Hi, some scriptkiddy is bragging about having my PC in his botnet. I don't really know what to do or even if I'm really in his botnet, so I'd like to check that point first. Is it possible to detect a botnet via wireshark? If yes, how would I know I'm infected? Thanks in advance fellows... asked 19 Dec '12, 07:31 QAI |
One Answer:
Wouldn't it be better to detect a bot infection with a malware scanner? I suggest to use one of the boot cd images mentioned in the following article
If none of those tools finds anything, then
Regards answered 19 Dec '12, 08:19 Kurt Knochner ♦ showing 5 of 6 show 1 more comments |
Thank you, I will try some of these discs now :)
Well, this kiddy was bragging via PM in a Forum, also stating the "honour" of beeing on of his few zombies. It's an annoying kid, but since I have no knowledge about networking, I get a bit nervous about such things^^
first scan your PC. If you don't find anything, demand a proof ;-) Just in case: BACKUP, BACKUP, BACKUP !!!
No virus found, now waiting for response to my proof demanding :)
Thank you Kurt!
Just in case: Run dumpcap with a ringbuffer to capture the whole traffic from your machine.
Get the interface number
Run dumpcap
Replace xxx with the interface number of step one. This will generate a max. of 8 Gbyte data. Make sure there is enough free space on disk.
As soon as you think there is something suspicious going on, stop dumpcap and note the exact time (incl. seconds). Then you can open the capture files with Wireshark and look for possible botnet traffic (around the time you stopped dumpcap). Unfortunately I can't tell you what to look for, as different bots use different communication methods.
BTW: To figure out if something suspicious is going on, you can run a network monitor tool that shows all connections from your system to the internet.
Hint: If a supplied answer resolves your question can you please "accept" it by clicking the checkmark icon next to it. This highlights good answers for the benefit of subsequent users with the same or similar questions.
Thanks a lot again, the scriptkiddy admitted he just wanted some attention. Network also shows nothing out of the usual, if I don't do something myself everything idles completely :)
Apparently one of those 99.99% ;-)