Why is Spoolsv sending UDP datagrams

P

PaulG

Zone alarm is blocking UDP datagrams occasionally being sent from my
PC running XP Home to various IP addresses around the world for
example...

- 218.87.86.104 = CHINANET jiangxi province network - China
- 213.132.100.180 = IP-Only Tele Communication AB - Denmark
- 200.13.220.72 = Administracion de Redes en Colomsat S.A. - Columbia
- 210.5.22.10 = NH-CABLE-COM-CN - China
- 62.215.229.162 = Fast Telecommunictions Company - Kuwai
and others in the US, Europe and even Liverpool.

I used TDIMon to trace the source and it says that they are coming
from spoolsv.exe and I have no idea why the spooler (if that's what it
genuinely is) should be trying to send 50 byte datagrams to such a
diverse set of IP addresses.

I have run the latest Norton antivirus, Adaware and Spybot checks and
all say the system is clean.

I've searched the forums and the web and found a few cases of people
with the same problem but no indications of what the cause and the
solution might be.

Can anyone suggest a possible cause, solition or qny idea for further
investigation.

Thanks ... Paul
 
P

PaulG

I had searched the hard file but not the registry - tried a couple of
the root strings xxx.xxx but didn't find any. I suppose they could be
stored as URLs and resolved by the DNS and searching files for ASCII
strings could easily miss something.

Anyone know how to check what the DNS traffic is?
 
Top