Thanks for the help.
I have tried to make a new account and it also does the same
(generating the traffic)...
What I then found new is that actually the first logged-in user always
fine, but the second and the third are not. When the second and third
user logged-in, the winlogon.exe for each of them start some TCP
traffic with some unknown web sites and last forever.
BTW, I have done extensive cleanup using varies anti-virus and anti-
spyware softwares...
I really need help on this one...is there some configuration I missed?
John
Here is the traffic log from firewall. It repeats itself forever...
#Version: 1.5
#Software: Microsoft Windows Firewall
#Time Format: Local
#Fields: date time action protocol src-ip dst-ip src-port dst-port
size tcpflags tcpsyn tcpack tcpwin icmptype icmpcode info path
2007-11-11 21:58:59 CLOSE TCP 192.168.1.100 85.17.99.232 2514 80 - - -
- - - - - -
2007-11-11 21:58:59 OPEN TCP 192.168.1.100 85.17.99.233 2524 80 - - -
- - - - - -
2007-11-11 21:59:00 OPEN TCP 192.168.1.100 85.17.99.232 2525 80 - - -
- - - - - -
2007-11-11 21:59:00 CLOSE TCP 192.168.1.100 85.17.99.232 2523 80 - - -
- - - - - -
2007-11-11 21:59:01 CLOSE TCP 192.168.1.100 85.17.99.233 2524 80 - - -
- - - - - -
2007-11-11 21:59:01 CLOSE TCP 192.168.1.100 85.17.175.232 2521 80 - -
- - - - - - -
2007-11-11 21:59:01 CLOSE TCP 192.168.1.100 85.17.175.233 2509 80 - -
- - - - - - -
2007-11-11 21:59:02 OPEN TCP 192.168.1.100 85.17.175.233 2526 80 - - -
- - - - - -
2007-11-11 21:59:02 OPEN TCP 192.168.1.100 85.17.175.232 2527 80 - - -
- - - - - -
2007-11-11 21:59:02 OPEN TCP 192.168.1.100 85.17.99.233 2528 80 - - -
- - - - - -
2007-11-11 21:59:02 OPEN TCP 192.168.1.100 85.17.99.233 2529 80 - - -
- - - - - -
2007-11-11 21:59:03 CLOSE TCP 192.168.1.100 85.17.99.233 2528 80 - - -
- - - - - -
2007-11-11 21:59:03 OPEN TCP 192.168.1.100 85.17.175.232 2530 80 - - -
- - - - - -
2007-11-11 21:59:03 CLOSE TCP 192.168.1.100 85.17.175.232 2527 80 - -
- - - - - - -
2007-11-11 21:59:03 CLOSE UDP 192.168.1.100 70.48.150.42 1088 31981 -
- - - - - - - -
2007-11-11 21:59:03 DROP UDP 192.168.1.1 239.255.255.250 1900 1900 280
- - - - - - - RECEIVE
2007-11-11 21:59:03 DROP UDP 192.168.1.1 239.255.255.250 1900 1900 298
- - - - - - - RECEIVE
2007-11-11 21:59:03 DROP UDP 192.168.1.1 239.255.255.250 1900 1900 352
- - - - - - - RECEIVE
2007-11-11 21:59:03 DROP UDP 192.168.1.1 239.255.255.250 1900 1900 344
- - - - - - - RECEIVE
2007-11-11 21:59:03 DROP UDP 192.168.1.1 239.255.255.250 1900 1900 274
- - - - - - - RECEIVE
2007-11-11 21:59:03 DROP UDP 192.168.1.1 239.255.255.250 1900 1900 316
- - - - - - - RECEIVE
2007-11-11 21:59:03 DROP UDP 192.168.1.1 239.255.255.250 1900 1900 348
- - - - - - - RECEIVE
2007-11-11 21:59:04 DROP UDP 192.168.1.1 239.255.255.250 1900 1900 294
- - - - - - - RECEIVE
2007-11-11 21:59:04 DROP UDP 192.168.1.1 239.255.255.250 1900 1900 346
- - - - - - - RECEIVE
2007-11-11 21:59:04 DROP UDP 192.168.1.1 239.255.255.250 1900 1900 340
- - - - - - - RECEIVE
2007-11-11 21:59:04 DROP UDP 192.168.1.1 239.255.255.250 1900 1900 272
- - - - - - - RECEIVE
2007-11-11 21:59:04 DROP UDP 192.168.1.1 239.255.255.250 1900 1900 315
- - - - - - - RECEIVE
2007-11-11 21:59:04 DROP UDP 192.168.1.1 239.255.255.250 1900 1900 345
- - - - - - - RECEIVE
2007-11-11 21:59:04 CLOSE TCP 192.168.1.100 85.17.99.232 2525 80 - - -
- - - - - -
2007-11-11 21:59:04 OPEN TCP 192.168.1.100 85.17.99.232 2531 80 - - -
- - - - - -
2007-11-11 21:59:04 CLOSE TCP 192.168.1.100 85.17.175.232 2520 80 - -
- - - - - - -