{"id":492146,"date":"2010-03-31T03:30:00","date_gmt":"2010-03-31T07:30:00","guid":{"rendered":"http:\/\/techie-buzz.com\/how-to\/how-to-find-out-who-is-spying-on-you.html"},"modified":"2010-04-27T10:09:35","modified_gmt":"2010-04-27T14:09:35","slug":"how-to-find-out-who-is-spying-on-you","status":"publish","type":"post","link":"https:\/\/mereja.media\/index\/492146","title":{"rendered":"How to Find Out Who Is Spying On You"},"content":{"rendered":"<p><a href=\"http:\/\/cache.techie-buzz.com\/images\/postimg\/HowtoFindOutWhoIsSpyingOnYou_634\/spyingonyou.png\"><img loading=\"lazy\" decoding=\"async\" style=\"display: inline; margin-left: 0px; margin-right: 0px; border: 0px;\" title=\"spying-on-you\" src=\"http:\/\/cache.techie-buzz.com\/images\/postimg\/HowtoFindOutWhoIsSpyingOnYou_634\/spyingonyou_thumb.png\" border=\"0\" alt=\"spying-on-you\" width=\"80\" height=\"61\" align=\"right\" \/><\/a>[<em>Windows Only<\/em>] Today, I found out that my computer at work had a trojan infection. Most of my co-workers would never have noticed the bug, but a little luck and the right tools made my discovery possible. Since I discovered the infection early, I was able to quickly \u00a0<a href=\"http:\/\/techie-buzz.com\/tips-and-tricks\/how-to-fix-gogooglecom-goyahoocom-or-gomsncom-redirect-virus.html\" >remove the malware<\/a>. Do you know if evil computers are connecting to your PC? If you really want to find out, I recommend that you try two utilities from NirSoft.<\/p>\n<p><strong>Download and Install:<\/strong><br \/>\n<a href=\"http:\/\/nirsoft.net\/utils\/cports.html\" >CurrPorts<\/a> and <a href=\"http:\/\/www.nirsoft.net\/utils\/ipnetinfo.html\" >IPNetInfo<\/a> are both portable applications that are offered as ZIP files. You can unpack these ZIP files anywhere on your hard drive or even onto a flash drive to use them. CurrPorts and IPNetInfo work best if you put the files from both programs into the same folder. After I downloaded and unpacked them,\u00a0 I ended up with the following files in my CPorts folder.<\/p>\n<p><a href=\"http:\/\/cache.techie-buzz.com\/images\/postimg\/HowtoFindOutWhoIsSpyingOnYou_634\/currportsfilelist.png\"><img loading=\"lazy\" decoding=\"async\" style=\"display: inline; border: 0px;\" title=\"currports-file-list\" src=\"http:\/\/cache.techie-buzz.com\/images\/postimg\/HowtoFindOutWhoIsSpyingOnYou_634\/currportsfilelist_thumb.png\" border=\"0\" alt=\"currports-file-list\" width=\"252\" height=\"277\" \/><\/a><\/p>\n<p><strong>Run CurrPorts:<br \/>\n<\/strong>You can run CurrPorts by launching the cports.exe file. It will scan your computer and display a list of processes on your PC that are using the network and internet connections. The list contains the following columns of information on each connection.<\/p>\n<p><span style=\"color: #008000;\">Process Name *<br \/>\n<\/span>Process ID<br \/>\nProtocol<br \/>\nLocal Port<br \/>\nLocal Port Name<br \/>\nLocal Address<br \/>\nRemote Port<br \/>\nRemote Port Name<br \/>\n<span style=\"color: #000000;\"><span style=\"color: #008000;\">Remote Address<\/span> *<br \/>\nRemote Host Name<br \/>\nState<br \/>\n<\/span><span style=\"color: #000000;\"><span style=\"color: #008000;\">Process Path<\/span> *<br \/>\nProduct Name<br \/>\nFile Description<br \/>\nFile Version<br \/>\nCompany<br \/>\nProcess Created On<br \/>\nUser Name<br \/>\nProcess Services<br \/>\nProcess Attributes<br \/>\nAdded On<br \/>\nModule Filename<br \/>\nRemote IP Country<br \/>\nWindow Title <\/span><\/p>\n<p><strong>Search the information:<\/strong><br \/>\nThe most important columns to pay attention to are the columns described below.<\/p>\n<p><span style=\"color: #008000;\"><em>Process Name<\/em><\/span> is the name of the program or service on your PC that is making the connection.<\/p>\n<p><span style=\"color: #008000;\"><em>Process Path<\/em><\/span> tells you where the program or service is located on your hard drive. It&#8217;s important to know this location if you suspect that you have a spyware, virus or trojan infection.<\/p>\n<p><span style=\"color: #008000;\"><em>Remote Address<\/em><\/span> is a set of numbers that is often called the &#8220;IP Address&#8221;. This address is needed to identify the computers connected to you by the internet.<\/p>\n<p>Many of the connections you&#8217;ll see won&#8217;t even have a remote address and you don&#8217;t have to pay as much attention to them. In order to unclutter the list and concentrate on the remote IP addresses, you can use the Options menu and uncheck the item labeled &#8220;<em>Display Items without Remote Address<\/em>&#8220;.<\/p>\n<p><a href=\"http:\/\/cache.techie-buzz.com\/images\/postimg\/HowtoFindOutWhoIsSpyingOnYou_634\/currportsdisplayoptions.png\"><img loading=\"lazy\" decoding=\"async\" style=\"display: inline; border: 0px;\" title=\"currports-display-options\" src=\"http:\/\/cache.techie-buzz.com\/images\/postimg\/HowtoFindOutWhoIsSpyingOnYou_634\/currportsdisplayoptions_thumb.png\" border=\"0\" alt=\"currports-display-options\" width=\"279\" height=\"122\" \/><\/a><\/p>\n<p><strong>Identify WHO IS connecting:<br \/>\n<\/strong>Now that you have some IP addresses displayed, you can find out more about them by using NifSoft&#8217;s IPNetInfo utility. When you right click on any remote address shown in CurrPorts, you can find out more about it by choosing the IPNetInfo option. IPNetInfo will pop up and give you the WHOIS information if it&#8217;s able to.<\/p>\n<p><a href=\"http:\/\/cache.techie-buzz.com\/images\/postimg\/HowtoFindOutWhoIsSpyingOnYou_634\/currportswithipnetinfo.png\"><img loading=\"lazy\" decoding=\"async\" style=\"display: inline; border: 0px;\" title=\"currports-with-ipnetinfo\" src=\"http:\/\/cache.techie-buzz.com\/images\/postimg\/HowtoFindOutWhoIsSpyingOnYou_634\/currportswithipnetinfo_thumb.png\" border=\"0\" alt=\"currports-with-ipnetinfo\" width=\"598\" height=\"242\" \/><\/a><\/p>\n<p>Here&#8217;s an example of the WHOIS info for a Google page in Internet Explorer.<\/p>\n<p><a href=\"http:\/\/cache.techie-buzz.com\/images\/postimg\/HowtoFindOutWhoIsSpyingOnYou_634\/ipnetinforeport.png\"><img loading=\"lazy\" decoding=\"async\" style=\"display: inline; border: 0px;\" title=\"ipnetinfo-report\" src=\"http:\/\/cache.techie-buzz.com\/images\/postimg\/HowtoFindOutWhoIsSpyingOnYou_634\/ipnetinforeport_thumb.png\" border=\"0\" alt=\"ipnetinfo-report\" width=\"393\" height=\"339\" \/><\/a><\/p>\n<p>IPNetInfo.exe can be run all by itself by launching the ipnetinfo.exe file. When it&#8217;s running this way, you will have to paste in the IP Addresses manually to initiate WHOIS searches.<\/p>\n<p><strong>Stop the Spies:<\/strong><br \/>\nOnce you&#8217;ve identified all the owners of those remote IP addresses, you should have a better idea about who they are. You can usually find out more about them by using the company name in an internet search. If you are still suspicious that the IP addresses you are seeing are from the bad guys, you can check in several places to find out if they are on a watch list. I recommend that you search for malicious addresses at <a href=\"http:\/\/hosts-file.net\/\" >hpHosts<\/a>. Just paste the remote IP address into the search box.<\/p>\n<p>If you&#8217;ve identified a connection you don&#8217;t want, you can right click on entries in CurrPorts and either &#8220;Close&#8221; the connection or &#8220;Kill&#8221; the process on your PC. If you have a process running on your machine that continues to connect to IPs that are suspect, you should probably save an HTML report as shown below, then run an Anti-Virus and Anti-Spyware scan. I recommend using <a href=\"http:\/\/download.cnet.com\/Malwarebytes-Anti-Malware\/3000-8022_4-10804572.html\" >MalwareBytes<\/a> or one of the other good <a href=\"http:\/\/download.cnet.com\/windows\/spyware-removers\/?&amp;filter=licenseName=%22Free%22%7c&amp;tag=ltcol;narrow\" >free spyware removers<\/a>. If that doesn&#8217;t do the trick, get some help from one of the Anti-Spyware forums. I always visit <a href=\"http:\/\/temerc.com\/forums\/viewforum.php?f=12\" >Temerc.com<\/a>&#8217;s forums when I need help.<\/p>\n<p>If you wish to ask me about some of your remote connections, you can select one or more items in CurrPorts, click on &#8220;View&#8221; &gt; &#8220;HTML Report &#8211; Selected Items&#8221;. When the report pops into your web browser, you can copy and paste the information into the comments below this article. You can also save the report from your browser using the File &gt; Save menu.<\/p>\n<p><a href=\"http:\/\/lh6.ggpht.com\/_kZpuGAisT0M\/SnUthvtq73I\/AAAAAAAAAOU\/6mlL2SWMdcI\/s1600-h\/V3.png\"><img loading=\"lazy\" decoding=\"async\" style=\"display: inline; border-width: 0px;\" title=\"V\" src=\"http:\/\/lh4.ggpht.com\/_kZpuGAisT0M\/SnUth8vryYI\/AAAAAAAAAOY\/nOYXvw9GJ_Y\/V_thumb1.png?imgmax=800\" border=\"0\" alt=\"V\" width=\"319\" height=\"216\" \/><\/a><\/p>\n<p>Have a good day and <strong>surf safely<\/strong>!<\/p>\n<div style=\"font-size:12px\">\n<strong>Share:<\/strong><br \/>\n<a href=\"http:\/\/techie-buzz.com\/how-to\/how-to-find-out-who-is-spying-on-you.html#commentrespond\" rel=\"bookmark\" >Comment on This Post<\/a> |<br \/>\n<a href=\"http:\/\/twitter.com\/home?source=techiebuzz&#038;status=How%20to%20Find%20Out%20Who%20Is%20Spying%20On%20You%20http%3A%2F%2Fbit.ly%2FasB9Ic%20via%20@techiebuzzer\" rel=\"bookmark\" >Tweet This<\/a> |<br \/>\n<a href=\"http:\/\/www.facebook.com\/sharer.php?u=http:\/\/techie-buzz.com\/how-to\/how-to-find-out-who-is-spying-on-you.html\" rel=\"bookmark\" >Share on Facebook<\/a> |<br \/>\n<a href=\"http:\/\/del.icio.us\/post?url=http:\/\/techie-buzz.com\/how-to\/how-to-find-out-who-is-spying-on-you.html&#038;title=How%20to%20Find%20Out%20Who%20Is%20Spying%20On%20You\" rel=\"bookmark\" >Save to Delicious<\/a> |<br \/>\n<a href=\"http:\/\/www.stumbleupon.com\/submit?url=http:\/\/techie-buzz.com\/how-to\/how-to-find-out-who-is-spying-on-you.html\" rel=\"bookmark\" >Stumble This<\/a> |<br \/>\n<a href=\"http:\/\/digg.com\/submit?phase=2&#038;url=http:\/\/techie-buzz.com\/how-to\/how-to-find-out-who-is-spying-on-you.html&#038;title=How%20to%20Find%20Out%20Who%20Is%20Spying%20On%20You\" rel=\"bookmark\" >Digg This<\/a> |<br \/>\n<a href=\"http:\/\/www.reddit.com\/submit?url=http:\/\/techie-buzz.com\/how-to\/how-to-find-out-who-is-spying-on-you.html&#038;title=How%20to%20Find%20Out%20Who%20Is%20Spying%20On%20You\" rel=\"bookmark\" >Reddit This<\/a>\n<\/div>\n<p><\/p>\n<div><strong style=\"font-size:11px;\">TAGS:<\/strong> <span style=\"text-transform:uppercase;font-size:11px;\"><a href=\"http:\/\/techie-buzz.com\/tag\/antilogger\" rel=\"tag\">AntiLogger<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/antimalware\" rel=\"tag\">Antimalware<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/antispyware\" rel=\"tag\">Antispyware<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/freeware\" rel=\"tag\">Freeware<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/network-tool\" rel=\"tag\">network tool<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/online-security\" rel=\"tag\">Online Security<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/security-breach\" rel=\"tag\">Security Breach<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/security-software\" rel=\"tag\">Security Software<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/windows-security\" rel=\"tag\">Windows Security<\/a><\/span><br \/>\n<\/small><\/div>\n<div>\n<br \/>\n<font size=\"4\"><strong>Announcement:<\/strong> Missing Mobile News in the Main RSS Feed? We have decided to remove the mobile content from the main feed, please subscribe to our dedicated <a href=\"http:\/\/go.techie-buzz.com\/mobilerssanch\" >Mobile News RSS Feed<\/a> at <a href=\"http:\/\/go.techie-buzz.com\/mobilerss\" >http:\/\/feeds.techie-buzz.com\/techiemobile<\/a>. Thank you for your understanding.<\/font><\/p>\n<\/div>\n<div style=\"background:#E1E1E1; border: dotted 1px; padding:5px; margin-top:5px;font-size:11px\">\n<a href=\"http:\/\/techie-buzz.com\/how-to\/how-to-find-out-who-is-spying-on-you.html\" title=\"How to Find Out Who Is Spying On You\">How to Find Out Who Is Spying On You<\/a> originally appeared on <a href=\"http:\/\/techie-buzz.com\" title=\"Techie Buzz\">Techie Buzz<\/a> written by Clif Sipe on Wednesday 31st March 2010 03:30:00 AM. Please read the <a href=\"http:\/\/techie-buzz.com\/terms-of-use\">Terms of Use<\/a> for fair usage guidance. <\/div>\n<p><\/p>\n<h2>Don&#8217;t miss these Related Posts:<\/h2>\n<ul>\n<li><a href=\"http:\/\/techie-buzz.com\/utilites\/monitor-tcpip-network-connections.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >Free Software To Monitor TCP\/IP Network Connections<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/how-to\/6-tools-for-anonymous-torrenting-options.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >6 Tools for Anonymous Torrenting Options<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/utilites\/manage-all-your-remote-connections-from-one-place.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >Manage All Your Remote Connections From One Place [Free Application]<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/utilites\/monitor-network-connections-with-moo0-connection-watcher.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >Monitor Network Connections With Moo0 Connection Watcher<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/tips-and-tricks\/how-to-add-exceptions-to-windows-firewall.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >How To Add Exceptions To Windows Firewall?<\/a><\/li>\n<\/ul>\n<h2>Join Techie Buzz on Your Favorite Social Networking Sites<\/h2>\n<ul>\n<li><a href=\"http:\/\/go.techie-buzz.com\/facebookfanrss\" title=\"Become a Techie Buzz fan on Facebook\">Become a Techie Buzz fan on Facebook<\/a><\/li>\n<li><a href=\"http:\/\/go.techie-buzz.com\/twitterrss\" title=\"Follow Techie Buzz on Twitter\">Follow Techie Buzz on Twitter<\/a><\/li>\n<\/ul>\n<p><a href=\"http:\/\/feedads.g.doubleclick.net\/~a\/Iy-hF8TEkl3BnL3FY5xAlKBO39s\/0\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~a\/Iy-hF8TEkl3BnL3FY5xAlKBO39s\/0\/di\" border=\"0\" ismap=\"true\"><\/img><\/a><br \/>\n<a href=\"http:\/\/feedads.g.doubleclick.net\/~a\/Iy-hF8TEkl3BnL3FY5xAlKBO39s\/1\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~a\/Iy-hF8TEkl3BnL3FY5xAlKBO39s\/1\/di\" border=\"0\" ismap=\"true\"><\/img><\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~r\/techiebuzz\/~4\/b_Ish29_wHE\" height=\"1\" width=\"1\"\/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[Windows Only] Today, I found out that my computer at work had a trojan infection. Most of my co-workers would never have noticed the bug, but a little luck and the right tools made my discovery possible. Since I discovered the infection early, I was able to quickly \u00a0remove the malware. Do you know if [&hellip;]<\/p>\n","protected":false},"author":1634,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-492146","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/492146","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/users\/1634"}],"replies":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/comments?post=492146"}],"version-history":[{"count":0,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/492146\/revisions"}],"wp:attachment":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/media?parent=492146"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/categories?post=492146"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/tags?post=492146"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}