Security Basics mailing list archives

Re: Any tools to log the traffic/process information on Windows startup?


From: krymson () gmail com
Date: 21 May 2008 19:02:37 -0000

A combination or PortReporter, Wireshark, and even just a cmd window running 'netstat -an' will be fine.

Could be lots of things, but I wouldn't be surprised if that were Skype traffic. :)



<- snip ->
I was checking up my desktop and found unexpected network traffic (destinations including dynamic IPs within Poland, 
US, and China) at windows startup (by checking the network traffic log on Kaspersky security firewall). Most of those 
traffic are UDP. I suspect they are enrollment or heartbeat signals from spywares or trojans. However, the scans 
(spybot, ad-aware, kaspersky, clamAV) yielded nothing.

To further investigate into this issue, I am trying to find a tool that can log all the network activities together 
with their corresponding processes at Windows startup. Does anyone know of such a tool?

Thanks!!

Yan


Current thread: