Thank you so much. All these guides talk about using netstat to identify trojans, but the steps always go. Step 1) Eliminate known ports and connections. Step 2) Run whois on unknown TCP connections. Step 3) Disregard everything you just did and run a virus scan. This is so useful, even years later.
@davidfont25967 жыл бұрын
Almost ten years later and this is still a useful, well thought out tutorial.
@Britec097 жыл бұрын
Thanks
@vanex0-07 ай бұрын
u doing well now?
@momogunsabah6 ай бұрын
2024, 14 years
@jcantonelli19 ай бұрын
14 years later and this video is still relevant - thanks!
@sickwtw Жыл бұрын
14 years ago and still helpful
@tubeDude488 жыл бұрын
CTRL-DEL doesn't always work, but CTRL-SHIFT ESC will! Also, once PIDs are showing, click on PID to put them in number order. This will speed-up looking for the PID.
@jerrylangebek56828 жыл бұрын
Amazing! The knowledge you bring forth with the clear and concise explanation of its use is extremely helpful. Thank you so much!
@jeffreytimothyvalerie75403 жыл бұрын
It was wonderful to notice that you had Kaspersky included, my preferred choice of anti-virus
@peterdasa126210 жыл бұрын
Ive probably watched 10 different spyware removal videos today They pretty well were all trying to say the same thing but you were by far the easiest to understand ..
@funnykat15665 жыл бұрын
Need an update to 2019
@azurestarton2 жыл бұрын
This helped me out a lot. My computer was hacked and my cursor was moving on it’s own. I got enraged so I decided to deal with this.
@amyamy5349 жыл бұрын
Nice one Brian. Mine was all clear but a relief to know. Very followable video even for me! Good job.
@Britec0914 жыл бұрын
@BearHit did you put the fport folder in c: root directory? and then run it for command line?
@Subparanon12 жыл бұрын
Actually if you have spyware that has installed a backdoor in your computer it would be LISTENING. Those 127 addresses that are established are your local loopback connections. When two pieces of software on your pc need to communicate with each other say different services your pc runs, they will use local loopbacks to do so. If your Itunes needs to talk to the apple mobile device manager, it's going to do it with a 127.0.0.1 IP.
@sarahbrigida66788 жыл бұрын
on windows 10 u have to go to processes and right click cpu and then select PID
@hackerperson61647 жыл бұрын
Sarah Latschkowski your right sweetie 😍😍
@kip5567 жыл бұрын
Netstat can also achieve this by being run as admin and using the switch -naob
@sebastian_bluemel6 жыл бұрын
Stupid creeps
@gregmendoza78335 жыл бұрын
Sarah Brigida thank you lmao it was that easy
@Britec0911 жыл бұрын
Your welcome John.
@pdenist14 жыл бұрын
This was an awesome video. For someone like myself who is so green it is not funny. I learn a lot!! Thanks from VA!!
@sevengenerations88794 жыл бұрын
A 2019 update is requested indeed! I was playing around with Process Monitor (part of the Sysinternals suite by Microsoft) because task manager is lacking ... it's more complex, but maybe easier in the end ....
@jari20183 жыл бұрын
windows taskmanager are for android and tab kids/users -and its totally useless in windows 10 -what a piece of junk
@Britec0915 жыл бұрын
its part of ITunes and Quicktime, should be safe just disable service if you dont want it
@Stewie432115 жыл бұрын
Great video Brian, very well narrated and a very useful tutorial....thanks!
@CoramDeoHawaii8 жыл бұрын
Very cool Britec - still the best pc guru!
@instaminox4 жыл бұрын
The requested operation requires elevation 🚨🚨🚨🚨
@carlamuzquiz12337 жыл бұрын
great videos very helpful with lots of information and you have a great way of explaining things clear and simple
@teamofwinter81284 жыл бұрын
Thank you very much i am from the future 2020 but thank you I wasnt able to use fport but i did the -ano and task manager Also i was unable to use spyware guide i just searched the process or program name and google got ur back
@gunjin211214 жыл бұрын
this is one of the best video tutorials that i've found yet! thanks! :D
@IvoNordman2 жыл бұрын
Adding -b after netstat lists executables along with their requested addresses. Or use TCPView freeware to view the connections in real time
@Britec0911 жыл бұрын
ESTABLISHED means there is a connection. So if you go to your browser and open it on a page you should see ESTABLISHED.
@georgegates5269 жыл бұрын
This is cool stuff Britec!!
@franklingregg47439 жыл бұрын
Thanks for the spyware and virus tips,,will be following you...how are you on Linux OS..?
@Chng30FsCenEry8 жыл бұрын
Excellent video! Thank you for posting it.
@MrFourseven6 жыл бұрын
Oldie but a goodie cheers bad
@WmTyndale4 жыл бұрын
What is keeping the malware from replacing your NETSTAT with a hacked copy of netstat?
@YANA41232 жыл бұрын
Thank you for the help and clear discriptions. cheers
@Britec0915 жыл бұрын
are you sure its a rootkit? have you scanned with gmer, also moving mouse could be down to a settings problem with your mouse
@tacosplease4906 Жыл бұрын
If you are not connected to the internet should there be "ESTABLISHED " connections?
@Britec0915 жыл бұрын
you can try panda root kit cleaner, sounds like a root kit you got, not easy to get rid of. try deleting it in safemode in command prompt or use a program call unlocker and kill process.
@ne12bot945 жыл бұрын
Question on backdoor , is their a away to manipulate the backdoor program and used it to your advantage?
@Islandscout810 жыл бұрын
Great and logical video. Though, the Fport link is no longer available. Also, in Windows 8, you can find where the program is located by right clicking it in task manager, then selecting "Open file location"
@BigHud833 жыл бұрын
Great explanation
@satamique6 жыл бұрын
Thank you! Still relevant in 2018 :)
@concisejellyfish11 жыл бұрын
1. open command. 2. enter :: cd c:\ 3. enter :: shutdown -i {brings up the gui mgmt. for network remote shutdown} 4. add 5. add the computer name using ip [netstat] with the port used the rest is self explanitory
@AnthonyCastano3 жыл бұрын
Very excellent video!!! Thank you. You pushed me in the right direction to find a virus in my cyber security class :)
@1pcmedic11 жыл бұрын
Sandysuicide, if the command requires elevation, rt click on the cmd program and chose run as administrator. Or when you double click the command prompt icon, hold the shift key down this automatically opens a elevated command prompt...
@jerryblack77198 ай бұрын
I noticed when I get rid of the trackers a lot of the established connection go away. If I kill them, will those connections stop?
@Mike-wk6sn5 жыл бұрын
Thanks, I think i just nearly got scammed today by one of those indian guys pretending yo be my phone company calling about unknown users using my ip address. He had me opening the cmd window and stuff and showing me how there were several unknown ip address on the netstat list. Thankfully they hang up mid way. I called my phone company about it and they said it's a scam. I called my bank and suspended & cancelled my credit card immediately. Thanks, I now know how to check if there's a malware on my pc.
@BertholdHinrichs10 жыл бұрын
well organized explanation, thanks
@eyalo9910 жыл бұрын
If I don't find the PID number in the Task Manager, how can I locate the process?
@seanblake24897 жыл бұрын
Great Job, Thanks for uploading.
@dearvifa34905 жыл бұрын
i'm trying to active NETSTAT -B but is not working. the command said the requested operation requires elevation ? could you pls help me with it
@1pcmedic11 жыл бұрын
Great job! Keep up the good work.
@pradeepmane19987 жыл бұрын
Thanks for the information and video.
@rickylove83111 жыл бұрын
Outstanding! Thanks a bunch.
@noseyparker696911 жыл бұрын
Are there instances where the PID number doesn't show up in the taskbar monitor? If so, what would you need to do? Cheers BRI, once again
@doogerville11 жыл бұрын
I had this too. just click where it says,"all" process. that will list it.
@noseyparker696911 жыл бұрын
thanks for that :)
@joeycarr139810 жыл бұрын
Under Processes in Task Manager there are always PID's presentwhich you may kill with the TASKKILL COMMAND c:\>taskkill pid number
@franciscoholguin8555 жыл бұрын
Since the requested operation requires evaluation???????
@salsabil449 жыл бұрын
Have I missed something? I´ve checked the Established PID numbers and they all correspond to a running process. Does that mean all is well? Or could a trojan or RAT not be disguised as a legit process? Is that not what they would normally do? So, in that case, how do we identify if all running processes are legitimate?
@Akuma_Raou Жыл бұрын
What if you have PID listed in your Netstat you can not find?
@Will-fr9hg4 жыл бұрын
Should I be worried about a statues of syn_sent?
@fekkyb Жыл бұрын
Hello Brian. I have a friend living in the US who recently has experienced strange things happening to his MSN email account. He’s not receiving mail from random people/email addresses. What can he do? Any ideas?
@marcomeeuwsen98913 жыл бұрын
So what if the PID number isn't showed @ taskmanager?
@guitian548 жыл бұрын
after you kill the process is there anything else that should be done
@noname2020x15 жыл бұрын
Thanks, great video and you hit the nail on the head!
@sarahmiles682110 жыл бұрын
I followed your directions, but the PID number list to the right of of cmd, is missing. I have Windows 8
@sarahmiles682110 жыл бұрын
Nevermind.. got it
@imitatioDei4 жыл бұрын
Hey great video . I have a problem there is a PID with an established connection but it doesn't show up in task manager. I found all the others except for one . Can you help?
@ChathurangaLakmal13 жыл бұрын
Thank you so much. This was very helpful. I'm using Windows 7 Ultimate and this works perfectly. Cheers.........!
@Britec0915 жыл бұрын
just run malwarebytes and superantispyware to remove trojans and spyware
@Britec0914 жыл бұрын
@Karloki100 your welcome
@camiloroa31823 жыл бұрын
Britec thanks in advance for your video, it was really informative and illustrative. However, I do know time has passed and I’m new on all this I was unable to configure or set up fport do you know how can I do it? Is it still available?
@chuckfinley40010 жыл бұрын
Hi and Thanks for posting this video.. its been really helpful... Question I'm unable to use the -b, the response is the command needs elevation.. what does that mean? thanks again
@ltg222710 жыл бұрын
run command prompt as admin
@onearmfrog15 жыл бұрын
Great video - Very useful! Thanks!
@jasonmcrgregor44764 жыл бұрын
hello quick question, i have established connections but its not on the task manager when i cross reference it. what do i do?
@DFish-pb5pt7 жыл бұрын
when I type netstat.exe it says that the requested operation requires elevation....
@vicky55734 жыл бұрын
put command prompt in start menu>right click on it>more>click on admin
@doogerville11 жыл бұрын
Very well done Sir, thanks.
@TheVijeeth11 жыл бұрын
hi when I type netstat -b, it says "the requested operation requires elevation". please help me
@teamofwinter81284 жыл бұрын
Same
@Macskinny764 жыл бұрын
i don't think it works for windows 10, mine did the same thing.
@vybezz63594 жыл бұрын
run cmd as admin
@ArmedBubble153 жыл бұрын
Right click command promt and use run as administrator
@miguelgarciagines11 жыл бұрын
Excellent and useful video.....thank you..
@pradyb6469 жыл бұрын
You are a legend.
@Blub0r15 жыл бұрын
very nice video. helped me a lot!
@notokay24855 жыл бұрын
What if the PID present in the command is not in the task, what should I do?
@WalkerStevensFineArt4U5 жыл бұрын
Dear Adrian, do you know if this is still relavent today? I've been hacked, and the hacker wants $$$, or he says he's going to formatt my hard drive. I need to find the malicious rootkit he says he's implanted in my hard drive. He says he's using a VNC Protocall, but I checked the permissions, and off-site permissions, and it doesn't show anyone has gotten past my security, or controlled my computer from off-site, yet someone has changed my passwords several times. Can you help me? Or, do you know someone who might be able to? Kind Regards, walker Stevens
@Britec0914 жыл бұрын
@gunjin2112 your welcome
@lefterispanos95432 жыл бұрын
Is there a way to permanently block an IP of a pid process that you found , that it might be a Trojan. Apart from using ps kill of course to kill the process.
@ns-yz1hj3 жыл бұрын
Of course if some skid didn't write the malware and it beacons back to it's c&c, then this doesn't do you much good does it?
@joeyd3121510 жыл бұрын
Good stuff here!
@Archon5112 жыл бұрын
Go to start>accessories> (right click) Command Prompt and run as admin.
@shinzengumi13 жыл бұрын
Hello, great video however I have a question. What does it mean if I find a PID listed on netstat -ano but it is not listed on my task manager PIDs? Thanks!
@juukame15 жыл бұрын
very nice vid keep em comin
@matthewmander44908 жыл бұрын
thanks mate, very informative.
@juggernautz3 жыл бұрын
Looks great except witn WIN7 I enter netstat -b I get a response "requested operation requires elevation" what does that mean and how do I get to the next screen? How do I open the next screen so I can review settings after typing netstat -b ? I have no issues with netstat -ano in fact the only PID's in question were from Google Chrome which is normal unless chrome has a live hack so I think those PID's are okay. Problem is days earlier I got hacked and my firewall & antivirus was disabled along with spyware and the jackal changed my screen saver and screen background to black. Nothing missing plus I write down all important (financial etc) passwords on a mini notebook. My email sub files were all opened and normal Thunderbird does not open sub files just the main email file opens to read & download email. Browser password protection is lousy & they know they lie about it because of constant threats security is our problem.
@merakibreezyy55543 жыл бұрын
run cmd as administrator and it should work just fine :)
@ivanakoprivica57847 жыл бұрын
Hello, I have one question. What if in cmd shows that there is one established connection with PID but in the task manager there is not that PID. What then?
@tim38547 жыл бұрын
I would like to know this too
@doubled56596 жыл бұрын
same with me , have u figured out the problem so far ?
@camiloroa31823 жыл бұрын
Check it by the IP address online.
@jonpaulchavez14594 жыл бұрын
need an update for 2020 and it looks "show process for all users" was uncheck is it needed?
@Britec0915 жыл бұрын
trouble with rootkit is there hard to detect, if I was you, I would do a operating system rebuild, that way your be sure its gone, rootkits let the person come in and out of your computer when they like. But if your sure its gone and you have deleted it then your be fine rescan with rootkit scanner to make sure somethink like gmer
@Britec0915 жыл бұрын
Hi Soilgirl Use malwarebytes and superantispyware and vundofix run them in safemode and you should be all clean. let me know how you get on Brian
@Maitreya8888 жыл бұрын
Excellent, thank you
@XristosVaxevanosgritec9 жыл бұрын
britec create a video to show us which ports are dangerous for virus and malware and how close them.
@Britec0915 жыл бұрын
Thanks Alot
@MrBl824512 жыл бұрын
brilliant mate.
@ChathurangaLakmal13 жыл бұрын
@theCIAguy007 I had the same problem & I found the solution. What you have to do is just open command prompt as administrator. (Just go to start>All Programs>Accessories> and Right click on Command Prompt and click on "Run as Administrator)
@i8ab11 жыл бұрын
I found some "established" connections when I pulled up that list. I had closed all other windows, so I am concerned. I checked each by name on "Spywareguide", and no results were found for most, only 1 called "system", didn't seem to be very dangerous. Does this mean I may be ok? Perhaps they are supposed to be there?
@s94200.8 жыл бұрын
after downloading fport from the mentioned site, im unable to run the command. Error message "fport is not recognized as an internal or external command, operable program or batch file". How do i resolve this issue?
@Britec0914 жыл бұрын
your welcome
@jtd48478 жыл бұрын
What if you have a established port that does not show up in the task manager? Is there a way to kill this port and is it a hacked port?
@AngelofDeath14328 жыл бұрын
What does it mean when you type in comand prompt ''netstat -b'' the you get the message ''the requested operation requires elevation''?
@LeandroBarbksa8 жыл бұрын
It means you need to run the CMD as an administrator. If it's Windows 10, right-click the Command Prompt in the start menu and select "Run as administrator".
@carlegleason13835 жыл бұрын
@@LeandroBarbksa Right click on CMD give Y administrator
@carlegleason13835 жыл бұрын
gives you the Adm.
@MrOnfireforGod9 жыл бұрын
I have downloaded fport and pskill. How can i use them in command prompt?