Connection to Symantec and Microsoft

Hi there,

just saw via my network monitoring that Spyshelter wants to connect to Symantec and also to microsoft. The question is why ?

Thank you for using SpyShelter.

SpyShelter does not connect to Symantec or Microsoft. You should see connections to SpyShelter.com for software updates, insights, software activation, and threat detection.

https://www.spyshelter.com/privacy-policy/

Yes is see the Connections to Spyshelter.com
Also internal connection (duh!)

But also trying to connect to :
ts-aia/ws/symantec/com
www/microsoft/com

(slash = dot … just had to switch it so post doesnt get blocked by forum rules)

No, we do not connect to those things. We are hosted on AWS so it should show Amazon AWS IP addresses.

Please try doing a secondary lookup on the IP addresses. Perhaps the software you are using is failing at its nslookup, or is it possible it’s another app doing those connections but somehow it appears as SpyShelter?

We definitely have no ability to connect to Symantec servers and we have no association with them in any way.

We do plan to add SpyShelter to the Microsoft Store soon, but we aren’t there yet and we have no ability or permission to use Microsoft servers at this time.

interesting.
While those are possibilties, there is no app on my PC that would connect to Symantec. Very strange…

Gonna keep an eye on it. Thank you for the quick response tho !

1 Like

I once used a network monitoring app that incorrectly resolved some IP addresses. It gave a result that shocked me, but then when I looked up the IP myself I found it was not at all what it said.

No idea why that happened…

Screenshot 2024-09-28 235726

Portmaster showing these connections. From Spyshelter-service outgoing

Strange. I will ask our team, but I think it must be a bug in the software you are using because we don’t seem to connect to those servers.

thanks. I also contacted the Dev of my Network Software regarding this issue.

But im telling you, so far the software never made any mistake.
And i used all kinds of apps in 3-4 years with it.

Appreciate your fast responses and effort resolving my issues ! :slight_smile:

I asked our team and figured out the answer to your question.

SpyShelter verifies its own digital signatures using trusted certificate authorities like Digicert and Symantec to ensure the software hasn’t been tampered with. To do this, our software checks the certificates in the system’s cert store, which you may notice under ‘CACerts.’ This behavior is common for applications that prioritize security and signature verification.

The reason I was initially confused is because SpyShelter itself doesn’t manually perform these checks. Instead, we rely on Windows APIs to handle certificate validation. While we don’t actively manage the certificate verification, the process still happens within the context of our application. This explains why the software you’re using shows activity related to SpyShelter, even though the actual certificate checks are performed by Windows, not directly by us.

That explains it. Thank you.

Im now gonna await the release via MS Store u mentioned.
Big Fan of the advantages of MS Store installs.

1 Like

I’d discover how it is that ASN is involved and why the CDN entity Edgecast (Edgio as of mid-2022, formerly Limelight) is doing it.

My SpyShelter connections are and have been to spyshelter dot net and cryptlex dot com, the latter, I believe, for a license key management API.

All my internet facing Win10 Pro 22H2 core services and processes are to azure dot com and msedge dot net. The Windows API validation Carl mentioned is doubtless happening in one of those, most likely Azure.

Cheers.

1 Like

Yes, that is correct. We use Cryptlex for our software activation system and we include them in our Privacy Policy also.

Thanks for reporting this issue so I could check it out!

Do u have an ETA for Spyshelter being available via Windows Store ?

1 Like

We submitted it yesterday. I’m not sure how long it takes to get added.

hi, :slight_smile:
any news ? its been over a week.

@SpyP

They found an issue. We fixed it, and I will resubmit on Monday.