Help - Search - Members - Calendar
Full Version: What Service Is Sending Out Ip Traffic?
BleepingComputer.com > Operating Systems > Windows Vista
   
godfrm2
Hello,
My Vista machine is generation SNMP traffic on port 161 to the following addresses: 49.23.27.50, 49.23.27.69, 49.27.42.25 - how can I identify what service is generating this traffic? I've run both Windows Defender and Spybot on the disk and have CA's eTrust, (all current) running.

Here's the Network Trace through Network Monitor 3.1

49.23.27.50 4 0.062400 192.168.1.101 49.23.27.50 SNMP SNMP: Version1, Community = public, Get request, RequestID = 16532, Length = 78
49.23.27.69 5 0.062400 192.168.1.101 49.23.27.69 SNMP SNMP: Version1, Community = public, Get request, RequestID = 16533, Length = 78
49.23.27.69 6 0.062400 192.168.1.101 49.23.27.69 SNMP SNMP: Version1, Community = public, Get request, RequestID = 16534, Length = 78
49.27.42.25 7 0.062400 192.168.1.101 49.27.42.25 SNMP SNMP: Version1, Community = public, Get request, RequestID = 16535, Length = 78


Thanks
Mark G.
usasma
This address is reserved by Iana.org - so it's not a "regular" IP address.
Being reserved gives several possibilities:
1) the IP is being "spoofed"
2) there is someone using this reserved address - either for legitimate or illegitimate purposes.
3) there is a legitimate need to communicate with this Iana IP address

I'd suggest using a Vista compatible firewall such as Zone Alarm or Webroot Desktop Firewall (just started testing this one) to see if it'll let you know what's doing this. Block all traffic and have it prompt you for each access.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.