[Dshield] PC exhibiting weird behavior

David Taylor ltr at isc.upenn.edu
Sat Dec 3 16:14:08 GMT 2005


Just to clarify.  You are seeing traffic from 'your' port 135 and 445? If
that is the case it is likely someone else is scanning your system and
doesn't necessarily mean your computer is infected.


==================================================
David Taylor //Sr. Information Security Specialist
University of Pennsylvania Information Security 
Philadelphia PA USA
(215) 898-1236
http://www.upenn.edu/computing/security/
================================================== 

SANS - The Twenty Most Critical Internet Security Vulnerabilities 
http://www.sans.org/top20/

SANS - Internet Storm Center
http://isc.sans.org

irc.freenode.net #dshield
http://freenode.net/



-----Original Message-----
From: list-bounces at lists.dshield.org [mailto:list-bounces at lists.dshield.org]
On Behalf Of Walzer, Jeff
Sent: Friday, December 02, 2005 4:19 PM
To: list at lists.dshield.org
Subject: [Dshield] PC exhibiting weird behavior


I have a W2K PC that I see sending occasional traffic to random IP
addresses from ports 135 and 445. I have done a complete virus scan and
it's clean, but I'm unable to figure out why it's trying to send from
ports 135 and 445 to random IP address. Any ideas as to what to do next?
 
Thanks...
_________________________________________
Using .Net? Need to know more about .Net Security?
http://isc.sans.org/banner_count.php?dest=dotnet

_______________________________________________
send all posts to list at lists.dshield.org
To change your subscription options (or unsubscribe), see:
http://www.dshield.org/mailman/listinfo/list




More information about the list mailing list