Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Microsoft-ds (445) 1

Status
Not open for further replies.

logicacmg000

Technical User
Sep 30, 2004
75
0
0
US
Service: microsoft-ds (445)

I am getting a lot of traffic on my log server being generated from a singlePC on our network using the service microsoft-df.

I have googled around a found various things on it, just wanted to double check here if this is okay or a virus infected machine. Thanks.
 
best check symantec or mcafee for any virous alerts on port 445, but normally AD uses port 445 to connect the server/client in an AD domain, 445 is simple message block and is used along side some of the netbios ports to map nodes on the network.

if you are not running an AD domain simply turn it off on the pc.
 
Like WatchguardMonkey said 445 is definitly a known port for viruses. Are you getting a broadcast on this port from the single PC? Are there outbound connections for this? Possibly a DDOS or DOS type attack.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top