Sniffing network traffic for signs of viruses/spyware - how?
I have some little shitty thing that can't get rid of - tried scanning my whole computer with Malwarebites, Microsoft Essentials, Spybot, Avira, Avast, AVG and everything else I could get my hands on and nothing can find it. The searches found a few infections that I got rid of, so I might have killed some of it, but it is still alive and running.
I can see it on Fiddler and Wireshark, I know Fiddler well and Wireshark barely, but neither tells me what starts the calls. What the thing does is it runs searches on Google.pl and occasionally visits other sites too or at least it used to, now it seems to be going to Google.pl all the time.
Yeah, also uninstalled Firefox and Chrome just to see if it will stop, but it didn't.
Downloaded Snort, but it is like Chinese to me, so I'm looking for a Windows based sniffer, hopefully easy one to use, which will identify the process that starts the calls - I downloaded something from Microsoft, but all I get is Unknown process, so that didn't help.
Any ideas?
|