Ok, to me it seems that the issue has nothing to do with Netgear Prosafe VPN Firewall. Your issue is to simply clean the trojan, am I correct?
You really have to touch each of the 36 (30 PC + 6 Servers) pc one by one. But start with the machines first since trojans get in from the workstations. Nobody browses the internet from the servers, but don't assume your servers are 100% clean, just do it at the end if you don't find anything.
Now, besides the generic cleaning there is something more advanced you can do. This depends on your switch. If you have a managed switch there is a feature that does port mirroring. (let me know if you need me to elaborate on that). If you don't have a managed switch then use a HUB temporarily. Here is why I'm telling you all this; there is a piece of software out there called packet sniffers and they inspect network traffic. You can use those to inspect all the traffic that is coming in and going out of your network.
and the reason why you need a hub with these software is because a HUB sends out all the traffic to all the ports, but a regular switch does not. And when you have the packet sniffer application you capture all that traffic while connected to one of the ports on the hub. and the expensive managed switch can do that if you know how to set it up. You can make only one of the ports mirror. Meaning that the port that is connected to the router will be mirrored to the port you are on so everything that is about to leave your switch will be copied to your pc before leaving (hence the word Mirroring comes into play)
Finally here is a list of popular FREE packet sniffers:
Wireshark
Microsoft Network Monitor
and finally Packetyzer
all 3 of them are free, but Wireshark is the most popular and is the industry standard. I personally usu the
microsoft one simply because of the interface. I don't know I like the way it looks. Packetyzer is also nice. It's up to you.
Let me know if you need more help
Main Topics
Browse All Topics





by: alanhardistyPosted on 2009-08-07 at 06:31:35ID: 25042447
Have a read through xmachine's comments in the following EE question and follow his advice:
http://www.experts- exchange.c om/Softwar e/Server_S oftware/ Em ail_Server s/Exchange /Q_2446355 0.html?cid =238#a2460 6079