dslreports logo
 
    All Forums Hot Topics Gallery
spc
uniqs
10

NetFixer
From My Cold Dead Hands
Premium Member
join:2004-06-24
The Boro
Netgear CM500
Pace 5268AC
TRENDnet TEW-829DRU

NetFixer to smith_in_co

Premium Member

to smith_in_co

Re: Constant Guard Security Alert?

said by smith_in_co:

So In trying to be a 'good' net citizen what can I do to eliminate the bot?
Assuming the bot is not a false positive to begin with.

I don't know about it being a false positive (but that has happened with Comcast's detection of the "DNS Changer" malware).

One possibility is that you may have actually already eliminated the bot (assuming that there is/was a bot). The »amibotted.comcast.net/ site does not do any kind of fresh scan when you visit it, it only reports that Comcast has at some point in time detected what it considers to be bot activity on the IP address from which you are accessing that site. Perhaps jlivingood See Profile or some other Comcast representative who is familiar with how their ConstantGuard scanner works can provide some insight about how long a delay there is before the »amibotted.comcast.net/ site will not report previously detected bot activity. Hopefully it is not like a sexual predator database where you will be in it forever.

Assuming that you are using a router, you might try cloning the MAC address from a PC into the router's WAN interface, and then rebooting both the cable modem (some EMTA modems may require that you remove the battery and/or press a special reset button) and the router. That should get Comcast's DHCP server to assign you a different public IP address, and you can then see if new bot activity is discovered on your new IP address.
smith_in_co
join:2003-12-12
Colorado Springs, CO

1 edit

smith_in_co

Member

It's my understanding that with the 4-dec release, they reset the you may have a bot message after 24 hours (old version was 7 days I think).

Sooo... after 24 hours you won't even know what the last seen time was....

In my case I've been getting the no bot message for two days now. But I don't think I've removed anything that has actually disabled a bot.

goofy01
join:2004-02-05
Hammond, IN

goofy01

Member

If I remember correctly from before, there was some kind of connection scanner (like ping plotter) that use to check your connection to a few different places to track downtime. This program had a few connections (might have been only one) that were later flagged as part of the botnet network. Not sure if this relates, just pointing out in case you have something like this running.