republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » What is 67.72.4.94?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
KAV classifies mIRC as Riskware? »
« Spybot caught Resellerratings trying to install...  
AuthorAll Replies

bthielen

join:2004-11-15

reply to Spooler
Re: ID Serve & Checking Automatic Update

Check out
»headers.bragger.net/info/footpri···tor.html

Leads to sandpiper.net then this..
»www.cw.com/about_us/company_prof···_7a.html


Spooler

@cableone.net

reply to BlitzenZeus
WiseGuy and Zeus:

Thanks again. Sorry this turned into such a long dialog, but each post resulted in new learning (for me, at least).
----------------
Wise Guy:

I turned Windows Updates off and on without rebooting as you suggested. Kept TCPview on top to see what happened in real time. Three IP's appeared:

Two to MSFT at 64.4.23.156 which is ID'd as v5.windowsupdate.microsoft.com in my router logs.

And then one to 67.72.120.62 which is ID'd as "Footprint Distributor" by the GRC ID Serve utility you suggested.

That's a neat little tool. Thanks for recommending it.
--------------

BlitzenZeus:

Once again, you are right on from the start.

The exercises since your first post confirm the outbound to IP 67.72.4.94 is connected to MSFT Windows AutoUpdates using Level Three and what turned the third party servers - "Footprint".

TCPview caught it in action just as you said it would.

Thanks Everyone.
------------------

Mods - looks like we are done here with this one.


BlitzenZeus
Burnt Out Cynic
Premium,MVM
join:2000-01-13
Beaverton, OR
reply to TheWiseGuy
PID 0 is actually a port waiting to timeout for its next use, the program that was listening is no longer bound to that port, and these are just past connections, however they do not show which program was listening.

TheWiseGuy
Dog And Butterfly
Premium,MVM
join:2002-07-04
Yonkers, NY

reply to Spooler
said by Spooler:

Also turned AutoUpdates off & back on and rebooted.
I didn't need to reboot, I hit apply (WinXP Home) and it immediately checked for Updates, disabled it, waited a couple of minutes and selected "Notify me but..." again and it connected out again.

I believe PID 0 is normally System Idle process.
--
Dog and Butterfly


Spooler

@cableone.net

reply to TheWiseGuy
Well, thanks again, Dr. S & WiseGuy:

Went to GRC and downloaded ID serve as suggested. It clearly confirms the ID of the IP in Question as a "Footprint" site.
(see above) Thanks for that tool.

Also turned AutoUpdates off & back on and rebooted.

Computer went to home page first (Yahoo), then to ZA sites, Perhaps AutoUpdates was using Akamai that time rather than Level 3.then to 81.52.249.182 which is identified as an Akamai site.

TCPview showed that site and "System"0 for a while then it disappeared from view.

Raises a new issue though, and that is:
What is the Process reported as "System 0" in TCPview where it normally reports the Service and PID?

TheWiseGuy
Dog And Butterfly
Premium,MVM
join:2002-07-04
Yonkers, NY


1 edit
reply to Spooler
Checking Automatic Update

OK had some time to do a couple of tests and check some tools.

You can try turning off automatic update, and then turning it back on, this should cause it to check for updates and may tell you if it is what is causing the connection. When I did this several times, Port Reporter recorded svchost connecting each time to three IPs, in one of the updates the last was a Footprint Server on the Level 3 network.
64.152.17.157

If that doesn't confirm it, you can install and run Port Reporter it may provide enough information to figure it out.

»support.microsoft.com/default.as···d=837243
--
Dog and Butterfly
Forums » Up and Running » Security » SecurityKAV classifies mIRC as Riskware? »
« Spybot caught Resellerratings trying to install...  


Tuesday, 01-Dec 05:45:44 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [60] Baltimore To Ban Lazy Cable Installs
· [48] Broadband Killed The Game Console
· [36] Rural Carriers Quickly Embracing Fiber
· [31] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [25] Charter Exits Chapter 11
· [22] Midcontinent Socked With Easement Lawsuit
· [4] Monday Evening Links
· [3] Monday Morning Links
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Is Microsoft Technet ok to use for my family PC's? [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]
· Are GPS's better today? [General Questions]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Why is VoIP Better than POTS? [VOIP Tech Chat]