[Dshield] PC exhibiting weird behavior

David Taylor ltr at isc.upenn.edu
Sat Dec 3 16:14:08 GMT 2005

Just to clarify.  You are seeing traffic from 'your' port 135 and 445? If
that is the case it is likely someone else is scanning your system and
doesn't necessarily mean your computer is infected.

David Taylor //Sr. Information Security Specialist
University of Pennsylvania Information Security 
Philadelphia PA USA
(215) 898-1236

SANS - The Twenty Most Critical Internet Security Vulnerabilities 

SANS - Internet Storm Center

irc.freenode.net #dshield

-----Original Message-----
From: list-bounces at lists.dshield.org [mailto:list-bounces at lists.dshield.org]
On Behalf Of Walzer, Jeff
Sent: Friday, December 02, 2005 4:19 PM
To: list at lists.dshield.org
Subject: [Dshield] PC exhibiting weird behavior

I have a W2K PC that I see sending occasional traffic to random IP
addresses from ports 135 and 445. I have done a complete virus scan and
it's clean, but I'm unable to figure out why it's trying to send from
ports 135 and 445 to random IP address. Any ideas as to what to do next?
Using .Net? Need to know more about .Net Security?

send all posts to list at lists.dshield.org
To change your subscription options (or unsubscribe), see:

More information about the list mailing list