded the "latest" version of Adobe Reader from Adobe's website.  Unfortunately, the latest version that is on the download page is the version we already had, 9.1.0.  Updates would still not work, even after a reinstall.

But I manually download the 9.1.1, 9.1.2, and 9.1.3 update files from the Adobe Reader Web page.  Installed those (this does not use the updater feature) and then, after getting to version 9.1.3 we can run the Adobe Updater successfully.

So, to summarize.  

In our case, it seems that the Adobe Updater that is installed with Adobe Reader 9.1.0 is the culprit. It must look like eMule to the Sonicwall.  Manually downloading the version 9.1.3 release and installing it corrected the issue.


 

by: terradminPosted on 2009-09-04 at 06:55:22ID: 25259684

We finally made some headway here...

After working with Microsoft PSS for over a month & not finding anything on the affected machines, we turned back to SonicWall for assistance.  After providing a series of packet captures from affected machines, non-affected machines, the AD servers & the firewall, the SW R&D team found something in the firmware which they believe to be the cause.   We will be applying a patch on 9/12 to test their hypothesis, as they were unable to recreate the issue internally.

Unfortunately, JimInKS resolution did not apply to us, as we were seeing detections from machines that were not running any Adobe products.

I will gladly update as soon as we have some results from the test.

 

by: JimInKSPosted on 2009-09-04 at 09:07:03ID: 25260975

terradmin,

Thanks for getting to the bottom of this.  I am seeing a few, "P2P eMule -- Obfuscated Protocol" alerts showing up on my logs for what appear to be "random" reasons. I hope Sonicwall finds a solution.

 

by: terradminPosted on 2009-09-04 at 09:26:38ID: 25261156

@JimInKS - in all the alerts we've seen, the destination port was 1025.  In your earlier post, your log indicates port 80 - is this the case on all fw entries?  

A few notes for you:
1. We found we were able to force the IPS Prevention Alert by attempting a 'gpupdate /force' from an affected machine
2. We removed an affected machine name from AD and DNS & disconnected it from the network.  After renaming a non-affected machine to the affected machine's name, alerts began again.  Alerts stopped after renaming the 2nd machine back to its original name.

The alerts began on our network after upgrading the firmware to SonicOS Enhanced 5.4.0.0 (feature upgrade).  We rolled back to 5.2.0.3 w/SW's help (not a public release - I believe the latest is 5.2.0.1), although this did not resolve the issue.

 

by: JimInKSPosted on 2009-09-04 at 09:48:34ID: 25261328

All the alerts I have looked at have been port 80.
I have been getting around 10 a day, but we are small, around 100 pc's with internet access.
We are running a NSA2400 firmware 5.4.0.0-20o which we installed recently (middle of July).
Did not see these on our old PRO 2040 SonicOS Enhanced 4.0.0.5-1e.

Oddly destination ip's (recently) are all 199.7.X.190, where the 3rd octet can be any of 48, 51, 52, 71

 

by: terradminPosted on 2009-09-04 at 10:08:40ID: 25261507

Those IPs belong to CRL.VERISIGN.NET, so I'd venture a guess that you're seeing false detections.  Still only happening from the one machine?

 

by: JimInKSPosted on 2009-09-04 at 11:16:15ID: 25262032

Right now it is about 7 machines on a kind of sporadic basis.  
I haven't done a lot of investigation.  After I got slammed by that 1 machine and seemingly fixed it with the Adobe update I haven't seen a huge number of these alerts.

Since it seems to be a Sonicwall issue I wasn't overly concerned and was hoping  someone with more expertise than I would find a definitive solution or Sonicwall would issue a firmware update that solved this issue.

I am a bit of novice at this. There are just 2 of us in IT. However, if an answer is not forthcoming I would be willing to do what I can to help find a solution.

 

by: terradminPosted on 2009-09-11 at 13:50:01ID: 25313360

@JimInKS

We'll be applying SW's patch tomorrow morning.  I'll post the results once I'm sure I haven't killed my network.  :)

If all goes well, my suggestion would be that you reach out to Michael Hopper at SonicWall - he was handling my case (support [at] sonicwall [dot] com) & simply reference eMule in the subject.  

Looking forward to closing this question once and for all....

:)

 

by: terradminPosted on 2009-09-13 at 17:43:30ID: 25322443

We upgraded to SonicOS Enhanced 5.5.0.0-m1_chestnut  over the weekend & have not had any alerts for approximately 36 hours.  It looks like the firmware update resolved the issue.

 

by: JimInKSPosted on 2009-09-14 at 07:23:46ID: 25325746

Good news.  Thanks for all your work on this.

 

by: terradminPosted on 2009-09-14 at 11:51:47ID: 25328190

@Moderator - please close this question & refund points as the solution was provided externally.

I'd like to ask that this be added to the PAQ if possible, in case similar issues crop up for other users.

 

by: ee_autoPosted on 2009-10-11 at 01:28:37ID: 25545239

Question PAQ'd, 500 points refunded, and stored in the solution database.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...