Trojans and TCP view

Trojans and TCP view

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Trojans and TCP view dos 01-24-2008
Posted by Volodymyr Shcherbyna on January 25, 2008, 10:49 am
If you were  Registered and logged in, you could reply and use other advanced thread options
You can download more advanced tool which shows the path for a processes
here: http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
regarding svchost.exe problem, read for TaskManager limitation in Windows
XP:
http://msmvps.com/blogs/v_scherbina/archive/2007/12/20/the-case-of-task-manager-that-does-not-kill.aspx

--
V
This posting is provided "AS IS" with no warranties, and confers no
rights.
> Hi David, After reading your answer to this post i went to Task Manger
> and found five (5) svchost.exe services running - 3 Network Services ,
> and 2 System. Now after seeing your answer and checking
> Process Library and finding out this svchost.exe could be used by a
> Trojan, How can i find out the path's of these services in Task Manger
> like in your example? Thanks Ron (Defender)
>
> "David H. Lipman" wrote:
>
>>
>> | Hi,
>> | my question is how to know that a trojan is comunicating with it's
>> owner?
>> | I'm using TCP view. Wich files are present on infected pc and are they
>> | visible trough tcp view?
>> | Can a trojan use legitimate files like firefox.exe and sends data
>> trough
>> | different ports? Please give me an example of tipical trojan
>> connection?
>> |
>> | Thanks.
>>
>> TCPView helps but not completely.
>>
>> Individual files by themsleves may show communication "home" or to peers.
>> However, some
>> malware can hook directly into the OS such that a particular EXE file
>> will not be indicated,
>> it will appear the OS is communicating to the malicious third part web
>> sites.
>>
>>
>> Trojans can use legit files by patching the legit files with malicious
>> code. Additionally,
>> malware often uses the EXE name of legit files such as firefox.exe
>> however what is important
>> is the Fully Qualified Name (FQN) and path to the EXE file.
>>
>> For example:
>> c:\windows\system32\svchost.exe is legit
>> C:\Program Files\Common Files\System\svchost.exe is NOT legit !
>>
>>
>> --
>> Dave
>> http://www.claymania.com/removal-trojan-adware.html
>> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>>
>>
>>



Posted by David H. Lipman on January 26, 2008, 11:34 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hi David, After reading your answer to this post i went to Task Manger
| and found five (5) svchost.exe services running - 3 Network Services ,
| and 2 System. Now after seeing your answer and checking
| Process Library and finding out this svchost.exe could be used by a
| Trojan, How can i find out the path's of these services in Task Manger
| like in your example? Thanks Ron (Defender)
|

It is common to have multiple SVCHOST.EXE processes running. Each load
specifcommunication
capabilities of the OS.

Like I said, it is not the name of the file that is important, it is the Fully
Qualified
Name and Path to that file.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by =?Utf-8?B?Um9uIEg=?= on January 25, 2008, 12:34 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Volodymyr, Thank You for that link i think this is something i should
have been using for a while now. Ron

"dos" wrote:

> Hi,
> my question is how to know that a trojan is comunicating with it's owner?
> I'm using TCP view. Wich files are present on infected pc and are they
> visible trough tcp view?
> Can a trojan use legitimate files like firefox.exe and sends data trough
> different ports? Please give me an example of tipical trojan connection?
>
> Thanks.

Posted by =?Utf-8?B?Um9uIEg=?= on January 26, 2008, 7:05 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
David, I haven't installed the program Volodymyr told me about yet
but knowing that the process runs multiple times has put me a little
more at ease. Thanks Ron


"dos" wrote:

> Hi,
> my question is how to know that a trojan is comunicating with it's owner?
> I'm using TCP view. Wich files are present on infected pc and are they
> visible trough tcp view?
> Can a trojan use legitimate files like firefox.exe and sends data trough
> different ports? Please give me an example of tipical trojan connection?
>
> Thanks.

Similar ThreadsPosted
? about Trojans July 16, 2005, 7:14 am
TROJANS!!!! August 9, 2006, 10:36 am
Trojans September 1, 2007, 8:58 pm
Trojans SBI October 30, 2007, 10:18 am
Trojans(?) January 13, 2008, 3:34 pm
Re: Trojans? Spy-ware? Oh my! June 15, 2007, 7:01 pm
Re: Trojans? Spy-ware? Oh my! June 15, 2007, 8:09 pm
The Cleaner finds RAS trojans, I can't find them on harddrive November 19, 2007, 2:52 am
Norton Enterprise AV - scan missing viruses, trojans, keyloggers, rootkits, etc??? April 12, 2007, 6:33 pm

The site map in XML format XML site map

Contact Us | Privacy Policy