<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Help me find out if someone is spying on my computer</title>
	<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer/</link>
	<description>Comments on Ask MetaFilter post Help me find out if someone is spying on my computer</description>
	<pubDate>Thu, 04 Jan 2007 10:12:46 -0800</pubDate>
	<lastBuildDate>Thu, 04 Jan 2007 10:12:46 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: Help me find out if someone is spying on my computer</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer</link>	
		<description>Can you help me diagnose if someone is spying on my computer? &lt;br /&gt;&lt;br /&gt; I think there is some kind of spyware installed on my computer, and I somewhat suspect that there is an actual person using it to spy on my (as opposed to generic spyware that is sort of a bot sending info about me somewhere).&lt;br&gt;
&lt;br&gt;
(Note, my computer is a Win XP machine)&lt;br&gt;
&lt;br&gt;
I first noticed that sometimes my cursor would jump around kind of suspiciously, jumping often to the start menu location or maybe one of the other corners of the screen.  There are a few other symptoms but no point in going into it here.  I started poking around, starting first with the normal standard tools.  HijackThis, AdAware, Spybot Search and Destroy, etc.  Not much is coming up.&lt;br&gt;
&lt;br&gt;
I do an nmap from a trusted computer on the computer I think is being spied upon.  I do a TCP and UDP scan and here are some select entries:&lt;br&gt;
&lt;br&gt;
1664/udp open|filtered netview-aix-4&lt;br&gt;
1666/tcp open          netview-aix-6&lt;br&gt;
&lt;br&gt;
A quick google search shows that this is usually some kind of network monitoring program.  Note that this doesn&apos;t necessarily mean that&apos;s what is running on that port...  I telnet to that port and I get:&lt;br&gt;
&lt;br&gt;
TTxfiles5server3server220revver5nocasefunprotocol&lt;br&gt;
&lt;br&gt;
No idea what this is supposed to be.  &lt;br&gt;
&lt;br&gt;
Of course, my network is fairly locked down so I don&apos;t think anyone can GET to this port from outside, but I think it might indicate that something nefarious is running, and that nefarious thing might connect from my network to some other computer somewhere.&lt;br&gt;
&lt;br&gt;
There is also something running at port 8080.  8080 is usually a web proxy port but I don&apos;t think I have anything running which would qualify as a web proxy.&lt;br&gt;
&lt;br&gt;
I have a lot of experience with computers and a decent amount of experience with computer security.  I&apos;m hoping someone can help me find out what might be running on my computer (if anything), how to get rid of it, and, to my mind, how to find out who or what it is.&lt;br&gt;
&lt;br&gt;
As sort of a caveat/afterthought... I play poker to supplement my income (it amounts to about 1/4 to 1/3 of my total income) so if someone is watching me, this would be very, very bad, and honestly, I&apos;ve had some reason to believe that someone might be watching me, in this regard.&lt;br&gt;
&lt;br&gt;
I&apos;ve started doing ethernet packet capturing both on the affected machine and on the network as a whole, and I hope to find something in that.  There&apos;s an awful lot of data to go through, though.</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2007:site.54366</guid>
		<pubDate>Thu, 04 Jan 2007 10:08:23 -0800</pubDate>
		<dc:creator>RustyBrooks</dc:creator>
		
			<category>computer</category>
		
			<category>security</category>
		
			<category>spyware</category>
		
	</item> <item>
		<title>By: RustyBrooks</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818507</link>	
		<description>As a side note, is there a reliable way in windows to find out what programs are listening to a given port?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818507</guid>
		<pubDate>Thu, 04 Jan 2007 10:12:46 -0800</pubDate>
		<dc:creator>RustyBrooks</dc:creator>
	</item><item>
		<title>By: b1tr0t</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818525</link>	
		<description>&lt;i&gt;I first noticed that sometimes my cursor would jump around kind of suspiciously, jumping often to the start menu location or maybe one of the other corners of the screen.&lt;/i&gt;&lt;br&gt;
&lt;br&gt;
Try a diferent mouse. Some poorly built optical mice will exhibit eratic behavior like this from time to time. The Microsoft &quot;S+ark&quot; mouse exhibits this behavior with a period of 15-20 minutes.&lt;br&gt;
&lt;br&gt;
Windows XP has enough inherently eratic behavior that it would probably be easy for a skilled hacker or spy to hide among all the noise.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818525</guid>
		<pubDate>Thu, 04 Jan 2007 10:24:21 -0800</pubDate>
		<dc:creator>b1tr0t</dc:creator>
	</item><item>
		<title>By: friedrice</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818526</link>	
		<description>Might not be much help, but when my mouse starting jumping around like that it was because my downstairs neighbor was using the same brand of wireless mouse.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818526</guid>
		<pubDate>Thu, 04 Jan 2007 10:24:46 -0800</pubDate>
		<dc:creator>friedrice</dc:creator>
	</item><item>
		<title>By: Pastabagel</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818537</link>	
		<description>I have a wired/usb optical mouse, and it jumps or moves around on its own as well.  Cleaning the desk under the mouse seems to help (I don&apos;t use a mouse pad).</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818537</guid>
		<pubDate>Thu, 04 Jan 2007 10:29:55 -0800</pubDate>
		<dc:creator>Pastabagel</dc:creator>
	</item><item>
		<title>By: poppo</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818549</link>	
		<description>Like others say, the mouse may not be related, but I might be worried about finding that banner waiting for me.&lt;br&gt;
&lt;br&gt;
Do a Google search for &quot;funprotocol&quot; and you&apos;ll find that it is spyware, according to them.  There may be a funprotocol.dll file you can remove.  Have a look at a few of those results.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818549</guid>
		<pubDate>Thu, 04 Jan 2007 10:35:23 -0800</pubDate>
		<dc:creator>poppo</dc:creator>
	</item><item>
		<title>By: cerebus19</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818552</link>	
		<description>&lt;i&gt;is there a reliable way in windows to find out what programs are listening to a given port?&lt;/i&gt;&lt;br&gt;
&lt;br&gt;
At a command prompt, type:&lt;br&gt;
&lt;br&gt;
netstat -a -b&lt;br&gt;
&lt;br&gt;
It can take a few minutes to generate the list, but that should do it.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818552</guid>
		<pubDate>Thu, 04 Jan 2007 10:37:07 -0800</pubDate>
		<dc:creator>cerebus19</dc:creator>
	</item><item>
		<title>By: poppo</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818553</link>	
		<description>&lt;a href=&quot;http://www.download.com/Active-Ports/3000-2085-10062969.html?part=dl-ActivePor&amp;subj=dl&amp;tag=button&quot;&gt;Active Ports&lt;/a&gt; will tell you the names of the processes that are running on ports 1664 and 1666.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818553</guid>
		<pubDate>Thu, 04 Jan 2007 10:38:32 -0800</pubDate>
		<dc:creator>poppo</dc:creator>
	</item><item>
		<title>By: RustyBrooks</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818556</link>	
		<description>I did searches on variations of that string from the server but apparently not just plain &quot;funprotocol&quot;.  That did return a few hits, I&apos;ll see if I can get anything from that.&lt;br&gt;
&lt;br&gt;
Regarding the mouse, maybe it&apos;s not related.  But I&apos;ve had and used this particular mouse for at least 2 years and the behaviour I&apos;ve described has been happening only over the last few months.  It&apos;s definitely strange enough to have caught my attention.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818556</guid>
		<pubDate>Thu, 04 Jan 2007 10:38:46 -0800</pubDate>
		<dc:creator>RustyBrooks</dc:creator>
	</item><item>
		<title>By: RustyBrooks</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818558</link>	
		<description>I&apos;m not sure that I trust netstat to give me the proper results, but I&apos;ll try that also.  And I&apos;ll definitely try Active Ports.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818558</guid>
		<pubDate>Thu, 04 Jan 2007 10:39:42 -0800</pubDate>
		<dc:creator>RustyBrooks</dc:creator>
	</item><item>
		<title>By: drstein</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818607</link>	
		<description>Give us a list of all of the poker programs that you&apos;ve installed. Perhaps the culprit is there. Have you ever run ad-aware or even the microsoft anti-spyware app?&lt;br&gt;
&lt;br&gt;
Another option is perhaps to get a second computer, do all of the poker playing from that machine and nothing else. Don&apos;t install IM apps or anything. Lock it down as tight as you can, disallow any unnecessary outbound traffic, and run everything as a non-privileged user. If you&apos;re making decent cash, it might be worth thinking about.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818607</guid>
		<pubDate>Thu, 04 Jan 2007 11:12:13 -0800</pubDate>
		<dc:creator>drstein</dc:creator>
	</item><item>
		<title>By: eustacescrubb</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818619</link>	
		<description>Why don&apos;t you simply disconnect your computer from the internet/network, and then see if the mouse problems persist, and run all the tests you describe above again.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818619</guid>
		<pubDate>Thu, 04 Jan 2007 11:20:23 -0800</pubDate>
		<dc:creator>eustacescrubb</dc:creator>
	</item><item>
		<title>By: NucleophilicAttack</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818649</link>	
		<description>The two ports you listed seem &quot;legit&quot; in general -- Google seems to show that they&apos;re opened by some sort of database server. &lt;br&gt;
&lt;br&gt;
If you don&apos;t have anything that could be running a SOCKS server or web proxy, port 8080 is rather suspect.&lt;br&gt;
&lt;br&gt;
Have you tried running a free spyware program like AdAware and/or SpyBot?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818649</guid>
		<pubDate>Thu, 04 Jan 2007 11:40:42 -0800</pubDate>
		<dc:creator>NucleophilicAttack</dc:creator>
	</item><item>
		<title>By: RustyBrooks</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818652</link>	
		<description>See original post: I&apos;ve run a lot of spyware detectors.&lt;br&gt;
&lt;br&gt;
The &quot;legit&quot; ports seem tied to funprotocol.dll (given the string returned when I attach to those ports).&lt;br&gt;
&lt;br&gt;
I&apos;m currently playing poker via a virtual machine on another computer with nothing on it.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818652</guid>
		<pubDate>Thu, 04 Jan 2007 11:42:13 -0800</pubDate>
		<dc:creator>RustyBrooks</dc:creator>
	</item><item>
		<title>By: molybdenum</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818695</link>	
		<description>It wouldn&apos;t hurt to try &lt;a href=&quot;http://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx&quot;&gt;Rootkit Revealer&lt;/a&gt; from Sysinternals.  It&apos;s designed to find files that try to hide from the Windows API.&lt;br&gt;
&lt;br&gt;
But I also second the idea of unplugging your NIC for a few days and seeing if the behavior persists.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818695</guid>
		<pubDate>Thu, 04 Jan 2007 12:11:17 -0800</pubDate>
		<dc:creator>molybdenum</dc:creator>
	</item><item>
		<title>By: RustyBrooks</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818712</link>	
		<description>For some reason I forgot to mention that I attached to port 8080 also.  I tried 2 requests, one to / and one to /poo (just to see what I got).  Here are the results:&lt;br&gt;
&lt;br&gt;
telnet 192.168.0.16 8080&lt;br&gt;
Trying 192.168.0.16...&lt;br&gt;
Connected to 192.168.0.16.&lt;br&gt;
Escape character is &apos;^]&apos;.&lt;br&gt;
GET /&lt;br&gt;
&lt;br&gt;
HTTP/1.0 301 OK&lt;br&gt;
Content-Length: 0&lt;br&gt;
location: http://valve:8080/@md=d&amp;amp;cd=//&amp;amp;c=1Xp@//?ac=83&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
---------------------------------------------------&lt;br&gt;
&lt;br&gt;
telnet 192.168.0.16 8080&lt;br&gt;
Trying 192.168.0.16...&lt;br&gt;
Connected to 192.168.0.16.&lt;br&gt;
Escape character is &apos;^]&apos;.&lt;br&gt;
GET /poo&lt;br&gt;
&lt;br&gt;
HTTP/1.0 200 OK&lt;br&gt;
Content-Type: text/html&lt;br&gt;
&lt;br&gt;
&amp;lt;tr&amp;gt;&lt;br&gt;
&amp;lt;td&amp;gt;&lt;br&gt;
&amp;lt;img src=&quot;/clearpixelIcon?ac=20&quot; height=&quot;5&quot; width=&quot;0&quot; border=&quot;0&quot; alt=&quot;&quot; title=&quot;&quot;&amp;gt;&amp;lt;/td&amp;gt;&lt;br&gt;
&amp;lt;/tr&amp;gt;&lt;br&gt;
&amp;lt;tr&amp;gt;&lt;br&gt;
&amp;lt;td colspan=&quot;6&quot; nowrap&amp;gt;&lt;br&gt;
&amp;lt;Font color=&quot;red&quot;&amp;gt;&lt;br&gt;
//poo - must refer to client &apos;guest&apos;.&lt;br&gt;
&lt;br&gt;
&amp;lt;/Font&amp;gt;&lt;br&gt;
&amp;lt;/td&amp;gt;&lt;br&gt;
&amp;lt;/tr&amp;gt;&lt;br&gt;
&amp;lt;tr&amp;gt;&lt;br&gt;
&amp;lt;td&amp;gt;&lt;br&gt;
&amp;lt;img src=&quot;/clearpixelIcon?ac=20&quot; height=&quot;5&quot; width=&quot;0&quot; border=&quot;0&quot; alt=&quot;&quot; title=&quot;&quot;&amp;gt;&amp;lt;/td&amp;gt;&lt;br&gt;
&amp;lt;/tr&amp;gt;</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818712</guid>
		<pubDate>Thu, 04 Jan 2007 12:22:15 -0800</pubDate>
		<dc:creator>RustyBrooks</dc:creator>
	</item><item>
		<title>By: stovenator</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818733</link>	
		<description>What happens when you telnet to port 8080? Have you tried issuing a  GET / HTTP/1.0 ? 8080 is often used by a number of webserver type applications, but could also be a firly easy place to disguise another malicious app. &lt;br&gt;
&lt;br&gt;
I&apos;ll second Rootkit Revealer. &lt;br&gt;
&lt;br&gt;
Also, try using &lt;a href=&quot;http://www.microsoft.com/technet/sysinternals/Networking/TcpView.mspx&quot;&gt;TCPView&lt;/a&gt; from Sysinternals for viewing network activity. See what process is attaching to ports 1664,1666,&amp;amp; 8080.&lt;br&gt;
&lt;br&gt;
You can also use &lt;a href=&quot;http://www.wireshark.org/&quot;&gt;Wireshark&lt;/a&gt; (new name for Ethereal) to capture packets. Try capturing anything on ports 1664,1666, and 8080.&lt;br&gt;
&lt;br&gt;
Lots of malicious programs like to phone home to an IRC channel to get instructions on how to proceed, so you may look for suspicious IRC traffic on those ports.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818733</guid>
		<pubDate>Thu, 04 Jan 2007 12:31:46 -0800</pubDate>
		<dc:creator>stovenator</dc:creator>
	</item><item>
		<title>By: stovenator</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818737</link>	
		<description>Also, be sure to check your HOSTS file, to see if there&apos;s anything suspicious in there.&lt;br&gt;
&lt;br&gt;
Is the name of your machine &quot;valve&quot; ? Try opening http://valve:8080 in your browser.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818737</guid>
		<pubDate>Thu, 04 Jan 2007 12:33:56 -0800</pubDate>
		<dc:creator>stovenator</dc:creator>
	</item><item>
		<title>By: cotterpin</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818741</link>	
		<description>The top google hits on &quot;must refer to client&quot; seem to indicate that this is a perforce server.  Perforce, if you&apos;re not familiar with it, is for source code control.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818741</guid>
		<pubDate>Thu, 04 Jan 2007 12:36:06 -0800</pubDate>
		<dc:creator>cotterpin</dc:creator>
	</item><item>
		<title>By: stovenator</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818753</link>	
		<description>Cotterpin is correct. It looks like this is the perforce web server. The format of the request (@md=d&amp;amp;cd=//&amp;amp;c=1Xp@//?ac=83) even matches how P4Web formats it&apos;s connect strings too.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818753</guid>
		<pubDate>Thu, 04 Jan 2007 12:40:12 -0800</pubDate>
		<dc:creator>stovenator</dc:creator>
	</item><item>
		<title>By: RustyBrooks</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818757</link>	
		<description>Yes, my machine is valve.  Opening valve:8080 just returns a blank page, but I think cotterpin is right about 8080.&lt;br&gt;
&lt;br&gt;
I am running perforce, so that is probably what the 8080 is.  I&apos;ll be able to tell better when I get home (right now I&apos;m connecting to all of these ports from a linux machine in my home network, don&apos;t have direct access to the affected machine)</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818757</guid>
		<pubDate>Thu, 04 Jan 2007 12:42:07 -0800</pubDate>
		<dc:creator>RustyBrooks</dc:creator>
	</item><item>
		<title>By: cmiller</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818810</link>	
		<description>Since you seem to have a Linux/Unix box handy, you might try having it &quot;masquerade&quot; your network connection.&lt;br&gt;
&lt;br&gt;
Valve --- linux --- Internet&lt;br&gt;
&lt;br&gt;
Make it network properly, and then you can use the linux box to snoop the bits on the wire.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818810</guid>
		<pubDate>Thu, 04 Jan 2007 13:35:17 -0800</pubDate>
		<dc:creator>cmiller</dc:creator>
	</item><item>
		<title>By: RustyBrooks</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818843</link>	
		<description>I&apos;m using a plain hub (i.e. not a switch) to attach the linux box and the windows box over ethernet.  Doing this, I can use the linux box to snoop on the data.  I&apos;ve had it capturing today, I&apos;ll look at the results when I get home.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818843</guid>
		<pubDate>Thu, 04 Jan 2007 14:05:04 -0800</pubDate>
		<dc:creator>RustyBrooks</dc:creator>
	</item><item>
		<title>By: crypticgeek</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818919</link>	
		<description>So safely assuming 8080 is the perforce web server, that still leaves the other two. If it IS indeed funprotocol spyware isn&apos;t it odd that none of your anti-spyware scans picked up on it? Did you search the drive for &quot;funprotocol&quot;? What are your netstat/active ports/hijack this results? &lt;br&gt;
&lt;br&gt;
If the process isn&apos;t funprotocol, you could try submitting whatever you find to virustotal and have it scanned, or post it to rapidshare and see if someone here can identify it. &lt;br&gt;
&lt;br&gt;
If it isn&apos;t listed in netstat or active ports, I second the recommendation of root kit revealer. You have to be careful interpreting the results though. &lt;br&gt;
&lt;br&gt;
Barring that, I third the recommendation of disconnecting and seeing what happens.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818919</guid>
		<pubDate>Thu, 04 Jan 2007 15:00:55 -0800</pubDate>
		<dc:creator>crypticgeek</dc:creator>
	</item><item>
		<title>By: RustyBrooks</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818933</link>	
		<description>Disconnecting would be tough.  This is the machine I do the bulk of my day-to-day work on.  Maybe this weekend I can try that.&lt;br&gt;
&lt;br&gt;
I haven&apos;t had a chance to try any of the diag methods mentioned in this post yet because the machine is at home and I&apos;m not (will be soon though)&lt;br&gt;
&lt;br&gt;
Thanks for all the suggestions and I will definitely post back here if I find anything else out.&lt;br&gt;
&lt;br&gt;
There is a non-zero chance that these ports (the funprotocol ones) are *also* a side effect of something I&apos;m not thinking of (like 8080 was) but &quot;funprotocol&quot; showing up when you telnet to the port seems to make that unlikely.&lt;br&gt;
&lt;br&gt;
No idea why the spyware apps did not find this, if I find where it&apos;s coming from I may have some info to provide them.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818933</guid>
		<pubDate>Thu, 04 Jan 2007 15:13:48 -0800</pubDate>
		<dc:creator>RustyBrooks</dc:creator>
	</item><item>
		<title>By: theora55</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#818958</link>	
		<description>Firefox made my mouse really erratic.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-818958</guid>
		<pubDate>Thu, 04 Jan 2007 15:30:52 -0800</pubDate>
		<dc:creator>theora55</dc:creator>
	</item><item>
		<title>By: jesirose</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#819075</link>	
		<description>&quot;As sort of a caveat/afterthought... I play poker to supplement my income (it amounts to about 1/4 to 1/3 of my total income) so if someone is watching me, this would be very, very bad, and honestly, I&apos;ve had some reason to believe that someone might be watching me, in this regard.&quot;&lt;br&gt;
&lt;br&gt;
I wouldn&apos;t advertise that. If you&apos;re playing online, that&apos;s now illegal where you live. If you simply meant you play it and that you have a computer which is acting up, that&apos;s cool. Otherwise, don&apos;t talk about your illegal activities :-P</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-819075</guid>
		<pubDate>Thu, 04 Jan 2007 17:06:59 -0800</pubDate>
		<dc:creator>jesirose</dc:creator>
	</item><item>
		<title>By: RustyBrooks</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#819264</link>	
		<description>&lt;i&gt;I wouldn&apos;t advertise that. If you&apos;re playing online, that&apos;s now illegal where you live. If you simply meant you play it and that you have a computer which is acting up, that&apos;s cool. Otherwise, don&apos;t talk about your illegal activities&lt;/i&gt;&lt;br&gt;
&lt;br&gt;
Frankly, I don&apos;t think you know what you&apos;re talking about.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-819264</guid>
		<pubDate>Thu, 04 Jan 2007 19:47:07 -0800</pubDate>
		<dc:creator>RustyBrooks</dc:creator>
	</item><item>
		<title>By: crypticgeek</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#819274</link>	
		<description>Off topic, but RustyBrooks is probably right. Unless there is a Texas statute I am aware of, his online gambling is perfectly legal. The recent federal law you are probably basing your view on did not making online gambling illegal, it make it illegal to fund from credit card, wire transfer, check, etc online gambling and wagering. This doesn&apos;t stop one from transferring money to a non-us financial institution, and then playing to play from there.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-819274</guid>
		<pubDate>Thu, 04 Jan 2007 20:03:04 -0800</pubDate>
		<dc:creator>crypticgeek</dc:creator>
	</item><item>
		<title>By: RustyBrooks</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#819304</link>	
		<description>For reference, 1666 was also perforce, and 1664 was for Steam (a game delivery service).  So no go there.  Between my paranoia and maybe a shitty mouse, perhaps there&apos;s nothing wrong with my system.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-819304</guid>
		<pubDate>Thu, 04 Jan 2007 20:55:07 -0800</pubDate>
		<dc:creator>RustyBrooks</dc:creator>
	</item><item>
		<title>By: crypticgeek</title>
		<link>http://ask.metafilter.com/54366/Help-me-find-out-if-someone-is-spying-on-my-computer#820202</link>	
		<description>Interesting. &lt;br&gt;
&lt;br&gt;
It&apos;s a little amusing actually. Considering perforce is used for source control at Valve, your machine is named valve, and the suspicious port was Steam.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54366-820202</guid>
		<pubDate>Fri, 05 Jan 2007 16:39:34 -0800</pubDate>
		<dc:creator>crypticgeek</dc:creator>
	</item>
	</channel>
</rss>
