View Full Version : KasperskyIS 2009 TR phoning home?
Einsturzende
May 20th, 2008, 06:04 AM
What Kaspersky needs on UDP outgoing port 7024 on itself startup?
Edit: for unneeded questions I added second screenshot
See pics. for more info.
200051
200052
plantextract
May 20th, 2008, 06:11 AM
do you have the kaspersky security network option enabled?
Einsturzende
May 20th, 2008, 06:14 AM
-{ Quote: "do you have the kaspersky security network option enabled?" }-
No, that is disabled
plantextract
May 20th, 2008, 06:28 AM
Well, it looks like it's the online database. the servers are definied here C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\klsrl.xml
it seems it's also connecting if hips is disabled, probably PDM uses it too (is it enabled), but it shouldn't send anything there, only recieve data
Einsturzende
May 20th, 2008, 06:48 AM
-{ Quote: "Well, it looks like it's the online database. the servers are definied here C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\klsrl.xml
it seems it's also connecting if hips is disabled, probably PDM uses it too (is it enabled), but it shouldn't send anything there, only recieve data" }-
Thanks for quick response, I have found that file too, but I have PD and HIPS disabled also, using ComodoFP 3 with D+
BTW, there is bytes in and out
It is weird, I believed only integrated update module should update KIS/KAV, It is not documented anywhere and it makes connection without user intervention of any kind, so I blocked it with CFP...
plantextract
May 20th, 2008, 06:50 AM
so you have EVERY part of the system security module disabled. if so then it might be a bug
lodore
May 20th, 2008, 07:03 AM
post on the Kl forums
http://forum.kaspersky.com/index.php?showforum=16
Baz_kasp
May 20th, 2008, 07:03 AM
Someone else asked about this too... I will try to find out for you.
Einsturzende
May 20th, 2008, 07:15 AM
I posted already on kaspersky forum (different nick), but I was unable to solve this issue there.
Baz you answered on that tread too.:)
Baz_kasp
May 20th, 2008, 07:16 AM
Saly? (lol!)
I sent some messages will see if I get a reply.
plantextract
May 20th, 2008, 07:20 AM
i think it's "saly". lol, btw if you ask on kaspersky again, i'you'll probably get the same answer ;)
Einsturzende
May 20th, 2008, 07:20 AM
-{ Quote: "so you have EVERY part of the system security module disabled. if so then it might be a bug" }-
Oh sorry, it is not disabled just not installed.
Einsturzende
May 20th, 2008, 07:35 AM
-{ Quote: "i think it's "saly". lol, btw if you ask on kaspersky again, i'you'll probably get the same answer ;)" }-
I "bumped" it once, but no reply...
-{ Quote: "Saly? (lol!)
I sent some messages will see if I get a reply." }-
Thanks...
zfactor
May 20th, 2008, 08:10 AM
its probably doing a check against the current database to see if a update is needed.. just a guess though
Einsturzende
May 20th, 2008, 09:40 AM
-{ Quote: "its probably doing a check against the current database to see if a update is needed.. just a guess though" }-
So Kaspersky doing "push" update, where is that written,
I think that is not the case...
More...
TonyW
May 20th, 2008, 12:00 PM
Just wondering: are your updates set to automatic?
Einsturzende
May 20th, 2008, 01:07 PM
-{ Quote: "Just wondering: are your updates set to automatic?" }-
No, I use manual update
So, am I just only one interested in those "weird" connections?
Mem
May 20th, 2008, 01:34 PM
-{ Quote: "So, am I just only one interested in those "weird" connections?" }-
I haven't seen those remote IP's or ports (ever) opened by KIS 7.0.1.325 on its startup so there isn't anything on my part to comment on.... others may be the same.
lordpake
May 20th, 2008, 01:37 PM
He's using the 2009 TR, a NOT yet officially released version. Instead of asking here, maybe he should be asking in the KL beta forum?
Einsturzende
May 20th, 2008, 05:02 PM
Ok, problem is solved on Kaspersky forum, KIS looking on that port and addresses for online database for programs which needs to be sorted in HIPS.
Thanks to all of you.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums