Are you on a dial up or broadband? And you're running XP, right?



"Joe Funk" <joefunk50@shaw.ca> wrote in message
news:RzfTa.483878$3C2.13143874@news3.calgary.shaw. ca...
> Sure - here's the running processes (look at all the security software!):
>
> Spybot-S&D process list report, 7/22/2003 11:20:20 AM
>
> PID: 0 ( 0) [System]
> PID: 4 ( 0) System
> PID: 364 ( 4) \SystemRoot\System32\smss.exe
> PID: 428 ( 364) CSRSS.EXE
> PID: 452 ( 364) \??\C:\WINDOWS\system32\winlogon.exe
> PID: 496 ( 452) C:\WINDOWS\system32\services.exe
> PID: 508 ( 452) C:\WINDOWS\system32\lsass.exe
> PID: 560 (1028) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
> PID: 660 ( 496) C:\WINDOWS\system32\svchost.exe
> PID: 704 ( 496) C:\WINDOWS\System32\svchost.exe
> PID: 832 ( 496) SVCHOST.EXE
> PID: 868 ( 452) C:\WINDOWS\System32\taskmgr.exe
> PID: 872 ( 496) SVCHOST.EXE
> PID: 1028 (1008) C:\WINDOWS\Explorer.EXE
> PID: 1084 ( 496) C:\WINDOWS\system32\spoolsv.exe
> PID: 1312 (1028) C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
> PID: 1328 (1028) C:\Program Files\Panicware\Pop-Up Stopper Free
> Edition\PSFree.exe
> PID: 1340 (1028) C:\Program Files\VisualZone\VisualZone.exe
> PID: 1348 (1028) C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
> PID: 1468 ( 496) C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
> PID: 1480 ( 496) C:\WINDOWS\System32\cisvc.exe
> PID: 1520 ( 496) C:\WINDOWS\System32\inetsrv\inetinfo.exe
> PID: 1548 (1480) C:\WINDOWS\System32\cidaemon.exe
> PID: 1664 ( 496) C:\WINDOWS\system32\ZONELABS\vsmon.exe
> PID: 2028 (1480) C:\WINDOWS\System32\cidaemon.exe
> __________________________________________________ _
>
> And here's the startup list:
>
> Spybot-S&D Startup list report, 7/22/2003 11:21:36 AM
>
> Located: HK_CU:Run, PopUpStopperFreeEdition
> file: "C:\Program Files\Panicware\Pop-Up Stopper Free

Edition\PSFree.exe"
>
> Located: HK_LM:Run, AVG_CC
> file: C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
>
> Located: Startup (common), VisualZone.lnk
> file: C:\Program Files\VisualZone\VisualZone.exe
> MD5: EDEB15D21942887CAB632F597127ED24
>
> Located: Startup (common), ZoneAlarm.lnk
> file: C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
> MD5: 53848739EBFC3931C4C232526F1C3F7A
> __________________________________________________ _
>
> I don't know what a packet sniffer is.
> I've noticed in the ZoneAlarm logs that my explorer.exe regularly

tries
> to access the internet. I disallowed it when I first installed ZoneAlarm
> because it didn't seem likely that explorer.exe would need to be talking

to
> anybody out there.
> I'm glad you asked because I've always thought it eerie that there's

so
> much activity in them there ports. In the 5 hours since I turned on my
> computer, I see that ZA has blocked 106 messages attempting to go either

in
> or out. I wish I knew more about what the **** those busy incoming probes
> are up to, and why so many Services are interested in accessing the net.
> Joe
>
> "mto" <nobody@nowhere.com> wrote in message
> news:vhqu0plk0clbdc@corp.supernews.com...
> > Can you guys get a list of your running programs and start up programs

> from
> > SpyBot and post them?
> >
> > Do any of you have packet sniffer detection installed? Seeing anything
> > unusual? What about a program trying to access the net through your
> > firewall?
> >