Windows 7 Forums

Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: How do I work out who connects to what application?

02 Dec 2009   #1
Bernard46

Windows 7 Home Premium 64 bit
 
 
How do I work out who connects to what application?

I have Win 7 Home Premium and I run Netgadget which tells me amongst other things what active connections there are on my system at the moment. I have often been curious about this information and wondered about how legitimate some of these connections are.

For instance right now I have a connection established to IP address 62.103.65.80 and netGadget says this is "dulac--r.static.otenet.gr". If I do a Whois search on the IP address I'm told it belongs to OTENET who are "Multiprotocol Service Provider to other ISP's and End Users located in Greece and having nodes in 63 cities".

Now I have no reason to believe this isn't a genuine site, but to the best of my knowledge there is no reason why I should have any connection right now to a site in Greece. I have my Hotmail account open and 2 IE tabs open to WHOIS and this forum. In addition I have several other gadgets open to the BBC, the UK Met office, Airmiles (a UK rewards company) and Skype.

So my question is does anyone know how I might track down which application on my system is holding the connection to the OTENET user?

By the way whilst I was writing this entry the Greek connection went away and I now see I have a connection to a site in Russia (83.149.3.64 ip-83-149-3-64.nwgsm.ru on port 57104) - I'm getting quite worried (paranoid, even) about these even though I have a good firewall etc all up to date.


My System SpecsSystem Spec
.

02 Dec 2009   #2
Jacee
Microsoft MVP

Windows 7 Ultimate 32bit SP1
 
 

Nwgsm.ru - Nw Gsm
Are you downloading anything? It could also be just a cyberspace ping.
My System SpecsSystem Spec
02 Dec 2009   #3
chev65

Windows 7 Ult, Windows 8.1 Pro,
 
 

Wireshark is pretty good at this sorta thing.
Wireshark Go deep.
My System SpecsSystem Spec
.


02 Dec 2009   #4
dmex

 

Quote   Quote: Originally Posted by Bernard46 View Post
So my question is does anyone know how I might track down which application on my system is holding the connection to the OTENET user?
Hi Bernard,

A tool I develop called Process Hacker should do exactly what you need, You can grab it from here: http://www.sevenforums.com/projects/...esshacker.html

Just click the network tab to view all processes network activity, you can also right-click a connection and ping/tracert/whois the connection directly from PH.
If you spot any processes with suspicious network connections, right-click them on the Processes tab and goto Miscellaneous > Upload to VirusTotal and have that executable scanned by over 30 different anti-virus engines

(FYI: The latest versions don't have four tabs, this does since Im working on a new interface )

How do I work out who connects to what application?-ph.jpg

Hope it helps

Steven


My System SpecsSystem Spec
03 Dec 2009   #5
Bernard46

Windows 7 Home Premium 64 bit
 
 
Fantastic

That's a great tool Steven - just what I needed and way beyond what I was expecting. You have yourself a donation - not a lot, but enough to buy yourself a beer or two when the sun gets too hot down there.

Can I make one suggestion? How about allowing a choice of colour coding based on the state of network connections (ala Process view) - say pastel shades which could be permanent (not go away after a few seconds) to enable one to monitor estblished or listening etc?

regards, Bernard
My System SpecsSystem Spec
03 Dec 2009   #6
torrentg

7600.20510 x86
 
 

From a command prompt:

netstat -abno

Wireshark is very good too. Process Hacker seems like a cool deal, although I never used it.
My System SpecsSystem Spec
Reply

 How do I work out who connects to what application?




Thread Tools





Similar help and support threads
Thread Forum
Sudden BSOD - no connection to any application nor type of work.
Hello, I have a Lenovo B5400, I have had problems since I bought it with sudden BSOD's , I cannot find any link to what causing this. Ive tried the following: Updating BIOS to the newest available Updating all drivers, and removing unnecessary bloatware from Lenovo Running a recalibration of...
BSOD Help and Support
cmd.exe application error - application was unable to start correctly
cmd.exe application error - application was unable to start correctly (0x0000142). Click ok to close the application Anyone know why it happened? I got this error when I tried to restart to install an update. However, in windows update, it showed I had nothing to update. There was the little...
General Discussion
Avoiding '<application name> is not a valid Win32 application' error.
OK, this is admittedly a strange one... I have used an old (probably a 16-bit) application as my time synchronizer this I've used for quite some time. Its name is TimeRC, and is a great synchronizer as it tracks moon phases along with the time (from selectable, multiple potential time servers)....
General Discussion
System Restore doesn't work: "rstrui.exe - application error"
My Win 7x64 desktop was off for several days, with the console unplugged. Upon first start up today, I was prompted to update the AMD driver to Catalyist 12.10, which I did. It seemed to have an effect on another app that I wanted to reverse, so I ran System Restore to right before the computer...
Backup and Restore
I disabled application info and application update in services.msc
And now I am so screwed. I can't even open services.msc, I can't install an update, I can't run updates and I can't re enable anything because I can't get into services to do it. Please don't say system restore because I disabled it. If you say get a mac, then yes, I agree!:D
BSOD Help and Support
Netbook connects at home but not at work?
Hi I have searched the forums to find an answer but have had no luck.... I have a HP netbook that connects fine wirelessly at home but when I try to connect at work I get a message saying "invalid ip configuration" I have used the internet connection before but this has only just...
Network & Sharing

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 16:37.

Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App