It happens on 2 of my machines on startup so I ruled that out that possibility.
Also, one of my infected machines, the windows server machine has apache but the other, my XP machine at home, does not have a web server at all.
The connection itself (75.125.111.2) does not appear to have an "A Record" but appears to be owned by an ISP called ThePlanet.com which provided dedicated and collocated servers
Is there any command that can tell me what program created that 75.125.112 connection on startup?