How to Use NETSTAT & FPORT Command to detect spyware, malware & trojans by Britec

  Рет қаралды 390,376

Britec09

Britec09

Күн бұрын

Пікірлер: 276
@Stiggandr1
@Stiggandr1 8 ай бұрын
Thank you so much. All these guides talk about using netstat to identify trojans, but the steps always go. Step 1) Eliminate known ports and connections. Step 2) Run whois on unknown TCP connections. Step 3) Disregard everything you just did and run a virus scan. This is so useful, even years later.
@davidfont2596
@davidfont2596 7 жыл бұрын
Almost ten years later and this is still a useful, well thought out tutorial.
@Britec09
@Britec09 7 жыл бұрын
Thanks
@vanex0-0
@vanex0-0 7 ай бұрын
u doing well now?
@momogunsabah
@momogunsabah 6 ай бұрын
2024, 14 years
@jcantonelli1
@jcantonelli1 9 ай бұрын
14 years later and this video is still relevant - thanks!
@sickwtw
@sickwtw Жыл бұрын
14 years ago and still helpful
@tubeDude48
@tubeDude48 8 жыл бұрын
CTRL-DEL doesn't always work, but CTRL-SHIFT ESC will! Also, once PIDs are showing, click on PID to put them in number order. This will speed-up looking for the PID.
@jerrylangebek5682
@jerrylangebek5682 8 жыл бұрын
Amazing! The knowledge you bring forth with the clear and concise explanation of its use is extremely helpful. Thank you so much!
@jeffreytimothyvalerie7540
@jeffreytimothyvalerie7540 3 жыл бұрын
It was wonderful to notice that you had Kaspersky included, my preferred choice of anti-virus
@peterdasa1262
@peterdasa1262 10 жыл бұрын
Ive probably watched 10 different spyware removal videos today They pretty well were all trying to say the same thing but you were by far the easiest to understand ..
@funnykat1566
@funnykat1566 5 жыл бұрын
Need an update to 2019
@azurestarton
@azurestarton 2 жыл бұрын
This helped me out a lot. My computer was hacked and my cursor was moving on it’s own. I got enraged so I decided to deal with this.
@amyamy534
@amyamy534 9 жыл бұрын
Nice one Brian. Mine was all clear but a relief to know. Very followable video even for me! Good job.
@Britec09
@Britec09 14 жыл бұрын
@BearHit did you put the fport folder in c: root directory? and then run it for command line?
@Subparanon
@Subparanon 12 жыл бұрын
Actually if you have spyware that has installed a backdoor in your computer it would be LISTENING. Those 127 addresses that are established are your local loopback connections. When two pieces of software on your pc need to communicate with each other say different services your pc runs, they will use local loopbacks to do so. If your Itunes needs to talk to the apple mobile device manager, it's going to do it with a 127.0.0.1 IP.
@sarahbrigida6678
@sarahbrigida6678 8 жыл бұрын
on windows 10 u have to go to processes and right click cpu and then select PID
@hackerperson6164
@hackerperson6164 7 жыл бұрын
Sarah Latschkowski your right sweetie 😍😍
@kip556
@kip556 7 жыл бұрын
Netstat can also achieve this by being run as admin and using the switch -naob
@sebastian_bluemel
@sebastian_bluemel 6 жыл бұрын
Stupid creeps
@gregmendoza7833
@gregmendoza7833 5 жыл бұрын
Sarah Brigida thank you lmao it was that easy
@Britec09
@Britec09 11 жыл бұрын
Your welcome John.
@pdenist
@pdenist 14 жыл бұрын
This was an awesome video. For someone like myself who is so green it is not funny. I learn a lot!! Thanks from VA!!
@sevengenerations8879
@sevengenerations8879 4 жыл бұрын
A 2019 update is requested indeed! I was playing around with Process Monitor (part of the Sysinternals suite by Microsoft) because task manager is lacking ... it's more complex, but maybe easier in the end ....
@jari2018
@jari2018 3 жыл бұрын
windows taskmanager are for android and tab kids/users -and its totally useless in windows 10 -what a piece of junk
@Britec09
@Britec09 15 жыл бұрын
its part of ITunes and Quicktime, should be safe just disable service if you dont want it
@Stewie4321
@Stewie4321 15 жыл бұрын
Great video Brian, very well narrated and a very useful tutorial....thanks!
@CoramDeoHawaii
@CoramDeoHawaii 8 жыл бұрын
Very cool Britec - still the best pc guru!
@instaminox
@instaminox 4 жыл бұрын
The requested operation requires elevation 🚨🚨🚨🚨
@carlamuzquiz1233
@carlamuzquiz1233 7 жыл бұрын
great videos very helpful with lots of information and you have a great way of explaining things clear and simple
@teamofwinter8128
@teamofwinter8128 4 жыл бұрын
Thank you very much i am from the future 2020 but thank you I wasnt able to use fport but i did the -ano and task manager Also i was unable to use spyware guide i just searched the process or program name and google got ur back
@gunjin2112
@gunjin2112 14 жыл бұрын
this is one of the best video tutorials that i've found yet! thanks! :D
@IvoNordman
@IvoNordman 2 жыл бұрын
Adding -b after netstat lists executables along with their requested addresses. Or use TCPView freeware to view the connections in real time
@Britec09
@Britec09 11 жыл бұрын
ESTABLISHED means there is a connection. So if you go to your browser and open it on a page you should see ESTABLISHED.
@georgegates526
@georgegates526 9 жыл бұрын
This is cool stuff Britec!!
@franklingregg4743
@franklingregg4743 9 жыл бұрын
Thanks for the spyware and virus tips,,will be following you...how are you on Linux OS..?
@Chng30FsCenEry
@Chng30FsCenEry 8 жыл бұрын
Excellent video! Thank you for posting it.
@MrFourseven
@MrFourseven 6 жыл бұрын
Oldie but a goodie cheers bad
@WmTyndale
@WmTyndale 4 жыл бұрын
What is keeping the malware from replacing your NETSTAT with a hacked copy of netstat?
@YANA4123
@YANA4123 2 жыл бұрын
Thank you for the help and clear discriptions. cheers
@Britec09
@Britec09 15 жыл бұрын
are you sure its a rootkit? have you scanned with gmer, also moving mouse could be down to a settings problem with your mouse
@tacosplease4906
@tacosplease4906 Жыл бұрын
If you are not connected to the internet should there be "ESTABLISHED " connections?
@Britec09
@Britec09 15 жыл бұрын
you can try panda root kit cleaner, sounds like a root kit you got, not easy to get rid of. try deleting it in safemode in command prompt or use a program call unlocker and kill process.
@ne12bot94
@ne12bot94 5 жыл бұрын
Question on backdoor , is their a away to manipulate the backdoor program and used it to your advantage?
@Islandscout8
@Islandscout8 10 жыл бұрын
Great and logical video. Though, the Fport link is no longer available. Also, in Windows 8, you can find where the program is located by right clicking it in task manager, then selecting "Open file location"
@BigHud83
@BigHud83 3 жыл бұрын
Great explanation
@satamique
@satamique 6 жыл бұрын
Thank you! Still relevant in 2018 :)
@concisejellyfish
@concisejellyfish 11 жыл бұрын
1. open command. 2. enter :: cd c:\ 3. enter :: shutdown -i {brings up the gui mgmt. for network remote shutdown} 4. add 5. add the computer name using ip [netstat] with the port used the rest is self explanitory
@AnthonyCastano
@AnthonyCastano 3 жыл бұрын
Very excellent video!!! Thank you. You pushed me in the right direction to find a virus in my cyber security class :)
@1pcmedic
@1pcmedic 11 жыл бұрын
Sandysuicide, if the command requires elevation, rt click on the cmd program and chose run as administrator. Or when you double click the command prompt icon, hold the shift key down this automatically opens a elevated command prompt...
@jerryblack7719
@jerryblack7719 8 ай бұрын
I noticed when I get rid of the trackers a lot of the established connection go away. If I kill them, will those connections stop?
@Mike-wk6sn
@Mike-wk6sn 5 жыл бұрын
Thanks, I think i just nearly got scammed today by one of those indian guys pretending yo be my phone company calling about unknown users using my ip address. He had me opening the cmd window and stuff and showing me how there were several unknown ip address on the netstat list. Thankfully they hang up mid way. I called my phone company about it and they said it's a scam. I called my bank and suspended & cancelled my credit card immediately. Thanks, I now know how to check if there's a malware on my pc.
@BertholdHinrichs
@BertholdHinrichs 10 жыл бұрын
well organized explanation, thanks
@eyalo99
@eyalo99 10 жыл бұрын
If I don't find the PID number in the Task Manager, how can I locate the process?
@seanblake2489
@seanblake2489 7 жыл бұрын
Great Job, Thanks for uploading.
@dearvifa3490
@dearvifa3490 5 жыл бұрын
i'm trying to active NETSTAT -B but is not working. the command said the requested operation requires elevation ? could you pls help me with it
@1pcmedic
@1pcmedic 11 жыл бұрын
Great job! Keep up the good work.
@pradeepmane1998
@pradeepmane1998 7 жыл бұрын
Thanks for the information and video.
@rickylove831
@rickylove831 11 жыл бұрын
Outstanding! Thanks a bunch.
@noseyparker6969
@noseyparker6969 11 жыл бұрын
Are there instances where the PID number doesn't show up in the taskbar monitor? If so, what would you need to do? Cheers BRI, once again
@doogerville
@doogerville 11 жыл бұрын
I had this too. just click where it says,"all" process. that will list it.
@noseyparker6969
@noseyparker6969 11 жыл бұрын
thanks for that :)
@joeycarr1398
@joeycarr1398 10 жыл бұрын
Under Processes in Task Manager there are always PID's presentwhich you may kill with the TASKKILL COMMAND c:\>taskkill pid number
@franciscoholguin855
@franciscoholguin855 5 жыл бұрын
Since the requested operation requires evaluation???????
@salsabil44
@salsabil44 9 жыл бұрын
Have I missed something? I´ve checked the Established PID numbers and they all correspond to a running process. Does that mean all is well? Or could a trojan or RAT not be disguised as a legit process? Is that not what they would normally do? So, in that case, how do we identify if all running processes are legitimate?
@Akuma_Raou
@Akuma_Raou Жыл бұрын
What if you have PID listed in your Netstat you can not find?
@Will-fr9hg
@Will-fr9hg 4 жыл бұрын
Should I be worried about a statues of syn_sent?
@fekkyb
@fekkyb Жыл бұрын
Hello Brian. I have a friend living in the US who recently has experienced strange things happening to his MSN email account. He’s not receiving mail from random people/email addresses. What can he do? Any ideas?
@marcomeeuwsen9891
@marcomeeuwsen9891 3 жыл бұрын
So what if the PID number isn't showed @ taskmanager?
@guitian54
@guitian54 8 жыл бұрын
after you kill the process is there anything else that should be done
@noname2020x
@noname2020x 15 жыл бұрын
Thanks, great video and you hit the nail on the head!
@sarahmiles6821
@sarahmiles6821 10 жыл бұрын
I followed your directions, but the PID number list to the right of of cmd, is missing. I have Windows 8
@sarahmiles6821
@sarahmiles6821 10 жыл бұрын
Nevermind.. got it
@imitatioDei
@imitatioDei 4 жыл бұрын
Hey great video . I have a problem there is a PID with an established connection but it doesn't show up in task manager. I found all the others except for one . Can you help?
@ChathurangaLakmal
@ChathurangaLakmal 13 жыл бұрын
Thank you so much. This was very helpful. I'm using Windows 7 Ultimate and this works perfectly. Cheers.........!
@Britec09
@Britec09 15 жыл бұрын
just run malwarebytes and superantispyware to remove trojans and spyware
@Britec09
@Britec09 14 жыл бұрын
@Karloki100 your welcome
@camiloroa3182
@camiloroa3182 3 жыл бұрын
Britec thanks in advance for your video, it was really informative and illustrative. However, I do know time has passed and I’m new on all this I was unable to configure or set up fport do you know how can I do it? Is it still available?
@chuckfinley400
@chuckfinley400 10 жыл бұрын
Hi and Thanks for posting this video.. its been really helpful... Question I'm unable to use the -b, the response is the command needs elevation.. what does that mean? thanks again
@ltg2227
@ltg2227 10 жыл бұрын
run command prompt as admin
@onearmfrog
@onearmfrog 15 жыл бұрын
Great video - Very useful! Thanks!
@jasonmcrgregor4476
@jasonmcrgregor4476 4 жыл бұрын
hello quick question, i have established connections but its not on the task manager when i cross reference it. what do i do?
@DFish-pb5pt
@DFish-pb5pt 7 жыл бұрын
when I type netstat.exe it says that the requested operation requires elevation....
@vicky5573
@vicky5573 4 жыл бұрын
put command prompt in start menu>right click on it>more>click on admin
@doogerville
@doogerville 11 жыл бұрын
Very well done Sir, thanks.
@TheVijeeth
@TheVijeeth 11 жыл бұрын
hi when I type netstat -b, it says "the requested operation requires elevation". please help me
@teamofwinter8128
@teamofwinter8128 4 жыл бұрын
Same
@Macskinny76
@Macskinny76 4 жыл бұрын
i don't think it works for windows 10, mine did the same thing.
@vybezz6359
@vybezz6359 4 жыл бұрын
run cmd as admin
@ArmedBubble15
@ArmedBubble15 3 жыл бұрын
Right click command promt and use run as administrator
@miguelgarciagines
@miguelgarciagines 11 жыл бұрын
Excellent and useful video.....thank you..
@pradyb646
@pradyb646 9 жыл бұрын
You are a legend.
@Blub0r
@Blub0r 15 жыл бұрын
very nice video. helped me a lot!
@notokay2485
@notokay2485 5 жыл бұрын
What if the PID present in the command is not in the task, what should I do?
@WalkerStevensFineArt4U
@WalkerStevensFineArt4U 5 жыл бұрын
Dear Adrian, do you know if this is still relavent today? I've been hacked, and the hacker wants $$$, or he says he's going to formatt my hard drive. I need to find the malicious rootkit he says he's implanted in my hard drive. He says he's using a VNC Protocall, but I checked the permissions, and off-site permissions, and it doesn't show anyone has gotten past my security, or controlled my computer from off-site, yet someone has changed my passwords several times. Can you help me? Or, do you know someone who might be able to? Kind Regards, walker Stevens
@Britec09
@Britec09 14 жыл бұрын
@gunjin2112 your welcome
@lefterispanos9543
@lefterispanos9543 2 жыл бұрын
Is there a way to permanently block an IP of a pid process that you found , that it might be a Trojan. Apart from using ps kill of course to kill the process.
@ns-yz1hj
@ns-yz1hj 3 жыл бұрын
Of course if some skid didn't write the malware and it beacons back to it's c&c, then this doesn't do you much good does it?
@joeyd31215
@joeyd31215 10 жыл бұрын
Good stuff here!
@Archon51
@Archon51 12 жыл бұрын
Go to start>accessories> (right click) Command Prompt and run as admin.
@shinzengumi
@shinzengumi 13 жыл бұрын
Hello, great video however I have a question. What does it mean if I find a PID listed on netstat -ano but it is not listed on my task manager PIDs? Thanks!
@juukame
@juukame 15 жыл бұрын
very nice vid keep em comin
@matthewmander4490
@matthewmander4490 8 жыл бұрын
thanks mate, very informative.
@juggernautz
@juggernautz 3 жыл бұрын
Looks great except witn WIN7 I enter netstat -b I get a response "requested operation requires elevation" what does that mean and how do I get to the next screen? How do I open the next screen so I can review settings after typing netstat -b ? I have no issues with netstat -ano in fact the only PID's in question were from Google Chrome which is normal unless chrome has a live hack so I think those PID's are okay. Problem is days earlier I got hacked and my firewall & antivirus was disabled along with spyware and the jackal changed my screen saver and screen background to black. Nothing missing plus I write down all important (financial etc) passwords on a mini notebook. My email sub files were all opened and normal Thunderbird does not open sub files just the main email file opens to read & download email. Browser password protection is lousy & they know they lie about it because of constant threats security is our problem.
@merakibreezyy5554
@merakibreezyy5554 3 жыл бұрын
run cmd as administrator and it should work just fine :)
@ivanakoprivica5784
@ivanakoprivica5784 7 жыл бұрын
Hello, I have one question. What if in cmd shows that there is one established connection with PID but in the task manager there is not that PID. What then?
@tim3854
@tim3854 7 жыл бұрын
I would like to know this too
@doubled5659
@doubled5659 6 жыл бұрын
same with me , have u figured out the problem so far ?
@camiloroa3182
@camiloroa3182 3 жыл бұрын
Check it by the IP address online.
@jonpaulchavez1459
@jonpaulchavez1459 4 жыл бұрын
need an update for 2020 and it looks "show process for all users" was uncheck is it needed?
@Britec09
@Britec09 15 жыл бұрын
trouble with rootkit is there hard to detect, if I was you, I would do a operating system rebuild, that way your be sure its gone, rootkits let the person come in and out of your computer when they like. But if your sure its gone and you have deleted it then your be fine rescan with rootkit scanner to make sure somethink like gmer
@Britec09
@Britec09 15 жыл бұрын
Hi Soilgirl Use malwarebytes and superantispyware and vundofix run them in safemode and you should be all clean. let me know how you get on Brian
@Maitreya888
@Maitreya888 8 жыл бұрын
Excellent, thank you
@XristosVaxevanosgritec
@XristosVaxevanosgritec 9 жыл бұрын
britec create a video to show us which ports are dangerous for virus and malware and how close them.
@Britec09
@Britec09 15 жыл бұрын
Thanks Alot
@MrBl8245
@MrBl8245 12 жыл бұрын
brilliant mate.
@ChathurangaLakmal
@ChathurangaLakmal 13 жыл бұрын
@theCIAguy007 I had the same problem & I found the solution. What you have to do is just open command prompt as administrator. (Just go to start>All Programs>Accessories> and Right click on Command Prompt and click on "Run as Administrator)
@i8ab
@i8ab 11 жыл бұрын
I found some "established" connections when I pulled up that list. I had closed all other windows, so I am concerned. I checked each by name on "Spywareguide", and no results were found for most, only 1 called "system", didn't seem to be very dangerous. Does this mean I may be ok? Perhaps they are supposed to be there?
@s94200.
@s94200. 8 жыл бұрын
after downloading fport from the mentioned site, im unable to run the command. Error message "fport is not recognized as an internal or external command, operable program or batch file". How do i resolve this issue?
@Britec09
@Britec09 14 жыл бұрын
your welcome
@jtd4847
@jtd4847 8 жыл бұрын
What if you have a established port that does not show up in the task manager? Is there a way to kill this port and is it a hacked port?
@AngelofDeath1432
@AngelofDeath1432 8 жыл бұрын
What does it mean when you type in comand prompt ''netstat -b'' the you get the message ''the requested operation requires elevation''?
@LeandroBarbksa
@LeandroBarbksa 8 жыл бұрын
It means you need to run the CMD as an administrator. If it's Windows 10, right-click the Command Prompt in the start menu and select "Run as administrator".
@carlegleason1383
@carlegleason1383 5 жыл бұрын
@@LeandroBarbksa Right click on CMD give Y administrator
@carlegleason1383
@carlegleason1383 5 жыл бұрын
gives you the Adm.
@MrOnfireforGod
@MrOnfireforGod 9 жыл бұрын
I have downloaded fport and pskill. How can i use them in command prompt?
They tried to hack me with UNDETECTED Malware
20:19
Eric Parker
Рет қаралды 40 М.
What type of pedestrian are you?😄 #tiktok #elsarca
00:28
Elsa Arca
Рет қаралды 21 МЛН
Motorbike Smashes Into Porsche! 😱
00:15
Caters Clips
Рет қаралды 23 МЛН
Из какого города смотришь? 😃
00:34
МЯТНАЯ ФАНТА
Рет қаралды 2 МЛН
This Makes Malware in 30 Seconds...
16:45
PCPal
Рет қаралды 19 М.
Setting up an UNDETECTABLE VM for Malware Analysis
8:04
Eric Parker
Рет қаралды 77 М.
CPE311 - Lab 02 - Datatypes and Variables
1:06:32
Dr. Ashraf Suyyagh
Рет қаралды 832
NETSTAT Command Explained
6:10
PowerCert Animated Videos
Рет қаралды 345 М.
How-to: Use NETSTAT.EXE to detect spyware/malware
5:42
Guiding Tech
Рет қаралды 636 М.
Forgot windows 11 password.. do this!! - New Method 2024
3:25
Savvy Tech Tips
Рет қаралды 906
Microsoft PowerShell for Beginners - Video 1 Learn PowerShell
27:57
Shane Young
Рет қаралды 1,7 МЛН
Booting an Operating System
11:11
Dhananjai Rao
Рет қаралды 102 М.