jumping crab.com

brotherboard

Member
Member
Local time
10:33 PM
Messages
54
Location
Hull, England
Hi

Please could anyone tell me why Firefox tries to constantly connect to jumpingcrab.com?
I say tries because I have it blocked in my hosts file to have it redirected to local host.
This activity shows up when using the command line - netstat -abf 5 > activity.txt

TCP 127.0.0.1:49775 sendmsg.jumpingcrab.com:49776 ESTABLISHED
[firefox.exe]

Also Avast is doing the same

TCP 127.0.0.1:12080 sendmsg.jumpingcrab.com:50430 ESTABLISHED
[AvastSvc.exe]
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built with TLC
OS
Windows11 Pro
CPU
Intel Skt 1200 Comet Lake Core i-7 3.80 GHZ
Motherboard
Gigabyte Z590 UD AC
Memory
32GB [4 x 8gb] Crucial Ballistix XMP DDR 4
Graphics Card(s)
ATI [MSI] Radeon RX 5500 XT 8GB DDR6
Sound Card
Realtek HD 7.1 Onboard
Monitor(s) Displays
iiyama G2730HSU-B1 27" G-Master 75Mhz HD LED
Screen Resolution
1920 X 1080
Hard Drives
Samsung EVO 970 NVMe 1TB [Boot drive]
Samsung EVO 850 SSD 500GB
Western Digital DC WD10EFRX-68PJCN0 1TB
Western Digital DC WD1002FBYS-02A6B0 Enterprise 1TB
PSU
Corsair TX750M
Case
Zalman Z9 Plus
Cooling
Thermalright True Spirit 120 BW
Keyboard
Havit KB432L blue key mechanical
Mouse
Havit KB 432L Programmable
Internet Speed
Fibre To The Home 100Mbps from KCom
Antivirus
Avast Free
Browser
Firefox
Other Info
Logitech C525 HD Webcam
Epson XP-640 Expression-Premium printer with direct CD/DVD printing
Specs

I see you filled out your specs. Congrats to you.

I would guess you have some malware. You can start by running Malware Bytes. If you don't have it here is a link to download and install.

Malwarebytes
 

My Computer

Computer Manufacturer/Model Number
BGC (Bob's Garage Crew)
OS
win 7 X64 Ultimate SP1
CPU
I3770K
Motherboard
Asus P8Z77-V Deluxe
Memory
G Skill F3-14900CL9-4GBXL x 4
Graphics Card(s)
NVIDIA GeForce GTX670 + Intel 4000
Sound Card
Realtek HD 5.1 (MOB)
Monitor(s) Displays
Asus VW224T (1)
Screen Resolution
1920 x 1080
Hard Drives
SATA Corsair Force GT 2.5" 180GB (System) Sata 3
OCZ Vertex3 120GB
OCZ Vertex 2 120GB 2.5" SATA II
ST31000524AS 1000.2GB
WD15EARS (External)
PSU
CoolerMaster 1000 Watt
Case
CoolerMaster HAF X
Cooling
CPU -- CoolerMaster 520N
Keyboard
MS Wireless 3000 V2
Mouse
MS Wireless 3000 V2
Internet Speed
Cable
Antivirus
Norton Internet Security
Browser
IE9
Other Info
AMI Bios 1805
OC'd 3%
Hi

HammerHead..... thanks for the reply I ran Malwarebytes as I do about once a week anyway, and it found two trojan objects so I deleted them. They weren't there on my last scan obviously!
A scan with Kapersky TDSSkiller anti rootkit detection came up clean as did a scan with SuperAntispyware. An on line analysis of a HiJackThis scan shows no suspicious items either

Netstat still reporting

TCP 127.0.0.1:12080 sendmsg.jumpingcrab.com:50430 ESTABLISHED
[AvastSvc.exe]

and

TCP 127.0.0.1:49187 sendmsg.jumpingcrab.com:49186 ESTABLISHED
[firefox.exe]
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built with TLC
OS
Windows11 Pro
CPU
Intel Skt 1200 Comet Lake Core i-7 3.80 GHZ
Motherboard
Gigabyte Z590 UD AC
Memory
32GB [4 x 8gb] Crucial Ballistix XMP DDR 4
Graphics Card(s)
ATI [MSI] Radeon RX 5500 XT 8GB DDR6
Sound Card
Realtek HD 7.1 Onboard
Monitor(s) Displays
iiyama G2730HSU-B1 27" G-Master 75Mhz HD LED
Screen Resolution
1920 X 1080
Hard Drives
Samsung EVO 970 NVMe 1TB [Boot drive]
Samsung EVO 850 SSD 500GB
Western Digital DC WD10EFRX-68PJCN0 1TB
Western Digital DC WD1002FBYS-02A6B0 Enterprise 1TB
PSU
Corsair TX750M
Case
Zalman Z9 Plus
Cooling
Thermalright True Spirit 120 BW
Keyboard
Havit KB432L blue key mechanical
Mouse
Havit KB 432L Programmable
Internet Speed
Fibre To The Home 100Mbps from KCom
Antivirus
Avast Free
Browser
Firefox
Other Info
Logitech C525 HD Webcam
Epson XP-640 Expression-Premium printer with direct CD/DVD printing
More Help

We will get some more help in a little while. Some members here a are good at this. They'll be along. In the meantime, I am not familiar with fire fox but you need to check your browser addons and if you see anything suspicous disable it.
 

My Computer

Computer Manufacturer/Model Number
BGC (Bob's Garage Crew)
OS
win 7 X64 Ultimate SP1
CPU
I3770K
Motherboard
Asus P8Z77-V Deluxe
Memory
G Skill F3-14900CL9-4GBXL x 4
Graphics Card(s)
NVIDIA GeForce GTX670 + Intel 4000
Sound Card
Realtek HD 5.1 (MOB)
Monitor(s) Displays
Asus VW224T (1)
Screen Resolution
1920 x 1080
Hard Drives
SATA Corsair Force GT 2.5" 180GB (System) Sata 3
OCZ Vertex3 120GB
OCZ Vertex 2 120GB 2.5" SATA II
ST31000524AS 1000.2GB
WD15EARS (External)
PSU
CoolerMaster 1000 Watt
Case
CoolerMaster HAF X
Cooling
CPU -- CoolerMaster 520N
Keyboard
MS Wireless 3000 V2
Mouse
MS Wireless 3000 V2
Internet Speed
Cable
Antivirus
Norton Internet Security
Browser
IE9
Other Info
AMI Bios 1805
OC'd 3%

My Computer

Computer Manufacturer/Model Number
BGC (Bob's Garage Crew)
OS
win 7 X64 Ultimate SP1
CPU
I3770K
Motherboard
Asus P8Z77-V Deluxe
Memory
G Skill F3-14900CL9-4GBXL x 4
Graphics Card(s)
NVIDIA GeForce GTX670 + Intel 4000
Sound Card
Realtek HD 5.1 (MOB)
Monitor(s) Displays
Asus VW224T (1)
Screen Resolution
1920 x 1080
Hard Drives
SATA Corsair Force GT 2.5" 180GB (System) Sata 3
OCZ Vertex3 120GB
OCZ Vertex 2 120GB 2.5" SATA II
ST31000524AS 1000.2GB
WD15EARS (External)
PSU
CoolerMaster 1000 Watt
Case
CoolerMaster HAF X
Cooling
CPU -- CoolerMaster 520N
Keyboard
MS Wireless 3000 V2
Mouse
MS Wireless 3000 V2
Internet Speed
Cable
Antivirus
Norton Internet Security
Browser
IE9
Other Info
AMI Bios 1805
OC'd 3%
Thanks for the replies

The following scans have all reported clean

Malwarebytes full scan
SuperAntispyware full scan
Avast Antivirus full scan
Kapersky TDSSkiller Anti-rootkit scan
HiJackthis Analysed online scan
CWS Shredder
ESET online scanner
Also Comodo CIS is not reporting this activity

Am I right to assume that by redirecting to my local host the connection is never made and I am safe for now till I can establish the culprit?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built with TLC
OS
Windows11 Pro
CPU
Intel Skt 1200 Comet Lake Core i-7 3.80 GHZ
Motherboard
Gigabyte Z590 UD AC
Memory
32GB [4 x 8gb] Crucial Ballistix XMP DDR 4
Graphics Card(s)
ATI [MSI] Radeon RX 5500 XT 8GB DDR6
Sound Card
Realtek HD 7.1 Onboard
Monitor(s) Displays
iiyama G2730HSU-B1 27" G-Master 75Mhz HD LED
Screen Resolution
1920 X 1080
Hard Drives
Samsung EVO 970 NVMe 1TB [Boot drive]
Samsung EVO 850 SSD 500GB
Western Digital DC WD10EFRX-68PJCN0 1TB
Western Digital DC WD1002FBYS-02A6B0 Enterprise 1TB
PSU
Corsair TX750M
Case
Zalman Z9 Plus
Cooling
Thermalright True Spirit 120 BW
Keyboard
Havit KB432L blue key mechanical
Mouse
Havit KB 432L Programmable
Internet Speed
Fibre To The Home 100Mbps from KCom
Antivirus
Avast Free
Browser
Firefox
Other Info
Logitech C525 HD Webcam
Epson XP-640 Expression-Premium printer with direct CD/DVD printing
Browser

Have you checked your browser for addons?

Do a file search on your OS disk for "jumpingcrab" and see what you come up with.
 

My Computer

Computer Manufacturer/Model Number
BGC (Bob's Garage Crew)
OS
win 7 X64 Ultimate SP1
CPU
I3770K
Motherboard
Asus P8Z77-V Deluxe
Memory
G Skill F3-14900CL9-4GBXL x 4
Graphics Card(s)
NVIDIA GeForce GTX670 + Intel 4000
Sound Card
Realtek HD 5.1 (MOB)
Monitor(s) Displays
Asus VW224T (1)
Screen Resolution
1920 x 1080
Hard Drives
SATA Corsair Force GT 2.5" 180GB (System) Sata 3
OCZ Vertex3 120GB
OCZ Vertex 2 120GB 2.5" SATA II
ST31000524AS 1000.2GB
WD15EARS (External)
PSU
CoolerMaster 1000 Watt
Case
CoolerMaster HAF X
Cooling
CPU -- CoolerMaster 520N
Keyboard
MS Wireless 3000 V2
Mouse
MS Wireless 3000 V2
Internet Speed
Cable
Antivirus
Norton Internet Security
Browser
IE9
Other Info
AMI Bios 1805
OC'd 3%
It appears to be a serious problem according to Norton. It's a AV redirect spoof. Could be why nothing you've loaded is finding it. You may have been downloading additional malware. You might try the Norton Power Eraser but I would download it on a different machine and save it to a thumb drive then run it from that on your machine. Pay particular attention to the warning that NPE uses "aggressive methods to detect threats" and be careful what you remove.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
many thanks I'll get to it later. Your input is much appreciated. I do have several back ups going back many weeks if all fails.

Carwiz

Following your instructions the Norton Power eraser retuned a report of no problems found.

Thanks for your input.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built with TLC
OS
Windows11 Pro
CPU
Intel Skt 1200 Comet Lake Core i-7 3.80 GHZ
Motherboard
Gigabyte Z590 UD AC
Memory
32GB [4 x 8gb] Crucial Ballistix XMP DDR 4
Graphics Card(s)
ATI [MSI] Radeon RX 5500 XT 8GB DDR6
Sound Card
Realtek HD 7.1 Onboard
Monitor(s) Displays
iiyama G2730HSU-B1 27" G-Master 75Mhz HD LED
Screen Resolution
1920 X 1080
Hard Drives
Samsung EVO 970 NVMe 1TB [Boot drive]
Samsung EVO 850 SSD 500GB
Western Digital DC WD10EFRX-68PJCN0 1TB
Western Digital DC WD1002FBYS-02A6B0 Enterprise 1TB
PSU
Corsair TX750M
Case
Zalman Z9 Plus
Cooling
Thermalright True Spirit 120 BW
Keyboard
Havit KB432L blue key mechanical
Mouse
Havit KB 432L Programmable
Internet Speed
Fibre To The Home 100Mbps from KCom
Antivirus
Avast Free
Browser
Firefox
Other Info
Logitech C525 HD Webcam
Epson XP-640 Expression-Premium printer with direct CD/DVD printing
Can you upload the HiJackThis log ? Can you open up your Ethernet properties and your wireless adapter properties and see if anything is listed under proxy .
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Oh boy, this is looking like a thread for the Security section. The host is a Chinese IP address

sendmsg.jumpingcrab.com information at DomainReverse.com

It looks like you have the new Trojan Upclicker

Trojan Upclicker malware infecting PCs via mouse input | ITProPortal.com

New Trojan Bypasses Detection with Manipulated Mouse Click - FIGHTERtools

Volatility Labs: What do Upclicker, Poison Ivy, Cuckoo, and Volatility Have in Common?

Upclicker Trojan Evades Sandbox Detection by Hiding in a Mouse Click | threatpost

I could not find any legit removal procedures at the usual security sites, but perhaps VistaKing, or others will be aware of this. A Guy
 

My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
Thread moved, also requested assistance from one of our malware specialists (Jacee).
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dwarf Dwf/11/2012 r09/2013
OS
Windows 8.1 Pro RTM x64
CPU
Intel Core-i5-3570K 4-core @ 3.4GHz (Ivy Bridge) (OC 4.4GHz)
Motherboard
ASRock Z77 Extreme4-M
Memory
4 x 4GB DDR3-1600 Corsair Vengeance CMZ8GX3M2A1600C9B (16GB)
Graphics Card(s)
MSI GeForce GTX770 Gaming OC 2GB
Sound Card
Realtek High Definition on board solution (ALC 898)
Monitor(s) Displays
ViewSonic VA1912w Widescreen (VGA)
Screen Resolution
1440x900
Hard Drives
OCZ Agility 3 SSD 120GB SATA III x2 (RAID 0)
Samsung HD501LJ 500GB SATA II x2
Hitachi HDS721010CLA332 1TB SATA II
Iomega 1.5TB Ext USB 2.0
WD 2.0TB Ext USB 3.0
PSU
XFX Pro Series 850W Semi-Modular
Case
Gigabyte IF233
Cooling
1 x 120mm Front Inlet 1 x 120mm Rear Exhaust
Keyboard
Microsoft Comfort Curve Keyboard 3000 (USB)
Mouse
Microsoft Comfort Mouse 3000 for Business (USB)
Internet Speed
NetGear DG834Gv3 ADSL Modem/Router (Ethernet) ~4.0 Mb/s (O2)
Antivirus
Avast! 8.0.1497
Browser
IE 11
Other Info
Optical Drive: HL-DT-ST BD-RE BH10LS30 SATA Bluray
Lexmark S305 Printer/Scanner/Copier (USB)
WEI Score: 8.1/8.1/8.5/8.5/8.25
Asus Eee PC 1011PX Netbook (Windows 7 x86 Starter)

My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
brotherboard,

While Jacee gets here, you can try the following:

This program reports if Proxy / DNS configurations are found...

Please download RogueKiller:
Tlcharger RogueKiller (Site Officiel)

When you get to the website, go to where it says:
(Download link) Lien de téléchargement:
rendu2x64.png


Select the version that applies to your system: x64
Click the dark-blue button to download.
Save to the Desktop.

Close all windows and browsers.
Right-click and select: Run as Administrator

At the program console, wait for the prescan to finish. (Under Status, it says: Prescan finished.)
Press: SCAN

When done, a report opens on the Desktop: RKreport.txt

Please provide the RKreport.txt (Mode: Scan) in your reply.
(Also, do not delete any entries, please.)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Thank you for all your replies. Having taken on board all the excellent advice, recommendations and spending a lot of time on this, I have done a full restore from original back up discs (without the bloatware !)
My Netstat scans are now showing no sign of the dreaded jumpingcrab.com connections. I'll keep a close check on things, and get back if it re-appears.
Thanks once again. Please mark as solved.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built with TLC
OS
Windows11 Pro
CPU
Intel Skt 1200 Comet Lake Core i-7 3.80 GHZ
Motherboard
Gigabyte Z590 UD AC
Memory
32GB [4 x 8gb] Crucial Ballistix XMP DDR 4
Graphics Card(s)
ATI [MSI] Radeon RX 5500 XT 8GB DDR6
Sound Card
Realtek HD 7.1 Onboard
Monitor(s) Displays
iiyama G2730HSU-B1 27" G-Master 75Mhz HD LED
Screen Resolution
1920 X 1080
Hard Drives
Samsung EVO 970 NVMe 1TB [Boot drive]
Samsung EVO 850 SSD 500GB
Western Digital DC WD10EFRX-68PJCN0 1TB
Western Digital DC WD1002FBYS-02A6B0 Enterprise 1TB
PSU
Corsair TX750M
Case
Zalman Z9 Plus
Cooling
Thermalright True Spirit 120 BW
Keyboard
Havit KB432L blue key mechanical
Mouse
Havit KB 432L Programmable
Internet Speed
Fibre To The Home 100Mbps from KCom
Antivirus
Avast Free
Browser
Firefox
Other Info
Logitech C525 HD Webcam
Epson XP-640 Expression-Premium printer with direct CD/DVD printing
Flush the DNS cache and restore MS's Hosts file ...

Copy and paste these lines in Note pad.

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0


Save as flush.bat to your desktop.
Double click on the flush.bat file to run it.Vista and Windows 7... right click the .bat file and choose to run as Administrator. Your computer will reboot itself.

Then, follow cottonball's instructions.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top