Need Opinion on the Following Suspicious Activity

Need Opinion on the Following Suspicious Activity

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Need Opinion on the Following Suspicious Activity Jeff Lloyd 08-17-2006
Posted by Jeff Lloyd on August 17, 2006, 6:23 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I noticed that even when I have nothing open in Windows XP Pro SP2, there is
activity galore...see below. I am not too sure how to address this.
Spyware software didn't catch anything out of the ordinary and ZoneAlarm
Firewall did not catch anything sinister either. There is always net
activity being received onto my computer even when it is not being used and
nothing is running. Please advise if at all possible as to what this is:
Thanks very much.

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\user>netstat

Active Connections

Proto Local Address Foreign Address State
TCP xppro:1046 64.215.164.234:http ESTABLISHED
TCP xppro:1047 207.46.20.93:http ESTABLISHED
TCP xppro:1048 64.4.21.189:https ESTABLISHED
TCP xppro:2869 192.168.0.1:6063 TIME_WAIT
TCP xppro:2869 192.168.0.1:6064 TIME_WAIT
TCP xppro:2869 192.168.0.1:6065 TIME_WAIT



Posted by Tom Willett on August 17, 2006, 6:33 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Start by looking up the IP addresses and see if they have anything to do
with your connection: www.dnsstuff.com

>I noticed that even when I have nothing open in Windows XP Pro SP2, there
>is activity galore...see below. I am not too sure how to address this.
>Spyware software didn't catch anything out of the ordinary and ZoneAlarm
>Firewall did not catch anything sinister either. There is always net
>activity being received onto my computer even when it is not being used and
>nothing is running. Please advise if at all possible as to what this is:
>Thanks very much.
>
> Microsoft Windows XP [Version 5.1.2600]
> (C) Copyright 1985-2001 Microsoft Corp.
>
> C:\Documents and Settings\user>netstat
>
> Active Connections
>
> Proto Local Address Foreign Address State
> TCP xppro:1046 64.215.164.234:http ESTABLISHED
> TCP xppro:1047 207.46.20.93:http ESTABLISHED
> TCP xppro:1048 64.4.21.189:https ESTABLISHED
> TCP xppro:2869 192.168.0.1:6063 TIME_WAIT
> TCP xppro:2869 192.168.0.1:6064 TIME_WAIT
> TCP xppro:2869 192.168.0.1:6065 TIME_WAIT
>



Posted by David H. Lipman on August 17, 2006, 7:29 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| I noticed that even when I have nothing open in Windows XP Pro SP2, there is
| activity galore...see below. I am not too sure how to address this.
| Spyware software didn't catch anything out of the ordinary and ZoneAlarm
| Firewall did not catch anything sinister either. There is always net
| activity being received onto my computer even when it is not being used and
| nothing is running. Please advise if at all possible as to what this is:
| Thanks very much.
|
| Microsoft Windows XP [Version 5.1.2600]
| (C) Copyright 1985-2001 Microsoft Corp.
|
| C:\Documents and Settings\user>netstat
|
| Active Connections
|
| Proto Local Address Foreign Address State
| TCP xppro:1046 64.215.164.234:http ESTABLISHED
| TCP xppro:1047 207.46.20.93:http ESTABLISHED
| TCP xppro:1048 64.4.21.189:https ESTABLISHED
| TCP xppro:2869 192.168.0.1:6063 TIME_WAIT
| TCP xppro:2869 192.168.0.1:6064 TIME_WAIT
| TCP xppro:2869 192.168.0.1:6065 TIME_WAIT
|

What's so suspicious ?

HotMail ?
Microsoft ?


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Colin Nash [MVP] on August 17, 2006, 8:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>I noticed that even when I have nothing open in Windows XP Pro SP2, there
>is activity galore...see below. I am not too sure how to address this.
>Spyware software didn't catch anything out of the ordinary and ZoneAlarm
>Firewall did not catch anything sinister either. There is always net
>activity being received onto my computer even when it is not being used and
>nothing is running. Please advise if at all possible as to what this is:
>Thanks very much.
>
> Microsoft Windows XP [Version 5.1.2600]
> (C) Copyright 1985-2001 Microsoft Corp.
>
> C:\Documents and Settings\user>netstat
>
> Active Connections
>
> Proto Local Address Foreign Address State
> TCP xppro:1046 64.215.164.234:http ESTABLISHED
> TCP xppro:1047 207.46.20.93:http ESTABLISHED
> TCP xppro:1048 64.4.21.189:https ESTABLISHED
> TCP xppro:2869 192.168.0.1:6063 TIME_WAIT
> TCP xppro:2869 192.168.0.1:6064 TIME_WAIT
> TCP xppro:2869 192.168.0.1:6065 TIME_WAIT
>

The http connections are the Windows Update site. Maybe you have automatic
updates turned on? (good)

The other lines appear to be UPnP traffic from your computer to your local
router. Nothing suspicious. You can disable Universal Plug and Play on the
router and/or turn off the services that support it on your PC if you don't
like it. (Start-> Run-> SERVICES.MSC and set SSDP Discovery Service and
Universal Plug
and Play Device Host to disabled and stopped ) MSN/Windows Live Messenger,
if you use it, is also known to generate some UPnP traffic on its own
regardless of whether you turn the services off.

About UPnP:
http://www.microsoft.com/technet/prodtechnol/winxppro/evaluate/upnpxp.mspx
http://en.wikipedia.org/wiki/Universal_Plug_and_Play


--
Colin Nash
Microsoft MVP
Windows Shell/User



Posted by Jeff Lloyd on August 18, 2006, 9:58 am
If you were  Registered and logged in, you could reply and use other advanced thread options

>
>>I noticed that even when I have nothing open in Windows XP Pro SP2, there
>>is activity galore...see below. I am not too sure how to address this.
>>Spyware software didn't catch anything out of the ordinary and ZoneAlarm
>>Firewall did not catch anything sinister either. There is always net
>>activity being received onto my computer even when it is not being used
>>and nothing is running. Please advise if at all possible as to what this
>>is: Thanks very much.
>>
>> Microsoft Windows XP [Version 5.1.2600]
>> (C) Copyright 1985-2001 Microsoft Corp.
>>
>> C:\Documents and Settings\user>netstat
>>
>> Active Connections
>>
>> Proto Local Address Foreign Address State
>> TCP xppro:1046 64.215.164.234:http ESTABLISHED
>> TCP xppro:1047 207.46.20.93:http ESTABLISHED
>> TCP xppro:1048 64.4.21.189:https ESTABLISHED
>> TCP xppro:2869 192.168.0.1:6063 TIME_WAIT
>> TCP xppro:2869 192.168.0.1:6064 TIME_WAIT
>> TCP xppro:2869 192.168.0.1:6065 TIME_WAIT
>>
>
> The http connections are the Windows Update site. Maybe you have
> automatic updates turned on? (good)
>
> The other lines appear to be UPnP traffic from your computer to your local
> router. Nothing suspicious. You can disable Universal Plug and Play on
> the router and/or turn off the services that support it on your PC if you
> don't like it. (Start-> Run-> SERVICES.MSC and set SSDP Discovery Service
> and Universal Plug
> and Play Device Host to disabled and stopped ) MSN/Windows Live
> Messenger, if you use it, is also known to generate some UPnP traffic on
> its own regardless of whether you turn the services off.
>
> About UPnP:
> http://www.microsoft.com/technet/prodtechnol/winxppro/evaluate/upnpxp.mspx
> http://en.wikipedia.org/wiki/Universal_Plug_and_Play
>
>
> --
> Colin Nash
> Microsoft MVP
> Windows Shell/User
>
Colin, thanks very much for your explanation to this. Much appreciated.

Jeff



Similar ThreadsPosted
ANN: PC Activity Monitor Professional 7.4 released March 17, 2005, 7:07 am
Strange network probe activity November 15, 2006, 2:41 pm
suspicious PC behaviour... December 23, 2004, 10:32 am
Suspicious IP message at start...trace? July 10, 2004, 10:21 am

The site map in XML format XML site map

Contact Us | Privacy Policy