Why would Windows Explorer try to access the internet??

A

andy

Whenever I start my computer I get a message from my
firewall that Windows Explorer has changed since my last
startup and that it is trying to contact IP 224.0.0.22

the path on my system is C:\WINDOWS\system32\ntoskrnl.exe

looking up the IP shows that it is for:IGMP.MCAST.NET

Any explaination would be appreciated.

Andy
 
M

Malke

andy said:
Whenever I start my computer I get a message from my
firewall that Windows Explorer has changed since my last
startup and that it is trying to contact IP 224.0.0.22

the path on my system is C:\WINDOWS\system32\ntoskrnl.exe

looking up the IP shows that it is for:IGMP.MCAST.NET

Any explaination would be appreciated.

Andy

What does a scan with a current antivirus program (meaning a version not
earlier than 2003 using updated virus definitions) show? What do your
firewall logs show?

Malke
 
M

Malke

andy said:
Whenever I start my computer I get a message from my
firewall that Windows Explorer has changed since my last
startup and that it is trying to contact IP 224.0.0.22

the path on my system is C:\WINDOWS\system32\ntoskrnl.exe

looking up the IP shows that it is for:IGMP.MCAST.NET

Any explaination would be appreciated.

Andy

Sorry to add a second response, but I see that you already looked at
your firewall log. It sounds very much like you have a trojan in place,
but you should also check to see what legitimate (but possibly
invasive) programs are "phoning home". Use Task Manager and msconfig to
see what is running and look at all the preferences for those programs
to see if they are searching for updates.

If you do have current av in place and the machine is clean, try running
some anti-spyware tools, too, like Ad-aware and Spybot S&D.

Malke
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top