Post: How to find an infection through CMD
08-28-2011, 08:00 PM #1
Pedo Leader
I’m too L33T
(adsbygoogle = window.adsbygoogle || []).push({}); Today we are going to learn how to find out if your computer is infected with a virus most likely a RAT or a Keylogger, then ill provide some way to remove it.

What you will need:
- Will to learn
- Internet

Part I

Scenario- *******.dk opens on your PC and you get some weird messages! You were hacked now you must remove the hacker before it gets worse!

Now its your turn!

- First what you want to do is open your task manager. See the picture in the spoiler for the rest of the directions!
You must login or register to view this content.
For Windows 7 users yall can go to the file i believe through the process so luck yall! That means you can delete the infection easier if you have one.

- Process Identifier (PID) For certain process using the internet it will always have a identify cation to link it to something.

- Now go to start and find the command prompt. It is found inside the "Accessories" part where paint and those other applications are.

- A black box should open that will be command prompt!

You must login or register to view this content.

Part II Find that jerk that infects you!

- Now that you have CMD open type this in "netstat -b or -o". Your choice and this large amount of things should pop up. For your PC it may look different because I have multiple networking applications up.
You must login or register to view this content.

- These are all the connections going in and out of your PC, you want to find on you don't know about.

- Boot up the task manager again and go to processes now look for something you don't know. Usually it will have a port attached to it too and sometimes it can be a no-ip. (Example: jguao.no-ip.org:5000) Use the process identifier to link the unknown process to it. Its basic comparing!

- Example of unknowns (Better Explained) jbo6.no-ip.org (this can also be a IP address)( Port:5000 )(PISad Awesome 3815) Now compare that in task manager to the process with that number and good you found him. If it says established also that means he is connected to you and you will pop up on his Booter/RAT.


Part III I found that jerk what do I do

- You have now found that stupid jerk that infects you what to do theres lots to do. Here is a list of sinister ways to get back at him.

1. Get your MetuS or XR or booter up and paste the IP in and smack his internet!
2. Hack him through the port!
3. Report him to FBI.gov!
4. Google a IP lookup website get his address and go shoot him or beat his ass!

Other ways less sinister!
1. See the HJT Team.
2. Find his files and remove them your self.
3. Get to know him and make friends and hope he uninstalls you.
4. If it a girl try try find her and get a lil sum sum lol.


Credits to HaKKuR
(adsbygoogle = window.adsbygoogle || []).push({});

The following 2 users say thank you to Pedo Leader for this useful post:

mattybenson, star10159
08-28-2011, 08:02 PM #2
Thanks bro, that really helped Winky Winky
08-28-2011, 08:11 PM #3
Pedo Leader
I’m too L33T
Originally posted by star10159 View Post
Thanks bro, that really helped Winky Winky
There is a thanks button there for a reason! Winky Winky
08-28-2011, 08:13 PM #4
mattybenson
Do a barrel roll!
Thanks for this.. Thanked Happy
08-28-2011, 08:13 PM #5
doesn't work for me
08-28-2011, 08:32 PM #6
Originally posted by Pedo
There is a thanks button there for a reason! Winky Winky


lol...yeah just thanked Winky Winky

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo