Sunday, February 5, 2006

wormed again?

I was going over the news sites when I saw this little popup box by the system tray.. seems that my antivirus has detected an outgoing pop3 connection (port 110) to some unknown and unfamiliar hosts. AVG checks for outgoing pop and smtp connections in order to detect email viruses..

I'm guessing that this would be normal except that I'm not checking any emails... and I don't have any email clients on.. no outlook/ thunderbird/ eudora, etc.. I checks my gmail via the web gui and that's it..

hmmm have I been wormed again?

this time I'm prepared with my tools.
I have packet capturing utility loaded , with specific filtering set to capture port 110 data.. I'm going to leave it overnight and analyze the packet data tomorrow...
I'll let you guys know on the outcome..

No comments:

Post a Comment