![]() |
|
|
|
#1
|
|||
|
|||
|
My bad . this may not be an exact answer but i hope these docs will help you
http://www.nirsoft.net/dll_information/windows8/profsvc_dll.html http://www.bleepingcomputer.com/tutorials/how-malware-hides-as-a-service/ Since you said ProfSvc.dll is initiating the connection , all that comes to my mind is a compromised dll or hooked one . I dont see any reason for windows dlls to connect to 3rd party software and aid them in updating . More details or exact behavior will help in determining the problem. i will suggest you to use an api logger to check the program behavior . |
| The Following User Gave Reputation+1 to Conquest For This Useful Post: | ||
niculaita (09-26-2014) | ||
|
#2
|
|||
|
|||
|
Does the binary of the application in question happen to be signed maybe? I don't know what firewall you use, but Comodo Firewall for example automatically adds executables signed by 'trusted vendors' to its internal database of safe files and allows them to access the internet without confirmation. Thankfully this behaviour can be disabled.
|
|
#3
|
|||
|
|||
|
Like I already said, not the software itself but svchost.exe is the one initiating the connection. I can't find any suspicios services, so I assume the connection is made by using some documented or some undocumented (but open) service calls.
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| iOS iBoot Source code leak - Probably termed as the biggest leak in the history | foosaa | Source Code | 13 | 03-14-2018 01:02 |
| Would you use a Firewall that had a cracked .dll? | Rhodium | General Discussion | 18 | 03-03-2004 00:00 |
| Best firewall? Your opinion | FEARHQ | General Discussion | 8 | 11-10-2002 06:14 |