![]() |
|
|
#1 |
![]() Join Date: Apr 2010
Location: Redditch, Worcestershire, England
Posts: 2,640 (2.35/day)
Thanks: 332
Thanked 857 Times in 604 Posts
|
gameux.dll trying to access secure MS IP address
I have a shed lot of logs in comodo firewall that gameux.dll is trying to access IP 65.55.162.27 << looked up as an MS IP address , over port 443 (https) this is being blocked by comodo though in the firewall logs gameux.dll is trying port after port, seems to be in order aswell, basically this dll is trying to get to that secure MS IP address for some reason and is port scanning to get out.........
I can't find much info on this dll though it appears to be an MS one and the behaviour of it is worrying, why is it scanning all available ports to access that IP? if this was anyone but MS this would be considered virus/spyware behaviour. It's possibly harmless but still. Anyone came across this? Seems this dll corresponds to MS Games Explorer that was intro'd in Vista, doesn't explain why it is trying to send information to a secure MS IP address
__________________
![]() Bioshock Infinite, FC3, Crysis 3, Shogun 2, Dirt Showdown AMD bundle keys for sale:
http://www.techpowerup.com/forums/sh...d.php?t=182837 |
|
|
|
|
|
#2 | |
|
Banned
Join Date: Nov 2010
Posts: 658 (0.72/day)
Thanks: 4
Thanked 74 Times in 59 Posts
|
Quote:
news flash, microsoft knows all about what you do with your computer unless you defeat these spyware features. |
|
|
|
|
|
|
#3 |
|
Hardcore Monkey Moderator
Join Date: Feb 2007
Location: Cheeseland (Wisconsin, USA)
Posts: 12,110 (5.28/day)
Thanks: 591
Thanked 5,488 Times in 2,932 Posts
|
My guess would be that it's trying to connect to information that the game explorer wants.
What that information is could be ratings or other info to display to you in the GE. It probably was written to try different port in the event that a specific port was busy or became unavailable. Since you are blocking it, it is probably trying all the ports it has in it's list of valid ports.
__________________
Cloud (noun, singular): A dynamic arrangement of multiple potential single points of failure, with a user at one end and their data at the other. Get more tech news on a wide variety of topics at NextPowerUp
|
|
|
|
|
|
#4 | |
|
Banned
Join Date: Nov 2010
Posts: 658 (0.72/day)
Thanks: 4
Thanked 74 Times in 59 Posts
|
Quote:
|
|
|
|
|
|
|
#5 |
![]() Join Date: Jul 2010
Location: Near Canterbury, uk
Posts: 1,886 (1.79/day)
Thanks: 634
Thanked 561 Times in 452 Posts
|
yes
game explorer connects to the internet for age ratings/ system requirements you can turn it off by clicking the 'options' button above the game explorer
__________________
“if you run short on cash, theres always that option. dont forget to use vasaline” -Freedomeclipse
“Before you complain about lag, think about Jesus. He lagged three days before respawning.” -repman244
|
|
|
|
| The Following User Says Thank You to cheesy999 For This Useful Post: |
|
|
#6 |
|
Banned
Join Date: Nov 2010
Posts: 658 (0.72/day)
Thanks: 4
Thanked 74 Times in 59 Posts
|
when someone can explain why disk indexer sends volume reports and registry info to microsoft. I will be all ears.
|
|
|
|
|
|
#7 | |
|
Eligible for custom title
Join Date: Aug 2007
Location: Glasgow, Scotland
Posts: 5,456 (2.59/day)
Thanks: 1,638
Thanked 821 Times in 712 Posts
|
Quote:
EDIT: Okay lol seems like everyone else managed to post while i was typing, its like fastest to the finger in this forum.
__________________
http://myinstants.com/instant/transformer/ |
|
|
|
|
|
|
#8 |
![]() Join Date: Jun 2010
Location: Jersey Shore
Posts: 211 (0.20/day)
Thanks: 42
Thanked 79 Times in 75 Posts
|
cheesy999 you are correct. I was searching on MS Technet and found this:
"I recently encontered this problem again, and have since gathered more data about the problem, and solution. The problem indeed lies with the game explorer. It will start when you first start a game that is not in the game explorer, and has not been installed into it by the game's installer (which most games do now). The game explorer detects it and adds the game to the list. It then attempts to gather more information about the game (rating, box art, etc). However, if it is unable to, the DLL will block in an endless loop of retries to the server to gather this information each time a game from the list is being started. This results in the game seemingly not loading. This being unable to can be due to a firewall blocking the connection on your computer. To solve this problem, I disabled my firewall. I immediately saw the boxart for all the games pop up, and the games in question subsequently loaded again." You can read the thread here: Starting Games It seems that disabling the Games Explorer stops this behavior. Personally I wouldn't disable my firewall. Last edited by ron732; Jun 14, 2011 at 08:09 PM. Reason: Firewall comment added |
|
|
|
|
|
#9 |
![]() Join Date: Jul 2010
Location: Near Canterbury, uk
Posts: 1,886 (1.79/day)
Thanks: 634
Thanked 561 Times in 452 Posts
|
cause Microsoft want to know what files poeple have on their computer, besides, its not as if they can do anything by knowing what you named your word document
__________________
“if you run short on cash, theres always that option. dont forget to use vasaline” -Freedomeclipse
“Before you complain about lag, think about Jesus. He lagged three days before respawning.” -repman244
|
|
|
|
|
|
#10 |
|
Eligible for custom title
Join Date: Aug 2007
Location: Glasgow, Scotland
Posts: 5,456 (2.59/day)
Thanks: 1,638
Thanked 821 Times in 712 Posts
|
Legally if Microsoft found anything it wouldn't be able to act on it. If they where using spyware for non updating purposes its technically spying. I mean i doubt Microsoft would like me looking at there computer files.
__________________
http://myinstants.com/instant/transformer/ |
|
|
|
|
|
#11 |
|
Banned
Join Date: Nov 2010
Posts: 658 (0.72/day)
Thanks: 4
Thanked 74 Times in 59 Posts
|
|
|
|
|
|
|
#12 |
![]() Join Date: Aug 2007
Location: Geneva, FL, USA
Posts: 3,010 (1.43/day)
Thanks: 567
Thanked 606 Times in 487 Posts
|
Perhaps more people would be conviced if you could explain how Disk Indexing and Games Explorer are related?
|
|
|
|
|
|
#13 |
|
Hardcore Monkey Moderator
Join Date: Feb 2007
Location: Cheeseland (Wisconsin, USA)
Posts: 12,110 (5.28/day)
Thanks: 591
Thanked 5,488 Times in 2,932 Posts
|
A link to this information or a packet dump of the data sent, please.
__________________
Cloud (noun, singular): A dynamic arrangement of multiple potential single points of failure, with a user at one end and their data at the other. Get more tech news on a wide variety of topics at NextPowerUp
|
|
|
|
| The Following User Says Thank You to Kreij For This Useful Post: |
|
|
#14 | |
![]() Join Date: Jul 2010
Location: Near Canterbury, uk
Posts: 1,886 (1.79/day)
Thanks: 634
Thanked 561 Times in 452 Posts
|
Quote:
btw i think the comp needs a bump
__________________
“if you run short on cash, theres always that option. dont forget to use vasaline” -Freedomeclipse
“Before you complain about lag, think about Jesus. He lagged three days before respawning.” -repman244
|
|
|
|
|
|
|
#15 | |
|
"I go fast!1!11!1!"
Join Date: Oct 2008
Location: IA, USA
Posts: 10,567 (6.29/day)
Thanks: 1,752
Thanked 2,594 Times in 1,959 Posts
|
Quote:
I would verify though that gameux.dll is, in fact, made by Microsoft though and not some illicit spoof. The genuine file should be C:\Windows\System32 and C:\Windows\SysWOW64 on 64-bit machines. It is between 2.4 and 2.7 MiB, the versin number should be similar to the OS number (6.#.OS Build number), the copyright field should be Microsoft Corporation but doesn't have a year, and the product name should be Microsoft Windows Operating System.
__________________
Golden Rule of Programming: Never assume. try { SteamDownload(); } catch (Steamception ex) { RageQuit(); } |
|
|
|
|
|
|
#16 |
![]() Join Date: Apr 2010
Location: Redditch, Worcestershire, England
Posts: 2,640 (2.35/day)
Thanks: 332
Thanked 857 Times in 604 Posts
|
I know what it is, i said that in my post, what I don't know is what data its collecting and the constant port scanning is behaviour of spyware, it could just be collecting data for updates etc. We shall see as I have now turned off all updates and asked it not to collect any data/art etc from the web about my games. So it has no reason now to want to gain access to that IP.
__________________
![]() Bioshock Infinite, FC3, Crysis 3, Shogun 2, Dirt Showdown AMD bundle keys for sale:
http://www.techpowerup.com/forums/sh...d.php?t=182837 |
|
|
|
|
|
#17 |
|
Hardcore Monkey Moderator
Join Date: Feb 2007
Location: Cheeseland (Wisconsin, USA)
Posts: 12,110 (5.28/day)
Thanks: 591
Thanked 5,488 Times in 2,932 Posts
|
I agree, NdM, let us know if it keeps trying to connect even though you have it shut off.
I can't find any information that gameux or the indexer is doing anythin insidious.
__________________
Cloud (noun, singular): A dynamic arrangement of multiple potential single points of failure, with a user at one end and their data at the other. Get more tech news on a wide variety of topics at NextPowerUp
|
|
|
|
|
|
#18 |
|
Banned
Join Date: Nov 2010
Posts: 658 (0.72/day)
Thanks: 4
Thanked 74 Times in 59 Posts
|
Who said anything about insidious. Its just collecting registry and file system info and broadcasting it over the network. Who know what they do with it. I personally don't my personal information to be exsposed over the network. I also have no idea of what exactly is being broadcast becuase I don't have the ability to understand the output from the service.
|
|
|
|
|
|
#19 | |
![]() Join Date: Jul 2008
Location: Clifton Park, NY
Posts: 3,126 (1.77/day)
Thanks: 98
Thanked 612 Times in 459 Posts
|
Quote:
__________________
|
|
|
|
|
|
|
#20 |
![]() Join Date: Nov 2011
Location: UT,US
Posts: 196 (0.35/day)
Thanks: 8
Thanked 5 Times in 5 Posts
|
@NdMk2o1o I also use comodo, even a packet dump won't reveal its content since is encrypted. I also had comodo alert me this file wanted to send data to that ip I only have this problem with Winning Eleven 8
|
|
|
|
|
|
#21 |
|
Benevolent Dictator
Join Date: May 2004
Location: Stuttgart, Germany
Posts: 13,758 (4.18/day)
Thanks: 184
Thanked 10,208 Times in 3,157 Posts
|
I've seen several games that send your gaming progress to the manufacturer's servers (using HTTPS port 443, too)
|
|
|
|
|
|
#22 |
|
"I go fast!1!11!1!"
Join Date: Oct 2008
Location: IA, USA
Posts: 10,567 (6.29/day)
Thanks: 1,752
Thanked 2,594 Times in 1,959 Posts
|
I'd say it's harmless.
__________________
Golden Rule of Programming: Never assume. try { SteamDownload(); } catch (Steamception ex) { RageQuit(); } |
|
|
|
|
|
#23 |
![]() |
Nice threadnecro
__________________
I am not here to be nice, I am not here to be polite BUT I am here to help ...
|
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| GPU-Z installer can't find DirectDrawCreateEx in ddraw.dll (use ddrawex.dll instead?) | Zetta Matrix | GPU-Z | 0 | May 22, 2010 09:54 PM |
| The Structure of and IP Address / 32 bit address | DreamSeller | Programming & Webmastering | 16 | Jul 11, 2009 02:32 PM |
| shadowflare ip address | badboy1 | Games | 2 | Dec 8, 2008 02:24 PM |
| IP address | nora.e | General Software | 4 | Jul 22, 2007 02:46 AM |