To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here
Home | News | Reviews | Special Reports | Editorials | Forums | Compare Prices | Camera Reviews

Your source for in-depth computer hardware info

http://hardwarecentral.com/
Go Back   HardwareCentral Forums > Hardware Forums > Networking and the Internet

Networking and the Internet Wired and wireless connections and problems, online services, and related issues.

Reply
 
Thread Tools Rate Thread Display Modes
  #1  
Old September 28th, 2006, 03:14 AM
ajm100 ajm100 is offline
Junior Member
 
Join Date: Jan 2000
Location: Home
Posts: 224
Unwanted traffic....

I noticed yesterday that my connection was communicating like mad without me doing it. I look for a process that was causing it, but did not find it. I ran spybot search and destory, Hijackthis and Housecall free online scan. I have AVG installed so don't think it is a virus. I had this computer on as DMZ so the firewall was off.
I have got the firewall on now, but is there a program that I can use to see who or what is accessing my computer?
__________________
Two wrongs don't make a right, but, three rights make a left!!!!!
Reply With Quote
  #2  
Old September 28th, 2006, 04:59 AM
Tuttle's Avatar
Tuttle Tuttle is offline
Resident Cynic
 
Join Date: Dec 1998
Location: Adelaide, South Australia
Posts: 6,916
Running "netstat" at a command prompt will show you active connections. If you have XP SP2, "netstat -o" will add a PID (process ID) column which you can match up using Task Manager (View | Select Columns to show PIDs).
__________________
Safe computing is a habit, not a toolkit.
Reply With Quote
  #3  
Old September 28th, 2006, 08:35 PM
ajm100 ajm100 is offline
Junior Member
 
Join Date: Jan 2000
Location: Home
Posts: 224
This is what netstat shows after a minute without the firewall running.

Any ideas??

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\netstat -a

Active Connections

Proto Local Address Foreign Address State
TCP amd64home:epmap amd64home:0 LISTENING
TCP amd64home:microsoft-ds amd64home:0 LISTENING
TCP amd64home:2869 amd64home:0 LISTENING
TCP amd64home:4695 amd64home:0 LISTENING
TCP amd64home:8755 amd64home:0 LISTENING
TCP amd64home:13829 amd64home:0 LISTENING
TCP amd64home:1038 amd64home:0 LISTENING
TCP amd64home:10110 amd64home:0 LISTENING
TCP amd64home:netbios-ssn amd64home:0 LISTENING
TCP amd64home:1915 gsmtp167.google.com:smtp TIME_WAIT
TCP amd64home:1917 mx1.caiw.net:smtp TIME_WAIT
TCP amd64home:1919 mta-v3.level3.mail.vip.re4.yahoo.com:smtp ESTAB
LISHED
TCP amd64home:1921 mx4.hotmail.com:smtp ESTABLISHED
TCP amd64home:1923 spf1.us4.outblaze.com:smtp TIME_WAIT
TCP amd64home:1924 idcmail-mx1so.cg.shawcable.net:smtp ESTABLISHED

TCP amd64home:1925 mail.worldwarehouse.com:smtp ESTABLISHED
TCP amd64home:1926 MBUG28.kfunigraz.ac.at:smtp TIME_WAIT
TCP amd64home:1929 virtual.everyday.com:smtp TIME_WAIT
TCP amd64home:1930 mail2.t-intra.de:smtp ESTABLISHED
TCP amd64home:1931 64.1.16.244.ptr.us.xo.net:smtp SYN_SENT
TCP amd64home:1932 mx1.mail.twtelecom.net:smtp TIME_WAIT
TCP amd64home:1934 ns.digdes.com:smtp SYN_SENT
TCP amd64home:1935 mx3.hotmail.com:smtp ESTABLISHED
TCP amd64home:1937 mta-v3.level3.mail.vip.re2.yahoo.com:smtp ESTAB
LISHED
TCP amd64home:1938 mx3.hotmail.com:smtp ESTABLISHED
TCP amd64home:1940 mta-v4.level3.mail.vip.mud.yahoo.com:smtp ESTAB
LISHED
TCP amd64home:1941 dsctc.com:smtp ESTABLISHED
TCP amd64home:1942 barracuda.vinu.edu:smtp TIME_WAIT
TCP amd64home:1943 mta-v4.level3.mail.vip.mud.yahoo.com:smtp ESTAB
LISHED
TCP amd64home:1944 jane.ne1.net:smtp FIN_WAIT_1
TCP amd64home:1945 cntrra20-gtw04.telkom.co.za:smtp FIN_WAIT_1
TCP amd64home:1947 momento.zianet.com:smtp TIME_WAIT
TCP amd64home:1949 theremail.prod.there.com:smtp ESTABLISHED
TCP amd64home:1950 zues.theofficeclub.com:smtp FIN_WAIT_1
TCP amd64home:1951 mx3.hotmail.com:smtp ESTABLISHED
TCP amd64home:1952 209.145.111.61:smtp ESTABLISHED
TCP amd64home:1953 mta-v3.level3.mail.vip.re4.yahoo.com:smtp TIME_
WAIT
TCP amd64home:1955 mail2.hotmail.com:smtp SYN_SENT
TCP amd64home:1956 ent-mocinrl05.gannett.com:smtp ESTABLISHED
TCP amd64home:1957 mta-v1.talk21.level3.mail.ukl.yahoo.com:smtp ES
TABLISHED
TCP amd64home:1958 cluster-j.mailcontrol.com:smtp ESTABLISHED
TCP amd64home:1959 mail3.firstdata.com:smtp ESTABLISHED
TCP amd64home:1960 sbi.comm.charter.net:smtp ESTABLISHED
TCP amd64home:1961 smtp.secureserver.net:smtp TIME_WAIT
TCP amd64home:1962 aus2.ihostsxode.net:smtp ESTABLISHED
TCP amd64home:1963 mx2.concepts.nl:smtp ESTABLISHED
TCP amd64home:1964 smtpin7.usinternet.com:smtp ESTABLISHED
TCP amd64home:1965 smtppool2.skynet.be:smtp ESTABLISHED
TCP amd64home:1966 mail.ucn.ca:smtp ESTABLISHED
TCP amd64home:1967 xl.mx.aol.com:smtp TIME_WAIT
TCP amd64home:1968 kr3.hostwide.net:smtp ESTABLISHED
TCP amd64home:1969 bay0-mc5-f.bay0.hotmail.com:smtp ESTABLISHED
TCP amd64home:1970 eagle.skynet.co.uk:smtp ESTABLISHED
TCP amd64home:1972 mx1.optonline.net:smtp ESTABLISHED
TCP amd64home:1973 mail.leakecar.com:smtp ESTABLISHED
TCP amd64home:1974 mx.datasync.com:smtp TIME_WAIT
TCP amd64home:1975 server46.appriver.com:smtp ESTABLISHED
TCP amd64home:1976 mx3.hotmail.com:smtp ESTABLISHED
TCP amd64home:1977 smtppool2.skynet.be:smtp ESTABLISHED
TCP amd64home:1978 email.tdsautomotive.com:smtp ESTABLISHED
TCP amd64home:1979 tor2.vistapages.com:smtp ESTABLISHED
TCP amd64home:1980 mx1.nildram.co.uk:smtp ESTABLISHED
TCP amd64home:1981 66.113.195.83:smtp ESTABLISHED
TCP amd64home:1982 mx.poczta.onet.pl:smtp ESTABLISHED
TCP amd64home:1983 janus2.movi.com.ar:smtp ESTABLISHED
TCP amd64home:1984 static-70-107-251-167.ny325.east.verizon.net:smt
p SYN_SENT
TCP amd64home:1985 mta-v4.level3.mail.vip.mud.yahoo.com:smtp ESTAB
LISHED
TCP amd64home:1986 mta-v3.level3.mail.vip.re2.yahoo.com:smtp SYN_S
ENT
TCP amd64home:1987 mta-v4.level3.mail.vip.mud.yahoo.com:smtp ESTAB
LISHED
TCP amd64home:1988 gateway-a.comcast.net:smtp ESTABLISHED
TCP amd64home:1989 gateway-a.comcast.net:smtp ESTABLISHED
TCP amd64home:1990 box3.mpowercom.net:smtp ESTABLISHED
TCP amd64home:1991 mta-v4.level3.mail.vip.mud.yahoo.com:smtp ESTAB
LISHED
TCP amd64home:1992 mta-v6.level3.mail.vip.mud.yahoo.com:smtp ESTAB
LISHED
TCP amd64home:1993 *.s200a1.psmtp.com:smtp ESTABLISHED
TCP amd64home:1994 211.100.255.30:smtp SYN_SENT
TCP amd64home:1995 mta-v4.level3.mail.vip.mud.yahoo.com:smtp SYN_S
ENT
TCP amd64home:1996 ip192-12-251-74.block6.us.syntegra.com:smtp EST
ABLISHED
TCP amd64home:1997 server88.appriver.com:smtp ESTABLISHED
TCP amd64home:1998 margaretandmargaret.com:smtp ESTABLISHED
TCP amd64home:1999 MAILGATE.fnni.com:smtp ESTABLISHED
TCP amd64home:2000 mail.global.frontbridge.com:smtp ESTABLISHED
TCP amd64home:2001 usea-naimss3.unisys.com:smtp ESTABLISHED
TCP amd64home:2002 eatl0x20.coxinc.com:smtp ESTABLISHED
TCP amd64home:2003 mail.l-e.cc:smtp ESTABLISHED
TCP amd64home:2004 adsl-065-081-070-149.sip.gnv.bellsouth.net:smtp
ESTABLISHED
TCP amd64home:2005 exchange.wboc.com:smtp ESTABLISHED
TCP amd64home:2006 barracuda.imsinternet.net:smtp ESTABLISHED
TCP amd64home:2007 clmboh-mx-04.mgw.rr.com:smtp SYN_SENT
TCP amd64home:2008 shobu.comcomclub.com:smtp SYN_SENT
__________________
Two wrongs don't make a right, but, three rights make a left!!!!!
Reply With Quote
  #4  
Old September 29th, 2006, 05:06 AM
Tuttle's Avatar
Tuttle Tuttle is offline
Resident Cynic
 
Join Date: Dec 1998
Location: Adelaide, South Australia
Posts: 6,916
Your system is sending a hell of a lot of email -- those aren't incoming connections, they're outgoing. You're infected with some sort of virus or trojan, and given stuff didn't pick it up, it's probably pretty new.

You might also try something like RootkitRevealer or Blacklight, in case whatever you're infected with is cloaking itself.
__________________
Safe computing is a habit, not a toolkit.
Reply With Quote
  #5  
Old September 29th, 2006, 05:25 AM
ajm100 ajm100 is offline
Junior Member
 
Join Date: Jan 2000
Location: Home
Posts: 224
I tried rootkitrevealer and it found nothing. Still looking.
__________________
Two wrongs don't make a right, but, three rights make a left!!!!!
Reply With Quote
  #6  
Old September 29th, 2006, 06:29 AM
jimbo1763's Avatar
jimbo1763 jimbo1763 is offline
Moderator
 
Join Date: Dec 1999
Location: Augusta, Georgia, USA
Posts: 3,728
Does your firewall monitor outgoing connections or only incoming? ZoneAlarm will do both, while I think the Windows one only does incoming. Seeing what is asking for outgoing permission might be helpful.
Reply With Quote
  #7  
Old September 29th, 2006, 06:34 AM
ajm100 ajm100 is offline
Junior Member
 
Join Date: Jan 2000
Location: Home
Posts: 224
I got both xp's firewall and my Motorola WR850G routers firewall running now. XP's is set to notify if something is blocked.
__________________
Two wrongs don't make a right, but, three rights make a left!!!!!
Reply With Quote
  #8  
Old September 29th, 2006, 06:51 AM
Tuttle's Avatar
Tuttle Tuttle is offline
Resident Cynic
 
Join Date: Dec 1998
Location: Adelaide, South Australia
Posts: 6,916
Both those will only restrict inbound traffic. They won't do anything with outbound traffic.
__________________
Safe computing is a habit, not a toolkit.
Reply With Quote
  #9  
Old September 29th, 2006, 07:17 AM
Perce Perce is offline
HWC Technician
 
Join Date: Dec 1998
Location: Clinton, MA, USA
Posts: 1,099
I agree with Tuttle, you are running boocoo email services/clients/connections! What AntiVirus and AntiSpyware are you running on your PC? Finally got my first cup of Coffee, reread your post, your running AVG, I'd recommend doing an online scan, makes sure you don't have a Virus running, go here and try this, I use this site to verify PC is virus free,

http://housecall.trendmicro.com/

and if you don't have any AntiSpyware running, download Adaware and Spybot and run scans with both of em,

http://www.download.com/Ad-Aware-SE-...bj=dl&tag=top5

http://www.safer-networking.org/en/download/index.html
__________________
486 CPU/32MB Memory/Windows 3.11(it rocks!) Sigh.........the good ol Days........

Last edited by Perce; September 29th, 2006 at 07:23 AM.
Reply With Quote
  #10  
Old September 29th, 2006, 07:29 AM
ajm100 ajm100 is offline
Junior Member
 
Join Date: Jan 2000
Location: Home
Posts: 224
I got AVG and have Spybot Search and Destroy which found nothing. Have went online to Trend Micro's free online scan and it found nothing. The Rootkit Revealer found nothing. I find nothing in the window process listings. I use Thunderbird for e-mail and IE and Firefox for web surfing.
__________________
Two wrongs don't make a right, but, three rights make a left!!!!!
Reply With Quote
  #11  
Old September 29th, 2006, 08:26 AM
ajm100 ajm100 is offline
Junior Member
 
Join Date: Jan 2000
Location: Home
Posts: 224
I think I found the problem files. Winsvcup.exe, Winupsvx.exe, and Mswinup.exe. The all were the exact same size and were installed on the same day at almost the same time. I installed the free Zone alarm and it poped up after a few minutes with one of them wanting access. I think I will keep ZoneAlarm...

I just deleted the files from the system 32 directory. I have still not found a program that would find them. They are listed as malware/spyware.
__________________
Two wrongs don't make a right, but, three rights make a left!!!!!

Last edited by ajm100; September 29th, 2006 at 08:41 AM.
Reply With Quote
  #12  
Old September 29th, 2006, 09:20 AM
Perce Perce is offline
HWC Technician
 
Join Date: Dec 1998
Location: Clinton, MA, USA
Posts: 1,099
Hmmmm heavy duty spyware, try this cleaner, A2Squared, does a much better job than Spybot and Adaware,

http://www.emsisoft.com/en/software/download/

You will still have some registry entries from that Malware, here is a site that may help you with it

http://fileinfo.prevx.com/fileinfo.asp?PXC=4e7e40962685
__________________
486 CPU/32MB Memory/Windows 3.11(it rocks!) Sigh.........the good ol Days........
Reply With Quote
  #13  
Old September 29th, 2006, 09:53 AM
jimbo1763's Avatar
jimbo1763 jimbo1763 is offline
Moderator
 
Join Date: Dec 1999
Location: Augusta, Georgia, USA
Posts: 3,728
Quote:
Originally Posted by ajm100
I think I found the problem files. Winsvcup.exe, Winupsvx.exe, and Mswinup.exe. The all were the exact same size and were installed on the same day at almost the same time. I installed the free Zone alarm and it poped up after a few minutes with one of them wanting access. I think I will keep ZoneAlarm...

I just deleted the files from the system 32 directory. I have still not found a program that would find them. They are listed as malware/spyware.
You may find that they magically regenerate when you reboot. When you run your various cleaners, be sure to do it while you are running in Safe Mode-that will improve your odds of catching and eliminating them.
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:26 AM.






Acceptable Use Policy

Internet.com
The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.