Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Computer downloading for no apparent reason (was WTF are VM upto now??)

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Networking
Register FAQ Community Calendar

Computer downloading for no apparent reason (was WTF are VM upto now??)
Reply
 
Thread Tools
Old 22-04-2008, 20:03   #31
whydoIneedatech
Guest
 
Services: VIRGIN MEDIA , 20 Mb BB, V+ Box, XL Phone and 2 Virgin Mobiles
Posts: n/a
Re: WTF are VM upto now??

Quote:
Originally Posted by TehTech View Post
Thanks so much Johnathan, the results are:

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

>netstat -a

Active Connections

Proto Local Address Foreign Address State
TCP lappy007:epmap lappy007:0 LISTENING
TCP lappy007:microsoft-ds lappy007:0 LISTENING
TCP lappy007:3389 lappy007:0 LISTENING
TCP lappy007:1025 lappy007:0 LISTENING
TCP lappy007:1025 localhost:1032 TIME_WAIT
TCP lappy007:1025 localhost:1034 TIME_WAIT
TCP lappy007:1025 localhost:1037 ESTABLISHED
TCP lappy007:1025 localhost:1039 FIN_WAIT_2
TCP lappy007:1025 localhost:1051 TIME_WAIT
TCP lappy007:1025 localhost:1055 TIME_WAIT
TCP lappy007:1025 localhost:1060 TIME_WAIT
TCP lappy007:1025 localhost:1069 TIME_WAIT
TCP lappy007:1025 localhost:1071 TIME_WAIT
TCP lappy007:1025 localhost:1073 TIME_WAIT
TCP lappy007:1025 localhost:1074 TIME_WAIT
TCP lappy007:1025 localhost:1077 TIME_WAIT
TCP lappy007:1025 localhost:1078 TIME_WAIT
TCP lappy007:1025 localhost:1079 TIME_WAIT
TCP lappy007:1025 localhost:1080 TIME_WAIT
TCP lappy007:1025 localhost:1081 TIME_WAIT
TCP lappy007:1025 localhost:1082 TIME_WAIT
TCP lappy007:1025 localhost:1083 TIME_WAIT
TCP lappy007:1025 localhost:1084 TIME_WAIT
TCP lappy007:1025 localhost:1087 TIME_WAIT
TCP lappy007:1025 localhost:1093 TIME_WAIT
TCP lappy007:1025 localhost:1094 TIME_WAIT
TCP lappy007:1025 localhost:1095 TIME_WAIT
TCP lappy007:1025 localhost:1096 TIME_WAIT
TCP lappy007:1025 localhost:1097 TIME_WAIT
TCP lappy007:1025 localhost:1098 TIME_WAIT
TCP lappy007:1027 lappy007:0 LISTENING
TCP lappy007:1028 lappy007:0 LISTENING
TCP lappy007:1037 localhost:1025 ESTABLISHED
TCP lappy007:1039 localhost:1025 CLOSE_WAIT
TCP lappy007:1049 localhost:1050 ESTABLISHED
TCP lappy007:1050 localhost:1049 ESTABLISHED
TCP lappy007:1053 localhost:1054 ESTABLISHED
TCP lappy007:1054 localhost:1053 ESTABLISHED
TCP lappy007:1057 localhost:1025 TIME_WAIT
TCP lappy007:1059 localhost:1025 TIME_WAIT
TCP lappy007:1061 localhost:1025 TIME_WAIT
TCP lappy007:1065 localhost:1025 TIME_WAIT
TCP lappy007:1066 localhost:1025 TIME_WAIT
TCP lappy007:netbios-ssn lappy007:0 LISTENING
TCP lappy007:1038 by2msg2043119.phx.gbl:1863 ESTABLISHED
TCP lappy007:1048 207.46.26.253:7001 TIME_WAIT
TCP lappy007:1048 207.46.26.254:7001 TIME_WAIT
TCP lappy007:1058 server3.cableforum.co.uk:http TIME_WAIT
TCP lappy007:1063 server3.cableforum.co.uk:http TIME_WAIT
TCP lappy007:1064 server3.cableforum.co.uk:http TIME_WAIT
TCP lappy007:1067 server3.cableforum.co.uk:http TIME_WAIT
TCP lappy007:1068 server3.cableforum.co.uk:http TIME_WAIT
UDP lappy007:microsoft-ds *:*
UDP lappy007:isakmp *:*
UDP lappy007:1030 *:*
UDP lappy007:1031 *:*
UDP lappy007:4500 *:*
UDP lappy007:ntp *:*
UDP lappy007:1029 *:*
UDP lappy007:discard *:*
UDP lappy007:ntp *:*
UDP lappy007:netbios-ns *:*
UDP lappy007:netbios-dgm *:*


>netstat -o -a

Active Connections

Proto Local Address Foreign Address State PID
TCP lappy007:epmap lappy007:0 LISTENING 1156
TCP lappy007:microsoft-ds lappy007:0 LISTENING 4
TCP lappy007:3389 lappy007:0 LISTENING 1092
TCP lappy007:1025 lappy007:0 LISTENING 1444
TCP lappy007:1027 lappy007:0 LISTENING 2264
TCP lappy007:1028 lappy007:0 LISTENING 2468
TCP lappy007:netbios-ssn lappy007:0 LISTENING 4
UDP lappy007:microsoft-ds *:* 4
UDP lappy007:isakmp *:* 912
UDP lappy007:1030 *:* 1252
UDP lappy007:1031 *:* 1252
UDP lappy007:4500 *:* 912
UDP lappy007:ntp *:* 1196
UDP lappy007:ntp *:* 1196
UDP lappy007:netbios-ns *:* 4
UDP lappy007:netbios-dgm *:* 4

Now the first 1 gave me some concern, but most of the first lot were PID 0 (system idle process) and I waited a few mins, then did another, which is a bit better!

The PID codes are:
0 - System Idle process
4 - System
912 - lsass.exe
1092 - svchost.exe (There are 6 of these, 3 as SYSTEM, 2 in NETWORK SERVICE, 1 as LOCAL SERVICE)
1444 - CCPROXY.EXE (internet security - norton)
2464 - ALG.EXE (Local Service)

So I cant see anything out of the ordinary so far, but will definately check them links out!

Thanks again!
In XP with nothing running you should have listed only between 7 and 10 TCP and UDP connections, if you have that many then you must have Spyware.

When you do a nestat do it as netstat -an for clearer results.

If you want to resolve what those connections are then download TCPVIEW from the following link http://technet.microsoft.com/en-us/s.../bb897437.aspx

You could also try Sam spade from this link http://www.pcworld.com/downloads/fil...scription.html

Also Process Explorer http://technet.microsoft.com/en-us/s.../bb896653.aspx

All 3 of the above tools are useful give them a go as you are more likely to have Spyware.
  Reply With Quote
Advertisement
Old 22-04-2008, 21:35   #32
Hugh
laeva recumbens anguis
Cable Forum Team
 
Hugh's Avatar
 
Join Date: Jun 2006
Age: 67
Services: Premiere Collection
Posts: 42,098
Hugh has a golden auraHugh has a golden aura
Hugh has a golden auraHugh has a golden auraHugh has a golden auraHugh has a golden auraHugh has a golden auraHugh has a golden auraHugh has a golden auraHugh has a golden auraHugh has a golden auraHugh has a golden auraHugh has a golden auraHugh has a golden aura
Re: WTF are VM upto now??

Quote:
Originally Posted by TehTech View Post
For once, well as far as we know anyway!

...snip.
Aaah, the old "guilty until proved innocent" ploy..........
__________________
There is always light.
If only we’re brave enough to see it.
If only we’re brave enough to be it
.
If my post is in bold and this colour, it's a Moderator Request.
Hugh is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 11:57.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.