View Single Post
Old 05-19-2015, 12:49 PM  
Antonio
Too lazy to set a custom title
 
Antonio's Avatar
 
Join Date: Oct 2001
Location: Spartaaaaaaaaa
Posts: 14,136
Sniffing network traffic for signs of viruses/spyware - how?

I have some little shitty thing that can't get rid of - tried scanning my whole computer with Malwarebites, Microsoft Essentials, Spybot, Avira, Avast, AVG and everything else I could get my hands on and nothing can find it. The searches found a few infections that I got rid of, so I might have killed some of it, but it is still alive and running.

I can see it on Fiddler and Wireshark, I know Fiddler well and Wireshark barely, but neither tells me what starts the calls. What the thing does is it runs searches on Google.pl and occasionally visits other sites too or at least it used to, now it seems to be going to Google.pl all the time.

Yeah, also uninstalled Firefox and Chrome just to see if it will stop, but it didn't.

Downloaded Snort, but it is like Chinese to me, so I'm looking for a Windows based sniffer, hopefully easy one to use, which will identify the process that starts the calls - I downloaded something from Microsoft, but all I get is Unknown process, so that didn't help.

Any ideas?
Antonio is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote