(Windows XP Home SP 2) My problem was unrequested internet traffic, which
used 20-50% of my dial-up internet capacity on a continuous basis. I had
discounted all apps and automatic updates, so I knew it was malware. As of
today (Apr-08) three name brand virus scanners can't identify the problem.
The traffic started immediately upon connect and showed a continuous up/down
wave on the Networking graph in Windows Task Manager. I addressed the problem
by installing Microsoft Network Monitor 3.1.
I could see a DNS query to msgr.dlservice.microsoft.com upon connection.
This is a sham use of Microsoft's name. The DNS query returned three IP
addresses (typically Asia Pacific APNIC or Level 3 Communications) which
would launch the malware.
In addition, I was getting MsgSvcSend frames
(www.registrycleanerexp.com.scam).
I still don't know what the malware was doing but by identifying the
problematic IPs and creating custom default blocks in my firewall I stopped
the traffic.
Problem IP Ranges
4.0.0.0 - 4.255.255.255 Level 3 Communications, Inc.
8.0.0.0 - 8.255.255.255 Level 3 Communications, Inc.
58.0.0.0 - 58.255.255.255 Asia Pacific Network Information Centre
60.0.0.0 - 60.255.255.255 Asia Pacific Network Information Centre
61.0.0.0 - 61.255.255.255 Asia Pacific Network Information Centre
121.0.0.0 - 121.255.255.255 Asia Pacific Network Information Centre
125.0.0.0 - 125.255.255.255 Asia Pacific Network Information Centre
192.221.0.0 - 192.221.255.255 Level 3 Communications, Inc.
198.76.0.0 - 198.79.255.255 Level 3 Communications, Inc.
199.92.0.0 - 199.95.255.255 Level 3 Communications, Inc.
202.0.0.0 - 203.255.255.255 Asia Pacific Network Information Centre
204.160.0.0 - 204.163.255.255 Level 3 Communications, Inc.
205.128.0.0 - 205.131.255.255 Level 3 Communications, Inc.
206.32.0.0 - 206.35.255.255 Level 3 Communications, Inc.
207.120.0.0 - 207.123.255.255 Level 3 Communications, Inc.
208.111.128.0 - 208.111.191.255 Limelight Networks
221.0.0.0 - 221.255.255.255 Asia Pacific Network Information Centre
222.0.0.0 - 222.255.255.255 Asia Pacific Network Information Centre
Now all I need is for Microsoft's Malware Removal Tool to catch up and clean
my system!