Finding out strange traffic



I have been investingating strange traffic that tries to connect to remote
port 80 on the Internet. There has been tens of different sites and they seem
to have nothing in common.

Virus DATs are in order, I have scanned the computers with Spybot and
Adaware.
And still it continues. I installed desktop firewalls even to desktops and
blocked port 80 and took a log. I'm pretty sure that no program that was
intentionally installed is causing the traggic.

Log shows that svchost.exe is connecting all around the world very
frequently on port 80.

Windows networking maybe easy to use as a programmer as you can use these
svchost etc. services for your networking needs, but how the hell do I find
out which program has started them (including from where)? Programs like
TCPView show that which command line has been used to start for example
svchost. But I have never seen anything except legimate looking rpcss or
something like that.

I think this is a shortcoming in Windows networking. Any ideas how can I dig
deeper?
.



Relevant Pages

  • Re: Remote Desktop and XP Pro SP2
    ... Disabling that port disables NetBIOS... ... opening that port to the internet has severe ... Jeffrey Randow (Windows Networking & Smart Display MVP) ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: Remote Desktop and XP Pro SP2
    ... Port 137 is not required for any remote desktop operation... ... Jeffrey Randow (Windows Networking & Smart Display MVP) ... >printer sharing in the sp2 firewall to see if this would serve the same ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: Terminal Services and etcservices
    ... Jeffrey Randow (Windows Networking & Smart Display MVP) ... >GetServByNameto get the TCP/IP port to listen on. ... >the services file to a unique directory for each terminal services ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: Finding out strange traffic
    ... > blocked port 80 and took a log. ... > svchost etc. services for your networking needs, but how the hell do I ... > I think this is a shortcoming in Windows networking. ...
    (microsoft.public.windowsxp.network_web)
  • Re: svchost.exe and the internet.........HELP!!
    ... Svchost uses Dcom on port 135 which in turn negotiates a NetBIOS session on ... I use sygate to and if you create a advanced rule for svchost.exe .. ... i installed broadband on my home computer (running Windows ...
    (comp.security.firewalls)