It is currently Tue Sep 01, 2026 4:05 pm


Svchost - weird outgoing connections

Discuss security related topics in here (Hacking, Cracking, and Protecting)
Do not post HJT Logs here

Moderator: PCguy

Svchost - weird outgoing connections

Postby lbb87 » Fri Feb 25, 2005 2:54 am

First I want to say that I've scanned my computer with my antivirus software and used two online virus scanners and my computer is clean. I've also scanned it with spyware/adware programs such as Ad-Aware and a few online spyware scanners and my computer is clean. I have a firewall properly installed/configured and have had no security problems at all recently. I'm running XP Home and I'm on dialup.

The problem started around Feb. 10 when I discovered that svchost.exe tries to make outgoing connections to download.microsoft.co (64.215.169.168) every 10 minutes on TCP port 80. I've had svchost blocked by firewall for the past three years and I've never had any problems doing that until Feb. 10. I have Automatic Windows Updates set to disabled/manual as I like to install the updates myself so I know exactly what's going on. In those cases I allow svchost to connect to Microsoft. It appears that the IP address belongs to Global Crossing and not Microsoft which makes me very suspicious. Svchost also tried to make outgoing connections to c7.zedo.com (65.161.97.145).

I can't figure out why all of a sudden svchost is trying to make this connection and if it's legitimate. It may be no big deal but I'd still like to know what's going on. Does anyone have any ideas?

Last year around this time, svchost was trying to make connections to time.windows.com but the IP address did not belong to Microsoft.
User avatar
lbb87
Newbie
Newbie
 
Posts: 11
Joined: Sun Nov 16, 2003 1:00 am

Thanks given:0
Thanks received:0
Top

Postby liljim » Fri Feb 25, 2005 5:22 am

for me, c7.xedo.com turned up a different address with unknown registrant info.


Target: c7.zedo.com
Date: 2/24/2005 (Thursday), 10:17:08 PM
Nodes: 11


Node Data
Node Net Reg IP Address Location Node Name
11 1 1 63.210.142.15 Boston unknown.level3.net


Packet Data
Node High Low Avg Tot Lost
11 252 252 252 1 0


Network Data
Network id#: 1
Level 3 Communications, Inc. LEVEL4-CIDR (NET-63-208-0-0-1)
63.208.0.0 - 63.215.255.255
Akamai Customer Care LVLT-ACC-221-63-210-142 (NET-63-210-142-0-1)
63.210.142.0 - 63.210.142.255

------------------------------------------------------------------------------------

I ran the ip you came up with and got this


Target: 65.161.97.145
Date: 2/24/2005 (Thursday), 10:23:25 PM
Nodes: 15


Node Data
Node Net Reg IP Address Location Node Name
15 1 - 65.161.97.145 Boston


Packet Data
Node High Low Avg Tot Lost
15 314 314 314 1 0


Network Data
Network id#: 1
Sprint SPRINTLINK-2-BLKS (NET-65-160-0-0-1)
65.160.0.0 - 65.174.255.255
Akamai Technologies SPRINTLINK (NET-65-161-97-128-1)
65.161.97.128 - 65.161.97.255




All of their information is private, that makes hard to say what they are or why you have outgoing traffic to them.
User avatar
liljim
Moderator
Moderator
 
Posts: 3017
Joined: Mon Mar 03, 2003 1:00 am
Location: Louisiana
Operating System:

Thanks given:0
Thanks received:12
Top


Return to Security

Who is online

Users browsing this forum: No registered users and 1 guest

cron