|
windows
newsgroups
|
|||||||||||||||||||||||
|
|||||||||||||||||||||||
Security - tcpview established connections paranoiaI have been suspicious of my network activity recently so downloaded
and ran tcpview. One of my established connections was as follows : System:4 TCP davidhomepc:netbios-ssn cable-212.76.249.73.coditel.net:3827 ESTABLISHED Why would I have a netbios connection to a belgian ip address? Does this sound like spyware activity? I have scanned my PC using numerous tools with negative results. Anyone? On 22 Oct 2006 04:15:28 -0700, dav***@sirwynn.plus.com wrote:
>I have been suspicious of my network activity recently so downloaded David,>and ran tcpview. One of my established connections was as follows : > >System:4 TCP davidhomepc:netbios-ssn cable-212.76.249.73.coditel.net:3827 ESTABLISHED > >Why would I have a netbios connection to a belgian ip address? Does >this sound like spyware activity? I have scanned my PC using numerous >tools with negative results. Anyone? If you're truly suspecting malware, only stop with a run of HijackThis and expert advice. If you could do that, and post a link to your forum posts where you get expert advice, we can help you better, and learn from the experience too. <http://nitecruzr.blogspot.com/2005/05/interpreting-hijackthis-logs-with.html> http://nitecruzr.blogspot.com/2005/05/interpreting-hijackthis-logs-with.html Are you protecting yourself? <http://nitecruzr.blogspot.com/2005/05/please-protect-yourself-layer-your.html> http://nitecruzr.blogspot.com/2005/05/please-protect-yourself-layer-your.html -- Cheers, Chuck, MS-MVP [Windows - Networking] http://nitecruzr.blogspot.com/ Paranoia is not a problem, when it's a normal response from experience. My email is AT DOT actual address pchuck mvps org. Chuck wrote:
Show quoteHide quote > On 22 Oct 2006 04:15:28 -0700, dav***@sirwynn.plus.com wrote: Cheers. I will run hijackthis and report. I have scanned my computer> > >I have been suspicious of my network activity recently so downloaded > >and ran tcpview. One of my established connections was as follows : > > > >System:4 TCP davidhomepc:netbios-ssn cable-212.76.249.73.coditel.net:3827 ESTABLISHED > > > >Why would I have a netbios connection to a belgian ip address? Does > >this sound like spyware activity? I have scanned my PC using numerous > >tools with negative results. Anyone? > > David, > > If you're truly suspecting malware, only stop with a run of HijackThis and > expert advice. If you could do that, and post a link to your forum posts where > you get expert advice, we can help you better, and learn from the experience > too. > <http://nitecruzr.blogspot.com/2005/05/interpreting-hijackthis-logs-with.html> > http://nitecruzr.blogspot.com/2005/05/interpreting-hijackthis-logs-with.html > > Are you protecting yourself? > <http://nitecruzr.blogspot.com/2005/05/please-protect-yourself-layer-your.html> > http://nitecruzr.blogspot.com/2005/05/please-protect-yourself-layer-your.html > > -- > Cheers, > Chuck, MS-MVP [Windows - Networking] > http://nitecruzr.blogspot.com/ > Paranoia is not a problem, when it's a normal response from experience. > My email is AT DOT > actual address pchuck mvps org. with AVG, Xoftspy and Windows Defender and found nothing. I ran rootkit revealer and found nothing. That should have put my mind at rest but I still see unusual (as far as I understand) activity. dav***@sirwynn.plus.com wrote:
Show quoteHide quote > Chuck wrote: and here it is :-> > On 22 Oct 2006 04:15:28 -0700, dav***@sirwynn.plus.com wrote: > > > > >I have been suspicious of my network activity recently so downloaded > > >and ran tcpview. One of my established connections was as follows : > > > > > >System:4 TCP davidhomepc:netbios-ssn cable-212.76.249.73.coditel.net:3827 ESTABLISHED > > > > > >Why would I have a netbios connection to a belgian ip address? Does > > >this sound like spyware activity? I have scanned my PC using numerous > > >tools with negative results. Anyone? > > > > David, > > > > If you're truly suspecting malware, only stop with a run of HijackThis and > > expert advice. If you could do that, and post a link to your forum posts where > > you get expert advice, we can help you better, and learn from the experience > > too. > > <http://nitecruzr.blogspot.com/2005/05/interpreting-hijackthis-logs-with.html> > > http://nitecruzr.blogspot.com/2005/05/interpreting-hijackthis-logs-with.html > > > > Are you protecting yourself? > > <http://nitecruzr.blogspot.com/2005/05/please-protect-yourself-layer-your.html> > > http://nitecruzr.blogspot.com/2005/05/please-protect-yourself-layer-your.html > > > > -- > > Cheers, > > Chuck, MS-MVP [Windows - Networking] > > http://nitecruzr.blogspot.com/ > > Paranoia is not a problem, when it's a normal response from experience. > > My email is AT DOT > > actual address pchuck mvps org. > > Cheers. I will run hijackthis and report. I have scanned my computer > with AVG, Xoftspy and Windows Defender and found nothing. I ran rootkit > revealer and found nothing. That should have put my mind at rest but I > still see unusual (as far as I understand) activity. Logfile of HijackThis v1.99.1 Scan saved at 10:51:21, on 23/10/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\Program Files\D-Link\Bluetooth Software\bin\btwdins.exe C:\WINDOWS\System32\svchost.exe E:\Program Files\Software602\602LAN SUITE\lansuits.exe C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Windows Media Connect 2\WMCCFG.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\D-Link\AirPlus G\AirGCFG.exe C:\Program Files\Windows Defender\MSASCui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\D-Link\Bluetooth Software\BTTray.exe E:\Program Files\FinePixViewer\QuickDCF.exe C:\PROGRA~1\D-Link\BLUETO~1\BTSTAC~1.EXE C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\logonui.exe C:\WINDOWS\system32\rdpclip.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\hijackthis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: BTTray.lnk = ? O4 - Global Startup: Exif Launcher.lnk = ? O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\D-Link\Bluetooth Software\btsendto_ie_ctx.htm O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\D-Link\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\D-Link\Bluetooth Software\btsendto_ie.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {5DA9D8E0-5A57-11CF-9E36-00C0930198C0} (Pegasus ImagN' 32-bit (Windowed) ActiveX Control v4.00) - http://217.34.40.203:180/LNetCam.cab O16 - DPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} - http://download.ppstream.com/bin/powerplayer.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120165564478 O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://212.100.105.93/Remote/msrdp.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{0EE063E6-8FB8-4BFA-9F69-90F57C1FCF56}: NameServer = 192.168.7.2 O17 - HKLM\System\CCS\Services\Tcpip\..\{A75FD857-12CC-4B53-902B-E0EF20BA1C67}: NameServer = 192.168.7.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{D791D1FF-AA64-4C3F-8476-7C4ED921CC7E}: NameServer = 192.168.7.2 O17 - HKLM\System\CS1\Services\Tcpip\..\{0EE063E6-8FB8-4BFA-9F69-90F57C1FCF56}: NameServer = 192.168.7.2 O17 - HKLM\System\CS2\Services\Tcpip\..\{0EE063E6-8FB8-4BFA-9F69-90F57C1FCF56}: NameServer = 192.168.7.2 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\D-Link\Bluetooth Software\bin\btwdins.exe O23 - Service: 602LAN SUITE (lansuits) - Software602 - E:\Program Files\Software602\602LAN SUITE\lansuits.exe O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe On 23 Oct 2006 05:57:15 -0700, dav***@sirwynn.plus.com wrote:
Show quoteHide quote > David,>dav***@sirwynn.plus.com wrote: >> Chuck wrote: >> > On 22 Oct 2006 04:15:28 -0700, dav***@sirwynn.plus.com wrote: >> > >> > >I have been suspicious of my network activity recently so downloaded >> > >and ran tcpview. One of my established connections was as follows : >> > > >> > >System:4 TCP davidhomepc:netbios-ssn cable-212.76.249.73.coditel.net:3827 ESTABLISHED >> > > >> > >Why would I have a netbios connection to a belgian ip address? Does >> > >this sound like spyware activity? I have scanned my PC using numerous >> > >tools with negative results. Anyone? >> > >> > David, >> > >> > If you're truly suspecting malware, only stop with a run of HijackThis and >> > expert advice. If you could do that, and post a link to your forum posts where >> > you get expert advice, we can help you better, and learn from the experience >> > too. >> > <http://nitecruzr.blogspot.com/2005/05/interpreting-hijackthis-logs-with.html> >> > http://nitecruzr.blogspot.com/2005/05/interpreting-hijackthis-logs-with.html >> > >> > Are you protecting yourself? >> > <http://nitecruzr.blogspot.com/2005/05/please-protect-yourself-layer-your.html> >> > http://nitecruzr.blogspot.com/2005/05/please-protect-yourself-layer-your.html >> Cheers. I will run hijackthis and report. I have scanned my computer >> with AVG, Xoftspy and Windows Defender and found nothing. I ran rootkit >> revealer and found nothing. That should have put my mind at rest but I >> still see unusual (as far as I understand) activity. It's good that you got no indications from the other tools. We'd really prefer, though, that you post the log in a recognised expert forum, for instance DSLR Security Cleanup. <http://www.dslreports.com/forum/cleanup> http://www.dslreports.com/forum/cleanup Are you directly connected to the Internet? Do you have a personal firewall? See the Layered Security link please. A NAT router, and / or personal firewall, would block any NetBT connections to outside computers. <http://nitecruzr.blogspot.com/2005/06/background-information-useful-in.html> http://nitecruzr.blogspot.com/2005/06/background-information-useful-in.html -- Cheers, Chuck, MS-MVP [Windows - Networking] http://nitecruzr.blogspot.com/ Paranoia is not a problem, when it's a normal response from experience. My email is AT DOT actual address pchuck mvps org.
Users can't access internet
DHCP client refuses to start Vista "talks" to XP PCs constantly! Novice with a network problem Dual ethernet use with two Networks in XP Extending network Can't join local network internet explorer 7 VPN Dial-in dialog keeps popping up after disconnecting Linksys WRT54GL File sharing problem with XP home network |
|||||||||||||||||||||||