There was a problem - some application is constantly trying to connect to specific IP addresses.
Checking through http://ip-whois.net/ shows that there is nothing there (no sites / domains). Lock through the HOSTS file does not work.

Is it possible to block these addresses or find out what kind of process is trying to send some data?

System - Windows XP SP3 , antivirus - AVAST, firewall - NETLIMITER .
It is also worth Malwarebytes Anti-Malware , which shows the blocking of the address to the malicious site every 2-3 seconds. But I can not find it in the logs, which indicates the program / process that is trying to do it.

Maybe someone will tell you how to properly configure AVAST / NETLIMITER to block outgoing connections or a way to catch this process / program?

  • one
    you are not on the sysadmin forum logged in here programmers are sitting. you need to make the rules in the firewall - perfect

1 answer 1

In * nix I would try to catch the process using a script from netstat -a --tcp and lsof, but in Windows it is not strong ...

Look, maybe it also has some analogues of these utilities.