outbound activity after last MS Update

  • Thread starter Thread starter Lynx
  • Start date Start date
L

Lynx

Greetings,
{XP Pro, SP2}
The following happened after applying latest MS Update (9 security tampons
from 15/08/2007)
To different firewals give very frequent and similar alerts involving
cvhost.exe, services.exe and C:\Windows\explorer.exe
for example:
IP: 203.206.129.49: http(80) - TCP
The addresses are, e.g.:
203.206.129.49
203.206.129.25
203.206.129.51
..etc. - those are "Asia Pacific Network Information Centre".
When I block many of those, another group starts to annoy me, like:
65.55.184.221
207.46.209.126
..etc. those are "Microsoft Corp".
I am blocking them too
Next time I restart there will be another range of addresses with mentioned
OrgNames, like:
210.9.72.177
210.9.72.169
207.46.209.126
I block them and everything is working fine after that ... but it is
annoying.
Can anybody, please, give me some ideas why such behaviour (unseen before
here) emerged after the last MS Update?
What this new uptate may need to report so insistently?
The last thing to add (despite it may not be relevant) - explorer.exe by
itself is blocked In/Out by me long time ago.
Thanks in advance
 
Hi Guys,
In addition to the above.
I ran the latest security update for Win 2000 Pro box on the same network
(it was switched off for this couple of days).
Peace and quiet. Nobody is trying to go out (at least for 9 hours already).
Windows explorer is blocked by firewall on that computer too. I can see and
work with shared drives in both directions. Everything is fine except
described XP behaviour.
Thanks
 
Back
Top