Windows 10: Many Microsoft / Odd Utilities try to randomly access remote IPs

Discus and support Many Microsoft / Odd Utilities try to randomly access remote IPs in AntiVirus, Firewalls and System Security to solve the problem; I have recently been instructed to activate custom rule set of Comodo firewall to be able to monitor what apps are trying to access the internet . To... Discussion in 'AntiVirus, Firewalls and System Security' started by nIGHTmAYOR, Jan 8, 2020.

  1. Many Microsoft / Odd Utilities try to randomly access remote IPs


    I have recently been instructed to activate custom rule set of Comodo firewall to be able to monitor what apps are trying to access the internet .

    To the irony I realized a huge number of connections are being done via programs that aren't really known to be any related to the internet either try to randomly access the internet or on triggering .

    For instance on bringing up the Windows Settings App (SystemSettings.exe) , it instantly attempts to connect to a remote ip , followed by Runtime Broker (RuntimeBroker.exe) that attempts to access a different remote ip .

    Then TaskHostW.exe does it in accelerated intervals , BackgroundTaskHost does it pretty often , SpeechModelDownload.exe does it pretty often too despite I don't even have Cortana enabled .

    And now for the cuteness of all seems WerMgr.exe and WerFault.exe does it like every 2 minutes that seems like a nag , on revising MS Event viewer I realize this is because of a COM 10016 error Microsoft itself instruct to neglect .

    Apart from Microsoft , despite that I made sure I stripped all bloatware of the NVidia driver , the lovely control panel app enjoys connecting to nvidia every hour for no particular reason . Google Chrome Update task does that too hourly .

    Now while we can relate the non Microsoft apps to be obsessive about making sure you are up to date even though in a too spooky rate now what about Microsoft ? This crazy rate of traffic multiplied by the amount of users are petabytes of useless blahs jamming the internet daily .

    But then apart , why would Microsoft wanna know live data about Windows Settings ? Is personal settings damn it ! You don't even sync it elsewhere !

    P.S Comodo does check if those were signed and official apps so no this isn't spoofy trojans case , or is it *Tongue

    Cheers
    *Cool

    :)
     
    nIGHTmAYOR, Jan 8, 2020
    #1
  2. Callender Win User

    Many Microsoft / Odd Utilities try to randomly access remote IPs

    It's really complicated and depends upon your machine setup. It's best to allow Microsoft entries then research them if you want to. Blocking some may have consequences.

    You can review logs:


    Many Microsoft / Odd Utilities try to randomly access remote IPs [​IMG]



    Many Microsoft / Odd Utilities try to randomly access remote IPs [​IMG]



    Many Microsoft / Odd Utilities try to randomly access remote IPs [​IMG]



    Many Microsoft / Odd Utilities try to randomly access remote IPs [​IMG]

    I suggested custom ruleset because it will show an alert for all new connections where you did not opt to block/ allow with the choice remembered for safe applications.
     
    Callender, Jan 8, 2020
    #2
  3. Callender Win User
    Many Microsoft / Odd Utilities try to randomly access remote IPs

    FYI: If you have concerns I'd suggest running the portable utility linked in this post:

    Foreign address after running netstat -f

    Enable the items highlighted in the red box:

    Many Microsoft / Odd Utilities try to randomly access remote IPs [​IMG]

    Anything where there is a red circle shown as an entry needs checking.
     
    Callender, Jan 8, 2020
    #3
  4. Many Microsoft / Odd Utilities try to randomly access remote IPs

    Many Microsoft / Odd Utilities try to randomly access remote IPs

    I have recently been instructed to activate custom rule set of Comodo firewall to be able to monitor what apps are trying to access the internet .

    To the irony I realized a huge number of connections are being done via programs that aren't really known to be any related to the internet either try to randomly access the internet or on triggering .

    For instance on bringing up the Windows Settings App (SystemSettings.exe) , it instantly attempts to connect to a remote ip , followed by Runtime Broker (RuntimeBroker.exe) that attempts to access a different remote ip .

    Then TaskHostW.exe does it in accelerated intervals , BackgroundTaskHost does it pretty often , SpeechModelDownload.exe does it pretty often too despite I don't even have Cortana enabled .

    And now for the cuteness of all seems WerMgr.exe and WerFault.exe does it like every 2 minutes that seems like a nag , on revising MS Event viewer I realize this is because of a COM 10016 error Microsoft itself instruct to neglect .

    Apart from Microsoft , despite that I made sure I stripped all bloatware of the NVidia driver , the lovely control panel app enjoys connecting to nvidia every hour for no particular reason . Google Chrome Update task does that too hourly .

    Now while we can relate the non Microsoft apps to be obsessive about making sure you are up to date even though in a too spooky rate now what about Microsoft ? This crazy rate of traffic multiplied by the amount of users are petabytes of useless blahs jamming the internet daily .

    But then apart , why would Microsoft wanna know live data about Windows Settings ? Is personal settings damn it ! You don't even sync it elsewhere !

    P.S Comodo does check if those were signed and official apps so no this isn't spoofy trojans case , or is it *Tongue

    Cheers
    *Cool
     
    nIGHTmAYOR, Jan 8, 2020
    #4
Thema:

Many Microsoft / Odd Utilities try to randomly access remote IPs

Loading...
  1. Many Microsoft / Odd Utilities try to randomly access remote IPs - Similar Threads - Many Microsoft Odd

  2. KB5018410 oddly breaks remote desktop

    in Windows 10 Software and Apps
    KB5018410 oddly breaks remote desktop: I have used remote desktop load balancing for about three years with little issue until yesterday, when my some, but not all, of my users started reporting an error similar to the following.The remote computer BETA.domain.com that you are trying to connect to is redirecting...
  3. KB5018410 oddly breaks remote desktop

    in Windows 10 Installation and Upgrade
    KB5018410 oddly breaks remote desktop: I have used remote desktop load balancing for about three years with little issue until yesterday, when my some, but not all, of my users started reporting an error similar to the following.The remote computer BETA.domain.com that you are trying to connect to is redirecting...
  4. Many of my utilities are not signed by Microsoft e.g. WinStore.App.exe, calculater.exe,...

    in AntiVirus, Firewalls and System Security
    Many of my utilities are not signed by Microsoft e.g. WinStore.App.exe, calculater.exe,...: Many of my utilities are not signed by Microsoft e.g. WinStore.App.exe, calculater.exe, Time.exe. I am very concerned about the integrity of my system. I am using Process Explorer V 16.30....
  5. Too many Asus Utilities

    in Windows 10 Installation and Upgrade
    Too many Asus Utilities: Recently purchased an Asus ROG GL10DHAMD Ryzen 7 3700X 8 Core, 1TB SSD, 1TB Hard Drive. There was way too much Bloat. Gotten rid of most of it but even though I have download Windows 10 2004 and burned to DVD, Did a 2 clean install these 9 "services" will not go away. Any...
  6. VPN Issue : The Remote Access Service IP configuration is unusable.

    in Windows 10 Network and Sharing
    VPN Issue : The Remote Access Service IP configuration is unusable.: When I am trying to connect VPN, I am getting error as below. [ATTACH] In this link mentioned to uninstall 1601 update,but there is no such kb installed. https://community.spiceworks.com/topic/1950631-the-remote-access-service-ip-configuration-is-unusable-mobile-connect...
  7. IP Addresses - Unwanted Remote Access

    in Windows 10 Network and Sharing
    IP Addresses - Unwanted Remote Access: I talked to Microsoft on an issue and told them I used a wireless connection on one of my two computers. One computer uses Vista (wireless) and the other Windows 10 (through a router). Microsoft said my issue could have been caused by someone remotely accessing my computer....
  8. IP Addresses - Unwanted Remote Access

    in Windows 10 Performance & Maintenance
    IP Addresses - Unwanted Remote Access: I talked to Microsoft on an issue and told them I used a wireless connection on one of my two computers. One computer uses Vista (wireless) and the other Windows 10 (through a router). Microsoft said my issue could have been caused by someone remotely accessing my computer....
  9. Remote Control and utilize screen?

    in Windows 10 Network and Sharing
    Remote Control and utilize screen?: Hi everyone. I'm new to this community, so I may be posting this in the wrong category but I hope someone may have knowledge on how to make this happen. I have three monitors available which I utilize (on my desk) and 2 PC running Windows 10. PC A is stronger but I want...
  10. To many IP addresses

    in Windows 10 Customization
    To many IP addresses: How do I remove all of the IP addresses that are slowing down my PC https://answers.microsoft.com/en-us/windows/forum/all/to-many-ip-addresses/b774e6ff-e3d0-4255-83c2-345e7db2884d