If you want to see what it is doing d/l - http://technet.microsoft.com/en-us/s...rnals/bb897437 tcpview will tell you what process is being envoked and by what IP address.
Yes sir, it is from Czech... Definetly bad. These guys get paid for email working email addresses, bank info, SSN, etc.. its a business to them. Some do it to gain notoriety in the space and that is how they prove themselves to join an organized crime unit of h4ckz0rz. (like being jumped into a gang)
Trying RIPE lookup...
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf
% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.
% Information related to '31.31.73.0 - 31.31.73.255'
inetnum: 31.31.73.0 - 31.31.73.255
netname: WEDOS-HOSTING
descr: WEDOS hosting services
country: CZ
admin-c: PS10635-RIPE
tech-c: PS10635-RIPE
status: ASSIGNED PA
mnt-by: WEDOS-MNT
mnt-lower: WEDOS-MNT
mnt-routes: WEDOS-MNT
remarks: INFRA-AW
source: RIPE # Filtered
person: Petr Stastny
address: WEDOS Internet, a.s.
address: Masarykova 1230
address: Hluboka nad Vltavou
address: 37341
phone: +420 380999775
abuse-mailbox: abuse@wedos.com
nic-hdl: PS10635-RIPE
mnt-by: WEDOS-MNT
source: RIPE # Filtered
% Information related to '31.31.72.0/21AS197019'
route: 31.31.72.0/21
descr: WEDOS Internet, a.s.
origin: AS197019
mnt-by: WEDOS-MNT
source: RIPE # Filtered
Originally posted by Tx Redneck
View Post
Trying RIPE lookup...
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf
% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.
% Information related to '31.31.73.0 - 31.31.73.255'
inetnum: 31.31.73.0 - 31.31.73.255
netname: WEDOS-HOSTING
descr: WEDOS hosting services
country: CZ
admin-c: PS10635-RIPE
tech-c: PS10635-RIPE
status: ASSIGNED PA
mnt-by: WEDOS-MNT
mnt-lower: WEDOS-MNT
mnt-routes: WEDOS-MNT
remarks: INFRA-AW
source: RIPE # Filtered
person: Petr Stastny
address: WEDOS Internet, a.s.
address: Masarykova 1230
address: Hluboka nad Vltavou
address: 37341
phone: +420 380999775
abuse-mailbox: abuse@wedos.com
nic-hdl: PS10635-RIPE
mnt-by: WEDOS-MNT
source: RIPE # Filtered
% Information related to '31.31.72.0/21AS197019'
route: 31.31.72.0/21
descr: WEDOS Internet, a.s.
origin: AS197019
mnt-by: WEDOS-MNT
source: RIPE # Filtered
Comment