| View previous topic :: View next topic |
| Author |
Message |
Tib
Lieutenant

 Joined: Jun 25, 2006 Posts: 159 Location: UK
|
Posted: Wed Aug 16, 2006 11:33 pm Post subject: Svchost phoning home moe often |
|
|
Hi, only me.
I know it seems common plcae for svchost.exe to phone home but recently it's been dong it more often on my pc. I know the system is malware free so I am jsut trying to find some mroe infromation on it. The sites I googled were rather breif so I was hopng you CC guys could shine some light on it.
Thanks
Tib
|
|
| Back to top |
|
 |
checkmate
Colonel
 Premium Member
 Joined: Feb 21, 2005 Posts: 1737
|
Posted: Thu Aug 17, 2006 3:15 am Post subject: Re: Svchost phoning home moe often |
|
|
Hello Tib,
do you have logs from your firewall, if you are using one? Please explain what you mean by "phoning home". svchost should not be connecting out routinely other than for DNS lookups on port 53, UDP. it will also connect on ports 80 and 443 when you are scanning for Microsoft updates, as well as rarely for ssdp discovery service/UPnP device host TCP 2869 and UDP 1900 (I even have this rule disabled for svchost) and time synchronization on ports 123 or 37.
|
|
| Back to top |
|
 |
checkmate
Colonel
 Premium Member
 Joined: Feb 21, 2005 Posts: 1737
|
Posted: Thu Aug 17, 2006 3:21 am Post subject: Re: Svchost phoning home moe often |
|
|
**EDIT**
I have not listed all the possibilities for svchost connecting to the network, but it should not be routinely "phoning home".
|
|
| Back to top |
|
 |
Tib
Guest IP: 81.153.*.*
|
Posted: Thu Aug 17, 2006 11:07 am Post subject: |
|
|
It appareas (although I cant check as im not on my home pc) to be connecting to the source of my bt connection which isukcoreserver.bt.bet or something along those lines.
|
|
| Back to top |
|
 |
checkmate
Colonel
 Premium Member
 Joined: Feb 21, 2005 Posts: 1737
|
Posted: Fri Aug 18, 2006 12:53 am Post subject: |
|
|
| Tib wrote: | | It appareas (although I cant check as im not on my home pc) to be connecting to the source of my bt connection which isukcoreserver.bt.bet or something along those lines. |
Can you include more info similar to the following:
6:46:53 PM svchost.exe OUT UDP 192.168.0.1 DNS *Allow UDP for SVCHOST.EXE to 53 ?
|
|
| Back to top |
|
 |
Tib
Lieutenant

 Joined: Jun 25, 2006 Posts: 159 Location: UK
|
Posted: Fri Aug 18, 2006 7:20 pm Post subject: |
|
|
ok here it is:
destination IP: 62.6.40.178.53.
Idnsc71.uk.bt.net.
Direction: outgoing
action taken: blocked
|
|
| Back to top |
|
 |
Tib
Guest IP: 81.151.*.*
|
Posted: Fri Aug 18, 2006 11:41 pm Post subject: |
|
|
Hmmm a more unusual problem I think is at hand. A program I use for Im called xfire (which is safe and everything) Had an outgoing intrusion blocked except it was going to a website called cluchkill.com or clutchkill.com something along those lines. As far as im aware my computer is malware free. I use AVG, ewido anti spyware free, Spybot, and ad aware and they picked up nothing so I don't think a trojans at work. Just very odd as I have seen programs connect back to there own site or the BT adress above but never to another random site. Any comments much aprechiated.
Tib
P.S Im going on holiday for two weeks so obviously I might not respond till then. 
|
|
| Back to top |
|
 |
Tib
Guest IP: 81.151.*.*
|
Posted: Fri Aug 18, 2006 11:47 pm Post subject: |
|
|
Sorry for another psot but can't log in on this pc. The destination Ip for the xfire adress was: 72.232.215.230.29000.
Thanks
Tib
|
|
| Back to top |
|
 |
checkmate
Colonel
 Premium Member
 Joined: Feb 21, 2005 Posts: 1737
|
Posted: Sat Aug 19, 2006 12:17 am Post subject: |
|
|
| Tib wrote: | ok here it is:
destination IP: 62.6.40.178.53.
Idnsc71.uk.bt.net.
Direction: outgoing
action taken: blocked |
It looks like it is just a DNS lookup on port 53, UDP. However, I can't really figure out what that ip belongs to using whois ip search, nor am I sure why it is blocked, unless you set your firewall to block those connection attempts? What you should do is contact your ISP and ask what their DNS ip addresses (usually they will have a primary and secondary) are and see if they match the one above. Also, make sure your svchost processes reside in your System32 folder only.
|
|
| Back to top |
|
 |
checkmate
Colonel
 Premium Member
 Joined: Feb 21, 2005 Posts: 1737
|
Posted: Sat Aug 19, 2006 12:25 am Post subject: |
|
|
| Tib wrote: | Sorry for another psot but can't log in on this pc. The destination Ip for the xfire adress was: 72.232.215.230.29000.
Thanks
Tib |
This I believe is harmless as it is probably a gaming server that your xfire program can access. A little more research on the first ip address you provided looks to be a UK location from a tracert I ran on it, giving me further belief it is probably a DNS server. Still, i would contact your ISP for information on their DNS ip addresses.
|
|
| Back to top |
|
 |
Tib
Lieutenant

 Joined: Jun 25, 2006 Posts: 159 Location: UK
|
Posted: Sat Aug 19, 2006 12:29 am Post subject: |
|
|
Thansk so much m8. I jsut got a bit scared and ran an onlien virsus can plus a hijackthis log. Now I can relax on my holiday. Thanks check mate.
Tib
|
|
| Back to top |
|
 |
Prince_Serendip
Site Moderator
 Joined: Sep 07, 2002 Posts: 17542
|
Posted: Sat Aug 19, 2006 5:11 am Post subject: |
|
|
Uh, that IP address should properly be read as 72.232.215.230 Port 29000. Here's the whois:
| Quote: | OrgName: Layered Technologies, Inc.
OrgID: LAYER-3
Address: 18816 Preston Road
Address: Suite #100
City: Dallas
StateProv: TX
PostalCode: 75252
Country: US
ReferralServer: rwhois://rwhois.layeredtech.com:4321
NetRange: 72.232.0.0 - 72.232.255.255
CIDR: 72.232.0.0/16
NetName: LAYERED-TECH-
NetHandle: NET-72-232-0-0-1
Parent: NET-72-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.LAYEREDTECH.COM
NameServer: NS2.LAYEREDTECH.COM
Comment: Please send all abuse complaints to
Comment: abuse@layeredtech.com
RegDate: 2005-09-07
Updated: 2006-03-07
RTechHandle: JPS66-ARIN
RTechName: Suo-Anttila, Jeremy Paul
RTechPhone: +1-972-398-7998
RTechEmail: jps@layeredtech.com
OrgAbuseHandle: LAT-ARIN
OrgAbuseName: LT Abuse Team
OrgAbusePhone: +1-972-398-7998
OrgAbuseEmail: abuse@layeredtech.com
OrgNOCHandle: LIT-ARIN
OrgNOCName: LT IP-Network Team
OrgNOCPhone: +1-972-398-7998
OrgNOCEmail: ipnet@layeredtech.com
OrgTechHandle: LNT3-ARIN
OrgTechName: LT NOC Team
OrgTechPhone: +1-972-398-7998
OrgTechEmail: ipnet@layeredtech.com |
http://www.layeredtech.com/ _________________
Microsoft MVP Consumer Security 2006, 2007 & 2008
|
|
| Back to top |
|
 |
Tib
Guest IP: 81.153.*.*
|
Posted: Sat Aug 19, 2006 11:01 am Post subject: |
|
|
Sorry for the mistake Prince Serendip. Will continue this thread when im back from holiday. BTW does it still appaear to be a game server of some sort?
Tib
|
|
| Back to top |
|
 |
checkmate
Colonel
 Premium Member
 Joined: Feb 21, 2005 Posts: 1737
|
Posted: Sat Aug 19, 2006 11:56 pm Post subject: |
|
|
No worries Tib,
I had already figured out the last numbers, 53 & 29000, appended at the end of the ip addresses were ports
Below I have attached a ss of the site: Clutchkill.com (72.232.215.230)
However, when I connected to the site it connected at that ip, but on remote port 80 (http). My feeling is it is a site that your xfire utility sometimes connects to and is probably nothing to worry about, but I am not completely certain. I am not an expert in this area. Tib, I want to offer some more information but I really need to run. We are entertaining guests tonight. I will post back tomorrow am.
By for now.
| Description: |
|
| Filesize: |
27.25 KB |
| Viewed: |
48 Time(s) |

|
|
|
| Back to top |
|
 |
checkmate
Colonel
 Premium Member
 Joined: Feb 21, 2005 Posts: 1737
|
Posted: Sun Aug 20, 2006 7:40 pm Post subject: Re: Svchost phoning home moe often |
|
|
Hi again Tib.
If you ever need a detailed listing of any and all TCP and UDP endpoints from your computer, there is a nifty, free utility I recommend from Sysinternals here:
If you are running Windows NT/2000/XP or Windows 98/Me, then download TCPView from here:
http://www.sysinternals.com/Utilities/TcpView.html Just scroll to the bottom of the page and choose the first download (81 KB). Create a folder under your Program files and name it whatever you want, then extract the download to the folder (4 files). Create a shortcut on your desktop to the Tcpview.exe file . Close any and all browsers then double-click the shortcut to launch TCPView. If you are running under a limited account, use the right-click->Run as option to launch it under administrative priveledges.
You will see 5 columns named: Process, Protocol, Local Address, Remote Address and State. This will enable you to see local and remote network status of all related processes. You can even right-click the process for its properties to see what directory it resides in. This is a very handy utility especially for anything that looks like a suspicious connection.
|
|
| Back to top |
|
 |
|
|