Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-trojan software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 4th, 2002, 09:40 AM
Lost_Prophet Lost_Prophet is offline
Infrequent Poster
 
Join Date: Apr 2002
Posts: 12
Default Active Ports reports "Unknown"...

I've got "Unknown" processes and would like to know what they could be. *Here is an export of my log...

Unknown * * *0 * * *68.46.226.160 * * *1795 * * *24.153.64.3 * * *110 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *68.46.226.160 * * *1796 * * *24.153.64.3 * * *110 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *1798 * * *127.0.0.1 * * *8080 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *1854 * * *127.0.0.1 * * *8080 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *1921 * * *127.0.0.1 * * *8080 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *1936 * * *127.0.0.1 * * *8080 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *1984 * * *127.0.0.1 * * *8080 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *2002 * * *127.0.0.1 * * *8080 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *1949 * * *127.0.0.1 * * *8080 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *68.46.226.160 * * *2024 * * *24.153.64.3 * * *110 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *68.46.226.160 * * *2022 * * *24.153.64.3 * * *110 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *2032 * * *127.0.0.1 * * *8080 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *2050 * * *127.0.0.1 * * *8080 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *2084 * * *127.0.0.1 * * *8080 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *68.46.226.160 * * *2130 * * *206.171.171.1 * * *80 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *2291 * * *127.0.0.1 * * *8080 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *2713 * * *127.0.0.1 * * *8080 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *2799 * * *127.0.0.1 * * *8080 * * *TIME_WAIT * * *TCP * * *
Unknown * * *0 * * *127.0.0.1 * * *8080 * * *127.0.0.1 * * *3031 * * *TIME_WAIT * * *TCP * * *

Thanks. *I have no idea if there is anything here I should be concerned about...
  #2  
Old April 4th, 2002, 10:44 AM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,627
Default Re: Active Ports reports "Unknown"...

The port 8080 that is listed numerous times is usually opened by a proxy service of some kind. *Are you using a proxy or a program like Proxomitron?

Port 110 is usually your e-mail client such as Outlook or Outlook Express. *Do you have it open?

Poet 80 is usually your browser such as IE or Opera. *Do you have it open?

I am not sure about port 3031. *Maybe someone else can help on this one.

More than likely these are nothing to worry about.

HTH a little bit,
Kent
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #3  
Old April 4th, 2002, 12:17 PM
Lost_Prophet Lost_Prophet is offline
Infrequent Poster
 
Join Date: Apr 2002
Posts: 12
Default Re: Active Ports reports "Unknown"...

I use Web Washer. *That might be using port 8080.
I also use IE and Outlook, so those make sense.

As for the others, I'm clueless. *

Thanks.
  #4  
Old April 4th, 2002, 12:37 PM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,627
Default Re: Active Ports reports "Unknown"...

I checked on port 3031 and a trojan called RAT.MicroSpy uses that port. *I would definitely scan your system with a good trojan scanner. *If you do not have one, I would recommend you to DL the trial v©†E3(Z@¸°en do a complete system scan.

I do not know if you use a FW or not, but I use and recommend KerioPFW. One it is free and then something else it does is map all open/listening ports back to the process that has them open. *I have never had a port being seen as open or closed, just stealth using this product. *It is simple but very effective.

HTH.

Regards,
Kent
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #5  
Old April 4th, 2002, 01:13 PM
Lost_Prophet Lost_Prophet is offline
Infrequent Poster
 
Join Date: Apr 2002
Posts: 12
Default Re: Active Ports reports "Unknown"...

Thanks.

I"m using Zone Alarm Standard for a Firewall and will be switching to ZA Pro v 2.6x either today or tomorrow. *I will be sure to block port 3031
 

Wilders Security Forums > Security Products > other anti-trojan software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:57 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums