Re: netsh.exe

From: plun (plun_at_telia.com)
Date: 09/14/04


Date: Tue, 14 Sep 2004 23:41:49 +0200

Espen Johannessen wrote:
> Actually I'm not sure if there is something wrong with the firewall. If
> there is a trojan that is responsible for the restarting of netsh.exe it may
> do so just to try to use it for shutting down the firewall!
>
> --Espen

One more thing about this, during logout or fast user
switching netsh.exe always crash for me
and several dump files are created.

Folder name always like WER36f.dir00 and so on.

Included files:
appcomcat.txt
manifest.txt
netsh.exe.hdmp , size always around 4MB !
netsh.exe.mdmp

Totally unreadable for me. ( *. txt OK)

Any MVP:s who knows how to check this dumpfiles ? or have
other clues ?

Any sniffer to see what commands netsh.exe to start ?

--
plun


Relevant Pages

  • Re: Can trojan bypass sniffer?
    ... > By now we all know that there are techniques to bypass personal firewall ... if I am running sniffer (let's say CommView or use ... > to log traffic) on the same machine, and suspect that I have Trojan with ... > frames for emails to make sure that I do not have ...
    (comp.security.firewalls)
  • Re: Trojans and ADWARE / NORTON
    ... | I just installed Norton Personal Firewall 2002 recently and under ... | Firewall/Internet Access Control there's a Configure button where I find ... open one of the default Trojan rules and take a good look at it. ... subsequently shows up as "Unused Port Blocking" or "Implicit Block Rule", ...
    (comp.security.firewalls)
  • Re: Trojans and ADWARE / NORTON
    ... > | I just installed Norton Personal Firewall 2002 recently and under ... open one of the default Trojan rules and take a good look at it. ... > security alert pop-out) if someone 'appears' to be attempting to do this. ... > list you used to get to the Trojan Block rule settings). ...
    (comp.security.firewalls)
  • Re: Advice Needed, Best Practices to Elim. XP Virus
    ... Backdoor is a trojan not a virus... ... Enable the Windows XP Internet Connection Firewall... ... Delete your cookies and temporary internet files after each session. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Is complete home security possible?
    ... My security before this occurred was ... >> firewall and virus program stopped loading with Windows. ... >> if the trojan somehow disabled them, but I know I didn't take them out ...
    (comp.security.firewalls)