View Full Version : Another Microsoft SPYWARE Attack !! Backup Utility tried to send TWO updates to Windows update
Jonmith
December 14th 03, 08:21 AM
Is Windows just Spyware or what? Since I've installed my firewall, I've
noticed that many programs are sending usage information to Windows Update.
Today I ran the backup utility and it fired off two communications to
Windows Update, see information below. I suppose this has been happening
all along, but I've only noticed it since blocking outgoing TCP with McAfee
firewall (good program by the way). Anyone know if this is standard
practice by Microsoft? Do they routinely collect usage information via this
kind of embedded spyware?
McAfee Firewall alerted on an attempt by the program "Microsoft Volume
Shadow Copy Service" located in C:\WINDOWS\SYSTEM32\VSSVC.EXE, to
communicate in a way that was disallowed by the program's filtering rules.
The data
direction was outbound. The IP protocol type was TCP/IP. The remote port
was 443 [HTTPS]. The domain name was v4.windowsupdate.microsoft.com. The IP
address was 207.46.134.126. The user's response to the alert was to deny the
communication this time.
AND
McAfee Firewall alerted on an attempt by the program "Ms DTC console program
v03.01.00.4414" located in C:\WINDOWS\SYSTEM32\MSDTC.EXE, to
communicate in a way that was disallowed by the program's filtering rules.
The data
direction was outbound. The IP protocol type was TCP/IP. The remote port
was 443 [HTTPS]. The domain name was v4.windowsupdate.microsoft.com. The IP
address was 207.46.134.126. The user's response to the alert was to deny the
communication this time.
Anyone know about this? Is it happening to any of you?
Shenan T. Stanley
December 14th 03, 08:21 AM
Jonmith <> wrote:
> Is Windows just Spyware or what? Since I've installed my firewall,
> I've noticed that many programs are sending usage information to
> Windows Update. Today I ran the backup utility and it fired off two
> communications to Windows Update, see information below. I suppose
> this has been happening all along, but I've only noticed it since
> blocking outgoing TCP with McAfee firewall (good program by the
> way). Anyone know if this is standard practice by Microsoft? Do
> they routinely collect usage information via this kind of embedded
> spyware?
>
> McAfee Firewall alerted on an attempt by the program "Microsoft Volume
> Shadow Copy Service" located in C:\WINDOWS\SYSTEM32\VSSVC.EXE, to
> communicate in a way that was disallowed by the program's filtering
> rules. The data
> direction was outbound. The IP protocol type was TCP/IP. The remote
> port was 443 [HTTPS]. The domain name was
> v4.windowsupdate.microsoft.com. The IP address was 207.46.134.126.
> The user's response to the alert was to deny the communication this
> time.
>
> AND
>
> McAfee Firewall alerted on an attempt by the program "Ms DTC console
> program v03.01.00.4414" located in C:\WINDOWS\SYSTEM32\MSDTC.EXE, to
> communicate in a way that was disallowed by the program's filtering
> rules. The data
> direction was outbound. The IP protocol type was TCP/IP. The remote
> port was 443 [HTTPS]. The domain name was
> v4.windowsupdate.microsoft.com. The IP address was 207.46.134.126.
> The user's response to the alert was to deny the communication this
> time.
>
> Anyone know about this? Is it happening to any of you?
So you ran something and it checked for updates...
OK....
--
Shenan Stanley
"Just trying to help"
-------------------------
How to use XPs Help and Support
http://tinyurl.com/fltf
How to Use the Microsoft Product Support Newsgroups
http://tinyurl.com/fkja
How to use Google
http://www.google.com/help/basics.html
http://tinyurl.com/fkmc
-------------------------
Jupiter Jones [MVP]
December 14th 03, 08:22 AM
Unless you turn off Automatic Updates, this is normal.
If you do not want the computer checking automatically for updates,
turn it off.
Right click My Computer, click Properties.
Click Automatic Updates tab.
Check/uncheck as desired.
Be sure you check for updates as they will no longer be installed
automatically.
--
Jupiter Jones [MVP]
An easier way to read newsgroup messages:
http://www.microsoft.com/windowsxp/pro/using/newsgroups/setup.asp
Please respond to newsgroup only for everyone's benefit.
"Jonmith" > wrote in message
. ..
> Is Windows just Spyware or what? Since I've installed my firewall,
I've
> noticed that many programs are sending usage information to Windows
Update.
> Today I ran the backup utility and it fired off two communications
to
> Windows Update, see information below. I suppose this has been
happening
> all along, but I've only noticed it since blocking outgoing TCP
with McAfee
> firewall (good program by the way). Anyone know if this is standard
> practice by Microsoft? Do they routinely collect usage information
via this
> kind of embedded spyware?
>
> McAfee Firewall alerted on an attempt by the program "Microsoft
Volume
> Shadow Copy Service" located in C:\WINDOWS\SYSTEM32\VSSVC.EXE, to
> communicate in a way that was disallowed by the program's filtering
rules.
> The data
> direction was outbound. The IP protocol type was TCP/IP. The remote
port
> was 443 [HTTPS]. The domain name was v4.windowsupdate.microsoft.com.
The IP
> address was 207.46.134.126. The user's response to the alert was to
deny the
> communication this time.
>
> AND
>
> McAfee Firewall alerted on an attempt by the program "Ms DTC console
program
> v03.01.00.4414" located in C:\WINDOWS\SYSTEM32\MSDTC.EXE, to
> communicate in a way that was disallowed by the program's filtering
rules.
> The data
> direction was outbound. The IP protocol type was TCP/IP. The remote
port
> was 443 [HTTPS]. The domain name was v4.windowsupdate.microsoft.com.
The IP
> address was 207.46.134.126. The user's response to the alert was to
deny the
> communication this time.
>
> Anyone know about this? Is it happening to any of you?
sjbibb
December 14th 03, 08:22 AM
Remember the day when you had to check for updates and if
you wanted them downloaded automaticly you had to set it
up for that. I really hate software that come already
set to bump updates and you have to go somewhere to stop
it.
>-----Original Message-----
>Unless you turn off Automatic Updates, this is normal.
>If you do not want the computer checking automatically
for updates,
>turn it off.
>Right click My Computer, click Properties.
>Click Automatic Updates tab.
>Check/uncheck as desired.
>Be sure you check for updates as they will no longer be
installed
>automatically.
>
>--
>Jupiter Jones [MVP]
>An easier way to read newsgroup messages:
>http://www.microsoft.com/windowsxp/pro/using/newsgroups/s
etup.asp
>Please respond to newsgroup only for everyone's benefit.
>
>
>"Jonmith" > wrote in message
. ..
>> Is Windows just Spyware or what? Since I've installed
my firewall,
>I've
>> noticed that many programs are sending usage
information to Windows
>Update.
>> Today I ran the backup utility and it fired off two
communications
>to
>> Windows Update, see information below. I suppose this
has been
>happening
>> all along, but I've only noticed it since blocking
outgoing TCP
>with McAfee
>> firewall (good program by the way). Anyone know if
this is standard
>> practice by Microsoft? Do they routinely collect
usage information
>via this
>> kind of embedded spyware?
>>
>> McAfee Firewall alerted on an attempt by the
program "Microsoft
>Volume
>> Shadow Copy Service" located in C:\WINDOWS\SYSTEM32
\VSSVC.EXE, to
>> communicate in a way that was disallowed by the
program's filtering
>rules.
>> The data
>> direction was outbound. The IP protocol type was
TCP/IP. The remote
>port
>> was 443 [HTTPS]. The domain name was
v4.windowsupdate.microsoft.com.
>The IP
>> address was 207.46.134.126. The user's response to the
alert was to
>deny the
>> communication this time.
>>
>> AND
>>
>> McAfee Firewall alerted on an attempt by the
program "Ms DTC console
>program
>> v03.01.00.4414" located in C:\WINDOWS\SYSTEM32
\MSDTC.EXE, to
>> communicate in a way that was disallowed by the
program's filtering
>rules.
>> The data
>> direction was outbound. The IP protocol type was
TCP/IP. The remote
>port
>> was 443 [HTTPS]. The domain name was
v4.windowsupdate.microsoft.com.
>The IP
>> address was 207.46.134.126. The user's response to the
alert was to
>deny the
>> communication this time.
>>
>> Anyone know about this? Is it happening to any of you?
>
>
>.
>
Jonathan Woodard [MSFT]
December 14th 03, 08:24 AM
I think everyone's explained this well, I just want to point out our privacy
policy:
http://v4.windowsupdate.microsoft.com/en/about.asp#privacypolicy
--
Thanks,
Jonathan (Microsoft)
This posting is provided "AS IS" with no warranties, and confers no rights.
--
"sjbibb" > wrote in message
...
> Remember the day when you had to check for updates and if
> you wanted them downloaded automaticly you had to set it
> up for that. I really hate software that come already
> set to bump updates and you have to go somewhere to stop
> it.
> >-----Original Message-----
> >Unless you turn off Automatic Updates, this is normal.
> >If you do not want the computer checking automatically
> for updates,
> >turn it off.
> >Right click My Computer, click Properties.
> >Click Automatic Updates tab.
> >Check/uncheck as desired.
> >Be sure you check for updates as they will no longer be
> installed
> >automatically.
> >
> >--
> >Jupiter Jones [MVP]
> >An easier way to read newsgroup messages:
> >http://www.microsoft.com/windowsxp/pro/using/newsgroups/s
> etup.asp
> >Please respond to newsgroup only for everyone's benefit.
> >
> >
> >"Jonmith" > wrote in message
> . ..
> >> Is Windows just Spyware or what? Since I've installed
> my firewall,
> >I've
> >> noticed that many programs are sending usage
> information to Windows
> >Update.
> >> Today I ran the backup utility and it fired off two
> communications
> >to
> >> Windows Update, see information below. I suppose this
> has been
> >happening
> >> all along, but I've only noticed it since blocking
> outgoing TCP
> >with McAfee
> >> firewall (good program by the way). Anyone know if
> this is standard
> >> practice by Microsoft? Do they routinely collect
> usage information
> >via this
> >> kind of embedded spyware?
> >>
> >> McAfee Firewall alerted on an attempt by the
> program "Microsoft
> >Volume
> >> Shadow Copy Service" located in C:\WINDOWS\SYSTEM32
> \VSSVC.EXE, to
> >> communicate in a way that was disallowed by the
> program's filtering
> >rules.
> >> The data
> >> direction was outbound. The IP protocol type was
> TCP/IP. The remote
> >port
> >> was 443 [HTTPS]. The domain name was
> v4.windowsupdate.microsoft.com.
> >The IP
> >> address was 207.46.134.126. The user's response to the
> alert was to
> >deny the
> >> communication this time.
> >>
> >> AND
> >>
> >> McAfee Firewall alerted on an attempt by the
> program "Ms DTC console
> >program
> >> v03.01.00.4414" located in C:\WINDOWS\SYSTEM32
> \MSDTC.EXE, to
> >> communicate in a way that was disallowed by the
> program's filtering
> >rules.
> >> The data
> >> direction was outbound. The IP protocol type was
> TCP/IP. The remote
> >port
> >> was 443 [HTTPS]. The domain name was
> v4.windowsupdate.microsoft.com.
> >The IP
> >> address was 207.46.134.126. The user's response to the
> alert was to
> >deny the
> >> communication this time.
> >>
> >> Anyone know about this? Is it happening to any of you?
> >
> >
> >.
> >
vBulletin® v3.6.4, Copyright ©2000-2012, Jelsoft Enterprises Ltd.