View Single Post
  #6  
Old 09-24-2014, 03:26
Conquest Conquest is offline
Friend
 
Join Date: Jan 2013
Location: 0x484F4D45
Posts: 125
Rept. Given: 46
Rept. Rcvd 29 Times in 17 Posts
Thanks Given: 33
Thanks Rcvd at 60 Times in 29 Posts
Conquest Reputation: 29
My bad . this may not be an exact answer but i hope these docs will help you

http://www.nirsoft.net/dll_information/windows8/profsvc_dll.html

http://www.bleepingcomputer.com/tutorials/how-malware-hides-as-a-service/

Since you said ProfSvc.dll is initiating the connection , all that comes to my mind is a compromised dll or hooked one . I dont see any reason for windows dlls to connect to 3rd party software and aid them in updating .

More details or exact behavior will help in determining the problem. i will suggest you to use an api logger to check the program behavior .
Reply With Quote
The Following User Gave Reputation+1 to Conquest For This Useful Post:
niculaita (09-26-2014)