Do I have a trojan?

Feb 19, 2001
20,155
23
81
I want to start off by saying I'm pretty saavy with software and hardware, so it's not usual for me to get infected. I've been infected once and that was because I downloaded something that looked like an MP3 off of Kazaa. It was a VBS. I knew to delete it right away but instead of a single click + delete, I hit double click and yea.. That was 5 years ago. A quick format fixed things though (thank goodness).


I just reformatted recently because I figured my 1 year old Windows XP is getting a little sluggish and I didnt keep up with my 6 months reformatting standards.

I'm running Kaspersky with a very updated database.

And recently I noticed that while playing Warcraft 3 I get a lot of lagouts. What happens is my network starts going crazy (and it's from my PC). I notice a lot of packets being sent from my end (6000/refresh.. does it refresh every second in the network monitor or what), and so it seems like upstream data only. Nothing is coming back though.

It slows my network access to a crawl and the router seems to get overlaoded too as my laptop cannot access any webpages. Once I pull the plug from my desktop, my laptop works again.

I looked into this by loading up PeerGuardian and I noticed that it comes as a bunch of outward access requests from various ports of my computer trying to go to 1 IP address.

Sounds suspiciously like a trojan.

That IP however is non functional (as in I can't get it to respond to ping requests... but maybe it's just firewalled). Either way I see no response and downstream data from that IP when my network goes haywire. And this can happen maybe 2 - 3 times in a day. Each time the IP is different. It usually goes away on its own too (this massive upstream flow) if I leave it alone.

Sometimes I come back to my computer after a few hours and I see my packets jump up to 3 million, so I know it's done this whole upstream thing a few times.

I installed Adaware and I did a scan. Nothing.
Kaspersky did a system scan and a C: scan. Nothing. I'm not sure about scanning the other 960gb I have, but I'm sure it should be fine.

Bottom line is I just don't want to reformat again after spending so many hours customizing my icons...
 

Muadib

Lifer
May 30, 2000
18,072
895
126
Dude, how the heck can you say your other 960gb are fine if you didn't scan them.
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
Using that adware infected application is not a good idea.
instead of a single click + delete, I hit double click
Consider using NoScript to prevent this
I looked into this by loading up PeerGuardian and I noticed that it comes as a bunch of outward access requests from various ports of my computer trying to go to 1 IP address.
Almost sounds like your computer has turned into a Zombie launching DoS attacks, but it seems like it would constantly be doing this rather than just three times a day. What process is eating your CPU up when your network activity spikes?

A few things to try:
[*]Running Mcafee's command line scanner in safe mode
[*]Fully update and run SUPERAntiSpyware and a-squared in safe mode.

Scan everything with Kaspersky and these tools (heuristics, if applicable, maxed out), not just your windows folder.
 
Feb 19, 2001
20,155
23
81
Originally posted by: Muadib
Dude, how the heck can you say your other 960gb are fine if you didn't scan them.

Because those are data drives where my music, movies, tv shows and games go. Almost all installations go into c:, my OS drive. I've scanned both C: and D: my XP and Vista partitions, but now I'll scan everything else for the heck of it.

Scadenfroh: Yeah.. that Kazaa incident is over 5 years old, back on my ancient computer. I was using Windows 98SE or something back then and since then I've reformatted that computer at least a dozen times.

When network activity spikes, nothing eats up my processes. I look it up instantly and I end the ones I deem uneccessary, and I've googled a few of the other processes, and everything looks good.

If I load up PeerGuardian, that thing spikes to 50% as it's trying to list every single network access request.

It may be more than 3 times aday. I first thought my Warcraft 3 was infected with something funny, but when I left my computer on for 6 hours once and came back I found my packets jumped to 3 million. Obviously something's wrong. Anyways it's just periodic.

I've found that disabling my network adapter and then re-enabling it maybe 10 min later or even 5 min later will fix the problem.

I'm scanning with Kaspersky as we speak and I'll let you. I'll run the other applications a little later.

If I can't find anything I'll reformat this weekend. =)
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
DO NOT CROSS POST. This belongs in the security forum, you already started it there, so please monitor that thread (with 7k+ posts you should know better)
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Originally posted by: DLeRium
I want to start off by saying I'm pretty saavy with software and hardware, so it's not usual for me to get infected. I've been infected once and that was because I downloaded something that looked like an MP3 off of Kazaa. It was a VBS. I knew to delete it right away but instead of a single click + delete, I hit double click and yea.. That was 5 years ago. A quick format fixed things though (thank goodness).


I just reformatted recently because I figured my 1 year old Windows XP is getting a little sluggish and I didnt keep up with my 6 months reformatting standards.

I'm running Kaspersky with a very updated database.

And recently I noticed that while playing Warcraft 3 I get a lot of lagouts. What happens is my network starts going crazy (and it's from my PC). I notice a lot of packets being sent from my end (6000/refresh.. does it refresh every second in the network monitor or what), and so it seems like upstream data only. Nothing is coming back though.

It slows my network access to a crawl and the router seems to get overlaoded too as my laptop cannot access any webpages. Once I pull the plug from my desktop, my laptop works again.

I looked into this by loading up PeerGuardian and I noticed that it comes as a bunch of outward access requests from various ports of my computer trying to go to 1 IP address.

Sounds suspiciously like a trojan.

That IP however is non functional (as in I can't get it to respond to ping requests... but maybe it's just firewalled). Either way I see no response and downstream data from that IP when my network goes haywire. And this can happen maybe 2 - 3 times in a day. Each time the IP is different. It usually goes away on its own too (this massive upstream flow) if I leave it alone.

Sometimes I come back to my computer after a few hours and I see my packets jump up to 3 million, so I know it's done this whole upstream thing a few times.

I installed Adaware and I did a scan. Nothing.
Kaspersky did a system scan and a C: scan. Nothing. I'm not sure about scanning the other 960gb I have, but I'm sure it should be fine.

Bottom line is I just don't want to reformat again after spending so many hours customizing my icons...

Can you tell what process on that box is generating all the network traffic?
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |