Strange Client Behavior: Port 8002 Looking for Other Ports

From: Will (DELETE_westes_at_earthbroadcast.com)
Date: 01/11/05


Date: Tue, 11 Jan 2005 10:05:38 -0800

I have strange symptoms on a Windows 2000 client. For long
periods each day, this client, which is behind Microsoft Proxy
2.0, stops access to the Internet. In the sniffer trace, what
I see is repetitive behavior where the client will send out TCP
connections from source port 8002 to successive ports on our DNS
server. It appears to attempt connection to each port three
times, and then it goes on to the next one. 1937, 1938, 1939,
etc.

This sure looks like some kind of port sniffing activity, maybe a
virus, but does anyone recognize the source port number and
behavior as belonging to some legitimate Windows 2000 client
behavior?

-- 
Will
Internet: westes at earthbroadcast.com


Relevant Pages

  • Re: thin client com ports
    ... I'm glad that you got at least one more client working! ... MCSE, CCEA, Microsoft MVP - Terminal Server ... the COM port settings? ... I am testing several thin clients. ...
    (microsoft.public.windows.terminal_services)
  • Re: network installation manager
    ... there is a firewall between master and client machines, ... NIM Communication within a Firewall Environment ... master via nimclient calls to the nimesis daemon. ... reserved port range of 1023-513. ...
    (comp.unix.aix)
  • Re: Serial port redirection
    ... Does anyone know if you have to use windows 2003 in order ... If you use Windows 2003 and the latest rdp client, ... >COM port, and expects an acknowledgement. ... >MCSE, CCEA, Microsoft MVP - Terminal Server ...
    (microsoft.public.windows.terminal_services)
  • Re: id- 1030 source - Userenv
    ... Leave the Default Gateway of the internal NIC blank of the server box. ... Configure the internal client computer's NIC and the internal NIC of the ... Click Internet Protocol, and then click Properties. ... Copy Network Files on Windows XP SP1 ...
    (microsoft.public.windows.server.sbs)
  • help: using smtp.gmail.com as SMART_HOST
    ... with my Google gmail address. ... is pop.gmail.com, using port 995. ... Retrieving mail is not the problem since my Google searches ... client, I believe the term is) to send my mail to Google's ...
    (comp.mail.sendmail)