PDA

View Full Version : help with intrusion TCP connections



isaac1917
2010-08-11, 14:36
Hi,
My PC got infected 2 days ago with the "antimalware software". Too many TCPs connections were opened. Thankfully, after spending long hours i was able to clear most but not all of the unwanted open TCP connection (there was a nasty sys file installed under windows/system 32/drivers ). Now when i run spybot and other spyware detectors, it said it is clean. however, i still have two entries when typing netstat. Those are:
TCP myself:3302 LB43.LOND.COTENDO.NET:http CLOSE_WAIT
TCP myself:3303 bzq-219-199-220.pop.bezeqint.net:http ESTABLISHED

linked to what it seems monitoring sites! anyhelp on how to clean them out. i used many softwares such as swdoctor, spybot, in vain. cheers.

isaac1917
2010-08-11, 15:05
[QUOTE=isaac1917;380450]Hi,
Those are:
TCP myself:3302 LB43.LOND.COTENDO.NET:http CLOSE_WAIT
TCP myself:3303 bzq-219-199-220.pop.bezeqint.net:http ESTABLISHED

[QUOTE]
the TCP connections are used by IEXPLORER AND FIREFOX processes

tashi
2010-08-11, 16:51
Hello isaac1917,

Please see the forum FAQ which also includes instructions on posting a preliminary DDS log: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288) :)

Then start a new topic and a volunteer analyst will advise you when available.

Best regards.