PC Review


Reply
Thread Tools Rate Thread

Spyware not identified?

 
 
David Jones
Guest
Posts: n/a
 
      22nd Apr 2005
C:\Windows\System32\rundll32.exe and C:\Windows\System32
\winlogon.exe are repeatedly trying to connect to the
Internet, specifically:
TCP Connection to h-213.61.6.3.host.de.colt.net
[213.61.6.3:80]
TCP Connection to hosting-68.76.rev.fr.colt.net
[213.41.76.68:80]
TCP Connection to 4.78.20.4:80
TCP Connection to 208.185.54.9.speedera.com
[208.185.54.9:80]

I understand that both of these exe's are integral parts
of XP, and it's whatever's calling them that's the
problem. I've got Norton Antivirus, and Microsoft Spyware
running and I've scanned my drives with AntiVir but
they've found nothing. I've stopped or disabled as many
services as I can, and done the same with msconfig to
prune the programs that run on startup

I can shutdown the RunDLL32.exe using Task Manager, but
not WinLogon.exe as it's a 'critical system process'

For now, I've just set Kerio Firewall to block both exe's
from accessing the Internet, but I'd like to find a more
permanent solution, because it repeatedly tries to
connect, increasing the local port number each time, until
I get a buffer overflow error and have to reboot.
 
Reply With Quote
 
 
 
 
Monitor
Guest
Posts: n/a
 
      24th Apr 2005
Submit a Suspected Spyware Report
>-----Original Message-----
>C:\Windows\System32\rundll32.exe and C:\Windows\System32
>\winlogon.exe are repeatedly trying to connect to the
>Internet, specifically:
>TCP Connection to h-213.61.6.3.host.de.colt.net
>[213.61.6.3:80]
>TCP Connection to hosting-68.76.rev.fr.colt.net
>[213.41.76.68:80]
>TCP Connection to 4.78.20.4:80
>TCP Connection to 208.185.54.9.speedera.com
>[208.185.54.9:80]
>
>I understand that both of these exe's are integral parts
>of XP, and it's whatever's calling them that's the
>problem. I've got Norton Antivirus, and Microsoft Spyware
>running and I've scanned my drives with AntiVir but
>they've found nothing. I've stopped or disabled as many
>services as I can, and done the same with msconfig to
>prune the programs that run on startup
>
>I can shutdown the RunDLL32.exe using Task Manager, but
>not WinLogon.exe as it's a 'critical system process'
>
>For now, I've just set Kerio Firewall to block both exe's
>from accessing the Internet, but I'd like to find a more
>permanent solution, because it repeatedly tries to
>connect, increasing the local port number each time,

until
>I get a buffer overflow error and have to reboot.
>.
>

 
Reply With Quote
 
 
 
 
Bill Sanderson
Guest
Posts: n/a
 
      26th Apr 2005
I can't tell what's going on here--but this may be legit traffic.

Is your ISP colt.net, or do they use colt.net's facilities?

--
FAQ for Microsoft Antispyware:
http://www.geocities.com/marfer_mvp/FAQ_MSantispy.htm

"David Jones" <(E-Mail Removed)> wrote in message
news:11f001c5476b$51a46c10$(E-Mail Removed)...
> C:\Windows\System32\rundll32.exe and C:\Windows\System32
> \winlogon.exe are repeatedly trying to connect to the
> Internet, specifically:
> TCP Connection to h-213.61.6.3.host.de.colt.net
> [213.61.6.3:80]
> TCP Connection to hosting-68.76.rev.fr.colt.net
> [213.41.76.68:80]
> TCP Connection to 4.78.20.4:80
> TCP Connection to 208.185.54.9.speedera.com
> [208.185.54.9:80]
>
> I understand that both of these exe's are integral parts
> of XP, and it's whatever's calling them that's the
> problem. I've got Norton Antivirus, and Microsoft Spyware
> running and I've scanned my drives with AntiVir but
> they've found nothing. I've stopped or disabled as many
> services as I can, and done the same with msconfig to
> prune the programs that run on startup
>
> I can shutdown the RunDLL32.exe using Task Manager, but
> not WinLogon.exe as it's a 'critical system process'
>
> For now, I've just set Kerio Firewall to block both exe's
> from accessing the Internet, but I'd like to find a more
> permanent solution, because it repeatedly tries to
> connect, increasing the local port number each time, until
> I get a buffer overflow error and have to reboot.



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Spyware Not Detected???? How to Submit a suspected spyware report Steve Dodson [MSFT] Security Signatures 4 10th Apr 2005 09:27 PM
MS Spyware not picking known spyware Pakman Anti-Spyware Installation 3 3rd Mar 2005 10:36 PM
Spyware not caught by MS anti-spyware tool Ara Barsamian Security Signatures 1 8th Feb 2005 05:23 PM
Microsoft anti spyware does not block spyware on hotmail Matt Security and Anti-Spyware Community 1 1st Feb 2005 04:43 PM
Spyware Program does not find spyware Barry Spyware Discussion 2 12th Jan 2005 07:25 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 01:22 AM.