
UNSOLVED
Windows Explorer sending hidden system data ??
Can anybody tell me why everytime I reboot (Windoze ME) it connects to the internet and attempts to send a data stream to different addresses. Brand new Dimension 8100 out of the box. Installed cable modem, connected to the net, installed ZoneAlarm, found all the hidden "Ratting" programs but I cant track down and turn off this one. The following is from ZoneAlarm :
Windows Explorer tried to connect to the Internet (239.255.255.250), but
was denied access by the Internet Lock.
User: default
Program: Windows Explorer
Time: 03/04/2001 19:32:58
This particular address belongs to :
whois -h whois.arin.net !net-mcast-net ...
University of Southern California (NET-MCAST-NET)
Information Sciences Institute
4676 Admiralty Way
Marina Del Rey, CA 90292-6695
US
Netname: MCAST-NET
Netblock: 224.0.0.0 - 239.255.255.255
but it changes to various addresses around the world about every 2 or 3 times of rebooting. Not a virus or anything reported by either McKaffee or Norton Anti Virus.
????? anybody ??????
Windows Explorer tried to connect to the Internet (239.255.255.250), but
was denied access by the Internet Lock.
User: default
Program: Windows Explorer
Time: 03/04/2001 19:32:58
This particular address belongs to :
whois -h whois.arin.net !net-mcast-net ...
University of Southern California (NET-MCAST-NET)
Information Sciences Institute
4676 Admiralty Way
Marina Del Rey, CA 90292-6695
US
Netname: MCAST-NET
Netblock: 224.0.0.0 - 239.255.255.255
but it changes to various addresses around the world about every 2 or 3 times of rebooting. Not a virus or anything reported by either McKaffee or Norton Anti Virus.
????? anybody ??????
Responses (4)
Solutions (0)
Hi,
Have you updated your antivirus definitions and performed a full system scan, setting it to scan all files? I would start with this as a trouble-shooting option, since it's possible that you are the victim of a denial of service trojan, such as Trinoo or one of the others out there.
If all you have installed is ZoneAlarm and no known phone-home programs are detected by AdAware (is this what you meant by finding "the hidden 'Ratting' programs?"), then the AV scan would be a reassurance that no known trojan or worm was at work.
Edit: I was unaware of perchersk's response when I began this; perhaps he/she is correct in the assessment given, but it seems odd that you are one of the few cases I see here reporting this behavior, and ZoneAlarm is a very commonly installed firewall among Dell users. If you feel any concern at this point, it would not hurt to scan the system. If it's clean, and NAV is up to date with most of the DOS trojans, then you will know that you won't need to worry on the issue.
HTH,
Kay- thx for your answers. I was given a very similar answer from IPC Computing Services:
>Windows Explorer tried to connect to the Internet (239.255.255.250),
>but
>was denied access by the Internet Lock.
>
>User: default
>Program: Windows Explorer
>Time: 03/04/2001 19:32:58
>
>whois -h whois.arin.net !net-mcast-net ...
>University of Southern California (NET-MCAST-NET)
> Information Sciences Institute
> 4676 Admiralty Way
> Marina Del Rey, CA 90292-6695
> US
>
> Netname: MCAST-NET
> Netblock: 224.0.0.0 - 239.255.255.255
>
> Coordinator:
> Internet Corporation for Assigned Names and Numbers (IANA-ARIN)
>
>iana@IANA.ORG
> (310) 823-9358
>
Your computer appears to be configured with an IP address from a
range of addresses that are reserved for a special purpose. If you are not
on a network, you don't need an IP. If you are on a network, please
talk to your network administrator about getting a valid IP address.
If you don't know how to reconfigure your computer and you don't have
a network administrator to help you, try going to the place where you
bought the machine.
Below is some information on the reserved address block in question.
IP addresses in the range 224.0.0.0-240.0.0.0 are reserved for use by
IP multicast services on the Internet. Various addresses in this
range are used by routers and others are used by systems that have
multicast IP enabled. If you see these addresses on your network, the
most likely causes are systems or network devices within your own
network that are using IP multicast.
IP multicasting is the networking technology that enables the delivery
of real-time multimedia while saving network bandwidth. Most of the
widely-used traditional Internet applications, such as web browsers
and email, 'unicast' between one sender and one receiver. In many
emerging applications, such as live transmission of multimedia
training and university courses one sender will 'multicast' to a group
of receivers simultaneously. Only the ones who are 'subscribing' to
the multicast data will receive it, thus reducing network traffic and
using available bandwidth economically.
ISI's name may appear in the association with IP multicast addresses
because of the role that ISI has played in the development of internet
protocols and the RFC documents that describe these protocols.
However with the growth of the internet, responsibility for the
management of these addresses has transitioned to the Internet
Corporation for Assigned Names and Numbers (ICANN). Should you have
any further questions or concerns, please contact ICANN directly
(310-823-9358 or icann@icann.org).
USC-ISI
IPC Computing Services Anneimosity
10 Posts
243
0
Posted August 16th, 2001 17:00
I had very similar problems to the one you are experiencing -- after being virtually "locked out" of my system by some strange "administrator," I discovered that whenever i used explorer, despite the fact it was set to a specific home page, zone alarm noted that it was being "sent" to a different connection number.
You would NOT believe the stuff I found in my pc. And since this is the second dell since February (the first one, right out of the box, as you say, did the same thing), I would suspect some sort of security issue afoot....something I've never encountered with any of my previous pcs.

pechersk
123 Posts
243
0
Posted April 4th, 2001 10:00
239.255.255.250 is a multicast address, routers advertise their presence with multicasts which are picked up by devices that need to be aware of other devices on the network.
It resolves to some school, but only because they secured the IPs. Multicast packets don't route like normal packets, none of the traffic is going to that domain.