Click here to get back home

Bait Server for Trojan

 HomeNewsGroups | Search

microsoft.public.security.virus - Computer virus info for MS Windows users 

get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Bait Server for Trojan Brock Hensley 05-28-2009
Posted by Brock Hensley on May 28, 2009, 2:51 pm
Please log in for more thread options
Hello,

I'm looking for any recommendations on how to track down the cause of a
Trojan infection.

We have a number of reports of the following infection on various servers.
The only common link we can find between all the infected servers is that
they do not have Windows Firewall enabled, which is how I assume they are
compromising the system in the first place and installing the FTP server
which is then detectable.

================
Troj/ServU-Gen (Sophos)
Aliases:
not-a-virus:Server-FTP.Win32.Serv-U.5000 (Kaspersky Lab)
not-a-virus:RiskWare.FTP.Serv-U.5000 (Kaspersky Lab)
Hacktool (Symantec)
BackDoor.Servu.5000 (Doctor Web)
Troj/ServU-Gen (Sophos)
BDS/ServU.ba.1 (H+BEDV)
Win32:Trojano-356 (ALWIL)
Trojan.ServU.G (SOFTWIN)
Trojan.Servu.1 (ClamAV)
Bck/ServU.BB (Panda)
Server-FTP.Win32.Serv-U
================

I'm trying to think of the best way to set up a "Bait" server with security
auditing & no Firewall to sniff the infection process.

WireShark?

Once the server is infected, it creates "DependOnService" registry entries
on a few services which causes File & Printer Sharing to not work as well as
a few other detectable things.

Any help would be appreciated!
-B


Posted by Peter Foldes on May 28, 2009, 7:11 pm
Please log in for more thread options
Multi multiposted

--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

show/hide quoted text


Posted by Johnw on May 28, 2009, 9:22 pm
Please log in for more thread options
Brock Hensley was thinking very hard :
show/hide quoted text

See if any of these help.

All Freeware.
http://www.softpedia.com/catList/193,1,3,0,1.html



Similar ThreadsPosted
Web Server infected? September 16, 2005, 2:58 pm
Compromise Server March 5, 2009, 6:51 am
SQL Server vunerability on Windows XP? June 4, 2005, 4:42 pm
Server Antivirus software July 12, 2005, 5:07 pm
Win 2K Server anti virus July 25, 2005, 4:49 pm
Couldn't log into Windows Server because of a virus January 21, 2007, 4:31 am
hijacking broswer maybe-can not find server June 6, 2005, 5:26 pm
Windows 2000 Server Problem June 13, 2005, 1:39 am
Anti-Virus on Server - Advice September 8, 2005, 12:33 pm
tools to test server Security September 24, 2005, 10:27 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Driving a better car - Fuelzilla.com

Cabling site for homeowners and pros alike - Cabling-Design.com

Friends:

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap
Privacy Policy