Results 1 to 4 of 4

Thread: Netstat log huge!

Hybrid View

  1. #1
    Join Date
    Apr 2007
    Posts
    2

    Netstat log huge!

    I have a few pages of info showing up when I run netstat. I have installed and ran AVG, Ccleaner, Spybot, and HiJackThis, nothing really comes up. Yes, I have ran everything in safemode, and everything is current.

    Netstat logs available upon request!

    Here is a log:
    Logfile of HijackThis v1.99.1
    Scan saved at 10:04:32 AM, on 4/12/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\stsystra.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EA Link\Core.exe" -silent
    O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
    O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/ca..._2.3.3.102.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1134411056562
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe

  2. #2
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Frankly I don't see much of anything in the HJT log. If nothing came up in the other programs then I would say the computer is clean. I don't see any firewall on the computer why are you not using a firewall?

  3. #3
    Join Date
    Apr 2007
    Posts
    2
    Because I am behind a router that has the firewall turned on. Here is a log from my netstat:
    Active Connections

    Proto Local Address Foreign Address State
    TCP MATT:1045 74-140-130-222.dhcp.insightbb.com:2489 ESTABLIS
    HED
    TCP MATT:1697 Mail.mindbank.com:smtp TIME_WAIT
    TCP MATT:1713 mail-gw.popmanager.com:smtp ESTABLISHED
    TCP MATT:1867 b.mx.voyager.net:smtp TIME_WAIT
    TCP MATT:1869 58x157x247x189.ap58.ftth.ucom.ne.jp:smtp TIME_W
    AIT
    TCP MATT:1876 mx1.spunky.mail.dreamhost.com:smtp TIME_WAIT
    TCP MATT:1877 data.ebay.com:smtp LAST_ACK
    TCP MATT:1883 mail.global.frontbridge.com:smtp TIME_WAIT
    TCP MATT:1884 mta-v8.mail.vip.mud.yahoo.com:smtp TIME_WAIT
    TCP MATT:1886 mta-v1.mail.vip.in.yahoo.com:smtp TIME_WAIT
    TCP MATT:1888 MAIL5.statefarm.com:smtp TIME_WAIT
    TCP MATT:1889 e3.ny.us.ibm.com:smtp TIME_WAIT
    TCP MATT:1892 207-91-139-213.nstci.net:smtp TIME_WAIT
    TCP MATT:1894 mta-v8.mail.vip.mud.yahoo.com:smtp TIME_WAIT
    TCP MATT:1896 mta-v8.mail.vip.mud.yahoo.com:smtp TIME_WAIT
    TCP MATT:1897 smtp1.msp.securence.com:smtp TIME_WAIT
    TCP MATT:1903 mfs.blackhills.com:smtp TIME_WAIT
    TCP MATT:1904 spf12.us4.outblaze.com:smtp TIME_WAIT
    TCP MATT:1910 mta-v14.mail.vip.re4.yahoo.com:smtp TIME_WAIT
    TCP MATT:1913 mx1.optonline.net:smtp TIME_WAIT
    TCP MATT:1914 mta-v8.mail.vip.mud.yahoo.com:smtp TIME_WAIT
    TCP MATT:1915 mta-v8.mail.vip.mud.yahoo.com:smtp TIME_WAIT
    TCP MATT:1918 *.s8a1.psmtp.com:smtp TIME_WAIT
    TCP MATT:1919 mta13.grp.scd.yahoo.com:smtp TIME_WAIT
    TCP MATT:1927 mail-kr.bigfoot.com:smtp TIME_WAIT
    TCP MATT:1928 tsugaike.janis.or.jp:smtp TIME_WAIT
    TCP MATT:1930 sitemail.everyone.net:smtp TIME_WAIT
    TCP MATT:1941 mgateway.renown.org:smtp TIME_WAIT
    TCP MATT:1942 gateway-a.comcast.net:smtp TIME_WAIT
    TCP MATT:1949 coexch1.itg-global.com:smtp TIME_WAIT
    TCP MATT:1952 mx2.mediageneral.net:smtp ESTABLISHED
    TCP MATT:1956 *.s8a1.psmtp.com:smtp TIME_WAIT
    TCP MATT:1959 smtp.mail.drexel.edu:smtp TIME_WAIT
    TCP MATT:1960 mta13.grp.scd.yahoo.com:smtp TIME_WAIT
    TCP MATT:1961 216.163.188.53:smtp TIME_WAIT
    TCP MATT:1964 psychotropics.org:smtp TIME_WAIT
    TCP MATT:1968 mta-v1.mail.vip.re3.yahoo.com:smtp TIME_WAIT
    TCP MATT:1969 relay4i.sun.com:smtp ESTABLISHED
    TCP MATT:1971 mta13.grp.scd.yahoo.com:smtp TIME_WAIT
    TCP MATT:1976 leo.lunarpages.com:smtp TIME_WAIT
    TCP MATT:1977 fltr-in4.mail.dreamhost.com:smtp TIME_WAIT
    TCP MATT:1978 mail.donet.com:smtp TIME_WAIT
    TCP MATT:1981 smtpin.ptd.net:smtp TIME_WAIT
    TCP MATT:1984 mta-v8.mail.vip.mud.yahoo.com:smtp TIME_WAIT
    TCP MATT:1985 ptang.com:smtp TIME_WAIT
    TCP MATT:1987 relay4i.sun.com:smtp ESTABLISHED
    TCP MATT:1990 mailserver.bmtc.com:smtp TIME_WAIT
    TCP MATT:1991 207.159.120.164:smtp TIME_WAIT
    TCP MATT:1996 nb-mx-vip3.prodigy.net:smtp TIME_WAIT
    TCP MATT:1997 mx-nrs1.mail-abuse.org:smtp TIME_WAIT
    TCP MATT:2001 nameservices.net:smtp TIME_WAIT
    TCP MATT:2006 www.paypal.com:https TIME_WAIT
    TCP MATT:2010 interceptor.coopertsmith.com:smtp TIME_WAIT
    TCP MATT:2011 chumashlodge90.org:smtp TIME_WAIT
    TCP MATT:2012 mail2.checkbridge.com:smtp TIME_WAIT
    TCP MATT:2013 mta-v8.mail.vip.mud.yahoo.com:smtp TIME_WAIT
    TCP MATT:2014 imsmx01.netvigator.com:smtp ESTABLISHED
    TCP MATT:2017 *.s6a1.psmtp.com:smtp TIME_WAIT
    TCP MATT:2021 *.s6a1.psmtp.com:smtp TIME_WAIT
    TCP MATT:2023 mail.hotmail.com:smtp SYN_SENT
    TCP MATT:2024 po-in-f147.google.com:http ESTABLISHED
    TCP MATT:2030 mail.global.frontbridge.com:smtp TIME_WAIT
    TCP MATT:2031 esmta-2.messageone.com:smtp TIME_WAIT
    TCP MATT:2033 mta-v8.mail.vip.mud.yahoo.com:smtp SYN_SENT
    TCP MATT:2036 *.s6a1.psmtp.com:smtp TIME_WAIT
    TCP MATT:2040 smtp2.uta.edu:smtp TIME_WAIT
    TCP MATT:2041 m1.dnsix.com:smtp TIME_WAIT
    TCP MATT:2044 mx3.spunky.mail.dreamhost.com:smtp TIME_WAIT
    TCP MATT:2046 mail.global.frontbridge.com:smtp TIME_WAIT
    TCP MATT:2047 mta13.grp.scd.yahoo.com:smtp ESTABLISHED
    TCP MATT:2048 mail.global.frontbridge.com:smtp ESTABLISHED
    TCP MATT:2049 fca-linksys.newnanutilities.org:smtp ESTABLISHE
    D

    C:\Documents and Settings\Matt Zrelak>

  4. #4
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Matt there is nothing wrong with either the netstat log or the HJT log. All looks fine to me.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •