Q for the computer/IT types

TrueBlueGT

is impressed!
Established Member
Joined
Feb 4, 2004
Messages
4,496
Location
In perpetual exile....
Are there programs that can be installed on a hard drive which will monitor the internet traffic (websites, times, etc) and then upload that information to a site which would be accessible via internet from another computer? I hope that makes sense or that you can decipher it. I'm by no means a computer guru so I don't know the terminology to refer to this kind of a program. Anyway, if there is such a program, obviously it would be running in the background literally every time you turn on the computer. How would I go about searching for such a bug on my pc & then removing it?

Any ideas are welcome.

Thanks
TBGT
 

moddestmike

2 Degrees/Still Confused
Established Member
Joined
Aug 17, 2004
Messages
3,142
Location
Houston
Are there programs that can be installed on a hard drive which will monitor the internet traffic (websites, times, etc) and then upload that information to a site which would be accessible via internet from another computer? I hope that makes sense or that you can decipher it. I'm by no means a computer guru so I don't know the terminology to refer to this kind of a program. Anyway, if there is such a program, obviously it would be running in the background literally every time you turn on the computer. How would I go about searching for such a bug on my pc & then removing it?



Any ideas are welcome.

Thanks
TBGT

I take it you had a botnet maliciously installed somewhere on your pc or you're wanting to spy on someone. Botnets more often than not bury themselves in the C:windows\system32 directory. I'd first suggest downloading something like TaskViewer (3rd party task viewer). This will allow you to clearly identify malicious tasks (depending on your comp literacy). Depending on which program you get, it should tell you which port its using and you could possibly run a tracert to see where its calling home to. Take you pc off the network and monitor it again and notice how many times it unsuccessfully attempts to "report back".

Now its going to get a bit tricky (or quite simple) depending on which type has embedded itself.
Start by finding a free version of Malwarebytes or AVG Anti-virus. Run updates on your OS before hand and then scan with said software. If you believe its still present. Let me know and we'll go further.

NetFlowAnalyzer or WireShark will allow you to more effectively monitor network traffic. Your probably experiencing a 7-12% bandwidth decrease because this fagbot is constantly communicating. More often than not, your PC is used as a hub to propagate spam and majority dont know it.

Some good resources on Botnets and how they behave so you can take preventive measures.

Botnet: Classification, Attacks, Detection, Tracing, and Preventive Measures
 
Last edited:

TrueBlueGT

is impressed!
Established Member
Joined
Feb 4, 2004
Messages
4,496
Location
In perpetual exile....
Actually I don't care to spy on anyone. I am however, worried the exact opposite may be true due to someone who previously had access to my computer.
 

moddestmike

2 Degrees/Still Confused
Established Member
Joined
Aug 17, 2004
Messages
3,142
Location
Houston
Actually I don't care to spy on anyone. I am however, worried the exact opposite may be true due to someone who previously had access to my computer.

What makes you think so, noticeable network traffic even when your not browsing\downloading? Unfamiliar services? Need more details to determine. Search for WireShark or NetFlowAnalyzer. Let it run without browsing and take note of which services are generating traffic. PM me the services.
 

TrueBlueGT

is impressed!
Established Member
Joined
Feb 4, 2004
Messages
4,496
Location
In perpetual exile....
What makes you think so, noticeable network traffic even when your not browsing\downloading? Unfamiliar services? Need more details to determine. Search for WireShark or NetFlowAnalyzer. Let it run without browsing and take note of which services are generating traffic. PM me the services.

I'll pm you the reason why and we'll go from there. Not something I want floating around the open message board.
 

Users who are viewing this thread



Top