Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Help - a possible bot

From: Emeric Miszti <emeric(at)uksecurityonline.com>
Date: Sat Nov 16 2002 - 05:59:19 EST

Hi Moshe,

What you are seeing with the incoming port 137 UDP requests is probably the Opeserv worm. Have a look at
http://antivirus.about.com/library/weekly/aa100102a.htm.

Everyone is seeing a lot of these at the moment and if you have a look at http://isc.incidents.org/ then you will see that port 137 is far and away the most attacked port at the moment.

You can easily identify this kind of activity because the source port of normal UDP 137 traffic is 137 and the destination is port 137. With the worm activity the source port becomes something above 1024 with the destination as 137.

Looking at your fport traces, etc it doesn't look like your PC is infected by Opaserv but what is worrying is that you may be responding to the port probes, thus making you a target for further attack and that may explain the high usage on svchost!

Make sure that you are not infected by Opaserv by checking through the details provided by anti-virus companies such as http://securityresponse.symantec.com/avcenter/venc/data/w32.opaserv.worm.html

Since the PC has been previously hacked I would be very suspicious anyway and wouldn't rely on the firewall doing its job properly. Dameware is a total remote control package so anything could have been installed. Personally I would rebuild the PC and then install a good firewall on a clean box. That is the only way you can ever be 100% sure you are clean.

Do you need help?X

Regards

-- 
Emeric Miszti
UK Security Online
http://www.uksecurityonline.com

Tel No: 0870 088 5689
Fax No: 0870 706 2162

PGP Public Key available at 
http://www.uksecurityonline.com/emeric.asc

On Fri, 2002-11-15 at 20:11, Moshe Aelion wrote:

> Hi everybody
---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Received on Mon Nov 18 02:37:58 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:51 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library