Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Malware Help Needed- Pop-ups, redirects, etc.


  • Please log in to reply

#31
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,017 posts
  • MVP

Try the free ESET online scan:

 

se IE and go to http://eset.com/onlinescan and click on ESET online Scanner.  Accept the terms then press Start (If you get a warning from your browser tell it you want to run it).  
 
# Check Scan Archives
# Push the Start button.
# ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
# When the scan completes, push LIST OF THREATS FOUND
# Push EXPORT TO TEXT FILE , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
# Push the BACK button.
# Push Finish
# Once the scan is completed, you may close the window.
# Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
# Copy and paste that log as a reply.
 
You might get some relief from adblock plus.  I use it on all my browsers.  Just go to adblockplus.org with each browser and you will be offered  an add-on that blocks most ads.  For IE they have to use a program that you download and install but for Firefox and Chrome it's just an extension.
 
Tonight let Avast run a boot-time scan:
 
 
Open Avast, Scan, Scan for Viruses, Change the Quick Scan (in the box in the center of the page) to Boot-time Scan.  Then at the bottom of the page click on Scan Settings.
 
Make sure both boxes are checked and click on the gray box to the right of the orange ones.  It should turn orange.  Change where it says "Fix Automatically" to "Move to
Chest."  OK.  Now click on Start and then close Avast.  Mute your speakers so it doesn't wake you up when Windows boots.
 
When you reboot you will see the scan start.  It will tell you where it saves its log.  Usually it's C:\ProgramData\AVAST Software\Avast\report\aswBoot.txt but it might change so verify the location.   This is a hidden location so you will need to tell Windows to let you see it:
 
 
Copy and paste the text from the log to a Reply when done.
 

  • 0

Advertisements


#32
andrea22

andrea22

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 139 posts

did the eset scan, it found nothing. Can't find it in the program files to get a log though.


  • 0

#33
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,017 posts
  • MVP

OK.  It's always good when we don't find anything.


  • 0

#34
andrea22

andrea22

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 139 posts

After installing abp to both IE and firefox, I've reinstalled firefox, and it was fine for a few hours until I started a lengthy ebay search, then I got that 'message from microsoft' again with the voiceover and black boxes, which renders everything useless on firefox, where I can't click on anything at all, all I can do is shut down. Only one popup on firefox prior to this.

 

Will now do the avast boot time scan.


  • 0

#35
andrea22

andrea22

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 139 posts

05/24/2016 00:31
Scan of C:

Scan of *STARTUP

File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_875fdb4529604f8428ed2441b2e79b17e3cfc26e_cab_15538c76\CbsPersist_20160319102059.cab|>CbsPersist_20160319102059.log Error 42127 {CAB archive is corrupted.}
Number of searched folders: 36136
Number of tested files: 1352176
Number of infected files: 0

----------------------------------------
05/31/2016 21:12
Scan of C:

Scan of *STARTUP

File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_875fdb4529604f8428ed2441b2e79b17e3cfc26e_cab_15538c76\CbsPersist_20160319102059.cab|>CbsPersist_20160319102059.log Error 42127 {CAB archive is corrupted.}
Number of searched folders: 36589
Number of tested files: 1345767
Number of infected files: 0

----------------------------------------
08/10/2016 13:36
Scan of C:

Scan of *STARTUP

Number of searched folders: 34054
Number of tested files: 1274462
Number of infected files: 0

----------------------------------------
08/13/2016 00:02
Scan of C:

Scan of *STARTUP

Number of searched folders: 34193
Number of tested files: 2266681
Number of infected files: 0


  • 0

#36
andrea22

andrea22

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 139 posts

I just opened gumtree (similar to craigslist) on IE and it's a pop-up/redirect nightmare. Every time I click the cursor into the search box another tab opens so I can't use the site at all. I now know just how many Asian women are waiting to meet me LOL....


  • 0

#37
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,017 posts
  • MVP

Next time it happens try CTRL + Alt + Del and Start Task Manager.  See if it gives you any hints as to what is going on.

 

Have you tried it with firefox in its safe mode?   IE has a similar mode:

 

Copy the next line:

 

"C:\Program Files\Internet Explorer\iexplore.exe" -extoff 
Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator.  Right click and Paste (or Edit then Paste) and the copied lines should appear.  Hit Enter.  IE should open with add-ons disabled.
 
 
Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator.
 
then type with an Enter after the line:
 
nslookup www.ebay.co.uk
 
This is what I get:
 

C:\Windows\system32>nslookup www.ebay.co.uk
Server:  cdns01.comcast.net
Address:  75.75.75.75
 
Non-authoritative answer:
Name:    e11847.g.akamaiedge.net
Address:  23.4.133.153
Aliases:  www.ebay.co.uk
          slot11847.ebay.com.edgekey.net

 

 

 
Do you get the same address?
 
 
 

  • 0

#38
andrea22

andrea22

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 139 posts

Okay I opened firefox and it was right back where it was yesterday (unuseable) so I have task manager open- what should I be looking for here? I haven't tried firefox or IE in safe mode yet.


  • 0

#39
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,017 posts
  • MVP

Under Applications do you see anythiing you don't recognize?  Under Processes should be one Firefox.exe*32  which uses 0-2% CPU and about 250K of memory.

 

If you open an elevated command window

 

Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator

 

and type (with an Enter after each line)

netstat -an > \junk.txt
notepad \junk.txt

That will show me what IP addresses it is talking to when this happens.


  • 0

#40
andrea22

andrea22

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 139 posts

Applications looks fine. processes shows one firefox, 4 to 6%, rest okay. Nothing else looks outstandingly weird to my eye. Back shortly with the other.


  • 0

Advertisements


#41
andrea22

andrea22

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 139 posts

Active Connections

  Proto  Local Address          Foreign Address        State
  TCP    0.0.0.0:135            0.0.0.0:0              LISTENING
  TCP    0.0.0.0:445            0.0.0.0:0              LISTENING
  TCP    0.0.0.0:554            0.0.0.0:0              LISTENING
  TCP    0.0.0.0:2869           0.0.0.0:0              LISTENING
  TCP    0.0.0.0:5357           0.0.0.0:0              LISTENING
  TCP    0.0.0.0:10243          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:12025          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:12110          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:12119          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:12143          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:12465          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:12563          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:12993          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:12995          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:17500          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:27275          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:49152          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:49153          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:49154          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:49155          0.0.0.0:0              LISTENING
  TCP    0.0.0.0:49171          0.0.0.0:0              LISTENING
  TCP    127.0.0.1:843          0.0.0.0:0              LISTENING
  TCP    127.0.0.1:5354         0.0.0.0:0              LISTENING
  TCP    127.0.0.1:5354         127.0.0.1:49157        ESTABLISHED
  TCP    127.0.0.1:5354         127.0.0.1:49158        ESTABLISHED
  TCP    127.0.0.1:12025        0.0.0.0:0              LISTENING
  TCP    127.0.0.1:12110        0.0.0.0:0              LISTENING
  TCP    127.0.0.1:12119        0.0.0.0:0              LISTENING
  TCP    127.0.0.1:12143        0.0.0.0:0              LISTENING
  TCP    127.0.0.1:12465        0.0.0.0:0              LISTENING
  TCP    127.0.0.1:12563        0.0.0.0:0              LISTENING
  TCP    127.0.0.1:12993        0.0.0.0:0              LISTENING
  TCP    127.0.0.1:12995        0.0.0.0:0              LISTENING
  TCP    127.0.0.1:17600        0.0.0.0:0              LISTENING
  TCP    127.0.0.1:27015        0.0.0.0:0              LISTENING
  TCP    127.0.0.1:27015        127.0.0.1:49191        ESTABLISHED
  TCP    127.0.0.1:27275        0.0.0.0:0              LISTENING
  TCP    127.0.0.1:49157        127.0.0.1:5354         ESTABLISHED
  TCP    127.0.0.1:49158        127.0.0.1:5354         ESTABLISHED
  TCP    127.0.0.1:49191        127.0.0.1:27015        ESTABLISHED
  TCP    127.0.0.1:49215        127.0.0.1:49216        ESTABLISHED
  TCP    127.0.0.1:49216        127.0.0.1:49215        ESTABLISHED
  TCP    127.0.0.1:49268        127.0.0.1:49269        ESTABLISHED
  TCP    127.0.0.1:49269        127.0.0.1:49268        ESTABLISHED
  TCP    127.0.0.1:51025        127.0.0.1:51026        ESTABLISHED
  TCP    127.0.0.1:51026        127.0.0.1:51025        ESTABLISHED
  TCP    127.0.0.1:51027        0.0.0.0:0              LISTENING
  TCP    127.0.0.1:51028        127.0.0.1:51029        ESTABLISHED
  TCP    127.0.0.1:51029        127.0.0.1:51028        ESTABLISHED
  TCP    127.0.0.1:51030        0.0.0.0:0              LISTENING
  TCP    127.0.0.1:51237        127.0.0.1:51238        ESTABLISHED
  TCP    127.0.0.1:51238        127.0.0.1:51237        ESTABLISHED
  TCP    192.168.8.100:139      0.0.0.0:0              LISTENING
  TCP    192.168.8.100:49170    168.1.69.114:53        CLOSE_WAIT
  TCP    192.168.8.100:49181    77.234.41.24:80        ESTABLISHED
  TCP    192.168.8.100:49198    108.160.172.236:443    CLOSE_WAIT
  TCP    192.168.8.100:49220    108.160.172.237:443    CLOSE_WAIT
  TCP    192.168.8.100:49788    23.253.10.48:443       CLOSE_WAIT
  TCP    192.168.8.100:49901    54.65.16.89:80         CLOSE_WAIT
  TCP    192.168.8.100:49904    52.192.131.248:443     CLOSE_WAIT
  TCP    192.168.8.100:49914    52.192.131.248:80      CLOSE_WAIT
  TCP    192.168.8.100:49915    50.19.113.85:80        CLOSE_WAIT
  TCP    192.168.8.100:49928    74.120.16.187:443      CLOSE_WAIT
  TCP    192.168.8.100:50041    93.184.215.200:443     CLOSE_WAIT
  TCP    192.168.8.100:50042    93.184.215.200:443     CLOSE_WAIT
  TCP    192.168.8.100:50084    64.4.45.13:443         ESTABLISHED
  TCP    192.168.8.100:50090    23.99.210.103:443      ESTABLISHED
  TCP    192.168.8.100:50323    77.234.42.30:53        CLOSE_WAIT
  TCP    192.168.8.100:50337    77.234.41.106:53       CLOSE_WAIT
  TCP    192.168.8.100:50514    77.234.42.114:53       CLOSE_WAIT
  TCP    192.168.8.100:50971    5.45.62.74:53          ESTABLISHED
  TCP    192.168.8.100:51080    162.125.18.133:443     ESTABLISHED
  TCP    192.168.8.100:51218    104.74.52.7:443        CLOSE_WAIT
  TCP    192.168.8.100:51219    104.74.52.7:443        CLOSE_WAIT
  TCP    192.168.8.100:51347    64.4.45.213:443        ESTABLISHED
  TCP    192.168.8.100:51349    23.99.208.121:443      ESTABLISHED
  TCP    192.168.8.100:51451    179.60.193.36:443      CLOSE_WAIT
  TCP    192.168.8.100:51452    179.60.193.36:443      CLOSE_WAIT
  TCP    192.168.8.100:51469    74.120.16.240:80       CLOSE_WAIT
  TCP    192.168.8.100:51877    108.160.172.193:443    CLOSE_WAIT
  TCP    192.168.8.100:51965    216.3.124.4:80         CLOSE_WAIT
  TCP    192.168.8.100:52059    31.13.95.46:443        ESTABLISHED
  TCP    192.168.8.100:52149    104.244.42.3:443       CLOSE_WAIT
  TCP    192.168.8.100:52162    104.244.42.133:443     CLOSE_WAIT
  TCP    192.168.8.100:52172    52.203.78.26:443       CLOSE_WAIT
  TCP    192.168.8.100:52360    23.1.240.123:80        CLOSE_WAIT
  TCP    192.168.8.100:52361    23.1.240.123:80        CLOSE_WAIT
  TCP    192.168.8.100:52391    23.215.234.170:443     CLOSE_WAIT
  TCP    192.168.8.100:52637    104.98.37.42:443       CLOSE_WAIT
  TCP    192.168.8.100:52681    104.98.37.42:443       CLOSE_WAIT
  TCP    192.168.8.100:52682    104.98.37.42:443       CLOSE_WAIT
  TCP    192.168.8.100:52689    23.215.234.170:443     CLOSE_WAIT
  TCP    192.168.8.100:52690    23.215.234.170:443     CLOSE_WAIT
  TCP    192.168.8.100:52694    23.215.234.170:443     CLOSE_WAIT
  TCP    192.168.8.100:52695    23.215.234.170:443     CLOSE_WAIT
  TCP    192.168.8.100:52696    23.215.234.170:443     CLOSE_WAIT
  TCP    192.168.8.100:52697    23.215.234.170:443     CLOSE_WAIT
  TCP    192.168.8.100:52699    66.211.181.192:443     CLOSE_WAIT
  TCP    192.168.8.100:52719    101.119.5.108:443      CLOSE_WAIT
  TCP    192.168.8.100:52756    66.135.209.27:80       ESTABLISHED
  TCP    192.168.8.100:52796    54.225.143.226:80      CLOSE_WAIT
  TCP    192.168.8.100:52797    104.72.70.25:80        TIME_WAIT
  TCP    192.168.8.100:52803    132.245.165.130:443    ESTABLISHED
  TCP    192.168.8.100:52804    179.60.193.3:443       ESTABLISHED
  TCP    192.168.8.100:52810    132.245.163.178:443    ESTABLISHED
  TCP    192.168.8.100:52819    54.235.209.127:80      CLOSE_WAIT
  TCP    192.168.8.100:52820    54.235.209.127:80      CLOSE_WAIT
  TCP    192.168.8.100:52821    132.245.165.130:443    ESTABLISHED
  TCP    192.168.8.100:52825    23.1.240.130:80        CLOSE_WAIT
  TCP    192.168.8.100:52853    66.135.212.240:80      TIME_WAIT
  TCP    192.168.8.100:52854    66.135.212.240:80      TIME_WAIT
  TCP    192.168.8.100:52857    104.114.168.137:80     TIME_WAIT
  TCP    192.168.8.100:52862    23.1.240.138:80        ESTABLISHED
  TCP    192.168.8.100:52868    66.135.216.134:80      TIME_WAIT
  TCP    192.168.8.100:52869    66.135.216.134:80      TIME_WAIT
  TCP    192.168.8.100:52870    104.71.28.148:80       TIME_WAIT
  TCP    192.168.8.100:52875    104.114.168.137:80     TIME_WAIT
  TCP    192.168.8.100:52877    66.211.180.37:80       TIME_WAIT
  TCP    192.168.8.100:52878    66.211.180.37:80       TIME_WAIT
  TCP    192.168.8.100:52879    104.114.164.23:80      TIME_WAIT
  TCP    192.168.8.100:52882    66.135.209.27:80       ESTABLISHED
  TCP    192.168.8.100:52888    66.135.212.240:443     TIME_WAIT
  TCP    192.168.8.100:52894    54.243.96.55:80        CLOSE_WAIT
  TCP    192.168.8.100:52895    54.243.96.55:80        CLOSE_WAIT
  TCP    192.168.8.100:52896    23.1.240.120:80        TIME_WAIT
  TCP    192.168.8.100:52898    104.28.29.94:80        CLOSE_WAIT
  TCP    192.168.8.100:52899    104.28.29.94:80        CLOSE_WAIT
  TCP    192.168.8.100:52900    104.28.29.94:80        CLOSE_WAIT
  TCP    192.168.8.100:52901    104.28.29.94:80        CLOSE_WAIT
  TCP    192.168.8.100:52902    104.28.29.94:80        CLOSE_WAIT
  TCP    192.168.8.100:52903    104.28.29.94:80        CLOSE_WAIT
  TCP    192.168.8.100:52904    101.119.5.108:443      ESTABLISHED
  TCP    192.168.8.100:52905    101.119.5.108:443      ESTABLISHED
  TCP    192.168.8.100:52906    64.233.189.95:80       TIME_WAIT
  TCP    192.168.8.100:52910    173.194.65.154:443     TIME_WAIT
  TCP    192.168.8.100:52912    101.119.5.91:443       TIME_WAIT
  TCP    192.168.8.100:52914    179.60.193.36:443      CLOSE_WAIT
  TCP    192.168.8.100:52916    101.119.5.94:443       TIME_WAIT
  TCP    192.168.8.100:52917    101.119.5.94:443       TIME_WAIT
  TCP    192.168.8.100:52920    172.217.25.173:443     TIME_WAIT
  TCP    192.168.8.100:52921    173.194.65.94:443      TIME_WAIT
  TCP    192.168.8.100:52924    54.230.134.55:443      ESTABLISHED
  TCP    192.168.8.100:52925    204.79.197.200:443     ESTABLISHED
  TCP    192.168.8.100:52926    204.79.197.200:443     ESTABLISHED
  TCP    192.168.8.100:52927    173.194.210.136:443    ESTABLISHED
  TCP    192.168.8.102:139      0.0.0.0:0              LISTENING
  TCP    [::]:135               [::]:0                 LISTENING
  TCP    [::]:445               [::]:0                 LISTENING
  TCP    [::]:554               [::]:0                 LISTENING
  TCP    [::]:2869              [::]:0                 LISTENING
  TCP    [::]:5357              [::]:0                 LISTENING
  TCP    [::]:10243             [::]:0                 LISTENING
  TCP    [::]:17500             [::]:0                 LISTENING
  TCP    [::]:49152             [::]:0                 LISTENING
  TCP    [::]:49153             [::]:0                 LISTENING
  TCP    [::]:49154             [::]:0                 LISTENING
  TCP    [::]:49155             [::]:0                 LISTENING
  TCP    [::]:49171             [::]:0                 LISTENING
  TCP    [::1]:12025            [::]:0                 LISTENING
  TCP    [::1]:12110            [::]:0                 LISTENING
  TCP    [::1]:12119            [::]:0                 LISTENING
  TCP    [::1]:12143            [::]:0                 LISTENING
  TCP    [::1]:12465            [::]:0                 LISTENING
  TCP    [::1]:12563            [::]:0                 LISTENING
  TCP    [::1]:12993            [::]:0                 LISTENING
  TCP    [::1]:12995            [::]:0                 LISTENING
  TCP    [::1]:27275            [::]:0                 LISTENING
  UDP    0.0.0.0:1434           *:*                   
  UDP    0.0.0.0:3702           *:*                   
  UDP    0.0.0.0:3702           *:*                   
  UDP    0.0.0.0:5004           *:*                   
  UDP    0.0.0.0:5005           *:*                   
  UDP    0.0.0.0:5355           *:*                   
  UDP    0.0.0.0:17500          *:*                   
  UDP    0.0.0.0:50062          *:*                   
  UDP    0.0.0.0:50483          *:*                   
  UDP    0.0.0.0:50546          *:*                   
  UDP    0.0.0.0:52836          *:*                   
  UDP    0.0.0.0:61891          *:*                   
  UDP    0.0.0.0:65437          *:*                   
  UDP    127.0.0.1:1900         *:*                   
  UDP    127.0.0.1:61887        *:*                   
  UDP    127.0.0.1:61889        *:*                   
  UDP    127.0.0.1:64432        *:*                   
  UDP    127.0.0.1:64433        *:*                   
  UDP    127.0.0.1:64435        *:*                   
  UDP    127.0.0.1:65435        *:*                   
  UDP    127.0.0.1:65436        *:*                   
  UDP    192.168.8.100:137      *:*                   
  UDP    192.168.8.100:138      *:*                   
  UDP    192.168.8.100:1900     *:*                   
  UDP    192.168.8.100:5353     *:*                   
  UDP    192.168.8.102:137      *:*                   
  UDP    192.168.8.102:138      *:*                   
  UDP    192.168.8.102:1900     *:*                   
  UDP    192.168.8.102:5353     *:*                   
  UDP    [::]:1434              *:*                   
  UDP    [::]:3702              *:*                   
  UDP    [::]:3702              *:*                   
  UDP    [::]:5004              *:*                   
  UDP    [::]:5005              *:*                   
  UDP    [::]:5355              *:*                   
  UDP    [::]:50484             *:*                   
  UDP    [::]:65438             *:*                   
  UDP    [::1]:1900             *:*                   
  UDP    [::1]:5353             *:*                   
  UDP    [::1]:64434            *:*                   
  UDP    [fe80::29db:9f0:6b8e:d0b4%12]:546  *:*                   
  UDP    [fe80::29db:9f0:6b8e:d0b4%12]:1900  *:*                   
  UDP    [fe80::68a4:5a69:f075:98e0%10]:1900  *:*                   


  • 0

#42
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,017 posts
  • MVP

Do the nslookup command and tell me what IP address you get for www.ebay.uk  


  • 0

#43
andrea22

andrea22

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 139 posts

ok done, the server is different. its resolver1.opendns.com with address of 208.67.222.222

 

the second address number is also different- I got 104.114.217.92

 

I couldn't seem to paste this in sorry.


  • 0

#44
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,017 posts
  • MVP

208.67.222.222 is OpenDNS so probably OK tho as a test try changing it to 8.8.8.8

 

104.114.217.92 is www.ebay.com.au not www.ebay.uk  What did you type in?  I don't see that in your netstat list either.

 

(To copy the text from a Command window, right click and select Mark then highlight the text and hit Enter.  Move to a Reply and Paste or Ctrl + v )

 

There is a program called tcpview.  http://live.sysinter...com/Tcpview.exe Download, Save and then run it by right clicking and Run As Admin.
 
Then File, Save As (to your desktop), tcp , OK.  This should createa  file tcp.txt on your desktop.  Attach or copy and paste it to a reply.

  • 0

#45
andrea22

andrea22

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 139 posts

Those first couple of things- I don't know how to do them I'm afraid.

 

here is the tcp log.

 

[System Process] 0 TCP Celia-PC 27275 localhost 49321 TIME_WAIT          
[System Process] 0 TCP Celia-PC 27275 localhost 49322 TIME_WAIT          
[System Process] 0 TCP Celia-PC 27275 localhost 49320 TIME_WAIT          
[System Process] 0 TCP celia-pc.homerouter.cpe 49271 151.101.40.134 http TIME_WAIT          
[System Process] 0 TCP celia-pc.homerouter.cpe 49274 101.119.5.94 https TIME_WAIT          
[System Process] 0 TCP celia-pc.homerouter.cpe 49294 101.119.5.83 https TIME_WAIT          
[System Process] 0 TCP celia-pc.homerouter.cpe 49295 101.119.5.83 https TIME_WAIT          
[System Process] 0 TCP celia-pc.homerouter.cpe 49308 172.217.25.174 https TIME_WAIT          
[System Process] 0 TCP celia-pc.homerouter.cpe 49315 101.119.5.102 https TIME_WAIT          
[System Process] 0 TCP celia-pc.homerouter.cpe 49316 101.119.5.102 https TIME_WAIT          
[System Process] 0 TCP Celia-PC 49320 localhost 27275 TIME_WAIT          
[System Process] 0 TCP Celia-PC 49321 localhost 27275 TIME_WAIT          
[System Process] 0 TCP Celia-PC 49322 localhost 27275 TIME_WAIT          
[System Process] 0 TCP celia-pc.homerouter.cpe 49327 77.234.42.56 http TIME_WAIT          
AppleMobileDeviceService.exe 1332 TCP Celia-PC 27015 localhost 49167 ESTABLISHED          
AppleMobileDeviceService.exe 1332 TCP Celia-PC 27015 Celia-PC 0 LISTENING          
AppleMobileDeviceService.exe 1332 TCP Celia-PC 49164 localhost 5354 ESTABLISHED          
AppleMobileDeviceService.exe 1332 TCP Celia-PC 49165 localhost 5354 ESTABLISHED          
AppleMobileDeviceService.exe 1332 UDP Celia-PC 58370 * *           
AppleMobileDeviceService.exe 1332 UDP Celia-PC 58371 * *           
AvastSvc.exe 1456 TCP Celia-PC 12025 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12110 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12119 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12143 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12465 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12563 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12993 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12995 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 27275 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 49158 localhost 49159 ESTABLISHED          
AvastSvc.exe 1456 TCP Celia-PC 49159 localhost 49158 ESTABLISHED          
AvastSvc.exe 1456 TCP Celia-PC 49160 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 49161 localhost 49162 ESTABLISHED          
AvastSvc.exe 1456 TCP Celia-PC 49162 localhost 49161 ESTABLISHED          
AvastSvc.exe 1456 TCP Celia-PC 49163 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP celia-pc.homerouter.cpe 49168 sea24.ff.avast.com http ESTABLISHED          
AvastSvc.exe 1456 TCP Celia-PC 12025 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12110 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12119 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12143 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12465 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12563 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12993 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 12995 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 TCP Celia-PC 27275 Celia-PC 0 LISTENING          
AvastSvc.exe 1456 UDP Celia-PC 64854 * *           
AvastSvc.exe 1456 UDP Celia-PC 64855 * *           
AvastSvc.exe 1456 UDP Celia-PC 64857 * *           
AvastSvc.exe 1456 UDP Celia-PC 64859 * *           
AvastSvc.exe 1456 UDP Celia-PC 64860 * *           
AvastSvc.exe 1456 TCPV6 [0:0:0:0:0:0:0:1] 12025 [0:0:0:0:0:0:0:0] 0 LISTENING          
AvastSvc.exe 1456 TCPV6 [0:0:0:0:0:0:0:1] 12110 [0:0:0:0:0:0:0:0] 0 LISTENING          
AvastSvc.exe 1456 TCPV6 [0:0:0:0:0:0:0:1] 12119 [0:0:0:0:0:0:0:0] 0 LISTENING          
AvastSvc.exe 1456 TCPV6 [0:0:0:0:0:0:0:1] 12143 [0:0:0:0:0:0:0:0] 0 LISTENING          
AvastSvc.exe 1456 TCPV6 [0:0:0:0:0:0:0:1] 12465 [0:0:0:0:0:0:0:0] 0 LISTENING          
AvastSvc.exe 1456 TCPV6 [0:0:0:0:0:0:0:1] 12563 [0:0:0:0:0:0:0:0] 0 LISTENING          
AvastSvc.exe 1456 TCPV6 [0:0:0:0:0:0:0:1] 12993 [0:0:0:0:0:0:0:0] 0 LISTENING          
AvastSvc.exe 1456 TCPV6 [0:0:0:0:0:0:0:1] 12995 [0:0:0:0:0:0:0:0] 0 LISTENING          
AvastSvc.exe 1456 TCPV6 [0:0:0:0:0:0:0:1] 27275 [0:0:0:0:0:0:0:0] 0 LISTENING          
Dropbox.exe 3640 TCP Celia-PC 843 Celia-PC 0 LISTENING          
Dropbox.exe 3640 TCP Celia-PC 17500 Celia-PC 0 LISTENING 3 399 6 798      
Dropbox.exe 3640 TCP Celia-PC 17600 Celia-PC 0 LISTENING          
Dropbox.exe 3640 TCP celia-pc.homerouter.cpe 49191 client.v.dropbox.com https CLOSE_WAIT          
Dropbox.exe 3640 TCP Celia-PC 49202 localhost 49203 ESTABLISHED          
Dropbox.exe 3640 TCP Celia-PC 49203 localhost 49202 ESTABLISHED          
Dropbox.exe 3640 TCP celia-pc.homerouter.cpe 49206 d.v.dropbox.com https CLOSE_WAIT          
Dropbox.exe 3640 TCP Celia-PC 49207 localhost 49208 ESTABLISHED          
Dropbox.exe 3640 TCP Celia-PC 49208 localhost 49207 ESTABLISHED          
Dropbox.exe 3640 TCP celia-pc.homerouter.cpe 49211 162.125.34.129 https ESTABLISHED          
Dropbox.exe 3640 TCP celia-pc.homerouter.cpe 49212 ec2-52-87-78-178.compute-1.amazonaws.com https CLOSE_WAIT          
Dropbox.exe 3640 TCP celia-pc.homerouter.cpe 49213 api.v.dropbox.com https CLOSE_WAIT          
Dropbox.exe 3640 TCP celia-pc.homerouter.cpe 49214 199.47.217.65 https ESTABLISHED 756 519,250   20,770  31   
Dropbox.exe 3640 TCP celia-pc.homerouter.cpe 49218 199.47.217.65 https ESTABLISHED 813 520,332   19,775  32   
Dropbox.exe 3640 TCP celia-pc.homerouter.cpe 49223 108.160.172.65 https ESTABLISHED 750 519,250   20,770  35   
Dropbox.exe 3640 TCP celia-pc.homerouter.cpe 49226 199.47.217.2 https ESTABLISHED 795 519,704   20,770  33   
Dropbox.exe 3640 TCP celia-pc.homerouter.cpe 49330 54.230.134.55 https ESTABLISHED          
Dropbox.exe 3640 TCP celia-pc.homerouter.cpe 49331 54.230.134.55 https ESTABLISHED          
Dropbox.exe 3640 TCP celia-pc.homerouter.cpe 49332 199.47.217.97 https ESTABLISHED          
Dropbox.exe 3640 TCP celia-pc.homerouter.cpe 49333 199.47.217.97 https ESTABLISHED          
Dropbox.exe 3640 UDP Celia-PC 17500 * *           
Dropbox.exe 3640 TCPV6 [0:0:0:0:0:0:0:0] 17500 [0:0:0:0:0:0:0:0] 0 LISTENING          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49259 104.28.28.94 http CLOSE_WAIT          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49262 192.0.76.3 http CLOSE_WAIT          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49265 192.0.76.3 http CLOSE_WAIT          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49283 192.0.76.3 http CLOSE_WAIT          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49284 192.0.76.3 http CLOSE_WAIT          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49285 104.28.28.94 http CLOSE_WAIT          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49286 104.28.28.94 http CLOSE_WAIT          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49287 192.0.76.3 http CLOSE_WAIT          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49288 192.0.76.3 http CLOSE_WAIT          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49291 104.28.28.94 http CLOSE_WAIT          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49292 104.28.28.94 http CLOSE_WAIT          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49303 173.194.72.157 https ESTABLISHED          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49309 104.28.28.94 http CLOSE_WAIT          
iexplore.exe 5088 TCP celia-pc.homerouter.cpe 49310 173.194.72.157 https ESTABLISHED          
iTunesHelper.exe 2908 TCP Celia-PC 49167 localhost 27015 ESTABLISHED          
iTunesHelper.exe 2908 UDP Celia-PC 54374 * *           
iTunesHelper.exe 2908 UDP Celia-PC 54375 * *           
lsass.exe 752 TCP Celia-PC 49154 Celia-PC 0 LISTENING          
lsass.exe 752 TCPV6 [0:0:0:0:0:0:0:0] 49154 [0:0:0:0:0:0:0:0] 0 LISTENING          
mDNSResponder.exe 1716 TCP Celia-PC 5354 localhost 49164 ESTABLISHED          
mDNSResponder.exe 1716 TCP Celia-PC 5354 localhost 49165 ESTABLISHED          
mDNSResponder.exe 1716 TCP Celia-PC 5354 Celia-PC 0 LISTENING          
mDNSResponder.exe 1716 UDP celia-pc.homerouter.cpe 5353 * *           
mDNSResponder.exe 1716 UDP celia-pc.homerouter.cpe 5353 * *           
mDNSResponder.exe 1716 UDP Celia-PC 58372 * *           
mDNSResponder.exe 1716 UDPV6 [0:0:0:0:0:0:0:1] 5353 * *           
mDNSResponder.exe 1716 UDPV6 [0:0:0:0:0:0:0:0] 58373 * *           
services.exe 700 TCP Celia-PC 49182 Celia-PC 0 LISTENING          
services.exe 700 TCPV6 [0:0:0:0:0:0:0:0] 49182 [0:0:0:0:0:0:0:0] 0 LISTENING          
sqlbrowser.exe 2068 UDP Celia-PC ms-sql-m * *           
sqlbrowser.exe 2068 UDPV6 [0:0:0:0:0:0:0:0] 1434 * *           
svchost.exe 976 TCP Celia-PC epmap Celia-PC 0 LISTENING          
svchost.exe 1068 TCP Celia-PC 49153 Celia-PC 0 LISTENING          
svchost.exe 1172 TCP Celia-PC 49155 Celia-PC 0 LISTENING          
svchost.exe 1812 UDP Celia-PC ssdp * *           
svchost.exe 1812 UDP celia-pc.homerouter.cpe ssdp * *           
svchost.exe 1812 UDP celia-pc.homerouter.cpe ssdp * *           
svchost.exe 1812 UDP Celia-PC ws-discovery * *           
svchost.exe 1812 UDP Celia-PC ws-discovery * *           
svchost.exe 1344 UDP Celia-PC llmnr * *           
svchost.exe 1812 UDP Celia-PC 59157 * *           
svchost.exe 1812 UDP Celia-PC 59931 * *           
svchost.exe 976 TCPV6 [0:0:0:0:0:0:0:0] epmap [0:0:0:0:0:0:0:0] 0 LISTENING          
svchost.exe 1068 TCPV6 [0:0:0:0:0:0:0:0] 49153 [0:0:0:0:0:0:0:0] 0 LISTENING          
svchost.exe 1172 TCPV6 [0:0:0:0:0:0:0:0] 49155 [0:0:0:0:0:0:0:0] 0 LISTENING          
svchost.exe 1068 UDPV6 [fe80:0:0:0:29db:9f0:6b8e:d0b4] 546 * *           
svchost.exe 1068 UDPV6 [fe80:0:0:0:68a4:5a69:f075:98e0] 546 * *           
svchost.exe 1812 UDPV6 [0:0:0:0:0:0:0:1] 1900 * *           
svchost.exe 1812 UDPV6 [fe80:0:0:0:29db:9f0:6b8e:d0b4] 1900 * *           
svchost.exe 1812 UDPV6 [fe80:0:0:0:68a4:5a69:f075:98e0] 1900 * *           
svchost.exe 1812 UDPV6 [0:0:0:0:0:0:0:0] 3702 * *           
svchost.exe 1812 UDPV6 [0:0:0:0:0:0:0:0] 3702 * *           
svchost.exe 1344 UDPV6 [0:0:0:0:0:0:0:0] 5355 * *           
svchost.exe 1812 UDPV6 [0:0:0:0:0:0:0:0] 59158 * *           
svchost.exe 1812 UDPV6 [0:0:0:0:0:0:0:1] 59930 * *           
svchost.exe 1344 UDP Celia-PC 58431 * *  5 225 1 114      
svchost.exe 1344 UDP Celia-PC 59472 * *           
System 4 TCP celia-pc.homerouter.cpe netbios-ssn Celia-PC 0 LISTENING          
System 4 TCP celia-pc.homerouter.cpe netbios-ssn Celia-PC 0 LISTENING          
System 4 TCP Celia-PC microsoft-ds Celia-PC 0 LISTENING          
System 4 TCP Celia-PC icslap Celia-PC 0 LISTENING          
System 4 TCP Celia-PC wsd Celia-PC 0 LISTENING          
System 4 TCP Celia-PC 10243 Celia-PC 0 LISTENING          
System 4 UDP celia-pc.homerouter.cpe netbios-ns * *           
System 4 UDP celia-pc.homerouter.cpe netbios-ns * *           
System 4 UDP celia-pc.homerouter.cpe netbios-dgm * *           
System 4 UDP celia-pc.homerouter.cpe netbios-dgm * *           
System 4 TCPV6 [0:0:0:0:0:0:0:0] microsoft-ds [0:0:0:0:0:0:0:0] 0 LISTENING          
System 4 TCPV6 [0:0:0:0:0:0:0:0] icslap [0:0:0:0:0:0:0:0] 0 LISTENING          
System 4 TCPV6 [0:0:0:0:0:0:0:0] wsd [0:0:0:0:0:0:0:0] 0 LISTENING          
System 4 TCPV6 [0:0:0:0:0:0:0:0] 10243 [0:0:0:0:0:0:0:0] 0 LISTENING          
wininit.exe 640 TCP Celia-PC 49152 Celia-PC 0 LISTENING          
wininit.exe 640 TCPV6 [0:0:0:0:0:0:0:0] 49152 [0:0:0:0:0:0:0:0] 0 LISTENING          
wmpnetwk.exe 5616 TCP Celia-PC rtsp Celia-PC 0 LISTENING          
wmpnetwk.exe 5616 UDP Celia-PC 5004 * *           
wmpnetwk.exe 5616 UDP Celia-PC 5005 * *           
wmpnetwk.exe 5616 TCPV6 [0:0:0:0:0:0:0:0] rtsp [0:0:0:0:0:0:0:0] 0 LISTENING          
wmpnetwk.exe 5616 UDPV6 [0:0:0:0:0:0:0:0] 5004 * *           
wmpnetwk.exe 5616 UDPV6 [0:0:0:0:0:0:0:0] 5005 * *           
 


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP