Question said:
Before I download this Antispyware Beta.
Where am I downloading it from? Microsoft or Somewhere
else?
PopUp windows says,
Name:MicrosoftAntiSpywareInstall.exe
Type: Application, 6.22MB
From: download.microsoft.com
The IP Address of download.microsoft.com is
208.172.158.219
OrgName: Savvis
OrgID: SAVVI-3
Address: 3300 Regency Parkway
City: Cary
StateProv: NC
PostalCode: 27511
Country: US
Does this sound correct?
They should state on the Download page of where it is
being downloaded from so you know it is correct.
As your PC may already have some malware/spyware on it
already and your PC may be redirected to a phoney site
for the download.
Anyway, any replies welcome.
As long as you start on a Microsoft web page, like
http://www.microsoft.com/spyware, to find the link to the download then
it is from Microsoft. Microsoft employs services from many 3rd party
vendors for world-wide load-balancing of downloads. They also employ
Akamai (maybe to run Microsoft's SUS) for load-balancing of Windows
Update.
If you do an "nslookup download.microsoft.com", you'll see the IP
addresses that are returned. There are multiple resolutions for that IP
name, one of which is the IP address you specified. You could check
your hosts file to make sure there wasn't some local lookup definition
for download.microsoft.com which took you elsewhere. You could even add
your own entry here but you can only specify a single IP address for the
local lookup, like "64.4.21.254 download.microsoft.com" to ensure the IP
name goes to that specify IP address (but malware that runs as a proxy
or an LSP (layered service provider) in the TCP layer could still
redirect you elsewhere). You could simply go to another host (not under
your control to obviate you installing the same malware on both hosts),
download the file, download it again on your host, and do a binary file
compare on the two.
The IP name shown in the download dialog may be from a DNS lookup on the
IP address that was actually specified. Since a reverse DNS lookup on
download.microsoft.com returns several IP addresses, any one of those
might have been what was actually specified for the download but the
download dialog did the IP address lookup and shows you the IP name
(which has several IP addresses for it). You could check your
firewall's logs to see to where you computer acutally connects during
the download. In my case, the download dialog said that the file would
be retrieved from download.microsoft.com but the firewall shows that I
connected to 64.4.21.254 (which is allocated to Microsoft's Hotmail
domain).
In fact, if you repeatedly run "nslookup download.microsoft.com" you
will notice the list of IP address will change. In one run of nslookup,
4.79.74.61 was listed and that is allocated to Level3 Communications.