Major problem with the "Diagnostics Tracking Service" on my 8.1 desktops.
Disabled service, but have no resolution.
utcsvc (Diagnostics Tracking Service) flooding Microsoft IPs with SSL/443 traffic.
T noticed Saturday a suspicious URLs:
•settings.data.glbdns2.microsoft.com - 65.55.44.108
•settings-win.data.microsoft.com
•onesettings-db5.metron.live.com.nsatc.net
nslookup settings.data.glbdns2.microsoft.com
Non-authoritative answer:
Name: OneSettings-bn2.metron.live.com.nsatc.net
Address: 65.55.44.108
Aliases: settings.data.glbdns2.microsoft.com
nslookup settings-win.data.microsoft.com (Monday morning)
Non-authoritative answer:
Name: OneSettings-bn2.metron.live.com.nsatc.net
Address: 65.55.44.108
Aliases: settings-win.data.microsoft.com
settings.data.glbdns2.microsoft.com
nslookup settings-win.data.microsoft.com (Sunday afternoon)
Non-authoritative answer:
Name: settings-win.data.microsoft.com
Addresses: 67.215.65.131
67.215.65.131
--------------------------- WS649
Microsoft Windows [Version 6.3.9600]
(c) 2013 Microsoft Corporation. All rights reserved.
C:\Windows\system32>SFC /SCANNOW
Beginning system scan. This process will take some time.
Beginning verification phase of system scan.
Verification 100% complete.
Windows Resource Protection found corrupt files but was unable to fix some
of them. Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For
example C:\Windows\Logs\CBS\CBS.log. Note that logging is currently not
supported in offline servicing scenarios.
utcsvc (Diagnostics Tracking Service)
65.55.44.108, Thursday the 4th :
<log><time>1433439487</time><orig>216.184.76.74</orig><src>192.168.5.47</src><dst>65.55.44.108</d
st><s_port>52167</s_port><d_port>443</d_port><action>HTTPS
Bypass</action><proto>tcp</proto><i_f_dir>inbound</i_f_dir><i_f_name>eth1</i_f_name><product>HTTP
S Inspection</product><state filename='fw.log' fileid='1433376394' position='1387714' /></log>
67.215.65.131 started Saturday night, first entry:
<log><time>1433640795</time><orig>216.184.76.74</orig><src>192.168.40.23</src><dst>67.215.65.131<
/dst><s_port>49814</s_port><d_port>443</d_port><action>HTTPS
Bypass</action><proto>tcp</proto><i_f_dir>inbound</i_f_dir><i_f_name>eth1</i_f_name><product>HTTP
S Inspection</product><state filename='fw.log' fileid='1433635498' position='42326' /></log>