home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Networking and Internet
Ask a Tech Support Question (free)!

weird remote tcp connection!!!

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 2612
Discussions: 200,998, Posts: 2,379,965, Members: 246,365
Old July 4th, 2005, 12:47 PM   Digg it!   #1 (permalink)
Member
 
Join Date: Feb 2005
Posts: 54
weird remote tcp connection!!!

Hello, I am having a possible problem. Not really sure if this is the correct forum but I'll give it a shot. Everytime I access internet explorer I get an established tcp connection through port 80 to the same remote ip along with the website I type in. For instance if I go to yahoo or playsite game sites I get the same tcp connection to this remote ip as well. Even just accessing my home page. I noticed this when I command prompted netstat and ran Active Ports program. Is this normal? I have run virus scans and adware scans. All came up negative. here is a HijackThis log (hopefully this is the right place to post it) Thank you for your assistance in advance.

Logfile of HijackThis v1.99.1
Scan saved at 11:31:52 AM, on 7/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\ISS\BlackICE\rapapp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\ISS\BlackICE\blackice.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\VisualICE\VisualICE.exe
C:\Program Files\ISS\BlackICE\blackd.exe
C:\Documents and Settings\He\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wcpo.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_ 2_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_ 2_0.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlackICE PC Protection.lnk = C:\Program Files\ISS\BlackICE\blackice.exe
O4 - Global Startup: VisualICE Report Utility.lnk = C:\Program Files\VisualICE\VisualICE.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...67&clcid=0x409
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1120025166515
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\BlackICE\blackd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\BlackICE\rapapp.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

I can also run StartDreck if needed. Not to sure about silentrunners though. My antivirus alerted me of a suspicious script when I tried to open the silentrunners file.
nettizen is offline   Reply With Quote
Old July 4th, 2005, 12:49 PM     #2 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 26,861
Blog Entries: 15
http://www.techimo.com/forum/t137826.html
GroundZero3 is online now   Reply With Quote
Old July 4th, 2005, 01:12 PM     #3 (permalink)
Member
 
Join Date: Feb 2005
Posts: 54
I apologize for posting another thread I thought you meant to go there and post the thread with the HijackThis log. Again I apologize. I'm fairly new to this. So sorry.
nettizen is offline   Reply With Quote
Old July 4th, 2005, 01:13 PM     #4 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 26,861
Blog Entries: 15
its okay, post your log into those sites and they will provide you a list of whats good and whats bad
GroundZero3 is online now   Reply With Quote
Old July 4th, 2005, 03:12 PM     #5 (permalink)
Registered User
 
Join Date: Jul 2005
Location: Austin, tx
Posts: 1,005
what is the ip address? if you do an nslookup on it, that may shed some light on the subject.
johnnyis42 is offline   Reply With Quote
Old July 5th, 2005, 11:36 AM     #6 (permalink)
Member
 
Join Date: Feb 2005
Posts: 54
tcp remote ip connection

The remote ip address is 205.188.221.21 (canonical name a205-188-221-21.deploy.akamaitechnologies.net.
aliases
addresses 205.188.221.21) domain name info:


Domain Name: AKAMAITECHNOLOGIES.NET
Registrar: TUCOWS INC.
Whois Server: whois.opensrs.net
Referral URL: http://domainhelp.tucows.com
Name Server: ACCESS.AKAMAI.COM
Name Server: YH.AKAMAI.COM
Name Server: YF.AKAMAI.COM
Name Server: YG.AKAMAI.COM
Name Server: YD.AKAMAI.COM
Name Server: YE.AKAMAI.COM
Name Server: YB.AKAMAI.COM
Name Server: YC.AKAMAI.COM
Status: ACTIVE
Updated Date: 26-jun-2002
Creation Date: 19-aug-1998
Expiration Date: 18-aug-2005

I've heard that microsoft uses it to it being an outside company isp cache server to the FBI..someone enlighten me please.
nettizen is offline   Reply With Quote
Old July 6th, 2005, 12:41 AM     #7 (permalink)
Member
 
Join Date: Feb 2005
Posts: 54
Could it be a web accelerator? With some investigating I determined that when I access the internet my computer gets a tcp connection to a remote ip through port 80. The ip is 205.188.228.136. If I block this connection with zone alarm I can only access my home page and anything on my favorites. When I did netstat after it was blocked It said the ip was "SYN_SENT" and another ip came up as established. The ip was 64.12.145.14 "deploy.akamaitechnologies". Seems to be the same people. I blocked that and netstat said "SYN_SENT" on that one too. It even said "FIN_WAIT" one time. No idea what that means. Zone Alarm also catches packets from ip 64.12.145.136. Please help me clear this up.
nettizen is offline   Reply With Quote
Old July 6th, 2005, 12:48 AM     #8 (permalink)
Member
 
Join Date: Feb 2005
Posts: 54
entry correction

Zone Alarm catches packets FROM 64.12.145.14
nettizen is offline   Reply With Quote
Old July 6th, 2005, 02:05 AM     #9 (permalink)
Super F@D Folder
 
Join Date: Jun 2004
Posts: 5,083
Send a message via AIM to sr71000
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_ 2_0.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll

those all look fishy to me....uber button class? that and taggedBM .....just something to look into. I imediately look at the BHO's because you have zone alarm and it's not catching a program accessing the internet...so it makes me look at bho's that just use ie!
sr71000 is offline   Reply With Quote
Old July 6th, 2005, 02:22 AM     #10 (permalink)
Member
 
"Heatmiser"'s Avatar
 
Join Date: May 2005
Location: South of heaven
Posts: 204
blackice is crap
ie is crap-use firefox
Microsoft antispyware is crap-just get rid of it
run ad-aware
run spybot s&d
try avg its free
"Heatmiser" is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
IP address translation, remote connection help!!! J1mmy Networking and Internet 7 June 7th, 2005 02:11 PM
XP Pro Remote Connection justinw Applications and Operating Systems 9 March 23rd, 2005 05:03 PM
TCP/IP Connection lost because of p2p app. Tec Networking and Internet 2 January 27th, 2004 05:39 PM
Remote Desktop Connection Cyberlore Networking and Internet 4 September 17th, 2003 01:55 PM
remote lan connection? VHockey86 Networking and Internet 14 September 3rd, 2003 03:24 PM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (3099)
Charges against non-tippers dropped.. (22)
Health Care Rationing (17)
Foxconn Blackops x48 MoBo (5)
Nvidia GTX 260 problem (14)
Delete an OS (17)
Laptop with wireless problem. (13)
Wireless Televisions. (12)
windows vista security holes (19)
CPU fan stops spinning randomly (11)
Regular Build (11)
Point and Shoot Camera Suggestions. (9)
[F@H SPAM 11/16/09] ! 1/2 months to.. (41)
windows 7 problem (7)
Recent Discussions
Outputing 1080p from my PC to my 720p.. (0)
panasonic dmr ez48veb recorder (0)
add ram to existing (3)
Need help getting speakers to work (2)
Nvidia GTX 260 problem (14)
Laptop with wireless problem. (13)
Point and Shoot Camera Suggestions. (9)
Is the PSU I received dead? (16)
FreeAgent drive software not x64 comp.. (1)
Intel 5100 AGN issues fixed yet? (28)
Foxconn Blackops x48 MoBo (5)
[F@H SPAM 11/16/09] ! 1/2 months to r.. (41)
Print spooler problem (17)
Q9650 vs. Q9550 (2)
Desktop Calendar Application (2)
Looking for new motherboard (1)
soundmon.exe (8)
Jedi Academy Problem (3)
Can a page file be "too big".. (1)
Size after cutting 700Mb file is 2.5 .. (0)
Delete an OS (17)
windows vista security holes (19)
updating BIOS via winflash, claims fi.. (1)
New Server Configuration Suggestions (0)
cheap gaming laptop? (12)


All times are GMT -4. The time now is 12:30 PM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28