Excessive Internet Traffic

Swampster

Senior member
Mar 17, 2000
349
0
0
Greetings from the Swamps of Sunny Central Florida,

I have a customer's computer that appears to have been attacked by some sort of bot or at least something similar.

Usually I am pretty good at finding these types of things, but this one has me stumped. I have used Hijackthis, AVG 8, Defender, SpyBot and AdAware plus manually scrubbing the Registry in all Software sections to remove anything suspitious or anything not removed completely by its uninstall program.

The customer had Norton 360 as his main security program, but it was trashed and wouldn't even run a complete scan without quiting on "unknown errors", which was why it now has AVG free and the others installed. It wouldn't even uninstall itself correctly and I had to manually remove the left-overs in Windows Explorer after doing a manual removal of anything "Norton" or "Symantic" in the Registry.

OS is XPHome w/SP3 and all further updates.

From time to time, it will seem that I have actually found it and its activity will go back to normal (network icon in System Tray showing no activity),then 15 or 20 minutes it starts up again and is pushing out so much that none of the other systems on my network have any bandwidth left.

Task Manager doesn't show anything that I can shut off that stops the activity, Process Explorer doesn't show anything running that looks at all suspitous.

Obviously I'm missing something . . . any body have any ideas???

Swampster
 

MadScientist

Platinum Member
Jul 15, 2001
2,183
63
91
Go to John's site (also linked in the sticky), read, and follow his directions on "Adware Spyware & Trojan Removal". As he suggests, run all the scans in Safe Mode with Networking and get updates, if available, for each program before scanning.

 

Swampster

Senior member
Mar 17, 2000
349
0
0
Thanks for the link MadScientist.

I have visited John's site, read throughly, and downloaded tools I didn't already have. Now all I have to do is spend the rest of the evening running the new tools to see if I can find this little broadband bandit!
 

QuixoticOne

Golden Member
Nov 4, 2005
1,855
0
0
Sounds like a rootkit issue. Hopefully your new tools will deal with it.
You can add something like ethereal to your mix to spy on the network traffic and see what the heck it is doing if that is of any incidental diagnostic use.

I'd be thinking an OS reinstall is a good idea if I had something that elusive / nasty.

It isn't unheard of for some defective or incompatible NICs or switches or whatever to start "jabbering" incessantly on the ethernet or get into some kind of "loop" bouncing packets back and forth. So I suppose it could be a network hardware / configuration issue, but it is suspicious if it doesn't happen immediately or consistently.

It could be there's code on there that is trying to DDOS some other site or blast infectious packets around your LAN or to other sites.

Heck I suppose it could be really hosed P2P S/W but then you *should* see some task running.
 

Swampster

Senior member
Mar 17, 2000
349
0
0
It was a series of Trojan Horses.

Aviria Rescure CD found it when EVERY OTHER scanner said I was totally clean. Looks like I will have to do some serious re-evaluation of my choice in security programs!!!