Toon posts:

netstat toont rare verbindingen

Pagina: 1
Acties:

Verwijderd

Topicstarter
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
C:\WINDOWS>netstat -a

Actieve verbindingen

  Proto  Lokaal adres             Extern adres        Status
  TCP    s1w4h2:1026            www.fleshlight.com:0   LISTENING
  TCP    s1w4h2:135              www.fleshlight.com:0   LISTENING
  TCP    s1w4h2:8088            www.fleshlight.com:0   LISTENING
  TCP    s1w4h2:1026            www.brawnylads.com:80  CLOSE_WAIT
  TCP    s1w4h2:137              www.fleshlight.com:0   LISTENING
  TCP    s1w4h2:138              www.fleshlight.com:0   LISTENING
  TCP    s1w4h2:nbsession    www.fleshlight.com:0   LISTENING
  TCP    s1w4h2:1025            www.fleshlight.com:0   LISTENING
  TCP    s1w4h2:1029            www.fleshlight.com:0   LISTENING
  TCP    s1w4h2:nntp             www.fleshlight.com:0   LISTENING
  TCP    s1w4h2:8080            www.fleshlight.com:0   LISTENING
  TCP    s1w4h2:8080            localhost:1764              TIME_WAIT
  TCP    s1w4h2:8080            localhost:1767              TIME_WAIT
  UDP    s1w4h2:nbname         *:*
  UDP    s1w4h2:nbdatagram   *:*
  UDP    s1w4h2:1029              *:*


Ik zie al enkele maanden die verbindingen met fleshlight.com (of andere spam-url's zoals een tracker).
Ik krijg niets te zien als ik naar die site surf. fleshlight.com is porno.
Ik heb daarvan trouwens nooit iets besteld of gedownload. :)
Ik vind "fleshlight" ook nergens terug op mijn pc.
Hij staat nu wel als 0.0.0.0 in mijn hosts-list.
Het lijkt nu net alsof ik flashlight.com als een proxyserver gebruik ...of zo.

s1w4h2 is volgens mij iets van zonealarm.
Waarom brawnylads.com in netstat staat weet ik ook niet (het is van de yproxy yenc-decoder). Je gaat toch niet via hun site naar nieuwsgroepen?

Als ik tcpview draai zie ik die site niet:
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
TCP s1w4h2:135                        s1w4h2:0   LISTENING      
TCP s1w4h2:1026                       s1w4h2:0  LISTENING       
TCP s1w4h2:1793                       s1w4h2:0  LISTENING       
TCP s1w4h2:8088                       s1w4h2:0  LISTENING       
TCP f122159.upc-f.chello.nl:137       s1w4h2:0  LISTENING       
TCP f122159.upc-f.chello.nl:138       s1w4h2:0  LISTENING       
TCP f122159.upc-f.chello.nl:nbsession s1w4h2:0  LISTENING       
TCP f122159.upc-f.chello.nl:1026    www.brawnylads.com:80 CLOSE_WAIT    
TCP f122159.upc-f.chello.nl:1793     216.239.59.104:80   ESTABLISHED    
TCP s1w4h2:nntp s1w4h2:0                    LISTENING       
TCP s1w4h2:1025 s1w4h2:0                    LISTENING       
TCP s1w4h2:1029 s1w4h2:0                    LISTENING       
TCP s1w4h2:8080 s1w4h2:0                    LISTENING       
TCP s1w4h2:8080 localhost:1790  TIME_WAIT       
TCP s1w4h2:8080 localhost:1791  TIME_WAIT       
TCP s1w4h2:8080 localhost:1794  TIME_WAIT       
UDP f122159.upc-f.chello.nl:nbname  *:*         
UDP f122159.upc-f.chello.nl:nbdatagram  *:*         
UDP s1w4h2:1029 *:*


Wat doet die fleshlight in netstat?
En hoe krijg ik het weg?

  • MissingDog
  • Registratie: Augustus 2002
  • Niet online
draai spybot eens....lijkt spyware oid te zijn.

  • intoxicated
  • Registratie: Januari 2001
  • Niet online

intoxicated

Haaaai :w | ALT-S

I&T -> SA

"Anyone who does not agree with me is mentally sick, and should be shot I'm afraid to say."
- Pastor Richards @ VCPR


  • Janoz
  • Registratie: Oktober 2000
  • Laatst online: 28-08 12:00

Janoz

Moderator Devschuur®

!litemod

Ik heb een vermoeden dat het toevoegen van dat domein aan de host lijst geen invloed heeft. AFAIK is het namelijk een reversed lookup waarbij een naam bij een IP wordt gezocht. Het toevoegen aan de host file lost dus niks op.

Gewoon standaardacties ondernemen: Virus scannen, trojans scannen, firewall en (zeer waarschijnlijk) ff een format oid.

Ken Thompson's famous line from V6 UNIX is equaly applicable to this post:
'You are not expected to understand this'


Verwijderd

Topicstarter
Ik heb al die checks (spybot, the cleaner, meerdere virusscanners, zonealarm, atm-procesviewer) al eens gedaan, maar zie geen afwijkingen.
Een format... daar heb ik echt geen zin in.

Zal netstat gewoon corrupt zijn? (Omdat tpcview geen fleshlight.com toont).

Verwijderd

Edit: Slecht gelezen.. :X

Al eens met HijackThis of ander soortgelijk prog gekeken wat er draait/opstart?
(Als ik daar ook overheen heb gelezen moet ik maar eens gaan slapen..)

[ Voor 67% gewijzigd door Verwijderd op 13-01-2004 00:01 ]


  • BoGhi
  • Registratie: Juli 2002
  • Laatst online: 22-04 18:28
Netstat zal waarschijnlijk niet corrupt zijn. Als je es 127.0.0.1 ipv 0.0.0.0 in je hosts file zet bij die entry..

Programmers don't die. They GOSUB without RETURN

Pagina: 1