Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus batch bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory monitor motherboard mouse network operating system printer problem ram registry router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
What is 209.244.0.3?

Reply  
Thread Tools
Hungry Guy's Avatar
Computer Specs
Junior Member with 9 posts.
 
Join Date: Sep 2008
Location: Here, there, everywhere
Experience: Intermediate
01-Sep-2008, 07:03 PM #1
Exclamation What is 209.244.0.3?
For the past several days, my firewall periodically pops up and tells me that it just blocked an intrusion attempt (portscan) from either 209.244.0.3(domain(53)) or 209.244.0.4.

Whenver this happens, I log off (I'm using dial-up), and log back on, and verify that I've been assigned a new IP.

Yet it continues to happen!

Are these IPs familiar to any of you regulars here? Is there some determined hacker stalking me? Or do I have malware on my machine? Or is this fairly routine and nothing to worry about as long as my firewall is blocking it?
jack213's Avatar
Senior Member with 242 posts.
 
Join Date: Jan 2006
01-Sep-2008, 07:19 PM #2
I'm no expert, but I strongly suggest you contact one, - (a moderator / administrator) and ask to move your post to the Malware Removal & HJT Logs forum asap.

An intrusion attempt is definatly not a routine occurance. You should probably download Hijack This from one of the links in that forum and await the instructions on how to use it. - Best of luck!

Last edited by jack213; 01-Sep-2008 at 07:48 PM..
bp936's Avatar
bp936 has a Photo Album
Computer Specs
Distinguished Member with 3,026 posts.
 
Join Date: Oct 2003
Location: Ontario, Canada
Experience: on dial-up
01-Sep-2008, 07:26 PM #3
paste this in the address bar,
I always check it at "whois" and see if I recognize anything
.http://tools.whois.net/index.php?fus...oisbyipresults
calvin-c's Avatar
Senior Member with 1,188 posts.
 
Join Date: May 2006
Experience: Advanced
01-Sep-2008, 09:44 PM #4
Note that a portscan is not an intrusion attempt. It's proper for a firewall to warn you of a portscan, but it shouldn't (IMO) call it an intrusion attempt. A portscan might trigger an intrusion attempt in the future or it might be beniqn. (I get something like one/hour on my firewall-and it's my ISP checking to make sure I'm not running a server in violations of my TOS.)

Don't get the idea that I'm in favor of portscans. Basically they're like what we used to call 'door rattlers'. Some of these were crooks looking for unlocked doors-and others were watchmen looking for the same thing. Basically, you can't tell whether a portscan is evil or benign until you know who's making it & why.

If the whois lookup comes back to your ISP it's probably benign.
__________________
Logic is a way to be wrong while proving that you're right
TOGG's Avatar
Distinguished Member with 5,362 posts.
 
Join Date: Apr 2002
Location: Birmingham, England
02-Sep-2008, 09:53 AM #5
Do you have any Messagelabs software installed?. The IP address you posted leads to something called 'resolver1.level3.net' and Googling that produces the following detail (unfortunately, I don't know how to interpret it!); http://www.robtex.com/dns/resolver1.level3.net.html

It doesn't seem too sinister if it proves to be some software doing periodic checks which cause the 'home' site to call back, but there could obviously be a nastier explanation.
__________________
Nothing matters very much, and few things matter at all.

Lord Balfour 1848-1930
Hungry Guy's Avatar
Computer Specs
Junior Member with 9 posts.
 
Join Date: Sep 2008
Location: Here, there, everywhere
Experience: Intermediate
02-Sep-2008, 07:32 PM #6
Well, my firewall called it an intrusion attempt. I'm not one to jump into emergency panic mode at these sort of things, that's why I asked in here if that IP was familiar to anyone... I asked over in the Malware forum and I'll go there next to see what anyone says...

I don't have Messagelabs software. I don't even know what that is...
TOGG's Avatar
Distinguished Member with 5,362 posts.
 
Join Date: Apr 2002
Location: Birmingham, England
02-Sep-2008, 07:45 PM #7
It appears to be a commercial 'anti everything' product; http://www.messagelabs.co.uk/products/ It could be something your ISP uses for anti spam purposes, check with them.
Hungry Guy's Avatar
Computer Specs
Junior Member with 9 posts.
 
Join Date: Sep 2008
Location: Here, there, everywhere
Experience: Intermediate
02-Sep-2008, 07:52 PM #8
Okay. Thanks for the info :-)

I just downloaded Hijack This. Call me paranoid, but I'm going to get offline and scan it with my AV before I install it...
Reply

Tags
209.244.0.3

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 11:27 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.