Detecting machines with bots and malware

Started by rmpf2

rmpf2

Detecting machines with bots and malware   22 November 2013, 13:27

Hi, i'm looking for an advice on how to use the Network Scanner to detect lan machines that are infected with bots and malware??? Thanks...
SoftPerfect Support forum - Andrew avatar image

Re: Detecting machines with bots and malware   22 November 2013, 13:39

I don't think that's really possible. It's not an antivirus product.

Re: How to detect?   22 November 2013, 15:04

One thing you can do with netscan is to look for open ports that are not normally open on your workstations. (i.e. 21, 23, 25, 80, 110, etc.)
rmpf2

Re: How to detect?   22 November 2013, 23:04

Can netscan check for Active traffic on those ports?

Re: How to detect?   22 November 2013, 23:53

I find Netscan comes in handy if your firefighting known infections. just scan for a know rogue remote file, or in the case of Conficker c:\windows\tasks\At1.job

You can also use pskill with commandline added to netscan to kill those rogue process'
Also scan for know rogue regkeys. But as Andrew states, Antivirus should be the first line of defense, with a central logging system

Reply to this topic

Sometimes you can find a solution faster if you try the forum search, have a look at the knowledge base, or check the software user manual to see if your question has already been answered.

Our forum rules are simple:

  • Be polite.
  • Do not spam.
  • Write in English. If possible, check your spelling and grammar.

Author:

Email:

Subject

A brief and informative title for your message, approximately 4–8 words:

     

Spam prevention: please enter the following code in the input field below.

 ********   ********   **    **  **     **  ********  
 **     **  **     **  ***   **  **     **  **     ** 
 **     **  **     **  ****  **  **     **  **     ** 
 ********   **     **  ** ** **  *********  **     ** 
 **         **     **  **  ****  **     **  **     ** 
 **         **     **  **   ***  **     **  **     ** 
 **         ********   **    **  **     **  ********  

Message: