Find processes the source port in XP

Does anyone know how to find out what process/program is tuned to a certain port on a PC running XP? Or if not, how to connect the use of ports by processes and programs. Here, this is why I need:

Here we have a rule that all Internet access must go through a HTTP proxy. Our firewall blocks any attempt to directly access the Internet.

I see the firewall drop some HTTP access. These usually consist of three connection attempts: the first, the first retry after 3 seconds and the second to try again after 6 seconds, then it gives up. This model has become so familiar, I guess this is the standard behavior of Microsoft TCP. These access occur, for example, when a web page contains Java which isn't taking proxy supported.

Now I have a PC that is much more persistent. Instead of giving up after three attempts, he waits another 12 seconds, takes a new source port and try again. Throughout the day, he repeats this try-3-try-6-try-12-change-try-3-model... Try as I might, I just can't understand what process on the computer generates these connection attempts. The target IP address is variable, but it still belongs to Akamai - which does not really help to identify the offending program. The target port is always 80/tcp.

My fear is that the PC is trying to participate in a DDoS on Akamai.

What I want is a tool that will tell me what program generates these packages, preferably within 21 seconds it takes for it to expire and change the source port.

Can someone help me?

Kevin Dorrell

Luxembourg

You can try one of these URL (there is a link at the end of the first to the second):

http://www.winnetmag.com/article/articleid/39955/39955.html

http://www.sysinternals.com/ntw2k/source/TCPView.shtml

Good luck!

Tags: Cisco Security

Similar Questions

  • How to find all the OBIEE ports in GNU / Linux

    How to find all the OBIEE ports in GNU / Linux?

    Thank you
    Jay.

    Hi Jay,.

    Did you check that?

    http://blog.Trivadis.com/b/andreasnobbmann/archive/2009/02/26/ports-used-in-OBIEE.aspx

    Rgds,
    DpKa

  • Uninstalling Java problem: "the installation source for this product is not available. Make sure the source exsists and that you can access. »

    Hi, I'm having a little trouble trying to uninstall Java, so I can reinstall it. I get this error message:

    "The installation source for this product is not available. Make sure the source exsists and that you can access. "When I try to find the installation package to uninstall. I'm the only person on my laptop Windows Vista Ultimate, and I am the administrator on the computer. I can't find something when I search for it during the uninstallation. When I go on ' computer > disc Local (c) > Progam Files > Java' I see a whole bunch of files, but I can't find the installation package with the 'Installation .msi package' at the end. I find 'install.rdf '.

    I was wondering if anyone can help find me the source for Java, so I can uninstall and reinstall so my Java work properly.

    Java has been uninstalled before when Elluminate program my brother (online meetings of his school) and I guess when he was relocated something went wrong, but I have 2 Java programs. One by one by Sun Microsystems Inc. and Oracle and I am trying to install are Sun Microsystems Inc..

    Help, please!

    Corky (Corkster)

    Java issues are best handled by people in the Java forum:

    http://Java.com/en/download/help/index_installing.XML?user_os=Vista

    http://Java.com/en/download/help/index.XML For the benefits of others looking for answers, please mark as answer suggestion if it solves your problem.

  • I want to detect and use the video entering via the HDMI port on the computer. I was told the HDMI port was not set, but I can't seem to find the signal or the video.

    I want to detect and use the video entering via the HDMI port on the computer. I was told the HDMI port was not set, but I can't seem to find the signal or the video.  Any suggestions?

    As Tom SC replied, you must contact the company that manufactured your computer.  In general, the ports HDMI on most computers is an out-bound port, send video / digital audio output.

    You should probably use a video capture card that can capture from HDMI source,

  • Satellite A30: Can not find the COM ports when trying to query the modem

    Hello.
    I have satellite A30 and I reinstall windows xp at home, but I can't find any com port whenever I try to query the modem the display hardware confilct, but in Device Manager no sign of error/confilct, I did everything what I can.
    Add the port,
    Add more then 1 port
    disable the printer port
    change the printer port
    Reinstall derver modem,
    In short, I've done everything I can. its always show (! yellow) mark.if I add the port and if I remove the port and there is no sign of error.
    If someone help me to solve this problem a little,
    regared.
    MGK.

    Post edited by: mghouskhan

    The modem uses a virtual com port. It s not a real port.
    I wonder why it usually happens after the installation of the new operating system, you must install drivers Toshiba together in the right order
    Installing the chipset utility is important

    The modem driver should do the work and you n t need to activate com ports
    Please choose the right side of the page of the Toshiba driver modem driver after installing the OS correctly. I think that's the key

  • Photosmart HP 6510 - can't find the USB port to connect to the computer. It is right in front of my face?

    Photosmart IHP 6510 - can't find the USB port to connect to the computer. It is right in front of my face? I can't find a diagram online. do not have wireless capability. With the help of MacPro with Snowleopard.Thanks.

    Hello

    The usb port is not #22. as seen in the picture. It's in the back of the printer on the side right hiand.

    Best regards

    ERICO

  • How can I find (and remove) the source of this irritation

    With irritating regularity, a dialog box appears on my screen that says "sh: / usr/bin/lockfile: no such file or directory (127) '."  How can I find and eliminate the source of this thing?

    Please update "SuperDuper" to the current version, or delete it if you don't need.

  • Find the source of the massive compilation errors

    Hi all

    I am trying to determine the source of the errors on a generation of RT and therefore a massive to remove compilation live broken and unused running the project is important enough, so the output from compilation of mass is large.  One thing I am struggling with trying to determine * why * an error.  For example, I get a few CompileFile: error 7, which indicates that something is looking for a file that does not exist.  How can I determine which leader is the search for the missing file?  I've attached the output from the massive compilation, but also a python file that I use to interpret the files to find errors.

    On another note about this file - what I'm doing with the release of Bad VI/Subvi?  It almost seems as if he is allowed to disregard this output.

    Any help is welcome. At soon cirrus

    (okay, that I'm lame but you are not allowed to attach python so here is the script below)

    FName = "mass_compile_log_10202016.txt."
    with open (fname) as f:
    line = f.readline () .strip)
    I = 0 # track the error number
    j = 0 # track the line number
    # Only goes to find the first 30 records
    <>
    s = line [0:3]
    j += 1

    # Not interested in a failure to load, search or bad messages VI...
    otherwise (s == ' # ' or s == 'ISP' or s == 'Sea' or s == "(C:"):
    I += 1 # increment the error
    Print (STR (i) + "[" + str (j) + ' "].") + line)
    line = f.readline () .strip)
    f.Close)

    Thank you, udka.

    In fact, I came across the easy solution (although there is always only one instance dangling out there that I can't explain).  Simply

    1. Create a new project
    2. Add a snapshot of the file you want to compile mass

    If you lack the screws in the massive compilation, these will appear in the missing build dependencies and you can know who is dependent on them.

    About the wrong screw - it is difficult to know if this could be due to the fact that the compilation of mass occurs on local and he can't find the RT del VI (since it is not on the RT system).  Whatever it is, I'm building again to see if I have an exe works on the RT system (the reason why I was making the massive compilation has been a failure on the exe - not when you build, but when running).  I have attached my log of recent massive compilation for the comparison of what I started with.

  • With the help of VISA can not find the com port

    I use visa read but cannot find any com port in Windows 7.

    How can I find the com port in Windows 7?

    Windows 7 is not released. A version of LabVIEW for windows 7 is not released. A version of NI-VISA for windows 7 is not released. Wait until MS releases windows 7. Then wait tile view deleted OR made available versions of LabVIEW and NI-VISA that work with windows 7.

  • Windows 95, saying that it cannot find the Source Word 95 path

    Cannot find the Source Word 95 path

    In what context you get this error, and what is the exact wording of the error message?

  • Pavilion hpe-112y: I have a hp Pavilion hpe-112y and would like to find the firewire port

    I have a hp Pavilion hpe-112y and would like to find the firewire port

    Looking at the back - #4 is the firewire port

  • I can't uninstall Silverlight 1 (1.0.30109.0) because the system can not find the source. How can I get it so I can install version 4?

    We strive to produce a report required by the State of California, which requires us to download Silverlight 4. The error message says you need to uninstall all previous versions of Silverlight, which there is one on the system: 1 of Silverlight (1.0.30109.0). The last update 29/01/11 at 12:38, an automatic update. When I go into "Control Panel" "Add/Remove Programs" find Microsoft Silverlight 1 and hit 'Delete' another error message tells me that it cannot find the source. I did a search on the hard drive and it came with c:/229fe816f9d5ed50e95460. I can access this file or delete it. How can I get Silverlight 1 out of this machine if I install Silverlight 4?

    Hello

    Your Windows XP question is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the IT Pro audience on the Silverlight forums. Please post your question in the below link:
    http://forums.Silverlight.NET/forums/13.aspx

    I hope this helps.

  • What is the relationship between the source code (LKS) file and the process file (L4P)?

    I know that Lookout produces a file of source code with an LKS extension when you save a file to process.  Can someone explain the relationship between the two files, especially while the (L4P) process is running?

    1. Is this just a backup file can be recompiled in a process file?
    2. A file corrupt LKS cause strange problems with operation process file?

    I currently have a very strange intermittent behavior with a process file run.  I first thought that the problem was associated with my Fieldpoint and/or their configuration modules.  Since then, I found that my process file has a file corrupt LKS.  I repaired and recompiled my LKS file to a new file to process.  I still don't know if I have solved the problem or not.  So, the problem is intermittent, I did that about 20-30 SECONDS to resolve the problems there before he goes.  Then he can not show up again for another 2-3 days.

    The .lks file is just the source code of your process. It can be opened by a different version of lookout, but does not have the .l4p file.

    The .lks file is not be used while a process is running. Lookout does not read the file more after his execution. So it should not affect the running process.

    What kind of problem, is it?

  • Where can I find the ability to change the com port settings in Windows 7

    Where can I find the ability to change the com port settings in Windows 7

    Port, Device Manager, select comport, right click, properties, Port settings

  • How to find the source of the MSIfe * .log files - windows 7

    In the windows/temp directory, I have more than 100 GB of logs with the syntax of MSIfe *. Each file is about 7 257 KB in size.

    Any suggestions on how I can determine the source of these files?

    Thank you

    Brad

    +++++++++++++++++++++++

    HERE ARE THE FIRST LINES OF ONE OF THE FILES:

    = Registration began: 19/06/2012-13:57:59 Build type: SHIP UNICODE 5.00.7601.00 appeal process: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe =.
    MSI (c) (14:84) [13:57:59:458]: Resetting cached policy values
    MSI (c) (14:84) [13:57:59:458]: value of strategy Machine 'Debug' is 0
    MSI (c) (14:84) [13:57:59:458]: * RunEngine:
    Product: {3D8DBCCD-FE59-3648-A084-6D2F78351F9E}
    Action:
    Command line:
    MSI (c) (14:84) [13:57:59:459]: Client and UI is none or basic: full installation running on the server.
    MSI (c) (14:84) [13:57:59:459]: grabbed execution mutex.
    MSI (c) (14:84) [13:57:59:461]: Cloaking enabled.
    MSI (c) (14:84) [13:57:59:461]: attempt of activation of all disabled privileges before calling install on server
    MSI (c) (14:84) [13:57:59:463]: meter is incremented to disable the stop. Counter after increment: 0
    MSI (s) (48:18) [13:57:59:466]: running the installation inside the multi-package transaction {3D8DBCCD-FE59-3648-A084-6D2F78351F9E}
    MSI (s) (48:18) [13:57:59:466]: grabbed execution mutex.
    MSI (s) (48:B8) [13:57:59:467]: Resetting cached policy values
    MSI (s) (48:B8) [13:57:59:467]: value of strategy Machine 'Debug' is 0
    MSI (s) (48:B8) [13:57:59:467]: * RunEngine:
    Product: {3D8DBCCD-FE59-3648-A084-6D2F78351F9E}
    Action:
    Command line:
    MSI (s) (48:B8) [13:57:59:467]: value of strategy Machine 'DisableUserInstalls' is 0
    MSI (s) (48:B8) [13:57:59:483]: SRSetRestorePoint is ignored for this transaction.
    MSI (s) (48:B8) [13:57:59:486]: dialogue of end not activated
    MSI (s) (48:B8) [13:57:59:486]: ==> C:\Windows\Installer\495c6.msi original packaging
    MSI (s) (48:B8) [13:57:59:486]: we're running out of ==> C:\Windows\Installer\495c6.msi package
    MSI (s) (48:B8) [13:57:59:501]: APPCOMPAT: substitution of uninstall flags found.
    MSI (s) (48:B8) [13:57:59:501]: APPCOMPAT: uninstall VersionNT found override.
    MSI (s) (48:B8) [13:57:59:501]: APPCOMPAT: substitution of uninstall ServicePackLevel found.
    MSI (s) (48:B8) [13:57:59:502]: APPCOMPAT: looking for entry with ProductCode '{3D8DBCCD-FE59-3648-A084-6D2F78351F9E}' appcompat database
    MSI (s) (48:B8) [13:57:59:502]: APPCOMPAT: no matching ProductCode found in the database.
    MSI (s) (48:B8) [13:57:59:505]: MSCOREE not loaded loading copy from system32
    MSI (s) (48:B8) [13:57:59:508]: value of strategy Machine 'DisablePatch' is 0
    MSI (s) (48:B8) [13:57:59:508]: value of strategy Machine 'AllowLockdownPatch' is 0
    MSI (s) (48:B8) [13:57:59:508]: value of strategy Machine 'DisableLUAPatching' is 0
    MSI (s) (48:B8) [13:57:59:508]: value of strategy Machine 'DisableFlyWeightPatching' is 0
    MSI (s) (48:B8) [13:57:59:508]: APPCOMPAT: looking for entry with ProductCode '{3D8DBCCD-FE59-3648-A084-6D2F78351F9E}' appcompat database
    MSI (s) (48:B8) [13:57:59:509]: APPCOMPAT: no matching ProductCode found in the database.

    Here are the comments Windows log files install.

    Detailed logging must have been lit at some point.

    There's a Fixit turn off in this article here:

    http://support.Microsoft.com/kb/2545723

Maybe you are looking for

  • Sound went along with internal speakers?

    Hello, I use a MacBook Air laptop and my sound no longer works. When I go and check the internal speakers of available devices is not available sound remotely right LogMeIn, which I have no idea what it is, and the type is peripheral network. The out

  • Return policy for Macbook

    Hello! I have a 12 "256 GB Macbook computer and I am not at all happy with it. It is extremely slow - cannot manage basic tasks in the finder, internet shuts down constantly on it, the keys get stuck and the trackpad mess up all the time and the batt

  • import photos from the iPod touch to mac

    Plugged my iPod touch Mac - and unable to highlight or show pictures to import on Mac.  It happened only on connect initial to iPod for Mac, but if you did not transfer the pictures so I can't get the photos recognized again by simply plugging in the

  • Venue Pro 8 (5855) Auto rotation disappeared after update

    There is some automatic updates - between Microsoft and Dell - and now there is no "rotation" button in the Win10 Panel and auto rotation no longer - manual only. I manually installed all the drivers available from the Dell downloads section. How to

  • Troubleshooting problems of vodafone UK network.

    Hello I would really appreciate if someone on this forum could help me to solve the problems of network on Vodafone UK. The same code works very well for US & Canada users. I've solved the problem with Novarris transcoder by setting the cache * http