Cinema 4D Tutorials: Who's Calling Home ? - Cinema 4D Tutorials

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Who's Calling Home ?

#1 User is offline   SFX 

  • Site Admin
  • PipPipPipPipPip
  • View gallery
  • Group: Admin
  • Posts: 2,341
  • Joined: 07-September 05
  • Favorite Apps:Cinema 4D, Max, RealFlow, Terragen, Motionbuilder
  • Location:London UK
  • Machine Specs:I7 930 4.2 Ghz 6 GB Ram

Posted 18 January 2008 - 05:44 PM

Boot your pc and let it settle doing all it's normal update checks then open a cmd prompt and type

netstat -b 5 > activity.txt

Let this run for a few mins then do a ctrl c to stop it

then type activity.txt

You will get a list of all the outbound activity

This is how i found a hidden nasty on my machine
0

#2 User is offline   Dark Crypto 

  • In The Pool
  • PipPipPipPip
  • Group: Poster
  • Posts: 297
  • Joined: 21-January 06
  • Favorite Apps:Cinema 4D
  • Location:Australia

Posted 19 January 2008 - 01:55 AM

Thanks!!!
0

#3 User is offline   Dark Crypto 

  • In The Pool
  • PipPipPipPip
  • Group: Poster
  • Posts: 297
  • Joined: 21-January 06
  • Favorite Apps:Cinema 4D
  • Location:Australia

Posted 30 January 2008 - 12:07 AM

I have reason to believe that i have a trojan virus running in the background, i ran this test and im getting a connection through svchost.exe, is that normal?
0

#4 User is offline   SFX 

  • Site Admin
  • PipPipPipPipPip
  • View gallery
  • Group: Admin
  • Posts: 2,341
  • Joined: 07-September 05
  • Favorite Apps:Cinema 4D, Max, RealFlow, Terragen, Motionbuilder
  • Location:London UK
  • Machine Specs:I7 930 4.2 Ghz 6 GB Ram

Posted 30 January 2008 - 03:07 AM

svchost.exe is a generic "holder" process for a number of programs, many legitamate but is also hijacked by trojan, dialers viruses etc

check from the results of the test where the packets are going, if they are obviously dubious e.g seem to be sending mail or going to some odd sites ( some will be clicking spammers google ads in the background)then you have been hijacked

run a root kit scanner as shown in an easrlier post

run spybot and hijackthis (google them) and of course run a good AV scan, try the free online one at symantech
0

#5 User is offline   SFX 

  • Site Admin
  • PipPipPipPipPip
  • View gallery
  • Group: Admin
  • Posts: 2,341
  • Joined: 07-September 05
  • Favorite Apps:Cinema 4D, Max, RealFlow, Terragen, Motionbuilder
  • Location:London UK
  • Machine Specs:I7 930 4.2 Ghz 6 GB Ram

Posted 30 January 2008 - 05:24 AM

when you have run hijackthis post your log results here and i can have a look and see if there is anything obviously abnormal
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users