1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Too many loopbacks?

Discussion in 'Networks' started by Daniel, Mar 26, 2009.

  1. Daniel

    Daniel Byte Poster

    236
    6
    25
    Hey guys,

    I've just done a netstat -o in CMD to just check for unusual connections.

    To my surprise, I have about maybe 20 - 30 loopback IP's, I looked at the PID but many seem to be linked to svchost.exe?

    I checked Google and svchost.exe can be linked to a virus, but then again anything can :biggrin

    By the way, I had no other apps running when I did the netstat -o.

    I can supply a print screen if anyone is interested.

    Thanks guys:biggrin!

    How you been? :p
     
    Certifications: 70-270, 70-290, 70-291
    WIP: None, but learning SEO/SEM
  2. danielno8

    danielno8 Gigabyte Poster

    1,305
    48
    92
    My computer usually has about 4/5. If you reboot is it 20-30 straight away? are they all "established"?
     
    Certifications: CCENT, CCNA
    WIP: CCNP
  3. zebulebu

    zebulebu Terabyte Poster

    3,748
    330
    187
    You are looking at local services running on your PC. If you check you'll see each one is associated with a port - (e.g. 137, 139). These are local RPC communications - and is the reason that they are running under svchost.exe. What you need to be worried about (if you can see any) is loads of connections to foreign (public) IP addresses - especially over suss-looking ports like IRC (6660-6669). These are most likely to indicate heinousness.
     
    Certifications: A few
    WIP: None - f*** 'em
  4. zebulebu

    zebulebu Terabyte Poster

    3,748
    330
    187
    Incidentally, to have a nice graphical view of the current processes and established ports, download Process Explorer and TCPView. Both are awesome and can help you visualise exactly what is going on with your PC
     
    Certifications: A few
    WIP: None - f*** 'em
  5. Daniel

    Daniel Byte Poster

    236
    6
    25
    This is what I'm getting:

    C:\Users\Dan>netstat -o

    Active Connections

    Proto Local Address Foreign Address State PID
    TCP 127.0.0.1:10080 Dan-PC:56580 ESTABLISHED 5908
    TCP 127.0.0.1:10080 Dan-PC:56586 ESTABLISHED 5908
    TCP 127.0.0.1:10080 Dan-PC:56588 ESTABLISHED 5908
    TCP 127.0.0.1:10080 Dan-PC:56628 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56634 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56636 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56638 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56639 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56641 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56652 ESTABLISHED 5908
    TCP 127.0.0.1:10080 Dan-PC:56654 ESTABLISHED 5908
    TCP 127.0.0.1:10080 Dan-PC:56756 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56758 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56762 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56765 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56776 ESTABLISHED 5908
    TCP 127.0.0.1:10080 Dan-PC:56778 ESTABLISHED 5908
    TCP 127.0.0.1:10080 Dan-PC:56802 ESTABLISHED 5908
    TCP 127.0.0.1:10080 Dan-PC:56822 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56824 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56828 ESTABLISHED 5908
    TCP 127.0.0.1:10080 Dan-PC:56836 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56838 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56840 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56842 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56844 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56846 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56848 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56852 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56853 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56857 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56860 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56861 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56864 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56866 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56868 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56870 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56877 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56880 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56884 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56886 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56888 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56890 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56900 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56904 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56908 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56910 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56912 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56914 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56916 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56918 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56920 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56921 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56923 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56926 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56930 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56932 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56934 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56936 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56937 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56946 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56947 ESTABLISHED 5908
    TCP 127.0.0.1:10080 Dan-PC:56949 ESTABLISHED 5908
    TCP 127.0.0.1:10080 Dan-PC:56952 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56954 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56956 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56960 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56962 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56968 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56970 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56972 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56974 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56976 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56978 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56983 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56985 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56996 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:56998 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57000 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57002 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57003 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57006 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57007 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57010 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57014 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57015 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57020 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57022 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57026 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57028 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57030 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57032 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57041 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57044 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57046 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57051 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57054 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57055 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57060 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57062 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57064 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57067 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57070 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57071 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57074 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57080 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57088 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57090 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57092 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57094 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57096 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57100 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57102 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57104 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57107 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57109 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57111 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57112 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57114 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57118 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57120 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57122 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57124 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57128 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57136 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57138 TIME_WAIT 0
    TCP 127.0.0.1:10080 Dan-PC:57142 TIME_WAIT 0
    TCP 127.0.0.1:49154 Dan-PC:49155 ESTABLISHED 1420
    TCP 127.0.0.1:49155 Dan-PC:49154 ESTABLISHED 1420
    TCP 127.0.0.1:49156 Dan-PC:49157 ESTABLISHED 1420
    TCP 127.0.0.1:49157 Dan-PC:49156 ESTABLISHED 1420
    TCP 127.0.0.1:49158 Dan-PC:49159 ESTABLISHED 1420
    TCP 127.0.0.1:49159 Dan-PC:49158 ESTABLISHED 1420
    TCP 127.0.0.1:49160 Dan-PC:49161 ESTABLISHED 1420
    TCP 127.0.0.1:49161 Dan-PC:49160 ESTABLISHED 1420
    TCP 127.0.0.1:49164 Dan-PC:49165 ESTABLISHED 2744
    TCP 127.0.0.1:49165 Dan-PC:49164 ESTABLISHED 2744
    TCP 127.0.0.1:49166 Dan-PC:49167 ESTABLISHED 2744
    TCP 127.0.0.1:49167 Dan-PC:49166 ESTABLISHED 2744
    TCP 127.0.0.1:56456 Dan-PC:56457 ESTABLISHED 4952
    TCP 127.0.0.1:56457 Dan-PC:56456 ESTABLISHED 4952
    TCP 127.0.0.1:56460 Dan-PC:56462 ESTABLISHED 4952
    TCP 127.0.0.1:56462 Dan-PC:56460 ESTABLISHED 4952
    TCP 127.0.0.1:56580 Dan-PC:10080 ESTABLISHED 4952
    TCP 127.0.0.1:56584 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56586 Dan-PC:10080 ESTABLISHED 4952
    TCP 127.0.0.1:56588 Dan-PC:10080 ESTABLISHED 4952
    TCP 127.0.0.1:56652 Dan-PC:10080 ESTABLISHED 4952
    TCP 127.0.0.1:56654 Dan-PC:10080 ESTABLISHED 4952
    TCP 127.0.0.1:56776 Dan-PC:10080 ESTABLISHED 4952
    TCP 127.0.0.1:56778 Dan-PC:10080 ESTABLISHED 4952
    TCP 127.0.0.1:56802 Dan-PC:10080 ESTABLISHED 4952
    TCP 127.0.0.1:56828 Dan-PC:10080 ESTABLISHED 4952
    TCP 127.0.0.1:56850 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56854 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56872 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56874 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56876 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56882 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56892 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56894 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56896 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56898 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56902 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56906 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56920 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56940 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56942 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56944 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56947 Dan-PC:10080 ESTABLISHED 4952
    TCP 127.0.0.1:56949 Dan-PC:10080 ESTABLISHED 4952
    TCP 127.0.0.1:56958 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56964 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56966 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56980 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56982 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56988 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56989 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56992 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:56994 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57012 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57018 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57024 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57034 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57036 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57038 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57040 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57047 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57049 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57052 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57066 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57076 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57078 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57081 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57084 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57086 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57098 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57106 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57109 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57126 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57130 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57132 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57134 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57140 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57144 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57146 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57148 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57150 Dan-PC:10080 TIME_WAIT 0
    TCP 127.0.0.1:57152 Dan-PC:10080 TIME_WAIT 0
    TCP 192.168.1.65:2869 speedtouch:26766 CLOSE_WAIT 4
    TCP 192.168.1.65:2869 speedtouch:26771 CLOSE_WAIT 4
    TCP 192.168.1.65:2869 speedtouch:26773 CLOSE_WAIT 4
    TCP 192.168.1.65:2869 speedtouch:26777 CLOSE_WAIT 4
    TCP 192.168.1.65:2869 speedtouch:26809 CLOSE_WAIT 4
    TCP 192.168.1.65:2869 speedtouch:26915 CLOSE_WAIT 4
    TCP 192.168.1.65:2869 speedtouch:26917 CLOSE_WAIT 4
    TCP 192.168.1.65:2869 speedtouch:27578 CLOSE_WAIT 4
    TCP 192.168.1.65:50509 speedtouch:http CLOSE_WAIT 5908
    TCP 192.168.1.65:51015 speedtouch:http CLOSE_WAIT 5908
    TCP 192.168.1.65:52477 speedtouch:http CLOSE_WAIT 5908
    TCP 192.168.1.65:53244 speedtouch:http CLOSE_WAIT 5908
    TCP 192.168.1.65:53661 speedtouch:http CLOSE_WAIT 5908
    TCP 192.168.1.65:54159 speedtouch:http CLOSE_WAIT 5908
    TCP 192.168.1.65:56581 92.31.236.41:http ESTABLISHED 5908
    TCP 192.168.1.65:56585 92.31.236.27:http TIME_WAIT 0
    TCP 192.168.1.65:56587 92.31.236.56:http ESTABLISHED 5908
    TCP 192.168.1.65:56589 92.31.236.11:http ESTABLISHED 5908
    TCP 192.168.1.65:56653 92.31.236.11:http ESTABLISHED 5908
    TCP 192.168.1.65:56655 92.31.236.11:http ESTABLISHED 5908
    TCP 192.168.1.65:56777 92.31.236.51:http ESTABLISHED 5908
    TCP 192.168.1.65:56779 ww-in-f155:http ESTABLISHED 5908
    TCP 192.168.1.65:56803 92.31.236.9:http ESTABLISHED 5908
    TCP 192.168.1.65:56831 92.31.236.51:http ESTABLISHED 5908
    TCP 192.168.1.65:56856 vps:http TIME_WAIT 0
    TCP 192.168.1.65:56875 vps:http TIME_WAIT 0
    TCP 192.168.1.65:56879 vps:http TIME_WAIT 0
    TCP 192.168.1.65:56943 vps:http TIME_WAIT 0
    TCP 192.168.1.65:56950 ww-in-f167:http ESTABLISHED 5908
    TCP 192.168.1.65:56951 ww-in-f167:http ESTABLISHED 5908
    TCP 192.168.1.65:56959 vps:http TIME_WAIT 0
    TCP 192.168.1.65:57025 vps:http TIME_WAIT 0
    TCP 192.168.1.65:57035 vps:http TIME_WAIT 0
    TCP 192.168.1.65:57037 vps:http TIME_WAIT 0
    TCP 192.168.1.65:57039 vps:http TIME_WAIT 0
    TCP 192.168.1.65:57057 vps:http TIME_WAIT 0
    TCP 192.168.1.65:57108 vps:http TIME_WAIT 0
    TCP 192.168.1.65:57133 vps:http TIME_WAIT 0
    TCP 192.168.1.65:57141 vps:http TIME_WAIT 0
    TCP 192.168.1.65:57145 vps:http TIME_WAIT 0
    TCP 192.168.1.65:57147 vps:http TIME_WAIT 0
    TCP 192.168.1.65:57149 vps:http TIME_WAIT 0
    TCP 192.168.1.65:57151 vps:http TIME_WAIT 0
    TCP 192.168.1.65:57153 vps:http TIME_WAIT 0

    All I'm doing is running Firefox, all apps closed and nothing else running.

    Looks very bad to me.
     
    Certifications: 70-270, 70-290, 70-291
    WIP: None, but learning SEO/SEM

Share This Page

Loading...