svchost suspicious connection

Discussion in 'ESET Smart Security' started by simo1337, Nov 8, 2009.

Thread Status:
Not open for further replies.
  1. simo1337

    simo1337 Registered Member

    Joined:
    Oct 30, 2009
    Posts:
    17
    As of this morning, I checked my systems' connections and noticed that svchost was establishing a connection on port 1173 with a remote IP (80.157.150.56:80).

    I would have guessed it would be an ordinary system update, except that when I looked up the IP, it was a RIPE NCC IP and got me worried. Why would svchost need to connect to an IP within the RIPE NCC range, it's not like Windows Update servers are located there ? or are they ?
     
  2. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,279
    Location:
    UK
Thread Status:
Not open for further replies.