Weird connections when using netstat

Reply

Join Date: Nov 2006
Posts: 62
Reputation: mps727 is an unknown quantity at this point 
Solved Threads: 0
mps727 mps727 is offline Offline
Junior Poster in Training

Weird connections when using netstat

 
0
  #1
Feb 26th, 2007
My internet connection has been going pretty slow lately. I've scanned for viruses and spyware but didn't find anything. So anyway I came across something that concerns me a little bit. I used netstat -o to view established connections and there's some open for weird things like this for example:

TCP michael-desktop:1715 downloads.aaa1screensavers.com:1716 ESTABLISHED 3084

I am of course a little suspicious of these. They all seem to have the same PID as well. On Windows though I don't know how to look up which process is assigned to which PID. Does this look like malware to anyone else? How can I find more information on this process and removing it? Also, would it be reasonable to assume that this is causing slowdown? There are 7 of these "weird" connections open.
Last edited by mps727; Feb 26th, 2007 at 8:12 pm.
Reply With Quote Quick reply to this message  
Join Date: Nov 2006
Posts: 62
Reputation: mps727 is an unknown quantity at this point 
Solved Threads: 0
mps727 mps727 is offline Offline
Junior Poster in Training

Re: Weird connections when using netstat

 
0
  #2
Feb 27th, 2007
Also, I think I forgot to make it clear, but I was wondering for future reference how to find out what process is assigned to the PID so I can determine what is establishing the connection.
Reply With Quote Quick reply to this message  
Join Date: May 2006
Posts: 1,827
Reputation: ithelp is a name known to all ithelp is a name known to all ithelp is a name known to all ithelp is a name known to all ithelp is a name known to all ithelp is a name known to all 
Solved Threads: 118
ithelp's Avatar
ithelp ithelp is offline Offline
Posting Virtuoso

Re: Weird connections when using netstat

 
0
  #3
Feb 27th, 2007
plug out the network cable for few minutes, and replug and see if the program is still running, the process is using port 1715, so either block the port or find out the process and kill it
Reply With Quote Quick reply to this message  
Join Date: Jan 2007
Posts: 1,763
Reputation: DimaYasny will become famous soon enough DimaYasny will become famous soon enough 
Solved Threads: 85
Moderator
Featured Poster
DimaYasny DimaYasny is offline Offline
Posting Virtuoso

Re: Weird connections when using netstat

 
0
  #4
Mar 8th, 2007
if you want to block the connected url permanently, you can enter it into the hosts file, with an ip of 127.0.0.1
that way any malware/spyware won't be able to find it and connect to it
Real stupidity always beats Artificial Intelligence. (Terry Pratchett)

BA BizMg, MCSE, DCSE, Linux+, Network+
Reply With Quote Quick reply to this message  
Join Date: Jan 2007
Posts: 1,763
Reputation: DimaYasny will become famous soon enough DimaYasny will become famous soon enough 
Solved Threads: 85
Moderator
Featured Poster
DimaYasny DimaYasny is offline Offline
Posting Virtuoso

Re: Weird connections when using netstat

 
0
  #5
Mar 8th, 2007
if you want to block the connected url permanently, you can enter it into the hosts file, with an ip of 127.0.0.1
that way any malware/spyware won't be able to find it and connect to it
Real stupidity always beats Artificial Intelligence. (Terry Pratchett)

BA BizMg, MCSE, DCSE, Linux+, Network+
Reply With Quote Quick reply to this message  
Join Date: Jan 2007
Posts: 1,763
Reputation: DimaYasny will become famous soon enough DimaYasny will become famous soon enough 
Solved Threads: 85
Moderator
Featured Poster
DimaYasny DimaYasny is offline Offline
Posting Virtuoso

Re: Weird connections when using netstat

 
0
  #6
Mar 8th, 2007
damn, that was a glitch in the matrix
sorry mods, please erase the extra posts

thanks )
Real stupidity always beats Artificial Intelligence. (Terry Pratchett)

BA BizMg, MCSE, DCSE, Linux+, Network+
Reply With Quote Quick reply to this message  
Join Date: Dec 2007
Posts: 1
Reputation: XTRM is an unknown quantity at this point 
Solved Threads: 0
XTRM XTRM is offline Offline
Newbie Poster

Re: Weird connections when using netstat

 
0
  #7
Dec 29th, 2007
Especialy good when you notice your internet running continously when you havn' even opend a window yet !!

Start
Run
Type 'cmd'
Type 'netstat'
You will see the strange connection name & ip
If you cant find the ip number type 'nslookup (domain name)' then enter
Once you got Ip and domain name install X-Netstat a free software that can kill and monitor those connections.
Open the program and click refresh, find the connection through the ip or domain name you have and kill it (Kill button).

BUT

Depending on the trojen or whatever the case may be it can come back, annoying.

Under the process section you can see the processes name, remember it.
Press Ctrl+Alt+Dlt
Click Processes tab
Find it and kill

Problem solved

Back to Sleep
Reply With Quote Quick reply to this message  
Join Date: Dec 2007
Posts: 7
Reputation: pappuravi80 is an unknown quantity at this point 
Solved Threads: 1
pappuravi80's Avatar
pappuravi80 pappuravi80 is offline Offline
Newbie Poster

Re: Weird connections when using netstat

 
0
  #8
Dec 30th, 2007
tips:
try removing startup items...
update your antivirus/spyware
check with the firewall settings...

Regards,
Pappu R.
Reply With Quote Quick reply to this message  
Join Date: Oct 2007
Posts: 55
Reputation: darsh999 is an unknown quantity at this point 
Solved Threads: 3
darsh999 darsh999 is offline Offline
Junior Poster in Training

Re: Weird connections when using netstat

 
0
  #9
Jan 16th, 2008
first of all change your anti virus system
it's a spam it generally happens with poor anti virus protection so get a new anti virus and get a rescan i hope the problem will be resolved
Asta La Vista !!!
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:


Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC