Hope this helps
Main Topics
Browse All TopicsI have an interesting thing going on...
Wireshark is showing I have about 12 icmp requests being sent every second from one of my servers (win 2008 64bit SBS FE)
The src ip is the lan card in the server, the destination ip keeps incrementing by 1 each scan.
I've tried tcpview, but that doesn't seem to show icmp?
I've tried MS Netmon 3.3, that shows the traffic, but 'unknown' process
Full malware bytes scan is clean
Panada Corporate Scan is clean
Kaspersky AVZ4 (script 2 comes back clean)
I'm thinking either the src ip is spoofed? or i have a rootkit hiding somewhere
Any one got ideas how to find out which process is generating this traffic?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Hi Mike,
Results
- Fport
Doesn't seem to like the OS. I open command prompt with admin priv, but on running the tool it say i need admin privs!
- F-Secure's Blacklight
Shows no hidden processes
- Rootkit Buster
Says it can't run on 64bit OS
I wonder if you have any further ideas? Maybe i don't have a rookit? There must be a way to show what is generating the ping traffic....
Kind regards,
I would recommend Sophos Anti-RootKit and see if it generates any results the others haven't found.
http://www.sophos.com/prod
Have you checked your startup and services through MS Config? Anything fishy?
For those interested, here is a screenshot showing the bandwidth usage. Crazy!
You can see I rebooted the server around 17:52. The bad ICMP data disappeared. I think i cam,e back sometime after 7pm. I need to go back to site and find out for sure.
I'm still looking for a way to show which process is generating this ICMP traffic - Any more ideas?
Business Accounts
Answer for Membership
by: MikeHolcombPosted on 2009-11-06 at 07:16:14ID: 25759795
You could use Fport v2.0 (http://www.foundstone.com /us/resour ces/prodde sc/fport.h tm) from Foundstone to see which service is conducting the outbound ping based on its source port.
n_EMEA/pro ducts/tech nologies/ b lacklight/ ) - An extremely effective rootkit detector and removal tool from F-Secure. /download/ rbuster.as p) - Another effective rootkit detector and removal tool from TrendMicro.
To check for rootkits, I would suggest using the following:
1. F-Secure's Blacklight (http://www.f-secure.com/e
2. Trend Micro's Rootkit Buster (http://www.trendmicro.com
Hope these help...
Mike