c:\\windows\slave.exe..trojan?

From: G (gonzalo_torresjr@hotmail.com)
Date: 02/19/03


From: "G" <gonzalo_torresjr@hotmail.com>
Date: Wed, 19 Feb 2003 02:04:10 -0800


Guys;
I have on my firewall detected a server called "RA
Service" which is remote anything similar to pcanywhere.
i see the log as trying to request access to the internet
3 times per reboot or login. There are several users in
this machine. I see the destination ip of 2 as empty,
but one is requesting to be allowed to connect to an ip
in Amsterdam (according to NeoTrace). Obviously this is
not acceptable but I have the follwoing question, Is that
executable standard with the windows installation? I
have checked the exe date and it was created around the
time this pc was configured. There are also users using
citrix ica client and some chat software. I have checked
online as some sites consider it a trojan...but before I
take it out I wanted to ask your more knoeledgeable
opinion...
thank you,



Relevant Pages

  • Re: possible?
    ... > this same exact get request came from several different address as well. ... > remote exploits in apache i've missed? ... i'm running Apache/1.3.19 Server.. ...
    (FreeBSD-Security)
  • RE: How to access the current EventSource through Remoting
    ... my remote application) to check if the tracing is enabled ... Maybe I could pass a parameter from the client ... >The name of the request event source (i.e. ...
    (microsoft.public.vsnet.enterprise.tools)
  • Re: IIS .ASP Remote Buffer Overflow [testing for vulnerable installations]
    ... If you want to test that an IIS4 or 5 server is vulnerable remotely you use ... The request needs to be correct according to RFC. ... IDS Sig: ... Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow ...
    (Vuln-Dev)
  • Re: Cant "DidTheyReadIt" be stopped?
    ... but I think that ZA Pro is able to block by remote IP address. ... and the server will log the IP address of the source of the request. ... except by either firewall blocking the site hosting the ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Cant "DidTheyReadIt" be stopped?
    ... but I think that ZA Pro is able to block by remote IP address. ... and the server will log the IP address of the source of the request. ... except by either firewall blocking the site hosting the ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)