Windows ME 4.9.3000
IE 6.00.2800.1123
AVG Antivirus Plus Firewall 7.5.448

Periodically a Dialog Box with the information below pops up after I have
connected to the Internet. This will happen two or three times in a row and
then I won't see it for about a month. I am guessing that it is some kind of
upgrade attempt by Windows.

My antivirus is active and scans regularly, the firewall is in place and
functioning, I run Adaware and Spybot regularly and do not find any
indication of a virus or malware.

What is causing this?
----------------------------------------------------------------------------
--------------------------------------------------
Application "SYSTEM" Is trying to establish connection with remote IP
address 216.248.131.235.

Do you want to allow this communication? Allow Deny

This confirmation is related to a system communication and therefore a
simple rule cannot be created in this case. If you wish to handle such
communication, create a rule for system services and protocols using the
System Service Rule Properties dialog.

Application: SYSTEM
Full path: SYSTEM
Local address: localhost 1237
Remote Address: 216.248.131.235 : 80
Connection: TCP connection
Direction: Out

--
~^~^~^~^~^~^~^~^~^~^~^~^~^~^
When in charge, ponder; when in trouble, delegate; when in doubt, mumble.

Dave

Re: SYSTEM Connection Attempt by MowGreen

MowGreen
Fri Mar 23 17:32:40 CDT 2007

It's not related to Windows nor Microsoft at all.

http://www.dnsstuff.com/tools/ipall.ch?ip=216.248.131.235
http://www.dnsstuff.com/tools/whois.ch?ip=216.248.131.235

Any of the above ring a bell ?

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============


Dave wrote:

> Windows ME 4.9.3000
> IE 6.00.2800.1123
> AVG Antivirus Plus Firewall 7.5.448
>
> Periodically a Dialog Box with the information below pops up after I have
> connected to the Internet. This will happen two or three times in a row and
> then I won't see it for about a month. I am guessing that it is some kind of
> upgrade attempt by Windows.
>
> My antivirus is active and scans regularly, the firewall is in place and
> functioning, I run Adaware and Spybot regularly and do not find any
> indication of a virus or malware.
>
> What is causing this?
> ----------------------------------------------------------------------------
> --------------------------------------------------
> Application "SYSTEM" Is trying to establish connection with remote IP
> address 216.248.131.235.
>
> Do you want to allow this communication? Allow Deny
>
> This confirmation is related to a system communication and therefore a
> simple rule cannot be created in this case. If you wish to handle such
> communication, create a rule for system services and protocols using the
> System Service Rule Properties dialog.
>
> Application: SYSTEM
> Full path: SYSTEM
> Local address: localhost 1237
> Remote Address: 216.248.131.235 : 80
> Connection: TCP connection
> Direction: Out
>

Re: SYSTEM Connection Attempt by Dave

Dave
Fri Mar 23 17:55:40 CDT 2007

I don't recognize anything in these two pages. And . . . I don't have any
connection to the companies or the cities mentioned. It's still a mystery as
to why my SYSTEM would try to connect . . .

--
Dave

"MowGreen [MVP]" <mowgreen@nowandzen.com> wrote in message
news:%23sDfosZbHHA.2076@TK2MSFTNGP04.phx.gbl...
> It's not related to Windows nor Microsoft at all.
>
> http://www.dnsstuff.com/tools/ipall.ch?ip=216.248.131.235
> http://www.dnsstuff.com/tools/whois.ch?ip=216.248.131.235
>
> Any of the above ring a bell ?
>
> MowGreen [MVP 2003-2007]
> ===============
> *-343-* FDNY
> Never Forgotten
> ===============
>
>
> Dave wrote:
>
> > Windows ME 4.9.3000
> > IE 6.00.2800.1123
> > AVG Antivirus Plus Firewall 7.5.448
> >
> > Periodically a Dialog Box with the information below pops up after I
have
> > connected to the Internet. This will happen two or three times in a row
and
> > then I won't see it for about a month. I am guessing that it is some
kind of
> > upgrade attempt by Windows.
> >
> > My antivirus is active and scans regularly, the firewall is in place and
> > functioning, I run Adaware and Spybot regularly and do not find any
> > indication of a virus or malware.
> >
> > What is causing this?
>
> --------------------------------------------------------------------------
--
> > --------------------------------------------------
> > Application "SYSTEM" Is trying to establish connection with remote IP
> > address 216.248.131.235.
> >
> > Do you want to allow this communication? Allow Deny
> >
> > This confirmation is related to a system communication and therefore a
> > simple rule cannot be created in this case. If you wish to handle such
> > communication, create a rule for system services and protocols using the
> > System Service Rule Properties dialog.
> >
> > Application: SYSTEM
> > Full path: SYSTEM
> > Local address: localhost 1237
> > Remote Address: 216.248.131.235 : 80
> > Connection: TCP connection
> > Direction: Out
> >



Re: SYSTEM Connection Attempt by MowGreen

MowGreen
Sat Mar 24 04:24:12 CDT 2007

If you have no idea why the SYSTEM is attempting to connect to the DNS
listed, then deny it. ;)

MG

Dave wrote:

> I don't recognize anything in these two pages. And . . . I don't have any
> connection to the companies or the cities mentioned. It's still a mystery as
> to why my SYSTEM would try to connect . . .
>

Re: SYSTEM Connection Attempt by Dave

Dave
Sat Mar 24 06:24:29 CDT 2007

You're right, of course, and that's what I do. I was just trying to figure
out who or what was trying to be connected to my computer.

Thank you

Dave

"MowGreen [MVP]" wrote
> If you have no idea why the SYSTEM is attempting to connect to the DNS
> listed, then deny it. ;)
>
> MG
>
> Dave wrote:
>
> > I don't recognize anything in these two pages. And . . . I don't have
any
> > connection to the companies or the cities mentioned. It's still a
mystery as
> > to why my SYSTEM would try to connect . . .
> >



Re: SYSTEM Connection Attempt by Norman

Norman
Sat Mar 24 06:33:14 CDT 2007

Do you have anything wireless?
Is that firewall part of the AVG?
I would likely keep at it until I found an answer.
Port 80 has a legitamate use. I think Winamp has an option to use it with
proxy.
Somewhere there is a list of what each port is used for, legitamately, which
might give a hint.
Does your firewall give any more details, such as files involved. ZA has a
feature that will check for changed files trying to access and close the
door when necessary.
If running a hardware router/firewall, you might check the logs there as
well, but if you have already been slipped a trojan, deny is best until you
figure it out.

Norman
"Dave" <xqzme.leedave@otelco.net> wrote in message
news:OvmE3bgbHHA.1508@TK2MSFTNGP06.phx.gbl...
> You're right, of course, and that's what I do. I was just trying to figure
> out who or what was trying to be connected to my computer.
>
> Thank you
>
> Dave
>
> "MowGreen [MVP]" wrote
> > If you have no idea why the SYSTEM is attempting to connect to the DNS
> > listed, then deny it. ;)
> >
> > MG
> >
> > Dave wrote:
> >
> > > I don't recognize anything in these two pages. And . . . I don't have
> any
> > > connection to the companies or the cities mentioned. It's still a
> mystery as
> > > to why my SYSTEM would try to connect . . .
> > >
>
>



Re: SYSTEM Connection Attempt by MowGreen

MowGreen
Sat Mar 24 13:44:39 CDT 2007

Is Deltacom your internet provider ?
http://www.deltacom.com/internet.asp

MG


Dave wrote:

> You're right, of course, and that's what I do. I was just trying to figure
> out who or what was trying to be connected to my computer.
>
> Thank you
>
> Dave
>
> "MowGreen [MVP]" wrote
>
>>If you have no idea why the SYSTEM is attempting to connect to the DNS
>>listed, then deny it. ;)
>>
>>MG
>>
>>Dave wrote:
>>
>>
>>>I don't recognize anything in these two pages. And . . . I don't have
>
> any
>
>>>connection to the companies or the cities mentioned. It's still a
>
> mystery as
>
>>>to why my SYSTEM would try to connect . . .
>>>
>
>
>

Re: SYSTEM Connection Attempt by Dave

Dave
Sat Mar 24 15:52:21 CDT 2007

Deltacom is NOT my ISP and I have never heard of them.

On the chance they would have some insight I sent a message to my ISP Tech
Support. Here is their answer:

"I believe you are correct when you mention the situation being involved
with web page transfers, seeing as how the activity is on port 80. This can
usually arise from an HTTP daemon.

The connection is also coming from your system itself, so it may be
something entirely innocuous, such as a background messenger trying to load
a banner in itself.

I would personally advise to temporarily disable all startup programs (aside
from the firewall, of course) temporarily to see if the issue persists. You
may also consider running some spyware and virus scans, if have not already
done so. I do not believe that this has much of anything to do with your ISP
or hosting services, but I figured I could throw out some ideas for you."

I'll post back when I learn more.
--
Dave


"MowGreen [MVP]" wrote
Is Deltacom your internet provider ?
http://www.deltacom.com/internet.asp

MG


Dave wrote:
You're right, of course, and that's what I do. I was just trying to figure
out who or what was trying to be connected to my computer.

Dave

"MowGreen [MVP]" wrote
If you have no idea why the SYSTEM is attempting to connect to the DNS
listed, then deny it. ;)

MG

Dave wrote:
I don't recognize anything in these two pages. And . . . I don't have any
connection to the companies or the cities mentioned. It's still a mystery as
to why my SYSTEM would try to connect . . .



Re: SYSTEM Connection Attempt by Dave

Dave
Sat Mar 24 16:34:32 CDT 2007

After your last message I decided to take a look in my Registry to see if
there were any references to Deltacom. Here is what I found:

HKEY_CURRENT_USER
Software\Microsoft\Internet Explorer\TypedURLS
Url1
http://www.deltacom.com/internet.asp

Does it seem reasonable that it would be safe to delete this entry?
Being a 79 year old novice user these kind of things scare me a little bit.

--
Dave

"MowGreen [MVP]" <mowgreen@nowandzen.com> wrote in message
news:Oo7Q3RkbHHA.4552@TK2MSFTNGP05.phx.gbl...
> Is Deltacom your internet provider ?
> http://www.deltacom.com/internet.asp
>
> MG
>
>
> Dave wrote:
>
> > You're right, of course, and that's what I do. I was just trying to
figure
> > out who or what was trying to be connected to my computer.
> >
> > Thank you
> >
> > Dave
> >
> > "MowGreen [MVP]" wrote
> >
> >>If you have no idea why the SYSTEM is attempting to connect to the DNS
> >>listed, then deny it. ;)
> >>
> >>MG

Dave wrote:

I don't recognize anything in these two pages. And . . . I don't have
any connection to the companies or the cities mentioned. It's still a
mystery as to why my SYSTEM would try to connect . . .


> >
> >



Re: SYSTEM Connection Attempt by Norman

Norman
Sat Mar 24 18:30:11 CDT 2007

That only means that at some time the url was typed into the address bar of
IE. Not a problem.
I checked port 80 and it used for HTTP server. But found that it was often
used for an attack.
http://www.cgisecurity.com/papers/fingerprinting-2.shtml
Maybe wading through this link will help, but if it is above you, then may I
suggest that you go to dslreports.com and look for the forum on firewalls.
They have some very knowledgeable people there and unless your firewall is
some strange animal, they likely have experience with it. Or maybe the
manufacturer has a forum.
But I would not let my guard down.
Yes the call is coming from your machine as you indicated by outbound.
Looking within your firewall may indicate whether your machine is trying to
just access or act as a server to the connection. Server would be a double
red flag I suspect.
Since you have not said which firewall, is it part of the AVG, and most
importantly if I am not familiar with it, its capabilities. I just looked at
their site and very little details are available for the firewall.
Right now it sounds very much like something altered a file in such a way
that it trys to make this connection.
Have you installed any software about the time this started happening that
might be trying force registration or autoupdate?
How long, and hopefully in maximum security, did you install the firewall
before this started happening.
Norman

"Dave" <xqzme.leedave@otelco.net> wrote in message
news:%23jMewwlbHHA.3584@TK2MSFTNGP02.phx.gbl...
> After your last message I decided to take a look in my Registry to see if
> there were any references to Deltacom. Here is what I found:
>
> HKEY_CURRENT_USER
> Software\Microsoft\Internet Explorer\TypedURLS
> Url1
> http://www.deltacom.com/internet.asp
>
> Does it seem reasonable that it would be safe to delete this entry?
> Being a 79 year old novice user these kind of things scare me a little
bit.
>
> --
> Dave
>
> "MowGreen [MVP]" <mowgreen@nowandzen.com> wrote in message
> news:Oo7Q3RkbHHA.4552@TK2MSFTNGP05.phx.gbl...
> > Is Deltacom your internet provider ?
> > http://www.deltacom.com/internet.asp
> >
> > MG
> >
> >
> > Dave wrote:
> >
> > > You're right, of course, and that's what I do. I was just trying to
> figure
> > > out who or what was trying to be connected to my computer.
> > >
> > > Thank you
> > >
> > > Dave
> > >
> > > "MowGreen [MVP]" wrote
> > >
> > >>If you have no idea why the SYSTEM is attempting to connect to the DNS
> > >>listed, then deny it. ;)
> > >>
> > >>MG
>
> Dave wrote:
>
> I don't recognize anything in these two pages. And . . . I don't have
> any connection to the companies or the cities mentioned. It's still a
> mystery as to why my SYSTEM would try to connect . . .
>
>
> > >
> > >
>
>



Re: SYSTEM Connection Attempt by Larry

Larry
Mon Mar 26 10:57:45 CDT 2007

MowGreen, why do you have to be such a "SMART ASS"
The man was asking a question, If you do not have a responsible
answer, i suggest you keep you "SMART ASS", mouth shut.



Re: SYSTEM Connection Attempt by Heather

Heather
Mon Mar 26 12:03:15 CDT 2007

Are you a bit dense?? He was telling him to *deny access* to it. I
would call that a *responsible answer*......particularly when no one
seemed to know what was doing it.

DUH!!

"Larry" <someone@msn.com> wrote in message
news:Z3SNh.3955$xE.2188@trnddc08...
> MowGreen, why do you have to be such a "SMART ASS"
> The man was asking a question, If you do not have a responsible
> answer, i suggest you keep you "SMART ASS", mouth shut.
>
>



Re: SYSTEM Connection Attempt by MowGreen

MowGreen
Mon Mar 26 16:12:03 CDT 2007

Best to let sleeping dogs lie, Larry. You obviously DO NOT know what you
are talking about

MG

Larry wrote:

> MowGreen, why do you have to be such a "SMART ASS"
> The man was asking a question, If you do not have a responsible
> answer, i suggest you keep you "SMART ASS", mouth shut.
>
>

Re: SYSTEM Connection Attempt by Dave

Dave
Wed Mar 28 09:25:18 CDT 2007

Comments inserted into message below: (I will continue to be cautious)
Thanks for your interest and suggestions.

--

Dave

"Norman" <nthums1@comcast.net> wrote in message
news:eJBt4GnbHHA.4476@TK2MSFTNGP03.phx.gbl...
> That only means that at some time the url was typed into the address bar
of
> IE. Not a problem.
> I checked port 80 and it used for HTTP server. But found that it was often
> used for an attack.
> http://www.cgisecurity.com/papers/fingerprinting-2.shtml
> Maybe wading through this link will help, but if it is above you, then may
I
> suggest that you go to dslreports.com and look for the forum on firewalls.
> They have some very knowledgeable people there and unless your firewall is
> some strange animal, they likely have experience with it. Or maybe the
> manufacturer has a forum.
> But I would not let my guard down.
> Yes the call is coming from your machine as you indicated by outbound.
> Looking within your firewall may indicate whether your machine is trying
to
> just access or act as a server to the connection. Server would be a double
> red flag I suspect.
> Since you have not said which firewall, is it part of the AVG, and most
> importantly if I am not familiar with it, its capabilities. I just looked
at
> their site and very little details are available for the firewall.

The Firewall is a part of AVG Software - this is NOT the FREE version.

> Right now it sounds very much like something altered a file in such a way
> that it trys to make this connection.
> Have you installed any software about the time this started happening that
> might be trying force registration or autoupdate?

No software has been installed recently. This problem has been recurring for
some time. I will see the warning for two or three days and then will not
see again it for three or four weeks. I have always denied access and
continue to search for answers. I continue to run my Anit-Virus scans,
Adaware, Spybot and, on occasion HiJack This. I don't find any problems
there. Below is my HijackThis log: (I am not very knowledgeable about these
things but don't see any problem Here)

Logfile of HijackThis v1.97.7
Scan saved at 12:30:51 PM, on 3/27/2007
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGFWSRV.EXE
C:\WINDOWS\BCMDMMSG.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\GWHOTKEY.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\COREL\WORDPERFECT OFFICE 2000\PROGRAMS\WPWIN9.EXE
C:\PROGRAM FILES\COREL\WORDPERFECT OFFICE 2000\PROGRAMS\PS90.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\COREL\WORDPERFECT OFFICE 2000\PROGRAMS\POP90.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\MAINT\09 - HIJACKTHIS.EXE

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [BCMDMMSG] BCMDMMSG.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38941.8102662037
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://www1.snapfish.com/SnapfishActivia.cab


> How long, and hopefully in maximum security, did you install the firewall
> before this started happening.

The Firewall was installed, in maximum security, at least a year ago. This
problem has been occuring for three or four months.
> Norman
>
> "Dave" <xqzme.leedave@otelco.net> wrote in message
> news:%23jMewwlbHHA.3584@TK2MSFTNGP02.phx.gbl...
> > After your last message I decided to take a look in my Registry to see
if
> > there were any references to Deltacom. Here is what I found:
> >
> > HKEY_CURRENT_USER
> > Software\Microsoft\Internet Explorer\TypedURLS
> > Url1
> > http://www.deltacom.com/internet.asp
> >
> > Does it seem reasonable that it would be safe to delete this entry?
> > Being a 79 year old novice user these kind of things scare me a little
> bit.
> >
> > --
> > Dave
> >
> > "MowGreen [MVP]" <mowgreen@nowandzen.com> wrote in message
> > news:Oo7Q3RkbHHA.4552@TK2MSFTNGP05.phx.gbl...
> > > Is Deltacom your internet provider ?
> > > http://www.deltacom.com/internet.asp
> > >
> > > MG
> > >
> > >
> > > Dave wrote:
> > >
> > > > You're right, of course, and that's what I do. I was just trying to
> > figure
> > > > out who or what was trying to be connected to my computer.
> > > >
> > > > Thank you
> > > >
> > > > Dave
> > > >
> > > > "MowGreen [MVP]" wrote
> > > >
> > > >>If you have no idea why the SYSTEM is attempting to connect to the
DNS
> > > >>listed, then deny it. ;)
> > > >>
> > > >>MG
> >
> > Dave wrote:
> >
> > I don't recognize anything in these two pages. And . . . I don't have
> > any connection to the companies or the cities mentioned. It's still a
> > mystery as to why my SYSTEM would try to connect . . .
> >
> >
> > > >
> > > >
> >
> >
>
>



Re: SYSTEM Connection Attempt by MowGreen

MowGreen
Wed Mar 28 15:55:01 CDT 2007

Dave,

You could run Process Explorer to see what processes are running:
http://www.microsoft.com/technet/sysinternals/Security/ProcessExplorer.mspx

Or, use AutoRuns to see what's loading on boot:
http://www.microsoft.com/technet/sysinternals/Security/Autoruns.mspx

MG

Dave wrote:

> Comments inserted into message below: (I will continue to be cautious)
> Thanks for your interest and suggestions.
>

Re: SYSTEM Connection Attempt by Norman

Norman
Sat Mar 31 07:53:43 CDT 2007

Thanks for those links. Once I figure out how to use them, I might be able
to find what seems to be eating memory and also an issue with outlook not
always fully exiting.
Thanks Norman
"MowGreen [MVP]" <mowgreen@nowandzen.com> wrote in message
news:OeyfatXcHHA.4488@TK2MSFTNGP03.phx.gbl...
> Dave,
>
> You could run Process Explorer to see what processes are running:
>
http://www.microsoft.com/technet/sysinternals/Security/ProcessExplorer.mspx
>
> Or, use AutoRuns to see what's loading on boot:
> http://www.microsoft.com/technet/sysinternals/Security/Autoruns.mspx
>
> MG
>
> Dave wrote:
>
> > Comments inserted into message below: (I will continue to be cautious)
> > Thanks for your interest and suggestions.
> >