Administrator DKT27 Posted January 5, 2010 Administrator Share Posted January 5, 2010 Install Prio - Download it from here(x64) - http://www.prnwatch....64_199_2091.exeThen after installation, go into task manager, into a new tab called TCP/IP see hover on the unkown connection and see what it says. Link to comment Share on other sites More sharing options...
LeetPirate Posted January 5, 2010 Share Posted January 5, 2010 Those weird IP in your screen shots are generated from http://www.libero.it/ and http://www.orange.fr/Looks like 2 ISP to me but I am not sure. It could just be random DHT connections to other users on those ISP, most likely harmless. The port used in uTorrent is for TCP traffic, UDP does not have to use that port and also UDP is meant to be connectionless so I do not believe it can be traffic shaped as with TCP packets. Link to comment Share on other sites More sharing options...
shought Posted January 5, 2010 Share Posted January 5, 2010 @LeetPirateI believe these are the outgoing connections... So I don't think they're ok. Might be wrong, obviously. Link to comment Share on other sites More sharing options...
mara- Posted January 5, 2010 Author Share Posted January 5, 2010 Well, I installed Prio and it does not add any new tab to task manager. Do I need to reboot?I downloaded TCPView from Microsoft page and all I can see that creates UDP connections is svchost.exe. I know that this can be a virus, but I scanned the whole computer and it's clean. Does anybody know some monitoring tool that can tie outgoing connection to specific process?Cheers ;) Link to comment Share on other sites More sharing options...
Toshiro Posted January 5, 2010 Share Posted January 5, 2010 Could you hard reset your router? (see the manual) This should clear all the ports. So you need to open one for Utorrent. Btw, Try deleting some torrents from Utorrent. I think seeding 100 torrents is a little to much :lol:Cause a friend of mine got dissconnected for downloading to much. Maybe you're uploading to much?You could also call them and ask them what the reason is.. Link to comment Share on other sites More sharing options...
shought Posted January 5, 2010 Share Posted January 5, 2010 You should search for svchost.exe and check if it appears in any odd-looking locations ;) Link to comment Share on other sites More sharing options...
mara- Posted January 5, 2010 Author Share Posted January 5, 2010 Could you hard reset your router? (see the manual) This should clear all the ports. So you need to open one for Utorrent. Btw, Try deleting some torrents from Utorrent. I think seeding 100 torrents is a little to much :lol:Cause a friend of mine got dissconnected for downloading to much. Maybe you're uploading to much?You could also call them and ask them what the reason is..These are just small torrents, under 50 KB, so I can gather points faster on pretome, nobody is even downloading it. And believe me, country where I live does not work anything to stop piracy. I know for some shops where you can buy games with cracks, so...You should search for svchost.exe and check if it appears in any odd-looking locations ;)I'll check that.Cheers ;) Link to comment Share on other sites More sharing options...
HX1 Posted January 5, 2010 Share Posted January 5, 2010 Well, I installed Prio and it does not add any new tab to task manager. Do I need to reboot?I downloaded TCPView from Microsoft page and all I can see that creates UDP connections is svchost.exe. I know that this can be a virus, but I scanned the whole computer and it's clean. Does anybody know some monitoring tool that can tie outgoing connection to specific process?Cheers ;)Process Hacker.. right here on NsaneForums.. will show it.. ( on the Network Tab, not to mention it could shed some light on anything its connected to )I dunno how this would help, BUT ESS BE > Protection Status > Network Connections.. gives exact specifics..Information for the two addresses that it connected to..% The RIPE Database is subject to Terms and Conditions.% See http://www.ripe.net/db/support/db-terms-conditions.pdf% Note: This output has been filtered.% To receive output for a database update, use the "-B" flag.% Information related to '151.15.0.0 - 151.15.255.255'inetnum: 151.15.0.0 - 151.15.255.255netname: IUNET-BNET15descr: IUnetdescr: Via Lorenteggio 257descr: Milano, I-20100country: ITadmin-c: IIS1-RIPEtech-c: IIS1-RIPEstatus: ASSIGNED PAmnt-by: AS1267-MNTmnt-lower: AS1267-MNTmnt-routes: AS1267-MNTsource: RIPE # Filteredperson: Infostrada Internet Staffaddress: Infostrada SpAaddress: Via Lorenteggio 257address: I-20152 Milanoaddress: Italyphone: +39 02 413311e-mail: <img src="/text2image.php?id=VSAFcQU3VDVVM1ERAGsGJlVuBTEAdFZ4CGAIdQ==" align="middle" alt="Email address protected from spam harvesters" />nic-hdl: IIS1-RIPEmnt-by: AS1267-MNTsource: RIPE # Filtered% Information related to '151.15.0.0/16AS1267'route: 151.15.0.0/16descr: INFOSTRADAorigin: AS1267remarks: removed cross-mnt: AS1267-MNTmnt-lower: AS1267-MNTmnt-routes: AS1267-MNTmnt-by: AS1267-MNTsource: RIPE # FilteredOrgName: RIPE Network Coordination CentreOrgID: RIPEAddress: P.O. Box 10096City: AmsterdamStateProv:PostalCode: 1001EBCountry: NLReferralServer: whois://whois.ripe.net:43NetRange: 90.0.0.0 - 90.255.255.255CIDR: 90.0.0.0/8NetName: 90-RIPENetHandle: NET-90-0-0-0-1Parent:NetType: Allocated to RIPE NCCNameServer: NS-PRI.RIPE.NETNameServer: SEC1.APNIC.NETNameServer: SEC3.APNIC.NETNameServer: SUNIC.SUNET.SENameServer: TINNIE.ARIN.NETNameServer: NS2.LACNIC.NETComment: These addresses have been further assigned to users inComment: the RIPE NCC region. Contact information can be found inComment: the RIPE database at http://www.ripe.net/whoisRegDate: 2005-06-30Updated: 2009-05-18# ARIN WHOIS database, last updated 2010-01-04 20:00# Enter ? for additional hints on searching ARIN's WHOIS database.## ARIN WHOIS data and services are subject to the Terms of Use# available at https://www.arin.net/whois_tou.htmlFound a referral to whois.ripe.net:43.% This is the RIPE Database query service.% The objects are in RPSL format.%% The RIPE Database is subject to Terms and Conditions.% See http://www.ripe.net/db/support/db-terms-conditions.pdf% Note: This output has been filtered.% To receive output for a database update, use the "-B" flag.% Information related to '90.2.196.0 - 90.2.196.255'inetnum: 90.2.196.0 - 90.2.196.255netname: IP2000-ADSL-BASdescr: BSMSO753 Montsouris Bloc 2country: FRadmin-c: WITR1-RIPEtech-c: WITR1-RIPEstatus: ASSIGNED PAremarks: for hacking, spamming or security problems send mail toremarks: <img src="/text2image.php?id=A3VTPAQkBnUFaAJjCXgFJFZmASIJSQZxUDADZAZjVj4EbQ1iA35SMwl7" align="middle" alt="Email address protected from spam harvesters" /> AND <img src="/text2image.php?id=BmEMblZwWi4DZgFBBnMGMgI5V2cCZgRrVDoILwVnBXs=" align="middle" alt="Email address protected from spam harvesters" />mnt-by: FT-BRXsource: RIPE # Filteredrole: Wanadoo France Technical Roleaddress: FRANCE TELECOM/SCRaddress: 48 rue Camille Desmoulinsaddress: 92791 ISSY LES MOULINEAUX CEDEX 9address: FRphone: +33 1 58 88 50 00e-mail: <img src="/text2image.php?id=AGdRM1ZwAHQFYFMTVjtXcFFlBToEYwRhUH8Ab1Uj" align="middle" alt="Email address protected from spam harvesters" />This could be the polling from your connection to ISP or DNS server...not for sure though.. the one in between from utorrent, is a Tor Onion Router Server in the Russian Federation. Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted January 5, 2010 Administrator Share Posted January 5, 2010 I think you will need reboot for Prio. Link to comment Share on other sites More sharing options...
mara- Posted January 6, 2010 Author Share Posted January 6, 2010 @ heath28mI checked with Process Hacker, and it shows only svchost.exe. And how did you check that IP adresses? I just checked and one is from Italy, other France (I just sow, in your post is also Italy, and Netherlands, how come you mention Russian Federation). BTW, now there is any Unknown connection, uTorrent is running. It's seems that most of unknown connections is on startup and it dissapears latter. This is really strange. To me, everything looks clean. Maybe cFosSpeed just can not identify program, nothing else. But then again, it's strange because, uTorrent was not running when I took that picture. And I also notice that after I exit uTorrent, some new connection are still appearing related to uTorrent for some short time, maybe 2-3 minutes. I don't know, I'm really puzzled here.I checked my system with:NAV2010MBAMSuperAntispywareMicrosoft Malicious Removal ToolSpybotHijachLog didn't shot nothingEverything is clean now, but I still can not understand how and why this unknown connections appear.@DKTOK, I'll see that tomorrow then.Cheers ;) Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted January 6, 2010 Administrator Share Posted January 6, 2010 Well I was not mentioning it all the time cause I thought it would be solved the easy way. I would suggest you use Wireshark a free protocol analyzer.I and my friends recommend it specially if you wanna catch a person who is responsible for keylogger or RAT on your computer. Once installed and run, stop all the internet activity and see if that unknown program is caught. There's a video tut made by one of my friend on wireshak, but I doubt I can post it here. Link to comment Share on other sites More sharing options...
mara- Posted January 6, 2010 Author Share Posted January 6, 2010 Well, send me a link via PM. I already had this program, but I didn't know how to use it. Tutorial would be really useful.Cheers ;) Link to comment Share on other sites More sharing options...
Bizarre™ Posted January 6, 2010 Share Posted January 6, 2010 @mara-:Try COMODO Firewall. Then go to Firewall > Common Tasks > View Active Connections.It should show all process trying to make a connection. Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted January 6, 2010 Administrator Share Posted January 6, 2010 Sendin PM in a min.It gives you some info on Wireshark. Link to comment Share on other sites More sharing options...
HX1 Posted January 6, 2010 Share Posted January 6, 2010 @ heath28mI checked with Process Hacker, and it shows only svchost.exe. And how did you check that IP adresses? I just checked and one is from Italy, other France (I just sow, in your post is also Italy, and Netherlands, how come you mention Russian Federation). BTW, now there is any Unknown connection, uTorrent is running. It's seems that most of unknown connections is on startup and it dissapears latter. This is really strange. To me, everything looks clean. Maybe cFosSpeed just can not identify program, nothing else. But then again, it's strange because, uTorrent was not running when I took that picture. And I also notice that after I exit uTorrent, some new connection are still appearing related to uTorrent for some short time, maybe 2-3 minutes. I don't know, I'm really puzzled here.ElcroWhois program here on my computer.. The 'Russain Federation' was (its physical location) the UDP connection to uTorrent, it is an anonymity server for Tor.. that is what I found after Finding that the address came up as --something--, Inc. So I ran a search of the search engines and found it t be listed as used by Tor.One last thought about 'Unknown' connections especially at Startup are some of the thousands of Scheduled tasks, some of which reach out to the Internet.. that are included in Windows 7 by default, some of which are as simple as scheduled RSS Feed Synchronization... Others for other reasons, the possible reason it is coming up as unknown being that 64 bit files have to have specific verification to be identified (same true of HJT logs in many cases.. ) I am also assuming that your running 64 Bit Windows as well.. SO essentially this truly could be running from svchost.exe or other system files.. Matching these running Task states may shed some light when matched with the occurrence of the connections themselves.The connections that survive the shutdown of uTorrent, can be residual connections from running operations which were not 'Stopped' before shutdown. In PeerBlock and Peer Guardian I also, many times see connections in both directions and have with various builds seen that uTorrent can even stay in the Task Manager, even making sure that the program is closed, not hidden or minimized to the TaskTray.. So this could also be expected operation as well, and may not always be an apparent issue..(being that this may just be part of the nature of the protocol itself) Link to comment Share on other sites More sharing options...
SIRavecavec Posted January 6, 2010 Share Posted January 6, 2010 Watch out MIRC, it would be great to run a simple mIRC version or use irssi to be more secure. I know mIRC bots can infect you being infected you will infect others. Mostly they are situated in ini files. Also it can make you to spam. Link to comment Share on other sites More sharing options...
HX1 Posted January 6, 2010 Share Posted January 6, 2010 Then maybe we will have to adapt the song 'Jizz in my Pants' that Lite posted in the Tavern to 'Spam in my Pantz'.. Link to comment Share on other sites More sharing options...
mara- Posted January 6, 2010 Author Share Posted January 6, 2010 Well, it seems that cFosSpeed can not identify this. I just checked with Prio in Task Manager, which DKT recommended, and only svchost creates UDP connections. In Wireshark I see same connections, and most of it go to port called esmmanager. Anyone know what this is?Cheers ;) Link to comment Share on other sites More sharing options...
Bizarre™ Posted January 6, 2010 Share Posted January 6, 2010 @mara-:The results from Google say it's from Symantec: Link Link to comment Share on other sites More sharing options...
mara- Posted January 6, 2010 Author Share Posted January 6, 2010 OK, then these connections are from Norton Antivirus 2010. It should be fine then. Thanks for the info. And thanks to everybody for help. I'll continue to monitor this for few day to make sure there is no any problems.Cheers ;) Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted January 6, 2010 Administrator Share Posted January 6, 2010 If esmmanager is that connection. Then why it's connecting two different IPs to two different places? :think:I would say it time to do what shought suggested. Link to comment Share on other sites More sharing options...
shought Posted January 6, 2010 Share Posted January 6, 2010 Call the ISP and verbally abuse them? :P Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted January 6, 2010 Administrator Share Posted January 6, 2010 Yea verbally, we don't wanna break any laws. :P And as far as I know, you can do anything with mouth till it's just verbally. :lol: Link to comment Share on other sites More sharing options...
mara- Posted January 6, 2010 Author Share Posted January 6, 2010 Well, I don't know if that's necessary. They said they will monitor me. It's the second day now, and the didn't contacted me or disconnected me, so I suppose that it's OK now.@DKTWell, I suspect on feature of Norton, it's called Insight Protection and it's connected with Norton Community Watch, so maybe this Community is located in more places in the world. Check the screen Shot:Cheers ;) Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted January 6, 2010 Administrator Share Posted January 6, 2010 I think they will monitor you for a week.It's best to ask them. It's really needed if we wanna come to a conclusion. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.