Welcome to WinForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Trojan? concerned

 
   Windows XP Arc1 (Home) -> Security Admin RSS
Next:  Test page prints ok, but cant print from a progra..  
Author Message
halvan2

External


Since: May 02, 2005
Posts: 3



(Msg. 1) Posted: Mon May 02, 2005 3:21 pm
Post subject: Trojan? concerned
Archived from groups: microsoft>public>windowsxp>security_admin (more info?)

I have noticed that my computer has automatically connected to the following
site

v5stats.windowsupdate.microsoft.com(207.46.253.221)

is this a genuine microsoft site or have I been "redirected by a trojan" or
similar?

I have noticed that
v5.windowsupdate.microsoft.com
seem to be genuine


I have also be automatically connected to:

go.microsoft.com(207.46.250.101),

I am using IE 6.0 SP" and XPProf v5.1 Sp2

 >> Stay informed about: Trojan? concerned 
Back to top
Login to vote
David H. Lipman

External


Since: Mar 14, 2004
Posts: 462



(Msg. 2) Posted: Mon May 02, 2005 9:00 pm
Post subject: Re: Trojan? concerned [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "halvan2" <halvan2 RemoveThis @discussions.microsoft.com>

| I have noticed that my computer has automatically connected to the following
| site
|
| v5stats.windowsupdate.microsoft.com(207.46.253.221)
|
| is this a genuine microsoft site or have I been "redirected by a trojan" or
| similar?
|
| I have noticed that
| v5.windowsupdate.microsoft.com
| seem to be genuine
|
| I have also be automatically connected to:
|
| go.microsoft.com(207.46.250.101),
|
| I am using IE 6.0 SP" and XPProf v5.1 Sp2
|

WHOIS results for 207.46.253.221

OrgName: Microsoft Corp
OrgID: MSFT
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US

NetRange: 207.46.0.0 - 207.46.255.255
CIDR: 207.46.0.0/16
NetName: MICROSOFT-GLOBAL-NET
NetHandle: NET-207-46-0-0-1
Parent: NET-207-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.MSFT.NET
NameServer: NS5.MSFT.NET
NameServer: NS2.MSFT.NET
NameServer: NS3.MSFT.NET
NameServer: NS4.MSFT.NET
Comment:
RegDate: 1997-03-31
Updated: 2004-12-09

TechHandle: ZM39-ARIN
TechName: Microsoft
TechPhone: +1-425-882-8080
TechEmail: ***@microsoft.com

OrgAbuseHandle: HOTMA-ARIN
OrgAbuseName: Hotmail Abuse
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: *****@hotmail.com

OrgAbuseHandle: MSNAB-ARIN
OrgAbuseName: MSN ABUSE
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: *****@msn.com

OrgAbuseHandle: ABUSE231-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: *****@microsoft.com

OrgNOCHandle: ZM23-ARIN
OrgNOCName: Microsoft Corporation
OrgNOCPhone: +1-425-882-8080
OrgNOCEmail: ***@microsoft.com

OrgTechHandle: MSFTP-ARIN
OrgTechName: MSFT-POC
OrgTechPhone: +1-425-882-8080
OrgTechEmail: ******@microsoft.com


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm

 >> Stay informed about: Trojan? concerned 
Back to top
Login to vote
halvan2

External


Since: May 02, 2005
Posts: 3



(Msg. 3) Posted: Tue May 03, 2005 6:53 am
Post subject: Re: Trojan? concerned [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Thanks Dave!

"David H. Lipman" wrote:

 > From: "halvan2" <halvan2 DeleteThis @discussions.microsoft.com>
 >
 > | I have noticed that my computer has automatically connected to the following
 > | site
 > |
 > | v5stats.windowsupdate.microsoft.com(207.46.253.221)
 > |
 > | is this a genuine microsoft site or have I been "redirected by a trojan" or
 > | similar?
 > |
 > | I have noticed that
 > | v5.windowsupdate.microsoft.com
 > | seem to be genuine
 > |
 > | I have also be automatically connected to:
 > |
 > | go.microsoft.com(207.46.250.101),
 > |
 > | I am using IE 6.0 SP" and XPProf v5.1 Sp2
 > |
 >
 > WHOIS results for 207.46.253.221
 >
 > OrgName: Microsoft Corp
 > OrgID: MSFT
 > Address: One Microsoft Way
 > City: Redmond
 > StateProv: WA
 > PostalCode: 98052
 > Country: US
 >
 > NetRange: 207.46.0.0 - 207.46.255.255
 > CIDR: 207.46.0.0/16
 > NetName: MICROSOFT-GLOBAL-NET
 > NetHandle: NET-207-46-0-0-1
 > Parent: NET-207-0-0-0-0
 > NetType: Direct Assignment
 > NameServer: NS1.MSFT.NET
 > NameServer: NS5.MSFT.NET
 > NameServer: NS2.MSFT.NET
 > NameServer: NS3.MSFT.NET
 > NameServer: NS4.MSFT.NET
 > Comment:
 > RegDate: 1997-03-31
 > Updated: 2004-12-09
 >
 > TechHandle: ZM39-ARIN
 > TechName: Microsoft
 > TechPhone: +1-425-882-8080
 > TechEmail: ***@microsoft.com
 >
 > OrgAbuseHandle: HOTMA-ARIN
 > OrgAbuseName: Hotmail Abuse
 > OrgAbusePhone: +1-425-882-8080
 > OrgAbuseEmail: *****@hotmail.com
 >
 > OrgAbuseHandle: MSNAB-ARIN
 > OrgAbuseName: MSN ABUSE
 > OrgAbusePhone: +1-425-882-8080
 > OrgAbuseEmail: *****@msn.com
 >
 > OrgAbuseHandle: ABUSE231-ARIN
 > OrgAbuseName: Abuse
 > OrgAbusePhone: +1-425-882-8080
 > OrgAbuseEmail: *****@microsoft.com
 >
 > OrgNOCHandle: ZM23-ARIN
 > OrgNOCName: Microsoft Corporation
 > OrgNOCPhone: +1-425-882-8080
 > OrgNOCEmail: ***@microsoft.com
 >
 > OrgTechHandle: MSFTP-ARIN
 > OrgTechName: MSFT-POC
 > OrgTechPhone: +1-425-882-8080
 > OrgTechEmail: ******@microsoft.com
 >
 >
 > --
 > Dave
<font color=purple> > <a style='text-decoration: underline;' href="http://www.claymania.com/removal-trojan-adware.html</font" target="_blank">http://www.claymania.com/removal-trojan-adware.html</font</a>>
<font color=purple> > <a style='text-decoration: underline;' href="http://www.ik-cs.com/got-a-virus.htm</font" target="_blank">http://www.ik-cs.com/got-a-virus.htm</font</a>>
 >
 >
 ><!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Trojan? concerned 
Back to top
Login to vote
StuartM

External


Since: Mar 15, 2006
Posts: 1



(Msg. 4) Posted: Wed Mar 15, 2006 7:43 pm
Post subject: RE: Trojan? concerned [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

it has also come to my attention that Windows XP computers on a network I
administer are connecting to Microsoft servers and sending data to them (with
an HTTP POST). This is not related to the Windows Update mechanism because I
turned it off. I believe it would be prudent for Microsoft to tell me exactly
what data is being sent, as this 'feature' or unsolicited connection does not
appear to be documented.

"halvan2" wrote:

> I have noticed that my computer has automatically connected to the following
> site
>
> v5stats.windowsupdate.microsoft.com(207.46.253.221)
>
> is this a genuine microsoft site or have I been "redirected by a trojan" or
> similar?
>
> I have noticed that
> v5.windowsupdate.microsoft.com
> seem to be genuine
>
>
> I have also be automatically connected to:
>
> go.microsoft.com(207.46.250.101),
>
> I am using IE 6.0 SP" and XPProf v5.1 Sp2
>
>
 >> Stay informed about: Trojan? concerned 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Windows Media Player....should I be concerned! - Hello-I purchased a new laptop that has about 12 programs according to my "add/remove programs" section. Yesterday, while I was on the internet(dial-up) a message popped up from my system tray something along the lines that "Viewpoint M...

Trojan Horse - Can anyone advise me where to find a secure method to remove a trojan horse from my PC? I am in the process of following instructions on how to do it manually (ie scan for files, safe mode, delete from registry, etc), but wanted to see if anyone had a...

Trojan - tofger - Somehow managed to get a trojan virus on my computer that tries to re-install at reboot. McAfee picks it up and deletes it but have not been able to remove the tag. Upon startup I get "svchost.exe application error." McAfee then pops up a...

Trojan Dropper.Small.5.E - Can anyone tell me how to remove this? Norton did not detect it,but grisoft did,and just put it in the Vault,because it couldn't be removed. Now I ran grisoft twice,which makes me think this Trojan Dropper.Small.5.E reinstalls it self. I may be wrong,and...

XP user in need - Trojan will not go! - My OS is XP Home SP1(all patches) and I run AVG 6.0 Free edition; Adaware SE; & Spybot S&D. AVG has found trojan horse "Collected.AE" in C:\Docs.&Sett.\Username\Local Sett.\Temp\installer.exe I have run AVG numerous times and it...
   Windows XP Arc1 (Home) -> Security Admin All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum

Categories:
 Windows XP
 Windows Vista!
 Win 2000/NT/98/ME


[ Contact us | Terms of Service/Privacy Policy ]