Vista Forums
Vista Forums Home Join Vista Forums Donate Vista Tutorials Store Tags

Welcome to Vista Forums we are your forum to discuss Windows Vista x64 and x86 systems.

Go Back   Vista Forums > Vista Forums > System Security

Unknown IP address showing up in log

Reply
 
Thread Tools Display Modes
Old 04-23-2008   #1 (permalink)
Newbie
tmcmulli is on a distinguished road
 
Join Date: Apr 2008
Vista Ultimate 32 and 64
Posts: 4

Unknown IP address showing up in log

I'm running Vista 64-bit, OneCare firewall, and have just downloaded and run ESET AV. I have an outbound ip address showing up in a sniffer log about every 5 minutes or so, only from this one machine. The IP address does not resolve, and doesn't seem to exist, but the fact that my machine is trying to reach out bugs me.

I found the problem on Airsnare, and caught the outbound ICMP request via Ethereal. Inside of a Linksys router, with only a non-standard VNC port forwarded to this machine.

Any ideas are GREATLY appreciated.
tmcmulli is offline   Reply With Quote

Old 04-24-2008   #2 (permalink)
ʛٯᴙᵁ

dmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud of
 
dmex's Avatar
 
Join Date: May 2007
Vista Ultimate
Posts: 1,716

Location: Fremantle, Western Australia
Re: Unknown IP address showing up in log

You can check with network-tools.com and see who is the registrant of the domain...Whats the IP?
dmex is offline   Reply With Quote
Old 04-24-2008   #3 (permalink)
Newbie
tmcmulli is on a distinguished road
 
Join Date: Apr 2008
Vista Ultimate 32 and 64
Posts: 4

Re: Unknown IP address showing up in log

Quote:
dmex
View Post
You can check with network-tools.com and see who is the registrant of the domain...Whats the IP?
I looked it up at whois and that didn't lead anywhere. Network-tools.com has it listed to bbnplanet.net, with a reference to markmonitor.com. Starting to definitely look like spyware, but three anti-spy programs have had zero results.

IP is 4.25.17.65.. system is hitting this address every two-three minutes, but the log shows the ip address doesn't exist. Thank God...
tmcmulli is offline   Reply With Quote
Old 04-24-2008   #4 (permalink)
ʛٯᴙᵁ

dmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud ofdmex has much to be proud of
 
dmex's Avatar
 
Join Date: May 2007
Vista Ultimate
Posts: 1,716

Location: Fremantle, Western Australia
Re: Unknown IP address showing up in log

I used another site Whois record for 4.25.17.65 and the results say the IP is owned by Las Vegas Little Theatre: By The Community, For The Community so I have no idea who owns that IP address try some of these sites and see if they all report a similar registrant whois - Google Search....

The IP address is active and responding to ping requests and not all malware/spyware is included in the latest definition updates (spybot S+D allows you to download beta updates, try them) so you might/might not have an infection but any system constantly hitting that IP is curious and an anomaly...
dmex is offline   Reply With Quote
Old 04-26-2008   #5 (permalink)
Newbie
tmcmulli is on a distinguished road
 
Join Date: Apr 2008
Vista Ultimate 32 and 64
Posts: 4

Re: Unknown IP address showing up in log

Unfortunately, LVLT is Level Three... that's their class A IP license...so no way of knowing who this thing is registered to from what I can tell. Spybot also didn't kill off anything. I even turned off my firewall (OneCare) for everything except VMware (the sniffer doesn't run under 64-bit).

So my next steps are to get a better firewall, or find a sniffer program that runs under 64-bit Vista. Out of my 7 machines running, this is the only one hitting that ip address...the more I search, the more confused I get...
tmcmulli is offline   Reply With Quote
Old 04-26-2008   #6 (permalink)
Newbie
tmcmulli is on a distinguished road
 
Join Date: Apr 2008
Vista Ultimate 32 and 64
Posts: 4

Re: Unknown IP address showing up in log: Solved

Looks like Airsnare was the culprit. I move the sniffer software to another machine, and the phantom ip address followed Airsnare, so I'm looking for new sniffer software...

so pissed right now....
tmcmulli is offline   Reply With Quote
 
Reply

Thread Tools
Display Modes









Vistax64.com is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48