G
Guest
Hello,
I have experienced 2 crashes of windows XP Pro (I have the corresponding
..dmp log files). The logs of the event viewer showed the below error message:
Event Type: Warning
Event Source: Tcpip
Event Category: None
Event ID: 4226
Date: 12/08/2006
Time: 12:07:36
User: N/A
Computer: VELKY-DELL
Description:
TCP/IP has reached the security limit imposed on the number of concurrent
TCP connect attempts.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 82 10 00 80 ....‚..€
0010: 01 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
Then I checked using netstat and found at that each time I am connected to
my routeur, there are always dozens of connections from my pc:2869 to the
routeur with status TIME_WAIT. It looks like my port 2869 is scanning all
ports of my routeur, as you can see with the below:
C:\Documents and Settings\Velky>netstat -no
Active Connections
Proto Local Address Foreign Address State PID
TCP 192.168.1.65:1034 64.236.46.64:80 CLOSE_WAIT 588
TCP 192.168.1.65:2006 64.12.171.248:143 ESTABLISHED 2496
TCP 192.168.1.65:2869 192.168.1.254:3233 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3234 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3235 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3236 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3237 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3238 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3239 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3240 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3241 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3242 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3243 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3244 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3245 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3246 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3247 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3248 TIME_WAIT 0
TCP 192.168.1.65:3733 64.12.171.248:143 TIME_WAIT 0
C:\Documents and Settings\Velky>netstat -no
Active Connections
Proto Local Address Foreign Address State PID
TCP 192.168.1.65:1034 64.236.46.64:80 CLOSE_WAIT 588
TCP 192.168.1.65:1290 64.12.180.149:143 TIME_WAIT 0
TCP 192.168.1.65:1293 64.12.180.149:143 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3354 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3355 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3356 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3357 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3358 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3359 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3360 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3361 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3362 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3363 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3364 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3365 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3366 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3367 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3368 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3369 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3370 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3371 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3372 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3373 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3374 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3375 TIME_WAIT 0
C:\Documents and Settings\Velky>
The problem is that I didn't manage to locate the program responsible for
this as the PID responsible seems to be 0, which is the PID for the System
Idle process in the task manager.
Of course, I have ran all the online AV scans in addition to my up-to-date
Norton AV, I also have McAffee Firewall, and Norton Worm Protection activated
all the time... Also I have a laptop that I connect through my wireless
routeur, and it doesn't display the same connection attempts at all.
Would you have an idea please ?
I would much appreciate if someone could kindly help me: plse send me your
suggestions here: mpasc9(At)aolnospam(dOt)com
Thanks
Pascal
I have experienced 2 crashes of windows XP Pro (I have the corresponding
..dmp log files). The logs of the event viewer showed the below error message:
Event Type: Warning
Event Source: Tcpip
Event Category: None
Event ID: 4226
Date: 12/08/2006
Time: 12:07:36
User: N/A
Computer: VELKY-DELL
Description:
TCP/IP has reached the security limit imposed on the number of concurrent
TCP connect attempts.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 82 10 00 80 ....‚..€
0010: 01 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
Then I checked using netstat and found at that each time I am connected to
my routeur, there are always dozens of connections from my pc:2869 to the
routeur with status TIME_WAIT. It looks like my port 2869 is scanning all
ports of my routeur, as you can see with the below:
C:\Documents and Settings\Velky>netstat -no
Active Connections
Proto Local Address Foreign Address State PID
TCP 192.168.1.65:1034 64.236.46.64:80 CLOSE_WAIT 588
TCP 192.168.1.65:2006 64.12.171.248:143 ESTABLISHED 2496
TCP 192.168.1.65:2869 192.168.1.254:3233 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3234 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3235 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3236 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3237 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3238 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3239 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3240 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3241 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3242 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3243 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3244 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3245 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3246 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3247 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3248 TIME_WAIT 0
TCP 192.168.1.65:3733 64.12.171.248:143 TIME_WAIT 0
C:\Documents and Settings\Velky>netstat -no
Active Connections
Proto Local Address Foreign Address State PID
TCP 192.168.1.65:1034 64.236.46.64:80 CLOSE_WAIT 588
TCP 192.168.1.65:1290 64.12.180.149:143 TIME_WAIT 0
TCP 192.168.1.65:1293 64.12.180.149:143 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3354 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3355 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3356 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3357 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3358 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3359 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3360 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3361 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3362 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3363 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3364 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3365 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3366 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3367 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3368 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3369 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3370 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3371 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3372 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3373 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3374 TIME_WAIT 0
TCP 192.168.1.65:2869 192.168.1.254:3375 TIME_WAIT 0
C:\Documents and Settings\Velky>
The problem is that I didn't manage to locate the program responsible for
this as the PID responsible seems to be 0, which is the PID for the System
Idle process in the task manager.
Of course, I have ran all the online AV scans in addition to my up-to-date
Norton AV, I also have McAffee Firewall, and Norton Worm Protection activated
all the time... Also I have a laptop that I connect through my wireless
routeur, and it doesn't display the same connection attempts at all.
Would you have an idea please ?
I would much appreciate if someone could kindly help me: plse send me your
suggestions here: mpasc9(At)aolnospam(dOt)com
Thanks
Pascal