Results 1 to 2 of 2

Thread: suspicious connections?

  1. #1
    jlsmith Guest

    Default suspicious connections?

    a warm hallo to all
    I'm wondering about a few active connections found on my pc. at first, there was one I had to ban, which even after clearing of cookies & dns refresh (I'm on dynamic dsl - home connection, just a modem - no network) always trying to connect with TCP and coming from the same isp with mine using port 80. I
    noticed this after I
    used the "netstat -na" command at the command prompt. There are also 4 established tcp connections from the loopback adapter ip address at ports 1028, 1029, 1030 & 1032.
    thanks in advance

    Operating System:Windows XP Pro
    Product Name:ZoneAlarm Internet Security Suite
    Software Version:6.1

  2. #2
    Join Date
    Dec 2005
    Posts
    9,056

    Default Re: suspicious connections?

    Hi Jlsmith! Port 80 is used for http, YahooIM, and various security softwares that would be monitoring ports (antivirus is the most common). Ports 1028,1029.1030 are used by DCOM as well as other security applications. As for port 1032, I have no immediate answer, but it maybe used by a/v as well.. There are tools to enhance the imformation available about the applications using the ports in your pc.Try TCPView from sysinternals.com as this will give you some information on what is using the ports as well as the open TCP and UDP"s. Don't forget the ZA has logs on the ports that are used, listened , opened, and by what processes. Take care Oldsod
    Best regards.
    oldsod

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •