Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Hidden windows ports, files and services. |
|---|---|
| Date: | Wed, 16 Feb 2005 08:49:24 -0500 |
Try using some tools that aren't affected by rootkits.
I gave you the URL to a good handful of them in my previous response.
So you don't have to go digging, here it is: http://home.arcor.de/scheinsicherheit/rootkits.htm
Have fun disecting your box, and do tell what you find!
Chris
Il lun, 2005-02-14 alle 20:38, Alex Yan ha scritto:Hi all,
Thanks a lot for your help. On weekend I tried some suggested options, but still didn't get much yet.
Scanned the system using the latest Norton AV and Stinger in the safe mode. Nothing came out.
Run "netstat -baon". It gives process IDs and program names for other processes. For the processes related to port 21, it says "No ownership information can be found".
Tried fport, cport, process explorer, etc, but no luck.
"telnet 127.0.0.1 21" gives prompt "220 ." and then times out in 15 seconds. No telnet service was found in Windows service list.Try to use Hijackthis and post the log. Some of the malware in the wild uses things such browser helper object, run as service or similar behavior, to hide itself. -- Mario "Reliant" Pascucci http://ilpettegolo.altervista.org/
| Previous by Date: | Re: Antivirus Comparison, nospam |
|---|---|
| Next by Date: | RE: CISSP without experience, Dante Mercurio |
| Previous by Thread: | Re: Hidden windows ports, files and services., Mario Pascucci |
| Next by Thread: | Re: Hidden windows ports, files and services., Michael Painter |
| Indexes: | [Date] [Thread] [Top] [All Lists] |