choopa.net

Thoughts on life, the universe and everything else not covered in other categories.

Moderator: LW Moderator

User avatar
jjim
Super Member
Posts: 569
Joined: Fri Jun 18, 2004 10:12 pm

choopa.net

Post by jjim »

I have been getting large ( 300MB +) unknown bandwidth usage from:


173.199.122.4.choopa.net PORT 80


Google comes up with a blank - Does anyone know what program uses this or what the bandwidth is from - I have never visited this site?? and all my updates are set to manual.
I only use Windows xp firewall - is there a way to block this address without having to install commercial firewall software - I find these programs annoying and they slow everything down.

Thx for any help
User avatar
Meddle
Super Member
Posts: 2621
Joined: Sun Nov 05, 2006 9:44 pm
Location: In the driver's seat.
Has thanked: 78 times
Been thanked: 123 times

Post by Meddle »

Put a line in your HOSTS file with a localhost address. This can be found at "C:\Windows\System32\drivers\etc\". Whether this will actually stop it or not I don't know, although I do know that it kills most ads on the web.

as such:

Code: Select all

127.0.0.1 173.199.122.4
choopa.net is a managed hosting site with Tier 1 bandwidth available. The address you've given is a sub-domain of that site. And port 80 is used for http for both TCP and UDP packets.

Lastly I have no idea why this site is sucking bandwidth from you. :?
User avatar
zobraks
Super Member
Posts: 2192
Joined: Tue May 15, 2007 7:13 pm
Location: Eurosongland 2008
Been thanked: 55 times

Re: choopa.net

Post by zobraks »

jjim wrote:I only use Windows xp firewall - is there a way to block this address without having to install commercial firewall software
Bad choice. The Windows XP built-in firewall cannot check & block outgoing traffic on your PC.

You can install the free version of ZoneAlarm (download link). I've been using it since 2003 with no problem whatsoever.
User avatar
otiscrusher
Super Member
Posts: 1680
Joined: Tue Aug 21, 2007 9:18 pm
Location: Russia

Post by otiscrusher »

173.199.122.4.choopa.net PORT 80
That's really bad. Stop that asap, otherwise... boom. :D
User avatar
jjim
Super Member
Posts: 569
Joined: Fri Jun 18, 2004 10:12 pm

Post by jjim »

Thanks for the tips @otiscrusher lol.
Forgot about the hosts trick. I just noticed that there are several different choopa.net instances.
Will adding :
127.0.0.1 choopa.net

cover them all ie:

173.199.122.4.choopa.net
209.222.12.40.choopa.net

and others they might try?
cdnp
Super Member
Posts: 651
Joined: Sun Jun 27, 2010 3:59 am
Has thanked: 4 times
Been thanked: 5 times

Re: choopa.net

Post by cdnp »

jjim wrote:I have been getting large ( 300MB +) unknown bandwidth usage from:
I am really new at this. How do you check your bandwidth usage?
User avatar
otiscrusher
Super Member
Posts: 1680
Joined: Tue Aug 21, 2007 9:18 pm
Location: Russia

Post by otiscrusher »

choopa.net
Actually, it's very familiar. It's probably russian stuff. :D Just don't hate my guts coz I've got nothing to do with that crap. :lol: I had much worse sht once when visited some XXX russian site a few yrs ago. :D Was very nasty.
User avatar
3dslUserLoad
Super Member
Posts: 187
Joined: Fri May 02, 2008 10:28 am
Been thanked: 7 times

Post by 3dslUserLoad »

Looking at the site http://choopa.net indicates that this is a commercial internet provider with domicile in New Jersey, USA.
It seems there is some choopa.net customer with the IP 173.199.122.4 who uses your computer as a proxy server for downloading/uploading processes. Maybe you are victim of a trojan or you run software which acts as a proxy. Therefore you have to locate and to eliminate this software which can be very difficult. I don't believe that installation of some Antivir stuff will help because the software is already active. I personally don't use any.

The HOSTS file is an old remnant from the time of the juvenile internet and is provided to speeding up DNS name resolution to IP addresses, for example if you want to access another computer in your home network by name instead of the IP address.
If you resolve the domain name "173.199.122.4.choopa.net" to your local IP of your computer (127.0.0.1) by HOSTS, then all outgoing requests to this domain name will be redirected to your local computer which will result in a timeout after some seconds. This can be used to block domain names (advertising sites).
But if the evil user changes its IP, e.g. to "173.199.134.70.choopa.net" or he changes his provider or uses yet another proxy to access your computer, then he will be able to misuse it again and you will have to insert another block entry into the HOSTS file. Therefore blocking by HOSTS is no perfect solution.

A better solution for general URL blocking is the network router if you have one and if it permits block entries.

The Windows firewall is very spartan and only able to block UNREQUESTED INCOMING connections, actually it is a slimmed router software.
To change properties of the Win-FW, run "control.exe", doubleclick "Windows Firewall", check "Active", choose tab "Exceptions" and revise the entries there. In my opinion there should no one be checked here, except you chitchat and/or do torrent or something. The same applies to the tab "Advanced", "Lan Connection Properties". (I don't know the English titles, so they might differ)
If the Win-FW isn't blocking traffic to the offending site but it is activated and maybe justified properly then you are running software which initiates such connections.

If you have some experience you can also take a look at the list of running services by invoking "services.msc" and search for suspicious entries there.
For example, if you have an NVIDIA card then there might be a running service like "NVIDIA...NVSvc" (don't know the correct name), which is being started after the installation of a graphic card driver. Or there might be something like "Update...blahblah". Such dubious services can be stopped and deleted afterwards by invoking "sc.exe delete <internal_service_name>".

Good luck.
User avatar
jjim
Super Member
Posts: 569
Joined: Fri Jun 18, 2004 10:12 pm

Post by jjim »

Thanks 3dslUserLoad
Very concerned that someone may be using me as a proxy.I use Netlimiter 3 pro which never shows the activity from choopa.net.
I have just installed the free Zonealarm but the settings look pretty basic and There dosen't appear to be any settings to block anything but programs.
Any tips on how else to block all instances of choopa.net much appreciated.
Thx.
User avatar
freakboy
Super Member
Posts: 955
Joined: Wed Jun 16, 2004 9:03 am

Post by freakboy »

Dl many antiviruses and turn off the internet. Scan scan scan.
User avatar
otiscrusher
Super Member
Posts: 1680
Joined: Tue Aug 21, 2007 9:18 pm
Location: Russia

Post by otiscrusher »

Dl many antiviruses
The most AVs not gonna install together, like KAV. You'll have to choose. KAV is the best thing these days. I guarantee you that. Fast and reliable.
User avatar
freakboy
Super Member
Posts: 955
Joined: Wed Jun 16, 2004 9:03 am

Post by freakboy »

I meant dl, install, scan, uninstall, move on to the next one, because you surelly got a virus. Go to wbb and dl Avast, Kaspersky, Norton, Trojan Hunter, Avg , smth Antispyware and so on. If you cought polymorphic virus, then youre <i>fudge</i>. Only full format would help.
As for me... I dont even use antivirus or firewall. :lol:
User avatar
otiscrusher
Super Member
Posts: 1680
Joined: Tue Aug 21, 2007 9:18 pm
Location: Russia

Post by otiscrusher »

because you surelly got a virus
May be just not enough sunshine?
If you cought polymorphic virus, then youre fudge. Only full format would help.
There're a few solutions but formatting probably gonna be faster. I had such virus and I dealth with it pretty easily. The operation was very time consuming though.
I dont even use antivirus or firewall.
Yeah, I don't wear any clothes either.
User avatar
Trey
Super Member
Posts: 1671
Joined: Thu Jul 12, 2007 3:43 am
Location: U.S.A. - Just like Disneyland! (but with more Porn, Drugs, and Guns)
Has thanked: 2 times
Been thanked: 13 times

Post by Trey »

You're going to want to run a Rootkit scan, try running MalewareBytes see if that picks up anything.
http://www.malwarebytes.org/
User avatar
hfric
3DSL Moderator
Posts: 5026
Joined: Sun Jan 09, 2005 2:51 am
Has thanked: 49 times
Been thanked: 233 times

Post by hfric »

1. install and use Spybot

Code: Select all

http://www.safer-networking.org/index2.html
2. install and use hijackthis

Code: Select all

http://download.cnet.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html
▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ஜ۩۞۩ஜ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
Image
▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ஜ۩۞۩ஜ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
Post Reply