Can you help me understand what this SYN_SENT means from a security standpoint on a home PC?
WINDOWSXP_SP2> netstat -a -n -b
Active Connections Proto Local Address Foreign Address State PID TCP 192.168.0.101:1058 63.236.111.222:80 SYN_SENT 912 C:\WINDOWS\system32\WS2_32.dll C:\WINDOWS\System32\WINHTTP.dll -- unknown component(s) -- [svchost.exe]
Here is what I tried ineffectively to debug so far. Can you help me debug more?
Upon bootup, with no web browsers running, I ran netstat -a -n -b and saw this SYN_SENT issue hanging at the SYN_SENT line. After a minute or two the netstat completed as shown above. .... I first looked up 63.236.111.222 on
formatting link
but it didn't know who that was. .... I then looked it up on
formatting link
which gave me THREE owners for the same IP address, none of which I recognize and certainly none I purposefully communicated with. .... I looked up tcp/ip port 1058 and found it was registered to "nim" but there is not much information about this port anywhere I could find. .... Wikipedia has almost nothing on this special nim port 1058
formatting link
.... The Microsoft Windows XP netstat doesn't even -list- a command called SYN_SENT (it lists SYN_SEND)
formatting link
.... However, other netstat manpages say " The socket is actively attempting to establish a connection. " but what does THAT tell me?
formatting link
.... A search for winhttp.dll & WS2_32.DLL is wierd. I couldn't find a DESCRIPTION for these dlls. That's wierd.
formatting link
Where do we find descriptions of dlls?
Some housekeeping notes .... I am running the latest Windows XP Service Pack 2
formatting link
.... I ran the Microsoft Malicious Software Removal Tool but it didn't find anything suspicious
formatting link
.... My avast antivirus doesn't list anything suspicious like Blaster or anything like that. .... I don't even -see- the connection in my sygate personal firewall traffic logs .... I'm wireless on a two PC home network
I'm flailing around ineffectively trying to figure this out so now I'm asking you for help.
Can you give me the straight scoop on how to stop this problem?
Thanks, .....Pam
read more and respond »
Posted 5 years ago
by Pam
in Networking Firewalls
Report misuse