Click here to get back home

A Sasser like worm on our network, almost gone but still there.

 HomeNewsGroups | Search | About
 microsoft.public.security.virus    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
A Sasser like worm on our network, almost gone but still there. RedPenguin 04-29-2006
Posted by RedPenguin on April 29, 2006, 1:58 pm
Please log in for more thread options

| Hi David, After reading your answer to this post i went to Task Manger
| and found five (5) svchost.exe services running - 3 Network Services ,
| and 2 System. Now after seeing your answer and checking
| Process Library and finding out this svchost.exe could be used by a
| Trojan, How can i find out the path's of these services in Task Manger
| like in your example? Thanks Ron (Defender)
|

It is common to have multiple SVCHOST.EXE processes running. Each load
specifcommunication
capabilities of the OS.

Like I said, it is not the name of the file that is important, it is the Fully
Qualified
Name and Path to that file.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Panda_man on April 29, 2006, 2:19 pm
Please log in for more thread options

| Hi David, After reading your answer to this post i went to Task Manger
| and found five (5) svchost.exe services running - 3 Network Services ,
| and 2 System. Now after seeing your answer and checking
| Process Library and finding out this svchost.exe could be used by a
| Trojan, How can i find out the path's of these services in Task Manger
| like in your example? Thanks Ron (Defender)
|

It is common to have multiple SVCHOST.EXE processes running. Each load
specifcommunication
capabilities of the OS.

Like I said, it is not the name of the file that is important, it is the Fully
Qualified
Name and Path to that file.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by David H. Lipman on April 29, 2006, 2:44 pm
Please log in for more thread options

| Hi David, After reading your answer to this post i went to Task Manger
| and found five (5) svchost.exe services running - 3 Network Services ,
| and 2 System. Now after seeing your answer and checking
| Process Library and finding out this svchost.exe could be used by a
| Trojan, How can i find out the path's of these services in Task Manger
| like in your example? Thanks Ron (Defender)
|

It is common to have multiple SVCHOST.EXE processes running. Each load
specifcommunication
capabilities of the OS.

Like I said, it is not the name of the file that is important, it is the Fully
Qualified
Name and Path to that file.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Similar ThreadsPosted
How to find virus/worm/trojan on network client September 21, 2005, 8:29 pm
Sasser virus January 11, 2007, 9:05 pm
Sasser & Blaster indication but no detection June 24, 2006, 11:45 pm
Worm VB.AS Aliases W32.Alcra.B and W32/Alcan.worm!p2p July 18, 2005, 5:37 am
WORM/DELF.FPV - new worm?? January 14, 2008, 6:58 am
Cannot use network after Sobig November 1, 2005, 2:57 pm
Network goes down every six days at 5:00 PM July 20, 2006, 3:09 pm
Norton and home network October 4, 2006, 4:05 pm
Audit your whole network with single software April 19, 2008, 3:00 am
The system can not log you on due to the following error. The network request is not supported. June 4, 2005, 9:30 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap