For Goshs Sake
2008-01-31, 06:00
From what I understand, someone ran an EXE downloaded from the net on this machine. AVG antivirus raised an alarm, but could not prevent infection. Since then, I closed the SMTP on the router, but it still looks like this machine downloads lots from the net - about 10 megs a minute.
There is no reason I should have all those connections:
c:\> netstat -b -o -v > 111
Active Connections
Proto Local Address Foreign Address State PID
TCP alex:2193 218.30.115.106:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2196 mta2-f.biz.mail.vip.mud.yahoo.com:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2197 mta2-f.biz.mail.vip.mud.yahoo.com:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2198 imp8.kp.org:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2199 mail3.americantilesupply.com:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2200 unallocated.star.net.uk:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2202 213.23.86.77:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2203 mail-fwd.mx.g19.rapidsite.net:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2206 81.23.235.185:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2207 218.30.111.181:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2210 mta-v7.mail.vip.mud.yahoo.com:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2204 localhost:30606 TIME_WAIT 0
TCP alex:2235 localhost:30606 TIME_WAIT 0
TCP alex:30606 localhost:2184 TIME_WAIT 0
TCP alex:30606 localhost:2186 TIME_WAIT 0
TCP alex:30606 localhost:2201 TIME_WAIT 0
TCP alex:30606 localhost:2187 TIME_WAIT 0
TCP alex:30606 localhost:2183 TIME_WAIT 0
TCP alex:30606 localhost:2185 TIME_WAIT 0
TCP alex:2209 207.167.205.198:http TIME_WAIT 0
TCP alex:2236 old.ccrdude.net:http TIME_WAIT 0
There is no reason I should have all those connections:
c:\> netstat -b -o -v > 111
Active Connections
Proto Local Address Foreign Address State PID
TCP alex:2193 218.30.115.106:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2196 mta2-f.biz.mail.vip.mud.yahoo.com:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2197 mta2-f.biz.mail.vip.mud.yahoo.com:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2198 imp8.kp.org:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2199 mail3.americantilesupply.com:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2200 unallocated.star.net.uk:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2202 213.23.86.77:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2203 mail-fwd.mx.g19.rapidsite.net:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2206 81.23.235.185:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2207 218.30.111.181:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2210 mta-v7.mail.vip.mud.yahoo.com:smtp SYN_SENT 600
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\WS2_32.dll
-- unknown component(s) --
C:\WINDOWS\system32\kernel32.dll
[services.exe]
TCP alex:2204 localhost:30606 TIME_WAIT 0
TCP alex:2235 localhost:30606 TIME_WAIT 0
TCP alex:30606 localhost:2184 TIME_WAIT 0
TCP alex:30606 localhost:2186 TIME_WAIT 0
TCP alex:30606 localhost:2201 TIME_WAIT 0
TCP alex:30606 localhost:2187 TIME_WAIT 0
TCP alex:30606 localhost:2183 TIME_WAIT 0
TCP alex:30606 localhost:2185 TIME_WAIT 0
TCP alex:2209 207.167.205.198:http TIME_WAIT 0
TCP alex:2236 old.ccrdude.net:http TIME_WAIT 0