Re: How to find process behing TCP connection ?

On 2006-09-26 Buozis, Martynas wrote:
I need an advice. I have Windows 2003 server. It occasionally show
strange and suspicious network behavior. I used command "netstat
-abov" and Process explorer tool from Sysinternals to find process
behind connections. I found that it is "System 4" and got stuck. How I
can identify what is behind this "System 4"?

System:4 is AFAIK not a real process, but basically the kernel. What do
you mean by "strange and suspicious network behavior"? Unusual network
traffic? Open ports? Have you tried to inspect the network traffic with
a protocol analyzer? Have you run a portscan against the host?

I thought it may be hidden process, but RootkitReveal from
Systinternals did not show anything.

You could try other rootkit detection tools (e.g. Blacklight [1] or
Anti-Rootkit [2]), or do an offline-analysis of the system.

I will be grateful for any ideas how to identify what is behind these
TCP connections from server to many computers!

I'd start with inspecting the traffic, preferably gathered through some


Ansgar Wiechers
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq

