Re: Please help me interpret a suspicious netstat SYN_SENT TCP port 1058 ?

Re: Please help me interpret a suspicious netstat SYN_SENT TCP port 1058 ?

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Re: Please help me interpret a suspicious netstat SYN_SENT TCP port 1058 ? Pam 02-25-2006
Posted by Pam on February 25, 2006, 1:04 am
If you were  Registered and logged in, you could reply and use other advanced thread options
>> WINDOWSXP_SP2> netstat -a -n -b
>> Proto Local Address Foreign Address State
PID
>> TCP 192.168.0.101:1058 63.236.111.222:80 SYN_SENT 912
>> C:\WINDOWS\system32\WS2_32.dll
>> C:\WINDOWS\System32\WINHTTP.dll
>> -- unknown component(s) --
>> [svchost.exe]

>What process had PID 912?

I rebooted and ran netstat again a few times and at first did not know how to
see what process was 912 until I found and installed something called NirSoft
CurrProcess http://www.nirsoft.net/utils/cprocess.html which told me it was
the "svchost.exe" process and that this process was owned by the "NT
AUTHORITY\SYSTEM".

I tried finding more information about that process by downloading something
called Sysinternals Process Explorer by Mark Russinovich
http://www.sysinternals.com but I could not comprehend the information in the
bottom bar of the window (Thread, Semaphore, Port, Mutant, KeyedEvent, Key,
WindowStation, etc).

It seems that one of my many svchost "Generic Host Process for Win32 Services"
processes is the culprit which is initiating "SYN_SENT" signals on random
ports to Quest Communications (63.236.111.222) at port 80.
But why?

Even though I ran and reran a virus scan, malware scan, Ad-Aware scan, Spybot
Search and Destroy scan, etc., do you think this unsolicited request to
63.236.111.222 at port 80 might be related to the strange C:\TEMP\GLB1A2B.EXE
file I saw but which went away after a reboot?

Similar ThreadsPosted
W2K netstat detects port 1433 is listenning but fport does NOT..., can't start mission critical sql server !!! October 14, 2005, 2:20 pm
Suspicious logfile ??? June 6, 2007, 4:13 pm
Suspicious E-Mail Messages January 13, 2007, 4:37 am
Port log April 22, 2008, 2:54 am
Scanning a port September 24, 2005, 2:27 am
What port Need Sdbot for Execute September 19, 2005, 2:21 pm
Port Block Allow NetBIOS changed November 9, 2005, 8:01 pm
ixplore listening on a localhost UDP Port? November 22, 2005, 4:06 pm
Re: Unknown svchost.exe DNS port 53 network activity December 20, 2006, 4:26 pm
Windows Defender problems after Port 135 and rpc disabling! Dr Lipman and others - help! April 9, 2006, 5:45 pm

The site map in XML format XML site map

Contact Us | Privacy Policy