RE: forcdos.exe, msagent directory, DOS or warez??

From: Wayne S. Ackley (wackley_at_ideorlando.org)
Date: 12/08/03

  • Next message: Mark Harris: "RE: Messenger service abuse (from inside the network)"
    To: <craig@broadband-computers.com>, <security-basics@securityfocus.com>
    Date: Mon, 8 Dec 2003 16:10:09 -0500
    
    

    Craig,

    I don't know it it helps, but.....

    forcedos.exe - Runs programs in MSDOS mode

    I think you are right, it probably was renamed.

    **************************************************
    Wayne S. Ackley
    IT Manager - Senior Network Engineer
    IDEORLANDO Facility
    3045 Technology Parkway
    Orlando, Florida 32826
    321-235-7524
    321-235-1484
    text pager: page_wayne@ideorlando.org
    Pager phone: 1-800-946-4646 pin#1431304
    **************************************************

    -----Original Message-----
    From: Craig Broad [mailto:craig@broadband-computers.com]
    Sent: Thursday, December 04, 2003 6:53 PM
    To: security-basics@securityfocus.com
    Subject: forcdos.exe, msagent directory, DOS or warez??

    Hi all,

    on a box recently moved to a managed network rack (GX networks), over the
    last 2 weeks we have noticed strange behaviour. One of the box's on the
    subnet has been maxing out the link's bandwidth, on further investigation,
    massive activity was found on ports 63501, 63502, 1734 and other high range
    ports. The behaviour was at least 8 hours of fully limiting output, and
    then up to 8 hours of normal level operation and then a return to full
    output. at least ever 3 cycles, there would be a upload to the server at a
    limit of abt 512kbps.

    using a sniffer (netprobe) the ports were identified, and using fport these
    were all linked to a executable called forcdos.exe. i have searched all
    search engines, and have seen not one single link, so i'm assuming it's
    something else renamed. The files has been placed in
    C:\winnt\system32\msagent\local\com1\server directory. We are assuming at
    this time it has come in via some SQL exploit. it look's as a full backdoor
    access has been achieved. Due to the non-local nature of the box, and the
    com1 directory name, we have crrently been unable to access the directory to
    retrieve the exe file.

    The box has been locked down with the windows inbuilt firewall, locking all
    tcpip ports not needed. the exe is still running within the computer, but
    is currently unable to get out of the box.

    Firstly does anyone have any advice on how to get to this exe file? I dont
    want to just posix rd it, as i want to see the file first, and secondly does
    anyone have any idea what this could be? DOS or Warez?

    many thanks for any advice. if anyone can suggest how to get to the file,
    we will make it available for analysis.

    -----------
    Craig Broad

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Mark Harris: "RE: Messenger service abuse (from inside the network)"

    Relevant Pages

    • RE: forcdos.exe, msagent directory, DOS or warez??
      ... massive activity was found on ports 63501, 63502, 1734 and other high range ... search engines, and have seen not one single link, so i'm assuming it's ... Firstly does anyone have any advice on how to get to this exe file? ...
      (Security-Basics)
    • Re: neighbor discovery problem
      ... My best advice here is to do what I did - which is ... The network is pretty simple, ... All three ports on a switch. ...
      (freebsd-stable)
    • Re: 2 pc network - cant see host files from pc 2 on pc 1
      ... Assuming that you have firewall protection via your internet router try ... workgroup because it will be needed for the network to work correctly. ... see if you can access TCP ports 139 and 445 on computer one of which at ... permissions. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: PC Tools Firewall Question
      ... So, it's to be assumed that the two machines that are connected to your router, the LAN or Local Area Network, are never to share resources or network between the two, which are the ports you're blocking below with the PFW. ...
      (comp.security.firewalls)
    • Re: Setting up Remote Desktop web connection in winxp mce to work
      ... Its possible her office network admins are blocking the outgoing ports. ... Also check to see your using the correct public IP for your router and make sure the router is configured to disable remote management. ... > anyway to test the remote connection, other than trying to connection> from ...
      (microsoft.public.windowsxp.work_remotely)

  • Quantcast