Hi, I am using a handy tool called Netstat Agent that shows all incoming/outgoing port connections. I am seeing this pop up every few minutes;
Port - tcp
Local address 192.168.1.X (my server)
Local Port - msolap-ptp2
Remote Address - PC-20050101010039 (no such workstation in my Active Directory)
Remote Port - sql-net
Process - svchost.exe
Country - China
Then almost immediately, I get a second report showing this:
Port - tcp
Local address 192.168.1.X (my server)
Local Port - 2726
Remote Address - 119.144.44.21 (no such IP address in my network)
Remote Port - 7000
Process - svchost.exe
SYMSENT
Country - China
Now, my svchost is supposedly infected with a trojan. I posted this in another forum but am now trying to see what effect it is having.
Port - tcp
Local address 192.168.1.X (my server)
Local Port - msolap-ptp2
Remote Address - PC-20050101010039 (no such workstation in my Active Directory)
Remote Port - sql-net
Process - svchost.exe
Country - China
Then almost immediately, I get a second report showing this:
Port - tcp
Local address 192.168.1.X (my server)
Local Port - 2726
Remote Address - 119.144.44.21 (no such IP address in my network)
Remote Port - 7000
Process - svchost.exe
SYMSENT
Country - China
Now, my svchost is supposedly infected with a trojan. I posted this in another forum but am now trying to see what effect it is having.