I
Iain
I have a machine at an ISP. The ISP is reporting an outrageous amount of
traffic (1 - 10GB per day).
My logs using Performance monitor more or less corroberate, these volumes,
but there is absolutely no indication in the logs (IIS et al) that anything
LIKE these volumes are being produced and the traffic was there before the
site was live.
Obviously I suspect some sort of trojan.
I'd like to track back which processes are using network bandwidth. How do
I do this?
(Oh, Windows 2003 Server Web Edition).
Allied to this, if the Tsak Manager reports a process as svchost.dll, how
can I find which service it is hosting?
Iain
(PS. McAfee Enterprise reports no viruses or other Malware)
traffic (1 - 10GB per day).
My logs using Performance monitor more or less corroberate, these volumes,
but there is absolutely no indication in the logs (IIS et al) that anything
LIKE these volumes are being produced and the traffic was there before the
site was live.
Obviously I suspect some sort of trojan.
I'd like to track back which processes are using network bandwidth. How do
I do this?
(Oh, Windows 2003 Server Web Edition).
Allied to this, if the Tsak Manager reports a process as svchost.dll, how
can I find which service it is hosting?
Iain
(PS. McAfee Enterprise reports no viruses or other Malware)