What Windows process initiate connection to other Port 139?

From: ys (yuu_shi_at_yahoo.com)
Date: 07/28/04


Date: 27 Jul 2004 15:37:33 -0700

I am not sure whether my machine got hacked. It keeps trying to make
TCP connection to port 139 on the other machine[s]. However, I found
no process based on its initiating port. It seems to me it was
spawned by other running process, but I am running out of idea to
track that down.

One thing I don't really understand is that how does my machine know
these IP addresses for connection; therefore, I suspect it has been
hacked.

Not sure whether it is related. There are a lot of machines trying to
make connections to my machine at port 135 and 445. Most initiating
IP are near. If this is normal, how do they know my IP? I just hope
my machine didn't boardcast its address for invitations! :(

I am using Windows 2000 Server with limited ports open to the net. I
captured these IP log from my hardware router.

ys



Relevant Pages

  • Re: Correction
    ... Normally to physically disconnect is just a matter of reaching for the ... >> I have an ADSL connection which polls my computer from time to time, ... > disallow each and every port with Windows Firewall? ...
    (microsoft.public.windowsxp.messenger)
  • Re: Using Remote Desktop From an SBS Domain
    ... when you tried to RDP while attached directly to a port on your router? ... Internet to initiate an IP conversation with your computer. ... This situation is different than if you ran your own NAT connection sharing ...
    (microsoft.public.windows.server.sbs)
  • Re: Still cant connect to RWW or OWA remotely
    ... it certainly appears to be something about the SBS configuration. ... Meridian.local Ethernet adapter Local Area Connection: ... Windows SMALL BUSINESS SERVER 2003 Windows IP Configuration ... 192.168.254.254) directly to a port on the router and then ...
    (microsoft.public.windows.server.sbs)
  • Re: Still cant connect to RWW or OWA remotely
    ... it certainly appears to be something about the SBS configuration. ... Meridian.local Ethernet adapter Local Area Connection: ... Windows SMALL BUSINESS SERVER 2003 Windows IP Configuration ... 192.168.254.254) directly to a port on the router and then ...
    (microsoft.public.windows.server.sbs)
  • Re: Random unprivileged TCP ports below 5000 kind-of open for a fraction of a second
    ... When Nmap (or many ... > other applications, such as Telnet) does a connectcall, the OS is ... > supposed to choose a good souce port to bind to for the connection. ... I saw a familiar "Connection reset by peer" every time the random port ...
    (Incidents)