Solved

netstat shows suspicious connections

Posted on 2008-10-17
4
1,155 Views
Last Modified: 2013-12-04
since few days,  there are lot of suspicoius activities on my desktop like double click does not open the file or database connection.
hence to check it i executed netstat command to see who is connected to my machine
and everytime i have this problem and after i run netstat i get list of connections, one of which is machine of my coworker. everytime i have such unusual behaviors running on my pc and i run netstat i find a connection with my co-workers' machine
the connection was through port - 1865
can you pl help whats going on,,,
0
Comment
Question by:at999
  • 2
4 Comments
 
LVL 17

Accepted Solution

by:
OriNetworks earned 250 total points
Comment Utility
You can begin by running netstat -b

the -b switch will show you what program is running on that port. It may be nothing to worry about but my biggest question is are you using a firewall?? This is the most basic step you can take to protect yourself. Also, do you have any antivirus software installed and up to date. Lastly, do you have a good AntiSpyware program such as Microsofts free Windows Defender installed?

I would do a full scan with you AntiVirus and AntiSpyware software just to be safe and make sure your firewall in ON
0
 
LVL 23

Assisted Solution

by:phototropic
phototropic earned 250 total points
Comment Utility
A Hijackthis scan log would help to show what is going on on your pc.

Download here:

http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

Download the installer. Click on "Do a system scan and save a logfile". Post the scan log here via the "attach code snippet" box below.
0
 

Author Comment

by:at999
Comment Utility
thnks for ur comments...

actually this is not continuous ,....
sometimes this happens, and everytime i see such supicious behavior of applications I use like double click on that application wont work etc.,  i find that the machine of my co-worker is connected to my machine

when i do a netstat -b,  it does not list any program that is running on this port...

i'll try turning firewall on...  will the window's xp firewal be enough
mny thnks
0
 

Author Comment

by:at999
Comment Utility
Netstat commands shows this

TCP    DEF:3782           ABC http  ESTABLISHED     732
c:\windows\system32\WS2_32.dll
C:\WINDOWS\system32\WININET.dll
-- unknown component(s) --

where ABC is my coworker's machine and DEF is my machine  
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Operating system developers such as Microsoft (https://www.microsoft.com) and Apple have made incredible strides in virus protection over the past decade. Operating systems come packaged with built in defensive tools such as virus protection and a f…
No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

7 Experts available now in Live!

Get 1:1 Help Now