Which software for Scanning simple network for rogue IP calls?

I am Penguin

Executive Member
Joined
Jan 26, 2009
Messages
7,713
I have Malwarebytes running on my system and it continually states that it is blocking access to a malicious IP or suspect sites. I would like to find the thread's causing these IP calls so I can determine the calling culprit/software! Any advice please. The programs I so far tried did not give me what I wanted!

I scanned the system for Virus /worms but it shows clean!
Yes, I have P2P software installed but they are not running.

Thanks in advance!
 

repitah

Well-Known Member
Joined
Jul 4, 2005
Messages
311
Perhaps use wireshark to watch your network port (what is going through it). Very useful. You can cut out the stuff like ssdp, dhcp in the filter area.
 

I am Penguin

Executive Member
Joined
Jan 26, 2009
Messages
7,713
Thanks, I tried it but it did not give what I wanted, maybe my fault. Actually the correct and usable application stared me square in the face and I did not even realize it. Control Panel\All Control Panel Items\Administrative Tools\Performance monitor> Open resource monitor. Under network view I could see all network users and the thread ID as well as who is actually screwing around on the net. It was btdna.exe. The sleek bitorrent running in the background with all Bitorrent activities "stopped". So no more alarms from Malwarebytes expected! I just killed the bugger by renaming all files in "program files" under DNA folder. It was uninstalled from the control panel but seems it only removed the actual install data but not the running process and files.

After some searching I found this to confirm the issue.

http://torrentfreak.com/bittorrent-dna-vulnerable-to-remote-hijack-080103/

Other neat utils helping even more, from sysinternals .com!
Process explorer
Process monitor
 
Last edited:

|tera|

Master of Messengers
Joined
Mar 31, 2006
Messages
25,906
Sysinternals = ProcessExplorer & Autoruns.

I can't go a week without using these(corporate environment, malware is like lunchbreaks :p ). Check out the whole Microsoft Sysinterals suite, nothing like it.

If you need help, let me know ;)
 

I am Penguin

Executive Member
Joined
Jan 26, 2009
Messages
7,713
Sysinternals = ProcessExplorer & Autoruns.

I can't go a week without using these(corporate environment, malware is like lunchbreaks :p ). Check out the whole Microsoft Sysinterals suite, nothing like it.

If you need help, let me know ;)

Thanks a lot,

I used Process explorer many times but never (hardly ever) used Process monitor, My bad for not trying it prior this thread.

I tried the Autoruns. Looks great. Now just to work out what is essential and what is leftover waste from those long lists. Now if I can just found a sysinternals application that can do the same but better than Hijackthis or RegShot to take a snapshot of the system and on a second snap show all the system changes and differences of files, registry and start-up's, etc.
 
Top