Advertisement

05.07.2008 at 05:37AM PDT, ID: 23382497
[x]
Attachment Details

system process talking to a server I have nothing to do with.  Has my PCs security been breached (hacked)?

Asked by imherson in Networking Security Vulnerabilities, Miscellaneous Security

Tags: Microsoft, Windows, xp 2003, system, process, SMB,

My PC regularly tries to contact another server in an other domain on another subnet that I have nothing to do with.  I am a LAN administrator and have not configured any client process that should connect with that server.  There are other servers on that subnet and on my subnet that my PC does connect to in this way.

I have disabled network crawling but my PC still tries to open a TCP session with the server
 I want to find out what is doing this or/ and prevent it from happening.  

Below is  what I see in port reporter.  My PC is 142.105.2.21.  The server which I should have nothing to do with is  142.105.96.112

Process ID: 4 (System)

System Process

PID      Port            Local IP      State             Remote IP:Port
4      TCP 445        0.0.0.0       LISTENING       0.0.0.0
4      TCP 139        142.105.2.21       LISTENING       0.0.0.0
4      TCP 1099        142.105.2.21       ESTABLISHED       142.105.2.52:445
4      TCP 1219        142.105.2.21       ESTABLISHED       142.105.96.112:139
4      UDP 445        0.0.0.0                    *:*
4      UDP 137        142.105.2.21                    *:*
4      UDP 138        142.105.2.21      

Below also are some lines from my windows firewall log:

008-04-04 08:15:05 OPEN TCP 142.105.2.21 142.105.96.112 1066 445 - - - -
2008-04-04 08:15:53 OPEN TCP 142.105.2.21 142.105.96.112 1075 445 - - - - - - - - -
2008-04-04 08:15:53 OPEN TCP 142.105.2.21 142.105.96.112 1076 139 - - - - - - - - -
2008-04-04 08:15:53 CLOSE TCP 142.105.2.21 142.105.96.112 1076 139 - - -
2008-05-06 08:34:56 DROP TCP 142.105.96.112 142.105.2.21 139 1221 48 SA 418609128 2589345294 65535 - - - RECEIVE

Start Free Trial
 
Loading Advertisement...
 
[+][-]05.07.2008 at 06:24AM PDT, ID: 21516098

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]05.07.2008 at 06:30AM PDT, ID: 21516146

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]05.07.2008 at 07:44AM PDT, ID: 21516950

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]05.07.2008 at 10:41AM PDT, ID: 21518657

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]05.07.2008 at 11:32AM PDT, ID: 21519114

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Networking Security Vulnerabilities, Miscellaneous Security
Tags: Microsoft, Windows, xp 2003, system, process, SMB,
Sign Up Now!
Solution Provided By: riotz
Participating Experts: 2
Solution Grade: B
 
 
 
Loading Advertisement...
Microsoft
  • Internet Protocols
  • Applications
  • Development
  • OS
  • Hardware
  • Windows Security
Apple
  • Operating Systems
  • Hardware
  • Programming
  • Networking
  • Software
Internet
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Spy / Ad Blockers
  • Web Browsers
  • New Net Users
  • Web Development
  • Chat / IM
  • Anti Spam
  • Web Servers
  • Anti-Virus
  • Email Clients
Gamers
  • Tips
  • Online / MMORPG
  • Puzzle
  • Emulators
  • Action / Adventure
  • Role Playing
  • Consoles
  • Game Programming
  • Strategy
  • Sports
  • Misc
  • Computer Games
Digital Living
  • Hardware
  • Automotive
  • New Net Users
  • New Users
  • Software
  • Digital Music
  • Gaming World
  • Home Security
  • Apple
  • Networking Hardware
Virus & Spyware
  • Vulnerabilities
  • IDS
  • Encryption
  • Anti-Virus
  • Operating Systems Security
  • Software Firewalls
  • WebApplications
  • Cell Phones
  • Operating Systems
  • Internet
  • Hardware Firewalls
Hardware
  • Displays / Monitors
  • Handhelds / PDAs
  • Components
  • Peripherals
  • Laptops/Notebooks
  • Servers
  • Misc
  • Apple
  • Embedded Hardware
  • Networking Hardware
  • Storage
  • Desktops
  • New Users
Software
  • System Utilities
  • Industry Specific
  • Network Management
  • Photos / Graphics
  • Page Layout
  • VMware
  • Misc
  • Web Development
  • OS
  • CYGWIN
  • Voice Recognition
  • Virtualization
  • Message Queue
  • Quality Assurance
  • Security
  • Firewalls
  • MultiMedia Applications
  • Development
  • Database
  • Office / Productivity
  • Business Management
  • OS/2 Apps
  • Server Software
  • Internet / Email
ITPro
  • OS
  • Storage
  • Encryption
  • Operating Systems Security
  • Apple Hardware
  • Laptops & Notebooks
  • Servers
  • Networking Hardware
  • Peripherals
  • Devices
  • Displays / Monitors
  • WebTrends / Stats
  • Search Engines
  • Firewalls
  • Web Computing
  • WebApplications
  • IDS
  • Vulnerabilities
  • Email Clients
  • File Sharing
  • Spy / Ad Blockers
  • Web Browsers
  • Web Servers
  • Networking
  • Anti-Virus
  • Consulting
  • Chat / IM
  • Anti Spam
Developer
  • Web Servers
  • Web Browsers
  • Game Programming
  • Dev Tools
  • Industry Specific
  • Office / Productivity
  • Database
  • CYGWIN
  • Web Development
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Programming
  • Content Management
  • Application Servers
  • Protocols
Storage
  • Removable Backup Media
  • Storage Technology
  • Servers
  • Grid
  • Remote Access
  • Backup / Restore
  • Misc
  • Hard Drives
OS
  • Miscellaneous
  • Security
  • Development
  • Linux
  • VMware
  • MainFrame OS
  • Unix
  • Apple
  • OS / 2
  • AS / 400
  • BeOS
  • Microsoft
  • VMS / OpenVMS
Database
  • Oracle
  • Miscellaneous
  • MySQL
  • Software
  • Sybase
  • Contact Management
  • PostgreSQL
  • Data Manipulation
  • Clarion
  • InterSystems Cache
  • Siebel
  • MUMPS
  • OLAP
  • SQLBase
  • SAS
  • GIS & GPS
  • 4GL
  • Berkeley DB
  • DB2
  • Informix
  • Interbase / Firebird
  • FoxPro
  • Reporting
  • LDAP
  • Filemaker Pro
  • MS SQL Server
  • dBase
  • MS Access
Security
  • Misc
  • Web Browsers
  • Software Firewalls
  • Operating Systems Security
  • File Sharing
  • Spy / Ad Blockers
  • Vulnerabilities
  • WebApplications
  • IDS
  • Anti-Virus
  • Encryption
  • Anti Spam
  • Email Clients
  • VPN
  • Chat / IM
Programming
  • Editors IDEs
  • Installation
  • Handhelds / PDAs
  • Multimedia Programming
  • System / Kernel
  • Automation
  • Algorithms
  • Game
  • Signal Processing
  • Project Management
  • Open Source
  • Database
  • Misc
  • Languages
  • Processor Platforms
  • Theory
Web Development
  • Scripting
  • Blogs
  • Web Servers
  • Software
  • Search Engines
  • Web Graphics
  • Web Services
  • Images
  • Internet Marketing
  • Images and Photos
  • Components
  • Document Imaging
  • Web Languages/Standards
  • Illustration
  • WebApplications
  • Fonts
  • WebTrends / Stats
  • Authoring
  • Digital Camera Software
  • Miscellaneous
Networking
  • Protocols
  • Apple Networking
  • Network Management
  • Message Queue
  • Application Servers
  • Content Management
  • File Servers
  • Email Servers
  • Misc
  • Java Editors & IDEs
  • Wireless
  • Networking Hardware
  • Backup / Restore
  • System Utilities
  • ISPs & Hosting
  • Web Servers
  • Storage Technology
  • Removable Backup Media
  • Servers
  • Web Computing
  • Broadband
  • Grid
  • OS / 2
  • Novell Netware
  • Unix Networking
  • Windows Networking
  • Security
  • Telecommunications
  • Operating Systems
  • Linux Networking
Other
  • Lounge
  • Business Travel
  • Community Support
  • New Net Users
  • Philosophy / Religion
  • Math / Science
  • Miscellaneous
  • URLs
  • Expert Lounge
  • Politics
  • Puzzles / Riddles
  • Automotive
Community Support
  • Suggestions
  • New to EE
  • New Topics
  • CleanUp
  • Announcements
  • General
  • Feedback
  • Input
  • EE Bugs
 
05.07.2008 at 06:24AM PDT, ID: 21516098
Well, port 139 is used for netbios file and printer sharing.  Do you have a mapped drive to that machine or to a printer on that machine?
 
05.07.2008 at 06:30AM PDT, ID: 21516146
no mapped drive or printer
 
05.07.2008 at 07:44AM PDT, ID: 21516950
Block the ip in your firewall and maybe check for a virus infection..

a good tool to help identify unwanted processes fastly is hijackthis.
 
05.07.2008 at 10:41AM PDT, ID: 21518657
I am blocking the inbound but how to block the outbound (I'm using windows firewall)
 
05.07.2008 at 11:32AM PDT, ID: 21519114
setup an ip-security filter

http://www.securityfocus.com/infocus/1559
Accepted Solution
 
 
20080716-EE-VQP-32 / EE_QW_2_20070628