Boot your pc and let it settle doing all it's normal update checks then open a cmd prompt and type
netstat -b 5 > activity.txt
Let this run for a few mins then do a ctrl c to stop it
then type activity.txt
You will get a list of all the outbound activity
This is how i found a hidden nasty on my machine
Page 1 of 1
Who's Calling Home ?
#3
Posted 30 January 2008 - 12:07 AM
I have reason to believe that i have a trojan virus running in the background, i ran this test and im getting a connection through svchost.exe, is that normal?
#4
Posted 30 January 2008 - 03:07 AM
svchost.exe is a generic "holder" process for a number of programs, many legitamate but is also hijacked by trojan, dialers viruses etc
check from the results of the test where the packets are going, if they are obviously dubious e.g seem to be sending mail or going to some odd sites ( some will be clicking spammers google ads in the background)then you have been hijacked
run a root kit scanner as shown in an easrlier post
run spybot and hijackthis (google them) and of course run a good AV scan, try the free online one at symantech
check from the results of the test where the packets are going, if they are obviously dubious e.g seem to be sending mail or going to some odd sites ( some will be clicking spammers google ads in the background)then you have been hijacked
run a root kit scanner as shown in an easrlier post
run spybot and hijackthis (google them) and of course run a good AV scan, try the free online one at symantech
#5
Posted 30 January 2008 - 05:24 AM
when you have run hijackthis post your log results here and i can have a look and see if there is anything obviously abnormal
Share this topic:
Page 1 of 1

Help











