dpastern
July 1st, 2007, 06:44 AM
Hi guys - new to the forum, was linked via a google search to this post:
http://www.cybertechhelp.com/forums/showthread.php?t=103465
Anyways - several odd things - firstly, I'm on a network, behind a router firewall etc. I'm not the admin of the network. Said network runs McAffee Enterprise 8 anti virus software. My PC runs like a dog (AMD 3000+, 2.5gb RAM, Windows XP pro) and my network connection/Internet connection always seems slower than the rest of the PCs on the network. I don't go to "those" websites (I'm sure you can figure out what I mean), I run the Microsoft anti spyware software on an automated daily scan at 2am, and Spybot once a week. I use both IE 7 and FireFox 2, usually IE though as I prefer it. Windows is patched up to date, and during the install process I installed Windows XP SP1 whilst d/l SP2 via another PC. Whilst setting up XP SP 1, I did not enable networking connectivity, and installed SP2 from CD before enabling it.
I run a bunch of software, the usual stuff, plus my own favourites such as Photoshop CS2, Neat Image, Capture One Pro etc. I can provide a full list of installed applications if you want, just in case it helps. Anyways, when connecting my system back to the network after an initial install of Windows, the anti virus software always has to be manually installed, it never seems to auto install onto my system as it should.
Anyways, here is my netstat file (netstat -ano) for your perusal:
Active Connections
Proto Local Address Foreign Address State PID
TCP MORGOTH:epmap MORGOTH.dia.net.au:0 LISTENING 888
c:\windows\system32\WS2_32.dll
C:\WINDOWS\system32\RPCRT4.dll
c:\windows\system32\rpcss.dll
C:\WINDOWS\system32\svchost.exe
-- unknown component(s) --
[svchost.exe]
TCP MORGOTH:microsoft-ds MORGOTH.dia.net.au:0 LISTENING 4
[System]
TCP MORGOTH:8081 MORGOTH.dia.net.au:0 LISTENING 1920
[FrameworkService.exe]
TCP MORGOTH:netbios-ssn MORGOTH.dia.net.au:0 LISTENING 1020
-- unknown component(s) --
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ADVAPI32.dll
[svchost.exe]
TCP MORGOTH:netbios-ssn MORGOTH.dia.net.au:0 LISTENING 4
[System]
TCP MORGOTH:4828 td-in-f166.google.com:http ESTABLISHED 2600
[iexplore.exe]
TCP MORGOTH:4829 da-in-f104.google.com:http ESTABLISHED 2600
[iexplore.exe]
TCP MORGOTH:4880 a203-111-15-232.deploy.akamaitechnologies.com:http ESTABLISHED 3092
[MsnMsgr.Exe]
TCP MORGOTH:4881 www.games.defencejobs.gov.au:http ESTABLISHED 3092
[MsnMsgr.Exe]
TCP MORGOTH:4887 by1msg2145217.phx.gbl:1863 ESTABLISHED 3092
[MsnMsgr.Exe]
TCP MORGOTH:4888 c.msn.com:http LAST_ACK 3092
[MsnMsgr.Exe]
TCP MORGOTH:4877 65.54.239.20:1863 TIME_WAIT 0
TCP MORGOTH:4885 207.46.26.253:7001 TIME_WAIT 0
TCP MORGOTH:4885 207.46.26.254:7001 TIME_WAIT 0
TCP MORGOTH:4886 65.54.239.20:1863 TIME_WAIT 0
UDP MORGOTH:1027 *:* 1216
C:\WINDOWS\system32\mswsock.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\DNSAPI.dll
c:\windows\system32\dnsrslvr.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:4500 *:* 668
[lsass.exe]
UDP MORGOTH:8082 *:* 1920
[FrameworkService.exe]
UDP MORGOTH:isakmp *:* 668
[lsass.exe]
UDP MORGOTH:1026 *:* 1216
C:\WINDOWS\system32\mswsock.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\DNSAPI.dll
c:\windows\system32\dnsrslvr.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:8081 *:* 1920
[FrameworkService.exe]
UDP MORGOTH:1028 *:* 1216
C:\WINDOWS\system32\mswsock.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\DNSAPI.dll
c:\windows\system32\dnsrslvr.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:1025 *:* 1216
C:\WINDOWS\system32\mswsock.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\DNSAPI.dll
c:\windows\system32\dnsrslvr.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:microsoft-ds *:* 4
[System]
UDP MORGOTH:4440 *:* 1216
C:\WINDOWS\system32\mswsock.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\DNSAPI.dll
c:\windows\system32\dnsrslvr.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:3661 *:* 1216
C:\WINDOWS\system32\mswsock.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\DNSAPI.dll
c:\windows\system32\dnsrslvr.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:4749 *:* 668
[lsass.exe]
UDP MORGOTH:1900 *:* 1316
c:\windows\system32\WS2_32.dll
c:\windows\system32\ssdpsrv.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP MORGOTH:4752 *:* 2600
[iexplore.exe]
UDP MORGOTH:ntp *:* 1020
c:\windows\system32\WS2_32.dll
c:\windows\system32\w32time.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP MORGOTH:4479 *:* 3092
[MsnMsgr.Exe]
UDP MORGOTH:1072 *:* 612
[winlogon.exe]
UDP MORGOTH:ntp *:* 1020
c:\windows\system32\WS2_32.dll
c:\windows\system32\w32time.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP MORGOTH:netbios-dgm *:* 1020
-- unknown component(s) --
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:netbios-ns *:* 1020
-- unknown component(s) --
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:1900 *:* 1316
c:\windows\system32\WS2_32.dll
c:\windows\system32\ssdpsrv.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP MORGOTH:netbios-dgm *:* 4
[System]
UDP MORGOTH:discard *:* 3092
[MsnMsgr.Exe]
UDP MORGOTH:netbios-ns *:* 4
[System]
UDP MORGOTH:ntp *:* 1020
c:\windows\system32\WS2_32.dll
c:\windows\system32\w32time.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
You'll note several odd things, several lines where it says:
-- unknown component(s) --
There is also this line:
TCP MORGOTH:4881 www.games.defencejobs.gov.au:http ESTABLISHED 3092
[MsnMsgr.Exe]
Now, I have never been to this site before, and this only shows on an initial netstat on starting up msn messenger live. If I run a 2nd scan, it doesn't show. Odd? The really odd thing is that I had this problem on a previous install of Windows, and it's back again after format/reinstall. Why? I did a google search on this site and only 2 hits, very very odd in my experience.
Furthermore, none of the other PCs on the network have this issue. It doesn't matter whether it's msn v7.6 (the last version before live messenger), or live messenger, it happens with both. It doesn't matter which user account I log into msn messenger on. I haven't tried logging into someone elses PC with my account details - yet. I want to see if it's an account based issue I guess.
Furthermore, since McAffee software is running, I should have the mcshield.exe process listening via netstat in the background, as several other PCs have it. My PC doesn't. I haven't taken this up with the owner of the network yet, I believe that he will not be interested at all and will just say I'm paranoid.
I'm proudly anti American government in my sentiment, and I'm not afraid to speak out against the atrocities that the US government does, in both terms of freedom, and illegal invasions of other countries and I suspect that this has got me now being spied on by government authorities.
I used to run GNU/Linux, which is my preferred operating system, but since I'm a photographer on the side, I need to use Photoshop/Neat Image/Capture One Pro, which don't run under WINE/Cedega/CrossOver office on Linux.
If you want me to provide other files, etc, I'll be happy to.
Any help/suggestions/ideas would be appreciated.
Cheers,
Dave
http://www.cybertechhelp.com/forums/showthread.php?t=103465
Anyways - several odd things - firstly, I'm on a network, behind a router firewall etc. I'm not the admin of the network. Said network runs McAffee Enterprise 8 anti virus software. My PC runs like a dog (AMD 3000+, 2.5gb RAM, Windows XP pro) and my network connection/Internet connection always seems slower than the rest of the PCs on the network. I don't go to "those" websites (I'm sure you can figure out what I mean), I run the Microsoft anti spyware software on an automated daily scan at 2am, and Spybot once a week. I use both IE 7 and FireFox 2, usually IE though as I prefer it. Windows is patched up to date, and during the install process I installed Windows XP SP1 whilst d/l SP2 via another PC. Whilst setting up XP SP 1, I did not enable networking connectivity, and installed SP2 from CD before enabling it.
I run a bunch of software, the usual stuff, plus my own favourites such as Photoshop CS2, Neat Image, Capture One Pro etc. I can provide a full list of installed applications if you want, just in case it helps. Anyways, when connecting my system back to the network after an initial install of Windows, the anti virus software always has to be manually installed, it never seems to auto install onto my system as it should.
Anyways, here is my netstat file (netstat -ano) for your perusal:
Active Connections
Proto Local Address Foreign Address State PID
TCP MORGOTH:epmap MORGOTH.dia.net.au:0 LISTENING 888
c:\windows\system32\WS2_32.dll
C:\WINDOWS\system32\RPCRT4.dll
c:\windows\system32\rpcss.dll
C:\WINDOWS\system32\svchost.exe
-- unknown component(s) --
[svchost.exe]
TCP MORGOTH:microsoft-ds MORGOTH.dia.net.au:0 LISTENING 4
[System]
TCP MORGOTH:8081 MORGOTH.dia.net.au:0 LISTENING 1920
[FrameworkService.exe]
TCP MORGOTH:netbios-ssn MORGOTH.dia.net.au:0 LISTENING 1020
-- unknown component(s) --
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ADVAPI32.dll
[svchost.exe]
TCP MORGOTH:netbios-ssn MORGOTH.dia.net.au:0 LISTENING 4
[System]
TCP MORGOTH:4828 td-in-f166.google.com:http ESTABLISHED 2600
[iexplore.exe]
TCP MORGOTH:4829 da-in-f104.google.com:http ESTABLISHED 2600
[iexplore.exe]
TCP MORGOTH:4880 a203-111-15-232.deploy.akamaitechnologies.com:http ESTABLISHED 3092
[MsnMsgr.Exe]
TCP MORGOTH:4881 www.games.defencejobs.gov.au:http ESTABLISHED 3092
[MsnMsgr.Exe]
TCP MORGOTH:4887 by1msg2145217.phx.gbl:1863 ESTABLISHED 3092
[MsnMsgr.Exe]
TCP MORGOTH:4888 c.msn.com:http LAST_ACK 3092
[MsnMsgr.Exe]
TCP MORGOTH:4877 65.54.239.20:1863 TIME_WAIT 0
TCP MORGOTH:4885 207.46.26.253:7001 TIME_WAIT 0
TCP MORGOTH:4885 207.46.26.254:7001 TIME_WAIT 0
TCP MORGOTH:4886 65.54.239.20:1863 TIME_WAIT 0
UDP MORGOTH:1027 *:* 1216
C:\WINDOWS\system32\mswsock.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\DNSAPI.dll
c:\windows\system32\dnsrslvr.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:4500 *:* 668
[lsass.exe]
UDP MORGOTH:8082 *:* 1920
[FrameworkService.exe]
UDP MORGOTH:isakmp *:* 668
[lsass.exe]
UDP MORGOTH:1026 *:* 1216
C:\WINDOWS\system32\mswsock.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\DNSAPI.dll
c:\windows\system32\dnsrslvr.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:8081 *:* 1920
[FrameworkService.exe]
UDP MORGOTH:1028 *:* 1216
C:\WINDOWS\system32\mswsock.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\DNSAPI.dll
c:\windows\system32\dnsrslvr.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:1025 *:* 1216
C:\WINDOWS\system32\mswsock.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\DNSAPI.dll
c:\windows\system32\dnsrslvr.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:microsoft-ds *:* 4
[System]
UDP MORGOTH:4440 *:* 1216
C:\WINDOWS\system32\mswsock.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\DNSAPI.dll
c:\windows\system32\dnsrslvr.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:3661 *:* 1216
C:\WINDOWS\system32\mswsock.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\DNSAPI.dll
c:\windows\system32\dnsrslvr.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:4749 *:* 668
[lsass.exe]
UDP MORGOTH:1900 *:* 1316
c:\windows\system32\WS2_32.dll
c:\windows\system32\ssdpsrv.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP MORGOTH:4752 *:* 2600
[iexplore.exe]
UDP MORGOTH:ntp *:* 1020
c:\windows\system32\WS2_32.dll
c:\windows\system32\w32time.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP MORGOTH:4479 *:* 3092
[MsnMsgr.Exe]
UDP MORGOTH:1072 *:* 612
[winlogon.exe]
UDP MORGOTH:ntp *:* 1020
c:\windows\system32\WS2_32.dll
c:\windows\system32\w32time.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP MORGOTH:netbios-dgm *:* 1020
-- unknown component(s) --
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:netbios-ns *:* 1020
-- unknown component(s) --
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
UDP MORGOTH:1900 *:* 1316
c:\windows\system32\WS2_32.dll
c:\windows\system32\ssdpsrv.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP MORGOTH:netbios-dgm *:* 4
[System]
UDP MORGOTH:discard *:* 3092
[MsnMsgr.Exe]
UDP MORGOTH:netbios-ns *:* 4
[System]
UDP MORGOTH:ntp *:* 1020
c:\windows\system32\WS2_32.dll
c:\windows\system32\w32time.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
You'll note several odd things, several lines where it says:
-- unknown component(s) --
There is also this line:
TCP MORGOTH:4881 www.games.defencejobs.gov.au:http ESTABLISHED 3092
[MsnMsgr.Exe]
Now, I have never been to this site before, and this only shows on an initial netstat on starting up msn messenger live. If I run a 2nd scan, it doesn't show. Odd? The really odd thing is that I had this problem on a previous install of Windows, and it's back again after format/reinstall. Why? I did a google search on this site and only 2 hits, very very odd in my experience.
Furthermore, none of the other PCs on the network have this issue. It doesn't matter whether it's msn v7.6 (the last version before live messenger), or live messenger, it happens with both. It doesn't matter which user account I log into msn messenger on. I haven't tried logging into someone elses PC with my account details - yet. I want to see if it's an account based issue I guess.
Furthermore, since McAffee software is running, I should have the mcshield.exe process listening via netstat in the background, as several other PCs have it. My PC doesn't. I haven't taken this up with the owner of the network yet, I believe that he will not be interested at all and will just say I'm paranoid.
I'm proudly anti American government in my sentiment, and I'm not afraid to speak out against the atrocities that the US government does, in both terms of freedom, and illegal invasions of other countries and I suspect that this has got me now being spied on by government authorities.
I used to run GNU/Linux, which is my preferred operating system, but since I'm a photographer on the side, I need to use Photoshop/Neat Image/Capture One Pro, which don't run under WINE/Cedega/CrossOver office on Linux.
If you want me to provide other files, etc, I'll be happy to.
Any help/suggestions/ideas would be appreciated.
Cheers,
Dave