<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:s="http://www.techrepublic.com/search" xmlns:dc="http://purl.org/dc/elements/1.1/"  xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
    <title><![CDATA[Questions & Answers: Rogue Process? ]]></title>
    <link><![CDATA[http://www.techrepublic.com/forum/questions/101-212242/rogue-process]]></link>
    <atom:link rel="hub" type="application/rss+xml" href="http://pubsubhubbub.appspot.com/" />
    <atom:link rel="self" type="application/rss+xml" href="http://www.techrepublic.com/forum/questions/101-212242/rss" />

    <description><![CDATA[]]></description>
    <language>en-us</language>
    <lastBuildDate>2013-05-18T18:26:43-07:00</lastBuildDate>
             

    <item>
        <title><![CDATA[Port 129]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/questions/101-212242/rogue-process?#msg-2177515]]></link>
        <description><![CDATA[Maybe someone owned your server and had that process running for probing other networks and systems.  Port 129 is apparently used by Password Generator Protocol.  The daily statistics are available from http://www.incidents.org/port.html?port=129.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/questions/101-212242/rogue-process?#msg-2177515]]></guid>
        <dc:creator><![CDATA[Toivo Talikka]]></dc:creator>
        <pubDate>Wed, 21 Feb 2007 17:38:59 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Rogue Process?]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/questions/101-212242/rogue-process?#msg-2177520]]></link>
        <description><![CDATA[Has anyone ever come across the sansv.exe process?  We found it on our SQL Server (Win 2K3 - fully patched) today after it crippled our internal network with packet traffic.  Killing the process seemed to directly relate to a huge drop in server communications (back to normal), but I can't seem to find any information on what it is or where it came from.It seemed to be generating a lot of traffic over a variety of ports &gt;2500 all destined for a series of seemingly random IP addresses (all outside our network) on Port 129.Has anyone ever seen this?  Is this an exploit?  Bug?  New Feature?  Compromise?]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/questions/101-212242/rogue-process?#msg-2177520]]></guid>
        <dc:creator><![CDATA[blarman]]></dc:creator>
        <pubDate>Wed, 21 Feb 2007 17:03:10 -0800</pubDate>
    </item>
    </channel>
</rss>

