Suspicious IP message at start...trace?

Suspicious IP message at start...trace?

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Suspicious IP message at start...trace? dontb 07-10-2004
Posted by dontb on July 10, 2004, 10:21 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I get a unknown IP message sent each time I start my computer.
Is there an application or some way that will allow me to associate the
program on my computer with the momentary IP message sent from my computer
at startup?

Background/configuration:
XP, Linksys Router
Wallwatcher: I use Wallwatcher to monitor all IP activity at my Linksys
router.
Kerio Firewall: I also use Kerio firewall to block this IP each time, but
at every startup a new IP message is sent from my computer.
Each time I add the new IP address to the Firewall block, a new one is sent
at the next startup.
I have used Spybot to cleanse and also Norton scan every day.

TCP View/Process Explore: I have used TCP View and Process Explore but I
dont see how those help me track this momentary message.

Is there an application or some way that will allow me to associate the
program on my computer with the momentary IP message sent from my computer
at startup?

Any thoughts appreciated.




Posted by dontb on July 10, 2004, 5:13 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Now this is getting strange....

I figured out how to put a address range block in the firewall and I blocked
the range of addressess assigned to the Amsterdam server. 80.0.0.0 -
80.255.255.255.

The firewall is set to flag announce attempts in this range. Now here is
the interesting part.

When I open a received email in Outlook, I get IP sends (that are now
blocked) to addresses in that range. Not all the emails...just some.

I just have the email open. Im not even composing. the IP data is:
Outlook, 80.67.66.70. port 80, TCP, local port 1970.

What do you make of that? Sounds very weird to me.

thanks for any inputs
> I get a unknown IP message sent each time I start my computer.
> Is there an application or some way that will allow me to associate the
> program on my computer with the momentary IP message sent from my computer
> at startup?
>
> Background/configuration:
> XP, Linksys Router
> Wallwatcher: I use Wallwatcher to monitor all IP activity at my Linksys
> router.
> Kerio Firewall: I also use Kerio firewall to block this IP each time, but
> at every startup a new IP message is sent from my computer.
> Each time I add the new IP address to the Firewall block, a new one is
sent
> at the next startup.
> I have used Spybot to cleanse and also Norton scan every day.
>
> TCP View/Process Explore: I have used TCP View and Process Explore but I
> dont see how those help me track this momentary message.
>
> Is there an application or some way that will allow me to associate the
> program on my computer with the momentary IP message sent from my computer
> at startup?
>
> Any thoughts appreciated.
>
>




Similar ThreadsPosted
this message is anonymous ? January 8, 2007, 5:49 am
What do you think of this warning message? September 13, 2007, 12:02 pm
suspicious PC behaviour... December 23, 2004, 10:32 am
Need Opinion on the Following Suspicious Activity August 17, 2006, 6:23 pm
How to start in security & forensics? November 13, 2004, 8:50 am
Any Good Book To Start ? August 6, 2007, 3:03 pm
Compile/Configure Apache 1.3.31 problem without error message July 19, 2004, 11:49 pm
yahoo messenger sending email message(automatically) July 23, 2004, 10:32 pm
opening restricted perms outlook 2003 message November 10, 2004, 2:03 am
Pointers required for mysterious Sending Mail message in Ooutlook November 30, 2004, 12:25 pm

The site map in XML format XML site map

Contact Us | Privacy Policy