WTF? Notepad trying to contact the Internet

novon

Diamond Member
Oct 9, 1999
3,711
0
0
Everytime I try to save a document to my desktop with Notepad, I get a ZoneAlarm pop-up that says it's trying to contact an outside IP address 204.127.199.8 . What the heck is going on?

Track:

Alert property Alert property value Technical explanation
Program Name Notepad A program running on your computer, which either attempted to send an IP packet over the Internet or is waiting for an incoming packet.
Filename notepad.exe The filename of the program that ZoneAlarm Pro found on your computer.
Program Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) The version of Notepad running on your computer.
Program Size 69120 The size of the program executable file in bytes.
Program MD5 388b8fbc36a8558587afc90fb23a3b99 The MD5 hash, or number, that uniquely identifies the executable.
Date Modified Aug-04-2004 12:56:54 AM The date when notepad.exe was most recently modified.
Connect Type Access This value can be either Access, which is an Internet connection attempt by Notepad or Server, which indicates that Notepad is waiting for connections coming in from the Internet.
Remote Port 53 The port Notepad is using on the remote computer.
Remote IP Address 204.127.199.8 The IP address of the remote computer that caused the alert.
Alert Date May-23-2005 11:56:07 AM PDT The time when ZoneAlarm Pro detected the alert on your computer.


OrgName: AT&T WorldNet Services
OrgID: ATTW
Address: 400 Interpace Parkway
City: Parsippany
StateProv: NJ
PostalCode: 07054
Country: US

NetRange: 204.127.0.0 - 204.127.255.255
CIDR: 204.127.0.0/16
NetName: ATTPLS
NetHandle: NET-204-127-0-0-1
Parent: NET-204-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.WORLDNET.ATT.NET
NameServer: NS2.WORLDNET.ATT.NET
Comment: __________________________________________
Comment: For matters pertaining to abuse, harassment
Comment: or spam, please contact abuse@att.net
Comment: __________________________________________
RegDate:
Updated: 1999-06-11

TechHandle: JC645-ARIN
TechName: Craig, John
TechPhone: +1-314-770-3395
TechEmail: jrcraig@att.com

OrgAbuseHandle: ATTAB-ARIN
OrgAbuseName: ATT Abuse
OrgAbusePhone: +1-919-319-8130
OrgAbuseEmail: abuse@att.net

OrgTechHandle: ICC-ARIN
OrgTechName: IP Customer Care
OrgTechPhone: +1-888-613-6330
OrgTechEmail: qhoang@att.com

OrgTechHandle: IPSWI-ARIN
OrgTechName: IP SWIP
OrgTechPhone: +1-888-613-6330
OrgTechEmail: help@ip.att.net

# ARIN WHOIS database, last updated 2005-01-03 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
 

novon

Diamond Member
Oct 9, 1999
3,711
0
0
I just caught it accessing another IP 63.240.76.198 . I just reinstalled windows too. They both go to The San Jose are of CA.
CERFnet CERFNET-BLK-5 (NET-63-240-0-0-1)
63.240.0.0 - 63.242.255.255
Project Redwood ISP (AT&T Internal) ATTENS-NYC3-007708-2 (NET-63-240-76-0-1)
63.240.76.0 - 63.240.77.255

# ARIN WHOIS database, last updated 2005-01-04 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.


CustName: Project Redwood ISP (AT&T Internal)
Address: 9805 Scranton Road
City: San Diego
StateProv: CA
PostalCode: 92121
Country: US
RegDate: 2001-11-16
Updated: 2001-11-16

NetRange: 63.240.76.0 - 63.240.77.255
CIDR: 63.240.76.0/23
NetName: ATTENS-NYC3-007708-2
NetHandle: NET-63-240-76-0-1
Parent: NET-63-240-0-0-1
NetType: Reassigned
Comment:
RegDate: 2001-11-16
Updated: 2001-11-16

TechHandle: CERF-HM-ARIN
TechName: AT&T Enhanced Network Services
TechPhone: +1-858-812-5000
TechEmail: notify@attens.com

OrgTechHandle: NETWO10-ARIN
OrgTechName: Network Provisioning
OrgTechPhone: +1-800-876-2373
OrgTechEmail: iptool@attens.com

# ARIN WHOIS database, last updated 2005-01-04 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database
 

warcrow

Lifer
Jan 12, 2004
11,093
11
81
Google "Project Redwood ISP" and read through some of the top 10 hits. Also, if you're really worried....why not call some of those names in the /whois?
 

shukusatsu

Junior Member
May 17, 2005
19
0
0
Spybot, Bazooka, AVG, Trojan Guarder Gold generally catch all of that stuff...tells you how to get rid of it/does it automatically for you.
 

novon

Diamond Member
Oct 9, 1999
3,711
0
0
Originally posted by: MercenaryForHire
You've got

W32.HLLW.Qaz.A

Fix tool located there.

- M4H

I just tried saving to the desktop from a different program and got the same contactin Internet problem, so it may not just Notepad.

Can anyone recommend a free Torjan checker?
 

birdpup

Banned
May 7, 2005
746
0
0
shukusatsu provided some recommendations. I prefer Lavasoft Adaware and AVG anti-virus. Spybot is also good.
 

novon

Diamond Member
Oct 9, 1999
3,711
0
0
I figured out the IP's are Comcast Internet's DNS servers. Why would saving somehting to my desktop contact my ISP's DNS server? Any one know how to stop it?
 

akugami

Diamond Member
Feb 14, 2005
5,837
2,101
136
Install Lavasoft's Adaware, run it. Download Grisoft's AVG Anti-VIrus and run that. It should catch most of the bugs in your system. Some you probably didn't even know you had. You can also use Spybot on the same system which may catch something that Adaware overlooks or is not aware of yet.
 

biostud

Lifer
Feb 27, 2003
18,407
4,968
136
try in the software forum

otherwise you can run a online virus scan, from Trend or other companies.
 

bocamojo

Senior member
Aug 24, 2001
818
0
0
Install Microsoft AntiSpyware and scan your system. Also the free AVG virus scanner. Between those two, you should be able to get your system cleaned up.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |