there is most certainly something strange going on…
i’m using mcafee 8.5, and noticed that it was griping about blocked activity. i looked at the logs, and bitcomet.exe was hammering out every 60 seconds an attempt to SMTP out to a specific address. after 60 minutes (and 60 tries), it tried to communicate via IRC to another IP address (also blocked), and then spent an hour hammering out SMTP traffic to another IP. repeat this process infinitely. i checked on my wife’s pc - same exact behavior (we’ve both been using .70).
i uninstalled mine, did a virus check and spyware check, went over the running processes with procexp.exe, looked for daffy traffic with tcpview, checked for strange BHO’s, and couldn’t find any wacky services or startup items. system is xp sp2, completely up to date with the latest hotfixes… so i went to bitcomet.com to download the new version, which re-directed me to cnet.com’s download site. that site prompted me to download, but explicitly stated that it was being pulled from a 3rd party (but did not state where). alas, it was late, and i did not check to see where it was going.
this morning, i installed .87, and sure enough - same behavior right out of the gate. so i created a virtual xp sp2 machine in vmware, loaded procexp.exe, tcpview, and mcafee 8.5, and then downloaded and install .87. and with no torrents going, it kep hammering out various ip addresses, trying to chat with them via irc.
now, all of this behavior has been blocked both at my router, and at the desktop level, so nothing has gotten through… but an examination of these IP addresses shows that they are IP’s from ISP’s all over the world, and they’re DHCP ranges for their subscribers (mostly cable modem users)… columbus ohio, oslo, taiwan… you name it. here are some of the IP’s:
5/17/2007 10:49:16 AM Blocked by port blocking rule C:\Program Files\BitComet\BitComet.exe Anti-virus Standard Protection:Prevent IRC communication 217.233.219.130:6666
5/17/2007 10:50:28 AM Blocked by port blocking rule C:\Program Files\BitComet\BitComet.exe Anti-virus Standard Protection:Prevent IRC communication 75.185.93.204:6669
5/17/2007 11:18:57 AM Blocked by port blocking rule C:\Program Files\BitComet\BitComet.exe Anti-virus Standard Protection:Prevent IRC communication 61.62.161.117:6668
5/17/2007 11:48:58 AM Blocked by port blocking rule C:\Program Files\BitComet\BitComet.exe Anti-virus Standard Protection:Prevent IRC communication 82.41.192.102:6667
5/17/2007 11:49:58 AM Blocked by port blocking rule C:\Program Files\BitComet\BitComet.exe Anti-virus Standard Protection:Prevent IRC communication 217.233.219.130:6666
5/17/2007 11:51:07 AM Blocked by port blocking rule C:\Program Files\BitComet\BitComet.exe Anti-virus Standard Protection:Prevent IRC communication 62.166.3.87:6666
5/17/2007 12:19:40 PM Blocked by port blocking rule C:\Program Files\BitComet\BitComet.exe Anti-virus Standard Protection:Prevent IRC communication 75.185.93.204:6669
at this point? i don’t trust bitcomet AT ALL.