Re: IRC Packets being generated. Dont know where from...

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 04/29/05


Date: Fri, 29 Apr 2005 13:16:16 -0400

From: "Scott Townsend" <scott-i@.-N0-SPAMplease.enm.com>

| The only think that would seem to run the App that I cant tell would be a
| SVCHOST.EXE, there are 2 of them running. Though I know they can be
| legitimate processes. All the other processes in the Process list are
| legitimate. So unless its masquerading as something I don't see it.
|
| Its killing me... I'm about ready to Format the dang thing!
|
| I'll try the msconfig files and see what it can show me.
|
| Thanks!
| Scott<-

Scott: (Scooter ?)

You are going to have to do some work...

Download the following tools from Sysinternals -- http://www.sysinternals.com/

Process Explorer v9.03
http://www.sysinternals.com/ntw2k/freeware/procexp.shtml

TCPView v2.4
http://www.sysinternals.com/ntw2k/source/tcpview.shtml

TDImon v1.01
http://www.sysinternals.com/ntw2k/freeware/tdimon.shtml

Use the above tools to track the source of IRC packets, either a DLL or EXE. Once the file
is identified...

Please submit the suspect file (DLL , EXE, etc..) to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against 18 different AV vendor's scanners.

Another way to submit is to send the suspect file to the following email address
scan<at>virustotal.com
{ replace <at> with @ } with only the word SCAN as the subject.

Please post back the EXACT results.

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Relevant Pages

  • Re: internal source code
    ... dll for my case) ... I have seen an app which does this but i cant remember its name or find ... Clone etc. functions in my derived class. ...
    (microsoft.public.dotnet.general)
  • Re: internal source code
    ... dll for my case) ... I have seen an app which does this but i cant remember its name or find ... Clone etc. functions in my derived class. ...
    (microsoft.public.dotnet.general)
  • Re: .NETs internal Source Code
    ... dll for my case) ... I have seen an app which does this but i cant remember its name or find ... Clone etc. functions in my derived class. ...
    (microsoft.public.dotnet.xml)
  • Re: Ahh - Cant open my vbp?
    ... I copied the vbp for the app ... ... >> I tried to load the project today and got all sorts of problems. ... > If you have it added as a Reference, VB will want to load it when ... Thats right - since I cant get into the project I cant delete it as a ...
    (microsoft.public.vb.general.discussion)
  • Re: URL Encoding Library / class whatever ?
    ... It seems you cant get to this functionality from a windwos based app. ... seem to instantiate a httpserverutility class or make use of its functions. ...
    (microsoft.public.dotnet.framework.aspnet)