[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [Full-Disclosure] Lots of traffic on port 1472 from explorer
- To: "Giuseppe Milicia" <milicia@xxxxxxxx>, <full-disclosure@xxxxxxxxxxxxxxxx>
- Subject: RE: [Full-Disclosure] Lots of traffic on port 1472 from explorer
- From: "Brent Colflesh" <brent.colflesh@xxxxxxxxxxx>
- Date: Tue, 21 Sep 2004 16:21:16 -0400
Keylogger?
http://www.pestpatrol.com/pestinfo/k/klp32.asp
Regards,
Brent
-----Original Message-----
From: full-disclosure-admin@xxxxxxxxxxxxxxxx
[mailto:full-disclosure-admin@xxxxxxxxxxxxxxxx]On Behalf Of Giuseppe
Milicia
Sent: Tuesday, September 21, 2004 3:14 PM
To: full-disclosure@xxxxxxxxxxxxxxxx
Subject: [Full-Disclosure] Lots of traffic on port 1472 from explorer
Hi guys,
from a home computer I'm seeing lots of traffic generated from
explorer on port 1472 towards the microsoft-ds port, typically
on IP addresses starting with 35.xx.xx.xx
It looks like a worm but I could not find any references around
and Trend Micro detects nothing.
Also there is some hidden process oakklp32.exe which is not shown
by the taskmanager but is costantly active, again I could not
find anything about it!
Ideas? Clues?
Thanks,
--
Giuseppe
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
---
Incoming mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.762 / Virus Database: 510 - Release Date: 9/13/2004
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.762 / Virus Database: 510 - Release Date: 9/13/2004
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html