Jose Morris said:
WUAUSERV connects only to the windowsupdate site.
www.windowsupdate.microsoft.com.
C:\>nslookup
www.windowsupdate.microsoft.com
Server : ns.nrb.be
Address: 217.117.32.3
*** ns.nrb.be can't find
www.windowsupdate.microsoft.com : Non-existent
domain
There are no other servers to which this
service connects to. It doesnt generate IP addresses to find local Windows
Update Web service because there arent any.
C:\>nslookup windowsupdate.microsoft.com
Serveur : ns.nrb.be
Address: 217.117.32.3
Name : a822.cd.akamai.net
Addresses: 80.15.236.8, 80.15.236.30, 80.15.236.33, 80.15.236.25
80.15.236.16, 80.15.236.31, 80.15.236.38, 80.15.236.32,
80.15.236.9
Aliases: windowsupdate.microsoft.com
windowsupdate.microsoft.com.edgesuite.net
or
C:\>nslookup v4.windowsupdate.microsoft.com
Server : ns.nrb.be
Address: 217.117.32.3
Nom : a1510.cd.akamai.net
Addresses: 80.15.236.22, 80.15.236.31, 80.15.236.14, 80.15.236.17
80.15.236.32, 80.15.236.23, 80.15.236.30
Aliases: v4.windowsupdate.microsoft.com
v4.windowsupdate.microsoft.com.edgesuite.net
SVCHost can host lots of services. And at any point of time you can see lots
of svchost.exe running. And a single host can host multiple services.
Wondering if the service you are mentioning also runs something else which
is trying to access that address.
On the machine I checked (W2K Adv. Server) there is only one process that
makes such connections, which command line is:
\WINNT\system32\svchost.exe -k wugroup. And wugroup denotes Windows Update
DLL group. I got these results from Systeml Internals networking toools like
TCPView.
Here's the DLL dump of the one SVCHOST that generates the traffic we're
talking about. They all look like legitimate DLLs from MS. I couldn't go
further and determine which of these DLLs owned the connection. Maybe you
can check which of these are for real and legitimate and which are fakes or
spyware but I doubt there might be ones.
The system is a W2K Adv. Server SP4 with all critical updates installed at
the time I posted my first message (Aug. 18th).
svchost.exe pid: 1588
Command line: D:\WINNT\system32\svchost.exe -k wugroup
Base Size Version Path
0x01000000 0x5000 5.00.2134.0001 D:\WINNT\system32\svchost.exe
0x78460000 0x81000 5.00.2195.6685 D:\WINNT\system32\ntdll.dll
0x78ed0000 0x62000 5.00.2195.6710 D:\WINNT\system32\ADVAPI32.DLL
0x77e70000 0xc4000 5.00.2195.6688 D:\WINNT\system32\KERNEL32.DLL
0x770c0000 0x6e000 5.00.2195.6753 D:\WINNT\system32\RPCRT4.DLL
0x77a40000 0xec000 5.00.2195.6769 D:\WINNT\system32\OLE32.DLL
0x77f40000 0x3c000 5.00.2195.6660 D:\WINNT\system32\GDI32.dll
0x77e00000 0x65000 5.00.2195.6688 D:\WINNT\system32\USER32.DLL
0x00440000 0x6000 5.04.3630.2554 d:\winnt\system32\wuauserv.dll
0x78000000 0x45000 6.01.9844.0000 D:\WINNT\system32\msvcrt.dll
0x70bd0000 0x65000 6.00.2800.1106 D:\WINNT\system32\SHLWAPI.dll
0x00470000 0x32000 5.04.3630.2554 D:\WINNT\system32\wuaueng.dll
0x779a0000 0x9b000 2.40.4522.0000 D:\WINNT\system32\OLEAUT32.dll
0x715f0000 0x27000 6.00.2800.1106 D:\WINNT\system32\ADVPACK.dll
0x77810000 0x7000 5.00.2195.6623 D:\WINNT\system32\VERSION.dll
0x75950000 0x6000 5.00.2195.6611 D:\WINNT\system32\LZ32.DLL
0x78d20000 0x63000 5.00.2195.6711 D:\WINNT\system32\USERENV.dll
0x76930000 0x1b000 5.00.2195.6673 D:\WINNT\system32\sfc.dll
0x67df0000 0xf1000 5.00.2195.6717 D:\WINNT\system32\sfcfiles.dll
0x65510000 0xd000 5.00.2195.6701 D:\WINNT\system32\WINSTA.dll
0x65370000 0x7000 5.00.2134.0001 D:\WINNT\system32\WTSAPI32.dll
0x66400000 0xa000 5.00.2195.6701 D:\WINNT\system32\UTILDLL.dll
0x77500000 0x22000 5.00.2195.6664 D:\WINNT\system32\TAPI32.dll
0x71710000 0x84000 5.81.4916.0400 D:\WINNT\system32\COMCTL32.DLL
0x783c0000 0x91000 5.00.2195.6622 D:\WINNT\system32\SETUPAPI.dll
0x750f0000 0x4f000 5.00.2195.6601 D:\WINNT\system32\NETAPI32.dll
0x78fb0000 0xf000 5.00.2195.6695 D:\WINNT\system32\SECUR32.DLL
0x75140000 0x6000 5.00.2134.0001 D:\WINNT\system32\NETRAP.DLL
0x750d0000 0xf000 5.00.2195.6666 D:\WINNT\system32\SAMLIB.DLL
0x74fb0000 0x14000 5.00.2195.6601 D:\WINNT\system32\WS2_32.DLL
0x74fa0000 0x8000 5.00.2134.0001 D:\WINNT\system32\WS2HELP.DLL
0x77940000 0x2b000 5.00.2195.6666 D:\WINNT\system32\WLDAP32.DLL
0x77970000 0x24000 5.00.2195.6680 D:\WINNT\system32\DNSAPI.DLL
0x74fd0000 0x9000 5.00.2195.6603 D:\WINNT\system32\WSOCK32.DLL
0x68880000 0xb000 5.00.2195.6602 D:\WINNT\system32\REGAPI.dll
0x772f0000 0x17000 5.00.2181.0001 D:\WINNT\system32\MPRAPI.dll
0x77380000 0x30000 5.00.2195.6601 D:\WINNT\system32\ACTIVEDS.DLL
0x77350000 0x23000 5.00.2195.6701 D:\WINNT\system32\ADSLDPC.DLL
0x77820000 0xe000 5.00.2168.0001 D:\WINNT\system32\RTUTILS.DLL
0x70200000 0x96000 6.00.2800.1106 D:\WINNT\system32\WININET.dll
0x77410000 0x79000 5.131.2195.6661 D:\WINNT\system32\CRYPT32.dll
0x77400000 0x10000 5.00.2195.6666 D:\WINNT\system32\MSASN1.DLL
0x77580000 0x24f000 5.00.3700.6705 D:\WINNT\system32\SHELL32.dll
0x72c60000 0x86000 2000.02.3504.0000 D:\WINNT\system32\CLBCATQ.DLL
0x69a00000 0x1d000 5.00.2195.6666 D:\WINNT\system32\NTMARTA.DLL
0x777f0000 0x1e000 5.00.2195.6659 D:\WINNT\system32\WINSPOOL.DRV
0x793c0000 0x11000 5.00.2195.6611 D:\WINNT\system32\MPR.DLL
0x77be0000 0x11000 5.00.2195.6666 D:\WINNT\system32\NTDSAPI.dll
0x76230000 0x3e000 2000.02.3504.0000 D:\WINNT\System32\es.dll
0x74100000 0x64000 2000.02.3504.0000 D:\WINNT\System32\TxfAux.Dll
0x782d0000 0x1f000 5.00.2195.6680 D:\WINNT\system32\msv1_0.dll
0x76080000 0x50000 5.01.2600.1188 D:\WINNT\system32\winhttp.dll
0x00b90000 0x8000 6.02.3630.2522 D:\WINNT\System32\qmgrprxy.dll
0x774b0000 0x33000 5.00.2195.6625 D:\WINNT\system32\RASAPI32.DLL
0x77490000 0x11000 5.00.2195.6604 D:\WINNT\system32\RASMAN.DLL
0x75a50000 0x5000 5.00.2195.6627 D:\WINNT\system32\sensapi.dll
0x77310000 0x13000 5.00.2195.6602 D:\WINNT\system32\iphlpapi.dll
0x774f0000 0x5000 5.00.2134.0001 D:\WINNT\system32\ICMP.DLL
0x77330000 0x19000 5.00.2195.6685 D:\WINNT\system32\DHCPCSVC.DLL
0x00c70000 0x204000 2.00.2600.1183 D:\WINNT\system32\msi.dll
0x77830000 0xc000 5.00.2195.6603 D:\WINNT\System32\rnr20.dll
0x777d0000 0x8000 5.00.2160.0001 D:\WINNT\System32\winrnr.dll
0x777e0000 0x5000 5.00.2168.0001 D:\WINNT\system32\rasadhlp.dll
0x74f50000 0x1e000 5.00.2195.6602 D:\WINNT\system32\msafd.dll
0x74f90000 0x7000 5.00.2195.6601 D:\WINNT\System32\wshtcpip.dll
0x768e0000 0x2b000 5.131.2195.6624 D:\WINNT\system32\wintrust.dll
0x77910000 0x23000 5.00.2195.6613 D:\WINNT\system32\IMAGEHLP.dll
0x7ca00000 0x23000 5.00.2195.6611 D:\WINNT\system32\rsaenh.dll
0x69b10000 0x115000 8.30.9926.0000 D:\WINNT\system32\msxml3.dll
0x78160000 0x27000 5.01.2195.6705 D:\WINNT\system32\schannel.dll
0x67400000 0x27000 5.00.2195.6612 D:\WINNT\system32\dssenh.dll
0x70440000 0x8f000 6.00.2800.1106 D:\WINNT\System32\mlang.dll