svchost suspicious connection

Discussion in 'ESET Smart Security' started by simo1337, Nov 8, 2009.

Thread Status:
Not open for further replies.
  1. simo1337

    simo1337 Registered Member

    Joined:
    Oct 30, 2009
    Posts:
    17
    As of this morning, I checked my systems' connections and noticed that svchost was establishing a connection on port 1173 with a remote IP (80.157.150.56:80).

    I would have guessed it would be an ordinary system update, except that when I looked up the IP, it was a RIPE NCC IP and got me worried. Why would svchost need to connect to an IP within the RIPE NCC range, it's not like Windows Update servers are located there ? or are they ?
     
  2. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.