Это видео недоступно.
Сожалеем об этом.

How to Use NETSTAT & FPORT Command to detect spyware, malware & trojans by Britec

Поделиться
HTML-код
  • Опубликовано: 4 июл 2009
  • How to Use NETSTAT & FPORT Command to detect spyware, malware & trojans and then use PSKILL to kill process so you can delete virus by Britec
    ---------------------------
    PSkill Program Download
    technet.microsoft.com/en-us/sy...
    ---------------------------
    Fport v 2.0 download
    www.foundstone.com/us/resource...
    ---------------------------
    Spyware guide
    www.spywareguide.com/
    Thanks
    Britec
    www.britec.org.uk
    www.briteccomputers.co.uk
    www.pcrepairhetfordshire.co.uk

Комментарии • 276

  • @davidfont2596
    @davidfont2596 7 лет назад +17

    Almost ten years later and this is still a useful, well thought out tutorial.

  • @jcantonelli1
    @jcantonelli1 6 месяцев назад +1

    14 years later and this video is still relevant - thanks!

  • @Britec09
    @Britec09  14 лет назад +1

    @BearHit did you put the fport folder in c: root directory? and then run it for command line?

  • @Stiggandr1
    @Stiggandr1 5 месяцев назад

    Thank you so much. All these guides talk about using netstat to identify trojans, but the steps always go.
    Step 1) Eliminate known ports and connections.
    Step 2) Run whois on unknown TCP connections.
    Step 3) Disregard everything you just did and run a virus scan.
    This is so useful, even years later.

  • @jerrylangebek5682
    @jerrylangebek5682 8 лет назад +8

    Amazing! The knowledge you bring forth with the clear and concise explanation of its use is extremely helpful.
    Thank you so much!

  • @amyamy534
    @amyamy534 8 лет назад +1

    Nice one Brian. Mine was all clear but a relief to know. Very followable video even for me! Good job.

  • @sickwtw
    @sickwtw 8 месяцев назад +1

    14 years ago and still helpful

  • @Stewie4321
    @Stewie4321 14 лет назад +1

    Great video Brian, very well narrated and a very useful tutorial....thanks!

  • @peterdasa1262
    @peterdasa1262 10 лет назад

    Ive probably watched 10 different spyware removal videos today
    They pretty well were all trying to say the same thing but you were by far the easiest to understand ..

  • @carlamuzquiz1233
    @carlamuzquiz1233 7 лет назад +2

    great videos very helpful with lots of information and you have a great way of explaining things clear and simple

  • @gunjin2112
    @gunjin2112 14 лет назад

    this is one of the best video tutorials that i've found yet! thanks! :D

  • @Chng30FsCenEry
    @Chng30FsCenEry 8 лет назад +1

    Excellent video! Thank you for posting it.

  • @tubeDude48
    @tubeDude48 8 лет назад +3

    CTRL-DEL doesn't always work, but CTRL-SHIFT ESC will!
    Also, once PIDs are showing, click on PID to put them in number order.
    This will speed-up looking for the PID.

  • @jeffreytimothyvalerie7540
    @jeffreytimothyvalerie7540 2 года назад

    It was wonderful to notice that you had Kaspersky included, my preferred choice of anti-virus

  • @mollyemanlaerton5167
    @mollyemanlaerton5167 9 лет назад

    Thanks so much for your video, it was very helpful!

  • @BertholdHinrichs
    @BertholdHinrichs 9 лет назад

    well organized explanation, thanks

  • @AnthonyCastano
    @AnthonyCastano 3 года назад

    Very excellent video!!! Thank you. You pushed me in the right direction to find a virus in my cyber security class :)

  • @funnykat1566
    @funnykat1566 4 года назад +19

    Need an update to 2019

  • @seanblake2489
    @seanblake2489 7 лет назад

    Great Job, Thanks for uploading.

  • @YANA4123
    @YANA4123 2 года назад

    Thank you for the help and clear discriptions. cheers

  • @franklingregg4743
    @franklingregg4743 9 лет назад

    Thanks for the spyware and virus tips,,will be following you...how are you on Linux OS..?

  • @noname2020x
    @noname2020x 14 лет назад

    Thanks, great video and you hit the nail on the head!

  • @1pcmedic
    @1pcmedic 10 лет назад

    Great job! Keep up the good work.

  • @doogerville
    @doogerville 10 лет назад

    Very well done Sir, thanks.

  • @Britec09
    @Britec09  15 лет назад

    are you sure its a rootkit? have you scanned with gmer, also moving mouse could be down to a settings problem with your mouse

  • @pradeepmane1998
    @pradeepmane1998 6 лет назад

    Thanks for the information and video.

  • @matthewmander4490
    @matthewmander4490 8 лет назад

    thanks mate, very informative.

  • @satamique
    @satamique 6 лет назад

    Thank you! Still relevant in 2018 :)

  • @ChathurangaLakmal
    @ChathurangaLakmal 12 лет назад

    Thank you so much. This was very helpful.
    I'm using Windows 7 Ultimate and this works perfectly.
    Cheers.........!

  • @pdenist
    @pdenist 14 лет назад

    This was an awesome video. For someone like myself who is so green it is not funny. I learn a lot!! Thanks from VA!!

  • @rickylove831
    @rickylove831 10 лет назад

    Outstanding! Thanks a bunch.

  • @BigHud83
    @BigHud83 3 года назад

    Great explanation

  • @miguelgarciagines
    @miguelgarciagines 10 лет назад

    Excellent and useful video.....thank you..

  • @onearmfrog
    @onearmfrog 15 лет назад

    Great video - Very useful! Thanks!

  • @georgegates526
    @georgegates526 8 лет назад

    This is cool stuff Britec!!

  • @ne12bot94
    @ne12bot94 5 лет назад

    Question on backdoor , is their a away to manipulate the backdoor program and used it to your advantage?

  • @CoramDeoHawaii
    @CoramDeoHawaii 8 лет назад

    Very cool Britec - still the best pc guru!

  • @Maitreya888
    @Maitreya888 8 лет назад

    Excellent, thank you

  • @Britec09
    @Britec09  11 лет назад +1

    Your welcome John.

  • @azurestarton
    @azurestarton 2 года назад

    This helped me out a lot.
    My computer was hacked and my cursor was moving on it’s own.
    I got enraged so I decided to deal with this.

  • @teamofwinter8128
    @teamofwinter8128 4 года назад

    Thank you very much i am from the future 2020 but thank you
    I wasnt able to use fport but i did the -ano and task manager
    Also i was unable to use spyware guide i just searched the process or program name and google got ur back

  • @songsitcook428
    @songsitcook428 5 лет назад

    Your a life saver thank you so much

  • @Blub0r
    @Blub0r 15 лет назад

    very nice video. helped me a lot!

  • @Britec09
    @Britec09  15 лет назад

    Thanks Alot

  • @Islandscout8
    @Islandscout8 9 лет назад +1

    Great and logical video. Though, the Fport link is no longer available. Also, in Windows 8, you can find where the program is located by right clicking it in task manager, then selecting "Open file location"

  • @Subparanon
    @Subparanon 12 лет назад +1

    Actually if you have spyware that has installed a backdoor in your computer it would be LISTENING. Those 127 addresses that are established are your local loopback connections. When two pieces of software on your pc need to communicate with each other say different services your pc runs, they will use local loopbacks to do so. If your Itunes needs to talk to the apple mobile device manager, it's going to do it with a 127.0.0.1 IP.

  • @sevengenerations8879
    @sevengenerations8879 4 года назад

    A 2019 update is requested indeed! I was playing around with Process Monitor (part of the Sysinternals suite by Microsoft) because task manager is lacking ... it's more complex, but maybe easier in the end ....

    • @jari2018
      @jari2018 3 года назад

      windows taskmanager are for android and tab kids/users -and its totally useless in windows 10 -what a piece of junk

  • @joeyd31215
    @joeyd31215 10 лет назад

    Good stuff here!

  • @bigjohn697791
    @bigjohn697791 10 лет назад

    brilliant thanks very much learnt a bit to take away with me :-)

  • @sarahbrigida6678
    @sarahbrigida6678 8 лет назад +9

    on windows 10 u have to go to processes and right click cpu and then select PID

    • @hackerperson6164
      @hackerperson6164 7 лет назад

      Sarah Latschkowski your right sweetie 😍😍

    • @kip556
      @kip556 7 лет назад

      Netstat can also achieve this by being run as admin and using the switch -naob

    • @sebastian_bluemel
      @sebastian_bluemel 5 лет назад

      Stupid creeps

    • @gregmendoza7833
      @gregmendoza7833 4 года назад

      Sarah Brigida thank you lmao it was that easy

  • @xPancakes4lyf
    @xPancakes4lyf 7 лет назад

    im trying to port forward the xbox live port 3074 udp/tcp, and it says the ports in use or some bs, so i looked all through the cmd and that port never showed up. i can enter 3074 tcp in port forwarding fine, but the udp wont, and theres no port 3074 udp in use or binded. is there a way to force find a specified port?

  • @jasonmcrgregor4476
    @jasonmcrgregor4476 4 года назад

    hello quick question, i have established connections but its not on the task manager when i cross reference it. what do i do?

  • @camiloroa3182
    @camiloroa3182 2 года назад

    Britec thanks in advance for your video, it was really informative and illustrative. However, I do know time has passed and I’m new on all this I was unable to configure or set up fport do you know how can I do it? Is it still available?

  • @Britec09
    @Britec09  15 лет назад

    trouble with rootkit is there hard to detect, if I was you, I would do a operating system rebuild, that way your be sure its gone, rootkits let the person come in and out of your computer when they like. But if your sure its gone and you have deleted it then your be fine rescan with rootkit scanner to make sure somethink like gmer

  • @filippersson4693
    @filippersson4693 6 лет назад

    If I enter task manager and "end activity" does it end forever or do I need to do this everytime I login to my pc?

  • @shinzengumi
    @shinzengumi 12 лет назад

    Hello, great video however I have a question. What does it mean if I find a PID listed on netstat -ano but it is not listed on my task manager PIDs? Thanks!

  • @rainpurple88
    @rainpurple88 11 лет назад +1

    hello there, for me the 'netstat -b' command returns "the requiested operation requires elevation".
    Please help

  • @mistercolkitt
    @mistercolkitt 13 лет назад

    very hepful thank you!

  • @niroopbs2141
    @niroopbs2141 7 лет назад

    cool, that works for me, thanks a lot !!

  • @salsabil44
    @salsabil44 9 лет назад

    Have I missed something? I´ve checked the Established PID numbers and they all correspond to a running process. Does that mean all is well? Or could a trojan or RAT not be disguised as a legit process? Is that not what they would normally do? So, in that case, how do we identify if all running processes are legitimate?

  • @juukame
    @juukame 15 лет назад

    very nice vid keep em comin

  • @TyrantExterminator1776
    @TyrantExterminator1776 3 года назад

    What does it mean if you find a PID number in CMD that does not show up in Task Manager details?

  • @1pcmedic
    @1pcmedic 10 лет назад

    Sandysuicide, if the command requires elevation, rt click on the cmd program and chose run as administrator. Or when you double click the command prompt icon, hold the shift key down this automatically opens a elevated command prompt...

  • @IvoNordman
    @IvoNordman 2 года назад

    Adding -b after netstat lists executables along with their requested addresses. Or use TCPView freeware to view the connections in real time

  • @lefterispanos9543
    @lefterispanos9543 2 года назад

    Is there a way to permanently block an IP of a pid process that you found , that it might be a Trojan. Apart from using ps kill of course to kill the process.

  • @Britec09
    @Britec09  14 лет назад

    @ACADIENNEXX right click command prompt and run as administrator

  • @guitian54
    @guitian54 7 лет назад

    after you kill the process is there anything else that should be done

  • @LonelyDev71
    @LonelyDev71 5 лет назад

    Thank you.

  • @imitatioDei
    @imitatioDei 4 года назад

    Hey great video . I have a problem there is a PID with an established connection but it doesn't show up in task manager. I found all the others except for one . Can you help?

  • @jerryblack7719
    @jerryblack7719 4 месяца назад

    I noticed when I get rid of the trackers a lot of the established connection go away. If I kill them, will those connections stop?

  • @carljarvi2914
    @carljarvi2914 8 лет назад

    cns back slash to clear the screen.. was so fast i didn't get that part?

  • @MrBl8245
    @MrBl8245 11 лет назад

    brilliant mate.

  • @Audiotorium87
    @Audiotorium87 10 лет назад

    Hello Brian
    I seem to have a problem running the Fport and Pskill programs. I am looking for any nasty's on my computer and was hoping that you can help me out. I've been doing a little bit of research into the CMD promp section but again seem to be having problems accessing certain areas requiring information.
    I first noticed that my files had reloaded them selves when I had previously deleted them, this as I am aware is a sign of computer hacking potentially. I have not run a system restore and my computer plays up.
    Please can you help me
    Curtis

  • @tacosplease4906
    @tacosplease4906 Год назад

    If you are not connected to the internet should there be "ESTABLISHED " connections?

  • @WmTyndale
    @WmTyndale 4 года назад

    What is keeping the malware from replacing your NETSTAT with a hacked copy of netstat?

  • @lawrencebayon7556
    @lawrencebayon7556 3 года назад

    i tried to look for pid in the task manager but i cant seem to see but its showing on the cmd prompt what should i do?

  • @pradyb646
    @pradyb646 9 лет назад

    You are a legend.

  • @MrOnfireforGod
    @MrOnfireforGod 9 лет назад

    I have downloaded fport and pskill. How can i use them in command prompt?

  • @MK-je3hj
    @MK-je3hj 2 года назад

    what does it mean if you can view a PID on Task Viewer but not seeing it on CMD.

  • @brooohus
    @brooohus 11 лет назад

    Some of the PID names i have in CMD arent under the processes so i cant found out what they are, why?

  • @chuckfinley400
    @chuckfinley400 9 лет назад

    Hi and Thanks for posting this video.. its been really helpful... Question I'm unable to use the -b, the response is the command needs elevation.. what does that mean? thanks again

    • @ltg2227
      @ltg2227 9 лет назад

      run command prompt as admin

  • @jonpaulchavez1459
    @jonpaulchavez1459 3 года назад

    need an update for 2020 and it looks "show process for all users" was uncheck is it needed?

  • @eyalo99
    @eyalo99 9 лет назад

    If I don't find the PID number in the Task Manager, how can I locate the process?

  • @christopherjspiteri
    @christopherjspiteri 7 лет назад

    I tried the -b command, I am using DietPi on my Raspberry Pi, its the only Linux system I have access to right now. Any idea how to get this to work ? Any help appreciated.

  • @concernedcitizen5220
    @concernedcitizen5220 6 лет назад

    Doesnt taskkill do the same thing as pskill?????

  • @timtom4707
    @timtom4707 8 лет назад

    Hello, when I do the b command it said ( the requested operation requires elevation) Please note I am registered as administrator

  • @Britec09
    @Britec09  15 лет назад

    you can try panda root kit cleaner, sounds like a root kit you got, not easy to get rid of.
    try deleting it in safemode in command prompt or use a program call unlocker and kill process.

  • @franciscoholguin855
    @franciscoholguin855 4 года назад

    Since the requested operation requires evaluation???????

  • @V11P11R11
    @V11P11R11 10 лет назад

    what does it mean when the number on the established list in command prompt doesnt show in the task manager??? how then could I remove that, is it ahacker ? or virus or is it not? please contact asap

  • @dearvifa3490
    @dearvifa3490 5 лет назад

    i'm trying to active NETSTAT -B but is not working. the command said the requested operation requires elevation ? could you pls help me with it

  • @Britec09
    @Britec09  15 лет назад

    Hi Soilgirl
    Use malwarebytes and superantispyware and vundofix
    run them in safemode and you should be all clean. let me know how you get on
    Brian

  • @eren3390
    @eren3390 4 года назад +1

    I have one pid that isnt showing up in taskmanager.. i have no clue what it is

  • @Britec09
    @Britec09  14 лет назад

    @Karloki100 your welcome

  • @AZRazi
    @AZRazi 4 года назад

    helpful tips dn

  • @s94200.
    @s94200. 7 лет назад

    after downloading fport from the mentioned site, im unable to run the command. Error message "fport is not recognized as an internal or external command, operable program or batch file". How do i resolve this issue?

  • @C-j-m-218
    @C-j-m-218 9 лет назад

    when i go to netstat -b its no longer giving me the port number of the running processes this was after an update ?? Has this happend to anyone else

  • @eddiejoeplebani497
    @eddiejoeplebani497 4 года назад

    bless you heart! thank you Ever so kindly... Thank you! Thank you! Thank you....

  • @stepho670
    @stepho670 12 лет назад

    what if i cant find the PID number in my processes? but it shows established on cmd prompt

  • @Britec09
    @Britec09  15 лет назад

    its part of ITunes and Quicktime, should be safe just disable service if you dont want it

  • @i-a-n-a-h-9024
    @i-a-n-a-h-9024 6 лет назад

    Help!??
    When I did the -b it said I need elevation