OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: crazytrain.com (subscribecrazytrain.com)
Date: Thu Jul 05 2001 - 22:28:38 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Not sure your OS?
     
    -> NT, grab inzider to see what PIDs are running, tdimon from sysinternals
    is another good one for this tracking. Windump or ethereal to see the
    traffic. Also, stay up at that time one morning and check running
    processes - tdimon will be good for this.

    farmerdude

    > Hi all
    >
    > My laptop is behaving very strangely, and I don't know why.
    > On some of the servers on the LAN, where my computer has no business, it
    > seems like I'm trying to login every night at 0300.
    > I have put up a sniffer so I can see that it actually is my pc doing this.
    > Now my quistion is.
    > How do I see what is causing my computer to start a connection to another
    pc
    > on UDP 138, every night. (when I sleep)
    > I have scanned my pc, and installed ZA, so I don't think that any outside
    > event is triggering this. I think that some service of some kind is
    running.
    > But how do I locate it?
    >
    > Brgds
    >
    >
    > Errit Müller
    >
    >