Welcome, Guest. Please login or register.
Did you miss your activation email?
May 22, 2013, 11:47:08 PM

Login with username, password and session length

663639 Posts
70568 Topics
145225 Members

Latest Member: KentonMcs

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Leak Testing/Attacks/Vulnerability Research
| | |-+  Suspicious Connections & Behaviour with COMODO Firewall
« previous next »
Pages: [1] Go Down Print
Author Topic: Suspicious Connections & Behaviour with COMODO Firewall  (Read 6417 times)
atsivxp
Newbie
*
Offline Offline

Posts: 5


« on: September 20, 2010, 07:42:58 PM »

Suspicious Connections & Behaviour with COMODO Firewall

I have seen some activity on my machine which borders on suspicious behaviour after
I install a certain program. When I came back COMODO said it had blocked intrusions
and I had about 279 out-bound connections, my active connections was suspicious with
IPs and ports which was quite dynamic. How can I tell if it is indeed harmful
connections and block them? I really want to get rid of those but need
a bit of guidance.

I am on a Windows 7 / 64-bit and I think I know the application that is making the
connections, or do I? Below is just a sample active connections and they keep changing.
Please help!

c:\windows\syswow64\svchost.exe

Protocol   Source         Destination
==============   ==============      ==============
TCP OUT      192.168.0.6:50751   77.67.10.135:443
TCP OUT      192.168.0.6:50692   77.67.10.132:443
UDP OUT      192.168.0.6:65392   96.6.40.21:3478
UDP OUT      192.168.0.6:65393   125.56.208.184:3478

many thanks
Logged
atsivxp
Newbie
*
Offline Offline

Posts: 5


« Reply #1 on: September 21, 2010, 06:25:18 AM »

I did a little research and found the IPs come from AKAMAI.
Still not sure so any good advice will do. If you need maore details please do let me know.

inetnum: 77.67.10.128[Who Is IP][trace][Reverse IP Search] - 77.67.10.255[Who Is IP][trace][Reverse IP Search]
netname: AKAMAI-TINET
descr: Akamai Technologies
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16707



« Reply #2 on: September 21, 2010, 07:17:42 PM »

Since Akamai only hosts about 25% of the complete internet 

I think some legit application is calling home for updates. I remember AVG updates were hosted with Akamai several years ago; they may still be hosted by Akamai, but haven't used AVG in the period until now.....Wink
Logged

atsivxp
Newbie
*
Offline Offline

Posts: 5


« Reply #3 on: September 22, 2010, 04:10:01 PM »

Uploaded the file windows\syswow64\svchost.exe to virustotal.com and it only one came out
positive, see below, still not sure. all the other virus checkers are negative, wondering if it is a false positive.

 eSafe 7.0.17.0 2010.09.21 Win32.TrojanHorse
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.036 seconds with 20 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com