Ik heb Windows XP net geinstalleerd, ook netjes met Windows Update geinstalleerd. Ik heb msn geinstalleerd en nog wat andere standaard software, maar geen ftp server oid. De kans dat ik een Trojan heb opgestart lijkt me ook klein, nog geen e-mail ontvangen in de 24 uur dat ik XP net geinstallerd heb. Ook niet met Kazaa rare dingen gedownload, kortom, wat ik zie bij mij netwerk-verbindingen hoort er echt niet thuis, en dat is dit:
-------------------

-------------------
Nu heet hij net zoals mijn firewire, maar soms heet hij anders, als ik hem uitschakel word hij na een tijdje vanzelf weer aangezet. Dan is hij weer weg, en na een tijdje komt hij weer tevoorschijn.
-------------------
Als ik een netstat -n geef, zie ik uiteraard het ip adress wat bij die @home gebruiker hoord:
Proto Lokaal adres Extern adres Status
TCP xxx.xxx.xxx.xxx:1575 217.121.245.153:2869 CLOSE_WAIT
TCP xxx.xxx.xxx.xxx:1576 217.121.245.153:2869 CLOSE_WAIT
-------------------
Of gewoon netstat:
Proto Lokaal adres Extern adres Status
TCP ccxxxxx-a:1033 cc50370-a.groni1.gr.home.nl:2869 CLOSE_WAIT
TCP ccxxxxx-a:1034 cc50370-a.groni1.gr.home.nl:2869 TIME_WAIT
TCP ccxxxxx-a:1038 cc50370-a.groni1.gr.home.nl:2869 CLOSE_WAIT
TCP ccxxxxx-a:5000 cc50370-a.groni1.gr.home.nl:3761 ESTABLISHED
TCP ccxxxxx-a:5000 cc50370-a.groni1.gr.home.nl:3763 ESTABLISHED
-------------------
Omdat ik bang ben dat ik zelf een trojan of zoiets heb heb ik mezelf gescanned met nmap:
Starting nmap V. 3.00 ( www.insecure.org/nmap/ )
Interesting ports on ccxxxxx-a.xxxxx.home.nl (xxx.xxx.xxx.xxx):
(The 1590 ports scanned but not shown below are in state: closed)
Port State Service
25/tcp filtered smtp
119/tcp filtered nntp
135/tcp open loc-srv
139/tcp filtered netbios-ssn
445/tcp open microsoft-ds
1025/tcp open NFS-or-IIS
1080/tcp filtered socks
1403/tcp open prm-nm-np
3128/tcp filtered squid-http
5000/tcp open UPnP
8080/tcp filtered http-proxy
Remote operating system guess: Windows Millennium Edition (Me), Win 2000, or WinXP
Nmap run completed -- 1 IP address (1 host up) scanned in 79 seconds
-------------------
Heel gek, er is iets raars maar ik weet niet wat dit zou kunnen zijn.
Ook weet ik niet op welke woorden ik zou moeten zoeken in google. Ik heb wel wat geprobeerd maar dat leverde niks op.
-------------------

-------------------
Nu heet hij net zoals mijn firewire, maar soms heet hij anders, als ik hem uitschakel word hij na een tijdje vanzelf weer aangezet. Dan is hij weer weg, en na een tijdje komt hij weer tevoorschijn.
-------------------
Als ik een netstat -n geef, zie ik uiteraard het ip adress wat bij die @home gebruiker hoord:
Proto Lokaal adres Extern adres Status
TCP xxx.xxx.xxx.xxx:1575 217.121.245.153:2869 CLOSE_WAIT
TCP xxx.xxx.xxx.xxx:1576 217.121.245.153:2869 CLOSE_WAIT
-------------------
Of gewoon netstat:
Proto Lokaal adres Extern adres Status
TCP ccxxxxx-a:1033 cc50370-a.groni1.gr.home.nl:2869 CLOSE_WAIT
TCP ccxxxxx-a:1034 cc50370-a.groni1.gr.home.nl:2869 TIME_WAIT
TCP ccxxxxx-a:1038 cc50370-a.groni1.gr.home.nl:2869 CLOSE_WAIT
TCP ccxxxxx-a:5000 cc50370-a.groni1.gr.home.nl:3761 ESTABLISHED
TCP ccxxxxx-a:5000 cc50370-a.groni1.gr.home.nl:3763 ESTABLISHED
-------------------
Omdat ik bang ben dat ik zelf een trojan of zoiets heb heb ik mezelf gescanned met nmap:
Starting nmap V. 3.00 ( www.insecure.org/nmap/ )
Interesting ports on ccxxxxx-a.xxxxx.home.nl (xxx.xxx.xxx.xxx):
(The 1590 ports scanned but not shown below are in state: closed)
Port State Service
25/tcp filtered smtp
119/tcp filtered nntp
135/tcp open loc-srv
139/tcp filtered netbios-ssn
445/tcp open microsoft-ds
1025/tcp open NFS-or-IIS
1080/tcp filtered socks
1403/tcp open prm-nm-np
3128/tcp filtered squid-http
5000/tcp open UPnP
8080/tcp filtered http-proxy
Remote operating system guess: Windows Millennium Edition (Me), Win 2000, or WinXP
Nmap run completed -- 1 IP address (1 host up) scanned in 79 seconds
-------------------
Heel gek, er is iets raars maar ik weet niet wat dit zou kunnen zijn.
Ook weet ik niet op welke woorden ik zou moeten zoeken in google. Ik heb wel wat geprobeerd maar dat leverde niks op.