finding an infected computer on the wrong subnet

  • 15 January 2015
  • 4 replies
  • 729 views

Webroot is reporting a heavily infected computer with an internal IP of 192.168.0.50 (the external IP routes to China) and an unrecognizable hostname.  This network is running on a 192.168.106.0/24 subnet, so I'm suspecting a trojan creating a separate instance on its own subnet.  Agent commands to clean up this computer seem to have no effect.   Can anyone offer some suggestions on how to physically locate this infected computer?

4 replies

Userlevel 7
Badge +56
That's a strange one - let me ping some support folks and see what they recommend.
Userlevel 7
Badge +56
They said to go ahead and open a ticket - they'll need to get logs to help you track this down.
great - thank you.
Userlevel 7
Badge +56
Sure thing - let us know how it turns out.

Reply