Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Basics: Re: Any tools to log the traffic/process information on Windows startup?

Re: Any tools to log the traffic/process information on Windows startup?

From: <krymson_at_gmail.com>
Date: 21 May 2008 19:02:37 -0000
('binary' encoding is not supported, stored as-is) A combination or PortReporter, Wireshark, and even just a cmd window running 'netstat -an' will be fine.

Could be lots of things, but I wouldn't be surprised if that were Skype traffic. :)

<- snip ->
I was checking up my desktop and found unexpected network traffic (destinations including dynamic IPs within Poland, US, and China) at windows startup (by checking the network traffic log on Kaspersky security firewall). Most of those traffic are UDP. I suspect they are enrollment or heartbeat signals from spywares or trojans. However, the scans (spybot, ad-aware, kaspersky, clamAV) yielded nothing.

To further investigate into this issue, I am trying to find a tool that can log all the network activities together with their corresponding processes at Windows startup. Does anyone know of such a tool?

Thanks!!

Yan
Received on May 21 2008

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]