View Full Version : Botnet wat
Rook
January 26th, 2009, 01:46 PM
I was reading in the other thread about botnets and etc and got to wondering about my PC... almost every night my ping shoots up to 200-300. One proven reason is because of my ISP plays some role in this garbage occasionally, but is it also possible the trojan I acquired about a month back, and thought I removed using Windows system restore could be causing this problem as well?
Phopojijo
January 26th, 2009, 01:52 PM
If it's a good virus it infected/disabled System Restore.
<shrugs>
A) Do you want to try to do some detective work...
B) Do you care...
C) Do you want to just backup your data and reinstall Windows?
Limited
January 26th, 2009, 02:00 PM
Usually your internet should speed up at night, because its an off peak time. Interesting.
Is there anyone else on your network that might be using some of the bandwidth?
Quick question Phopojijo, my installation is on C:,I have a secondary drive (D:) if I was to reinstall windows on C and backup my files on D, which that be alright? Even though D: might also be infected.
Rook
January 26th, 2009, 02:00 PM
A) As in?
B) Well yeah, can't play online games for shit, esp in cases where I'm wanting to do scrimmages with my clan.
C) I considered that but I use a shared computer, of course all my data could be easily re-installed... it would just be time consuming, especially lolWoW and it's patches.
Phopojijo
January 26th, 2009, 02:15 PM
Usually your internet should speed up at night, because its an off peak time. Interesting.
Is there anyone else on your network that might be using some of the bandwidth?
Quick question Phopojijo, my installation is on C:,I have a secondary drive (D:) if I was to reinstall windows on C and backup my files on D, which that be alright? Even though D: might also be infected.It's possible some trojan horse could load on your D-drive... however if Windows is reinstalled -- you'd physically need to *open* the virus.
If you think about it... if it's just sitting on your harddrive and Windows is reinstalled -- what would turn the virus on each time your computer boots? Nothing except you o.o
If you pay CAREFUL attention to what you install and/or run... it's fine.
****
Now -- Rook:
Press Ctrl + Shift + Esc... click the networking tab. It's probable that the virus didn't mask its network activity -- so you can see the strain on your network card. If you see yourself get fairly large spikes in your Network Card and you aren't doing anything... you probably have a virus. At that point it's finding out what's causing problems. (Or something's autopatching, who knows... could be Quicktime, lord knows that causes more shit than it's worth.)
Rook
January 26th, 2009, 03:22 PM
@Limited, no its just this computer, we used to have 2 computers going thru a router and the connection was fine.
Now -- Rook:
Press Ctrl + Shift + Esc... click the networking tab. It's probable that the virus didn't mask its network activity -- so you can see the strain on your network card. If you see yourself get fairly large spikes in your Network Card and you aren't doing anything... you probably have a virus. At that point it's finding out what's causing problems. (Or something's autopatching, who knows... could be Quicktime, lord knows that causes more shit than it's worth.)
My pings/connections are fine right now, but when they go crazy again I'll check that out and report back in.
edit - This is a screen shot of my current network utilization.
http://img228.imageshack.us/img228/4567/networkdb6.jpg
Phopojijo
January 26th, 2009, 03:28 PM
Yeah... viruses kinda only really peak at certain times... probably when the user wouldn't likely be using it.
((Or if it's tied to a botnet through some random IRC channel... whenever the owner logs in and /orders your PC around)).
You could also try (in a command prompt) "netstat -ano" and "tasklist" to see who's listening on what port.
NullZero
January 26th, 2009, 04:31 PM
I live practically next to london server, but every single bloody night, my ping goes to about 300-400 ping, so I never play halo when all the american's get on. It's a bitch.
Phopojijo
January 26th, 2009, 05:20 PM
Well the problem with diagnosing viruses is that they're so damn diverse. That's why most people say "fuck it, just reinstall Windows".
You could physically remove each and every virus in existence if you know exactly what they do.
However some viruses want to be sneaky... they want to get installed as Root and drop everyone's permissions so that it's impossible to find (without scanning the harddrive from a Linux disk since it could easily infect multiple Windows harddrives on the same machine.)
Some viruses want to be loud and clear... installing malware and adware to spam you with popups every 2 clicks of the mouse.
Some viruses unpatch Windows and open up security holes for a hacker to reinfect you if you fix it.
Some viruses use uPnP to change your router settings to allow unsolicited traffic into security holes in your computer.
Some viruses brute-force passwords into other networked computers to spread.
Some viruses try every IP address in existance to infect other computers.
Some viruses log into IRC channels and wait for the chanop to set a DDoS (ICMP Flood) target.
Some autorun by creating registry keys.
Some autorun by registering as hardware and loading fake drivers.
Some autorun by editting the kernel itself.
It's just impossible these days to know what each virus did... how many viruses you actually have... etc. It's possible, but you're never guarenteed to be infection free (you're never guarenteed infection free anyway...).
Rook
January 26th, 2009, 05:53 PM
http://img216.imageshack.us/img216/1673/uhheu6.jpg
^ well the network bar didn't change at all pretty much, and in halo pings shot up to 233 in a server I was getting 66 in minutes before.. checked other servers via xfire and they shot up to ~200 too.
:/
Phopojijo
January 26th, 2009, 06:08 PM
Your ISP could have a bad router <shrugs>
Like I said, these things are so ludicrously hard to diagnose it's pretty much only sane to format Windows and play it safe -- or just run with the problems until it becomes obvious.
That's kinda what I was getting at in my last post... it's not that it's impossible to remove viruses these days... it's that the diagnostics to do so makes it abundantly not worth it.
StankBacon
January 26th, 2009, 06:12 PM
does this happen on your windows 7 install?
Rook
January 27th, 2009, 09:42 PM
I haven't been able to check my windows 7 install yet.. My internet has been out all day and school was even canceled, all we saw was rain, none of the ice or snow. How does the internet manage to go out is unexplainable. Right now it's slower than dial up though, took about a minute to load the modacity forums index.
Sel
January 27th, 2009, 09:48 PM
I still can not believe that your school board is so incredibly scared of bad weather that they cancel school because of rain.
We have 30cm of snow out and a blizzard and we dont get cancelled school.
:S
Rook
January 28th, 2009, 10:07 AM
Whatever I'm at school right now, the internet/phone went out again at 2am last night.
I still can not believe that your school board is so incredibly scared of bad weather that they cancel school because of rain.
We have 30cm of snow out and a blizzard and we dont get cancelled school.
:S
lolcanada
Powered by vBulletin® Version 4.2.5 Copyright © 2024 vBulletin Solutions Inc. All rights reserved.