CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[DONE]Svchost phoning home moe often
Goto page 1, 2  Next
 
Post new topic   Reply to topic       All -> FavForums -> Firewalls [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Tib

Lieutenant
Lieutenant


Joined: Jun 25, 2006
Posts: 159
Location: UK

PostPosted: Wed Aug 16, 2006 11:33 pm    Post subject: Svchost phoning home moe often
Reply with quote

Hi, only me. Very Happy

I know it seems common plcae for svchost.exe to phone home but recently it's been dong it more often on my pc. I know the system is malware free so I am jsut trying to find some mroe infromation on it. The sites I googled were rather breif so I was hopng you CC guys could shine some light on it.


Thanks

Tib

Back to top
View users profile Send private message
checkmate

Colonel
Colonel
Premium Member

Joined: Feb 21, 2005
Posts: 1737

Premium

PostPosted: Thu Aug 17, 2006 3:15 am    Post subject: Re: Svchost phoning home moe often
Reply with quote

Hello Tib,

do you have logs from your firewall, if you are using one? Please explain what you mean by "phoning home". svchost should not be connecting out routinely other than for DNS lookups on port 53, UDP. it will also connect on ports 80 and 443 when you are scanning for Microsoft updates, as well as rarely for ssdp discovery service/UPnP device host TCP 2869 and UDP 1900 (I even have this rule disabled for svchost) and time synchronization on ports 123 or 37.

Back to top
View users profile Send private message
checkmate

Colonel
Colonel
Premium Member

Joined: Feb 21, 2005
Posts: 1737

Premium

PostPosted: Thu Aug 17, 2006 3:21 am    Post subject: Re: Svchost phoning home moe often
Reply with quote

**EDIT**

I have not listed all the possibilities for svchost connecting to the network, but it should not be routinely "phoning home".

Back to top
View users profile Send private message
Tib

Guest
IP: 81.153.*.*






PostPosted: Thu Aug 17, 2006 11:07 am    Post subject:
Reply with quote

It appareas (although I cant check as im not on my home pc) to be connecting to the source of my bt connection which isukcoreserver.bt.bet or something along those lines.

Back to top
checkmate

Colonel
Colonel
Premium Member

Joined: Feb 21, 2005
Posts: 1737

Premium

PostPosted: Fri Aug 18, 2006 12:53 am    Post subject:
Reply with quote

Tib wrote:
It appareas (although I cant check as im not on my home pc) to be connecting to the source of my bt connection which isukcoreserver.bt.bet or something along those lines.


Can you include more info similar to the following:

6:46:53 PM svchost.exe OUT UDP 192.168.0.1 DNS *Allow UDP for SVCHOST.EXE to 53 ?

Back to top
View users profile Send private message
Tib

Lieutenant
Lieutenant


Joined: Jun 25, 2006
Posts: 159
Location: UK

PostPosted: Fri Aug 18, 2006 7:20 pm    Post subject:
Reply with quote

ok here it is:

destination IP: 62.6.40.178.53.

Idnsc71.uk.bt.net.

Direction: outgoing

action taken: blocked

Back to top
View users profile Send private message
Tib

Guest
IP: 81.151.*.*






PostPosted: Fri Aug 18, 2006 11:41 pm    Post subject:
Reply with quote

Hmmm a more unusual problem I think is at hand. A program I use for Im called xfire (which is safe and everything) Had an outgoing intrusion blocked except it was going to a website called cluchkill.com or clutchkill.com something along those lines. As far as im aware my computer is malware free. I use AVG, ewido anti spyware free, Spybot, and ad aware and they picked up nothing so I don't think a trojans at work. Just very odd as I have seen programs connect back to there own site or the BT adress above but never to another random site. Any comments much aprechiated.

Tib

P.S Im going on holiday for two weeks so obviously I might not respond till then. Wink

Back to top
Tib

Guest
IP: 81.151.*.*






PostPosted: Fri Aug 18, 2006 11:47 pm    Post subject:
Reply with quote

Sorry for another psot but can't log in on this pc. The destination Ip for the xfire adress was: 72.232.215.230.29000.

Thanks


Tib

Back to top
checkmate

Colonel
Colonel
Premium Member

Joined: Feb 21, 2005
Posts: 1737

Premium

PostPosted: Sat Aug 19, 2006 12:17 am    Post subject:
Reply with quote

Tib wrote:
ok here it is:

destination IP: 62.6.40.178.53.

Idnsc71.uk.bt.net.

Direction: outgoing

action taken: blocked


It looks like it is just a DNS lookup on port 53, UDP. However, I can't really figure out what that ip belongs to using whois ip search, nor am I sure why it is blocked, unless you set your firewall to block those connection attempts? What you should do is contact your ISP and ask what their DNS ip addresses (usually they will have a primary and secondary) are and see if they match the one above. Also, make sure your svchost processes reside in your System32 folder only.

Back to top
View users profile Send private message
checkmate

Colonel
Colonel
Premium Member

Joined: Feb 21, 2005
Posts: 1737

Premium

PostPosted: Sat Aug 19, 2006 12:25 am    Post subject:
Reply with quote

Tib wrote:
Sorry for another psot but can't log in on this pc. The destination Ip for the xfire adress was: 72.232.215.230.29000.

Thanks


Tib


This I believe is harmless as it is probably a gaming server that your xfire program can access. A little more research on the first ip address you provided looks to be a UK location from a tracert I ran on it, giving me further belief it is probably a DNS server. Still, i would contact your ISP for information on their DNS ip addresses.

Back to top
View users profile Send private message
Tib

Lieutenant
Lieutenant


Joined: Jun 25, 2006
Posts: 159
Location: UK

PostPosted: Sat Aug 19, 2006 12:29 am    Post subject:
Reply with quote

Thansk so much m8. I jsut got a bit scared and ran an onlien virsus can plus a hijackthis log. Now I can relax on my holiday. Thanks check mate.

Tib

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Sat Aug 19, 2006 5:11 am    Post subject:
Reply with quote

Uh, that IP address should properly be read as 72.232.215.230 Port 29000. Here's the whois:

Quote:
OrgName: Layered Technologies, Inc.
OrgID: LAYER-3
Address: 18816 Preston Road
Address: Suite #100
City: Dallas
StateProv: TX
PostalCode: 75252
Country: US

ReferralServer: rwhois://rwhois.layeredtech.com:4321

NetRange: 72.232.0.0 - 72.232.255.255
CIDR: 72.232.0.0/16
NetName: LAYERED-TECH-
NetHandle: NET-72-232-0-0-1
Parent: NET-72-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.LAYEREDTECH.COM
NameServer: NS2.LAYEREDTECH.COM
Comment: Please send all abuse complaints to
Comment: abuse@layeredtech.com
RegDate: 2005-09-07
Updated: 2006-03-07

RTechHandle: JPS66-ARIN
RTechName: Suo-Anttila, Jeremy Paul
RTechPhone: +1-972-398-7998
RTechEmail: jps@layeredtech.com

OrgAbuseHandle: LAT-ARIN
OrgAbuseName: LT Abuse Team
OrgAbusePhone: +1-972-398-7998
OrgAbuseEmail: abuse@layeredtech.com

OrgNOCHandle: LIT-ARIN
OrgNOCName: LT IP-Network Team
OrgNOCPhone: +1-972-398-7998
OrgNOCEmail: ipnet@layeredtech.com

OrgTechHandle: LNT3-ARIN
OrgTechName: LT NOC Team
OrgTechPhone: +1-972-398-7998
OrgTechEmail: ipnet@layeredtech.com


http://www.layeredtech.com/


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Tib

Guest
IP: 81.153.*.*






PostPosted: Sat Aug 19, 2006 11:01 am    Post subject:
Reply with quote

Sorry for the mistake Prince Serendip. Will continue this thread when im back from holiday. BTW does it still appaear to be a game server of some sort?


Tib

Back to top
checkmate

Colonel
Colonel
Premium Member

Joined: Feb 21, 2005
Posts: 1737

Premium

PostPosted: Sat Aug 19, 2006 11:56 pm    Post subject:
Reply with quote

No worries Tib,

I had already figured out the last numbers, 53 & 29000, appended at the end of the ip addresses were ports Smile

Below I have attached a ss of the site: Clutchkill.com (72.232.215.230)

However, when I connected to the site it connected at that ip, but on remote port 80 (http). My feeling is it is a site that your xfire utility sometimes connects to and is probably nothing to worry about, but I am not completely certain. I am not an expert in this area. Tib, I want to offer some more information but I really need to run. We are entertaining guests tonight. I will post back tomorrow am.

By for now.




Clutchkill_com.png
 Description:
 Filesize:  27.25 KB
 Viewed:  48 Time(s)

Clutchkill_com.png


Back to top
View users profile Send private message
checkmate

Colonel
Colonel
Premium Member

Joined: Feb 21, 2005
Posts: 1737

Premium

PostPosted: Sun Aug 20, 2006 7:40 pm    Post subject: Re: Svchost phoning home moe often
Reply with quote

Hi again Tib.

If you ever need a detailed listing of any and all TCP and UDP endpoints from your computer, there is a nifty, free utility I recommend from Sysinternals here:

If you are running Windows NT/2000/XP or Windows 98/Me, then download TCPView from here:

http://www.sysinternals.com/Utilities/TcpView.html Just scroll to the bottom of the page and choose the first download (81 KB). Create a folder under your Program files and name it whatever you want, then extract the download to the folder (4 files). Create a shortcut on your desktop to the Tcpview.exe file . Close any and all browsers then double-click the shortcut to launch TCPView. If you are running under a limited account, use the right-click->Run as option to launch it under administrative priveledges.

You will see 5 columns named: Process, Protocol, Local Address, Remote Address and State. This will enable you to see local and remote network status of all related processes. You can even right-click the process for its properties to see what directory it resides in. This is a very handy utility especially for anything that looks like a suspicious connection.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Firewalls All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer