I'm looking to talk to anyone willing to help, I have already visited lots of forums and done the laundry list. I'm not looking for someone to fix my problem, I just want to gather some intel.
History: I start getting a lot of
Since I run a server, I figure I'd dump a pcap and look at it with wireshark. IT was a bit overwhelming but I saw a lot of google hits. So I then fund a nifty tool online and regrettable, but willingly uploaded my data. It did some analysis and shows 3m uploaded to google in just a short time.
The green is a PC on my network, and yellow is google. The blue is amazon cloud services, that may make a bit of sense, but What the heck is sending so much data to google. I ran this PC thru ever virus scanner I have collected over the years, and its spotless. I run a firmware and monitored traffic but nothing was called out. Any idea what I can do to figure out the responsible app?
netstat shows tons of ports open
if I follow the PID it leads to the svchost, so not much help I think?
and saw this
I do use RPC but its not open.
I really just want to figure out why all of these 5k ports are open. I'm sure that is where the data is being set, they seem to be probing random servers even some local PCs on my network.
History: I start getting a lot of
Since I run a server, I figure I'd dump a pcap and look at it with wireshark. IT was a bit overwhelming but I saw a lot of google hits. So I then fund a nifty tool online and regrettable, but willingly uploaded my data. It did some analysis and shows 3m uploaded to google in just a short time.
The green is a PC on my network, and yellow is google. The blue is amazon cloud services, that may make a bit of sense, but What the heck is sending so much data to google. I ran this PC thru ever virus scanner I have collected over the years, and its spotless. I run a firmware and monitored traffic but nothing was called out. Any idea what I can do to figure out the responsible app?
netstat shows tons of ports open
if I follow the PID it leads to the svchost, so not much help I think?
and saw this
I do use RPC but its not open.
I really just want to figure out why all of these 5k ports are open. I'm sure that is where the data is being set, they seem to be probing random servers even some local PCs on my network.