Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 22, 2013, 08:42:12 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663628
Posts
70564
Topics
145225
Members
Latest Member:
KentonMcs
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Virus/Malware Removal Assistance
lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
« previous
next »
Pages:
[
1
]
Author
Topic: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10 (Read 15885 times)
skeil909
Newbie
Offline
Posts: 2
lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
on:
August 18, 2009, 11:36:11 AM »
I blocked this outbound connection when it popped up this morning after logging into my PC. The only program I installed yesterday was the new Champions Online Beta from FilePlanet. I had rebooted several times during and since the install and not seen this message before. There are no additional (visible) services or applications running during or after boot up.
File Info: (looks normal)
c:\windows\system32\lsass.exe
Last modified: Tuesday, April 21, 2009, 10:38:11 PM
Size: 30.5 KB (31,232 bytes)
That IP address comes up as:
OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL
Any ideas what this is or what it's for?
Logged
Toggie
Guest
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #1 on:
August 18, 2009, 11:45:26 AM »
Welcome to the forum skeil909.
Lsass.exe is the Local Security service and is usually ok, although there are rogues. Make sure this is the genuine article.
Protocol 41 is used by IPv6, see my post here:
Re: Windows Vista NOT completely safe with CIS (IPv6).
«
Last Edit: August 19, 2009, 06:23:55 AM by Quill
»
Logged
Creasy
Product Translator
Comodo's Hero
Offline
Posts: 858
I'm watching you.
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #2 on:
August 19, 2009, 06:13:37 AM »
Quote from: skeil909 on August 18, 2009, 11:36:11 AM
I blocked this outbound connection when it popped up this morning after logging into my PC. The only program I installed yesterday was the new Champions Online Beta from FilePlanet. I had rebooted several times during and since the install and not seen this message before. There are no additional (visible) services or applications running during or after boot up.
File Info: (looks normal)
c:\windows\system32\lsass.exe
Last modified: Tuesday, April 21, 2009, 10:38:11 PM
Size: 30.5 KB (31,232 bytes)
That IP address comes up as:
OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL
Any ideas what this is or what it's for?
Your IP look up is wrong.
Actual information for the IP is.
92.242.128.0 - 92.242.159.255
UK-BAREFRUIT-20071227
BAREFRUIT-AS Barefruit Ltd Autonomous System
country:UK
Don't worry.
It not an attack, you can allow it.
Because your ISP use "
http://www.barefruit.co.uk/
" DNS and HTTP service.
92.242.144.10 belongs to
http://www.barefruit.co.uk/
Visit barefruit website. You will see what kind of service they provide.
You can call your ISP. They will say samething like me.
Logged
Wrong messages are dangerous, but wrong interpretation of correct messages is even more dangerous.
-Andre Kostolany-
I'm a MAN!!
I'm not a girl!
Toggie
Guest
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #3 on:
August 19, 2009, 06:28:20 AM »
If you use Comodos DNS servers, it's quite likely you will see redirects to Barefruit on occasion. The reason for this is they offer a service that replaces the usual 404 message with something more informative.
Logged
skeil909
Newbie
Offline
Posts: 2
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #4 on:
August 19, 2009, 12:06:26 PM »
Quote from: Creasy on August 19, 2009, 06:13:37 AM
Your IP look up is wrong.
Actual information for the IP is.
92.242.128.0 - 92.242.159.255
UK-BAREFRUIT-20071227
BAREFRUIT-AS Barefruit Ltd Autonomous System
country:UK
Networksolutions.com appears to be giving incorrect data.
Logged
ediabid
Newbie
Offline
Posts: 3
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #5 on:
August 24, 2009, 10:09:00 PM »
Quote from: skeil909 on August 19, 2009, 12:06:26 PM
Networksolutions.com appears to be giving incorrect data.
This link to
http://www.db.ripe.net/whois?form_type=simple&full_query_string=&searchtext=92.242.144.10&submit.x=4&submit.y=5&submit=Search
gives the correct data.
Logged
frusty
Newbie
Offline
Posts: 2
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #6 on:
September 09, 2009, 02:01:32 AM »
Quote from: Quill on August 19, 2009, 06:28:20 AM
If you use Comodos DNS servers, it's quite likely you will see redirects to Barefruit on occasion. The reason for this is they offer a service that replaces the usual 404 message with something more informative.
can you, or anyone, tell me why spoolsv.exe would be trying to connect there (92.242.144.10:xxx) when I attempt to print something from my computer? That's what the firewall is telling me it's doing. I haven't used my printer (Brother MFC 420CN) since before I recently updated Comodo Firewall and now I can't print or scan. The printer's installation diagnostic software states it's installed correctly but unable to communicate. I tried complete uninstall and reinstall of the printer software.
Interestingly enough, I uninstalled and reinstalled CF BEFORE having this problem. I thought it was kind of strange that it hadn't updated in a while and when I tried to manually update via the program, I got error messages. Like I said, I uninstalled, ran CCleaner and DL'd it again. Am I going to have to do uninstall-reinstall again?
In any case, I still don't see why that should have to do with the spool server trying to route to breadfruit's site.
Please help before I go bald from pulling my hair out!
oh, also FWIW I am only using the firewall not Comodo's antivirus. I have avast AV.
Logged
Toggie
Guest
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #7 on:
September 09, 2009, 02:19:16 AM »
Welcome to the forum frusty.
I'd hazard a guess and suggest this is something to do with IPP (Internet Printing Protocol) which has been supported under Windows since XP, I think.
It's generally possible to disable this, so it's a way of checking. Which flavour of the OS are you using?
Logged
frusty
Newbie
Offline
Posts: 2
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #8 on:
September 09, 2009, 12:11:43 PM »
Quote from: Quill on September 09, 2009, 02:19:16 AM
Welcome to the forum frusty.
I'd hazard a guess and suggest this is something to do with IPP (Internet Printing Protocol) which has been supported under Windows since XP, I think.
It's generally possible to disable this, so it's a way of checking. Which flavour of the OS are you using?
I'm using XP SP3
Logged
Toggie
Guest
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #9 on:
September 09, 2009, 07:54:45 PM »
Quote
I'm using XP SP3
If you're using XP Pro you have two methods at your disposal, if not you'll have to use the registry method.
Take look here:
http://technet.microsoft.com/en-us/library/bb490831.aspx
Logged
jaeger-k
Newbie
Offline
Posts: 10
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #10 on:
March 21, 2010, 04:33:12 PM »
Quote from: Creasy on August 19, 2009, 06:13:37 AM
Your IP look up is wrong.
Actual information for the IP is.
92.242.128.0 - 92.242.159.255
UK-BAREFRUIT-20071227
BAREFRUIT-AS Barefruit Ltd Autonomous System
country:UK
Don't worry.
It not an attack, you can allow it.
Because your ISP use "
http://www.barefruit.co.uk/
" DNS and HTTP service.
92.242.144.10 belongs to
http://www.barefruit.co.uk/
Visit barefruit website. You will see what kind of service they provide.
You can call your ISP. They will say samething like me.
Thanks for this info, was effective for me too!
jk
Logged
CTS_AE
Newbie
Offline
Posts: 6
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #11 on:
December 05, 2010, 11:22:47 PM »
My screen saver was trying to connect to 92.242.144.10 on port 41
Now tell me why does
Windows\System32\Ribbons.scr need to connect to the internet?
odd thing though, is that this apparently seems to be comodo specific :\
«
Last Edit: December 05, 2010, 11:44:57 PM by CTS_AE
»
Logged
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
Offline
Posts: 1795
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #12 on:
December 08, 2010, 06:29:43 PM »
based on this
http://www.techspot.com/vb/topic149687.html
sounds like you got a MBR rootkit
I'd strongly would follow the steps in there
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
HateBarefruit
Newbie
Offline
Posts: 1
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #13 on:
November 26, 2011, 02:01:06 PM »
Since installing Comodo I have had several odd alerts regarding
audiodg
attempting to connect to Barefruit ip's
I've just blocked Barefruit's ip range.
This seems odd as hell to me that random programs would (for no apparent reason) attempt to connect...
~WDB
Logged
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4036
Re: lsass.exe Protocol: 41 (ipv6) to 92.242.144.10
«
Reply #14 on:
November 26, 2011, 04:09:24 PM »
Unfortunately, the description of Audiodg.exe doesn't exactly provide many clues as to its function. Essentially, this system process loads in the context of svchost and provides isolation of third-party audio drivers and DRM processing. It also provides access to kernel mode components.
Barefruit is a company that works with DNS providers to display targeted advertising through landing pages, instead of the usual HTTP/DNS error pages. If I remember correctly, this company is used by UltraDNS who used to host Comodos DNS services - Comodo now have their own DNS services.
To try and understand why you're seeing these connections, we'd need, if possible, a little more information, such as the IP address involved in the query, assuming it's not just barefruit. The type of audio software in use and whether it's using DRM.
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.242 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com