PDA

View Full Version : Explorer.exe connecting on startup


revol
15-04-2004, 22:45
Hey people, (first-poster here, hello to everyone :) )

I'm an NTL 512k STB BB user, running Windows XP Pro (Sp1) fully updated with all current security 'fixes'. Today I noticed a strange log in my Kerio personal firewall. It seems that on startup, the program 'Explorer.exe' appears to either be trying to be accessed or trying to establish a connection with another address. I set up a rule to block TCP/UDP attempts on 'Explorer.exe', and got the following logs:


Blocked:Out UDP, localhost:3011->239.255.255.250:1900, Owner: C:\Windows\Explorer.exe
Blocked:Out UDP, localhost:3011->127.0.0.1:3011, Owner: C:\Windows\Explorer.exe


The localhost ports are usually in the range 3009-3014 (from whats been logged so far), and these logs only appear just at startup. After 7 or 8 attempts are blocked (on different ports in the range), it stops trying and nothing else gets logged. Kerio shows no open incoming or outgoing connections through anything suspicious.


I've never seen this before, (I got scared) and re-installed Windows completely, only to find the problem still occuring. I have done a full virus check through Trend Micro's Housecall, and run Spybot S&D (up to date) with nothing logged on either.


One thing struck me that on one reboot, a different connection was blocked through Explorer.exe:


Blocked: Out TCP, localhost:3034->207.46.248.249:80, Owner: C:\Windows\Explorer.exe
Blocked: Out TCP, localhost:3033->207.46.248.249:80, Owner: C:\Windows\Explorer.exe


I ran a SmartWHOIS on the IP and it is a Microsoft Corporation address (maybe these are just harmless connections logged only because I put a complete block on Explorer.exe, and I haven't noticed them in the past?). Anyway, due to my Firewall config no connections are successful through Explorer.exe, but I'm still concerned why these have only just appeared.


Any help/advice? Sorry if the post is lay-man, I'm not too up on Network systems.


-rev

Xaccers
15-04-2004, 22:59
Oh god I can't remember the details but this caused so many conspiracy theories.
Think it's something to do with the search facility in explorer

darkangel
15-04-2004, 23:01
<snip>

239.255.255.250 is an iana reserved address no 100% sure what this does but it's harmless as far as i know.
207.46.248.249 is the windows search assistant server sc.microsoft.com again harmless.

Defiant
15-04-2004, 23:13
run spybot and adaware both free on www.download.com (http://www.download.com) see what they say

Paul
15-04-2004, 23:16
Port 1900 is the PnP equipment discovery stuff I believe.

abailey152
15-04-2004, 23:37
Yep, it's Universal Plug and Play (Pray??? ;) ). Unless you actually need UPnP, port 1900 can be blocked.

I had to open it up, however, to use some voice functions in Windows Messenger via Internet Connection Sharing through my LAN. ICS runs as a software router, so it needs to be UPnP capable for Messenger to be able to assign ports for the voice functions. At least this is what Microsoft KB said! :erm:

Tezcatlipoca
16-04-2004, 00:40
Yep, it's Universal Plug and Play (Pray??? ;) ). Unless you actually need UPnP, port 1900 can be blocked.

I had to open it up, however, to use some voice functions in Windows Messenger via Internet Connection Sharing through my LAN. ICS runs as a software router, so it needs to be UPnP capable for Messenger to be able to assign ports for the voice functions. At least this is what Microsoft KB said! :erm:

Also, to completely stop & disable the UPnP service in XP (unless you actually need it for some reason):

Goto "Start", then "Run", & enter "services.msc" & hit OK (or go to the "Services" tool in the Administrative Tools section in the Control Panel).

Look through the list of services for these entries: "Universal Plug and Play Device Host" *and* "SSDP Discovery Service".

Double click on one, Stop it, & then change its startup type to "Disabled" & hit "Apply". Then Stop & Disable the other of these two services.

Or, you can simply use GRC.com's "UnPlug N Pray" app to stop & disable the UPnP services: http://www.grc.com/unpnp/unpnp.htm (also info there on UPnP).

revol
16-04-2004, 05:31
Thanks a lot guys. UPnP was stopped already but I set it to 'Disabled'. SSDP I stopped and disabled, and now the strange problem has gone! ;) It's just weird that I never noticed it before. Ho hum.

Great forum, great advice. Mucho appreciated.

-rev

Tricky
16-04-2004, 18:30
One thing to watch for is a trojan doing the rounds as "explorer.exe " (note the space at the end) - You may have this on your box (make sure your virus scanners are up to date also).

Do a search for explorer.ex* on your machine and see how many come back.