Bait Server for Trojan

Bait Server for Trojan

Secure Home | Search | About

Microsoft Antivirus Discussions - Anti-virus discussions related to Microsoft products 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Bait Server for Trojan Brock Hensley 05-28-2009
Posted by Brock Hensley on May 28, 2009, 2:51 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

I'm looking for any recommendations on how to track down the cause of a
Trojan infection.

We have a number of reports of the following infection on various servers.
The only common link we can find between all the infected servers is that
they do not have Windows Firewall enabled, which is how I assume they are
compromising the system in the first place and installing the FTP server
which is then detectable.

================
Troj/ServU-Gen (Sophos)
Aliases:
not-a-virus:Server-FTP.Win32.Serv-U.5000 (Kaspersky Lab)
not-a-virus:RiskWare.FTP.Serv-U.5000 (Kaspersky Lab)
Hacktool (Symantec)
BackDoor.Servu.5000 (Doctor Web)
Troj/ServU-Gen (Sophos)
BDS/ServU.ba.1 (H+BEDV)
Win32:Trojano-356 (ALWIL)
Trojan.ServU.G (SOFTWIN)
Trojan.Servu.1 (ClamAV)
Bck/ServU.BB (Panda)
Server-FTP.Win32.Serv-U
================

I'm trying to think of the best way to set up a "Bait" server with security
auditing & no Firewall to sniff the infection process.

WireShark?

Once the server is infected, it creates "DependOnService" registry entries
on a few services which causes File & Printer Sharing to not work as well as
a few other detectable things.

Any help would be appreciated!
-B


Posted by Peter Foldes on May 28, 2009, 7:11 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Multi multiposted

--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

> Hello,
>
> I'm looking for any recommendations on how to track down the cause of a
> Trojan infection.
>
> We have a number of reports of the following infection on various servers.
> The only common link we can find between all the infected servers is that
> they do not have Windows Firewall enabled, which is how I assume they are
> compromising the system in the first place and installing the FTP server
> which is then detectable.
>
> ================
> Troj/ServU-Gen (Sophos)
> Aliases:
> not-a-virus:Server-FTP.Win32.Serv-U.5000 (Kaspersky Lab)
> not-a-virus:RiskWare.FTP.Serv-U.5000 (Kaspersky Lab)
> Hacktool (Symantec)
> BackDoor.Servu.5000 (Doctor Web)
> Troj/ServU-Gen (Sophos)
> BDS/ServU.ba.1 (H+BEDV)
> Win32:Trojano-356 (ALWIL)
> Trojan.ServU.G (SOFTWIN)
> Trojan.Servu.1 (ClamAV)
> Bck/ServU.BB (Panda)
> Server-FTP.Win32.Serv-U
> ================
>
> I'm trying to think of the best way to set up a "Bait" server with security
> auditing & no Firewall to sniff the infection process.
>
> WireShark?
>
> Once the server is infected, it creates "DependOnService" registry entries
> on a few services which causes File & Printer Sharing to not work as well as
> a few other detectable things.
>
> Any help would be appreciated!
> -B


Posted by Johnw on May 28, 2009, 9:22 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Brock Hensley was thinking very hard :
> Any help would be appreciated!

See if any of these help.

All Freeware.
http://www.softpedia.com/catList/193,1,3,0,1.html



Similar ThreadsPosted
Web Server infected? September 16, 2005, 2:58 pm
Compromise Server March 5, 2009, 6:51 am
Server Antivirus software July 12, 2005, 8:07 pm
Win 2K Server anti virus July 25, 2005, 4:49 pm
Couldn't log into Windows Server because of a virus January 21, 2007, 4:31 am
Anti-Virus on Server - Advice September 8, 2005, 7:33 am
tools to test server Security September 24, 2005, 10:27 pm
setiathome virus on a 2003 server October 24, 2005, 3:20 am
Adding Server with Corporate: Standard on all PCs too? November 16, 2005, 7:45 am
Symantec Corporate AV and SQL Server Performance January 7, 2006, 1:43 pm

The site map in XML format XML site map

Contact Us | Privacy Policy