Identify this trojan *SOLVED*

Mucman

Diamond Member
Oct 10, 1999
7,246
1
0
Of course the one machine on my network that runs Windows has to get a trojan :). I don't
use the machine, it's primarily for my roomy, and guest usage. It's running Win98. It's connected
to a hub, and when I am using my laptop in the living room, I connect to that hub. I noticed that
my LAN transfer speed was much worse than normal lately. I ran a packet sniffer on my OpenBSD
firewall and found the resulting log:

tcpdump log

It looks like it is trying to do a buffer overflow on DNS servers. I guess it's time for me to tighten
down my firewall and only let port 53 out for the two caching nameservers I have on my LAN.

Nothing seems out of whack in the process list on the Windows box, but it's been a long time
since I've really dug deep into Windows. My guess is that the trojan got on from an IE exploit.
I ran a virus check on it (housecall.antivirus.com) and the results were clean.
 

Mucman

Diamond Member
Oct 10, 1999
7,246
1
0
Would adware being attacking DNS servers? I haven't had much time to do too much research (darn school).

For now I'm just going to block port 53 requests from that machine (it should be using my internal name
servers for DNS requests anyways)
 

Mucman

Diamond Member
Oct 10, 1999
7,246
1
0
Originally posted by: pwddesign
No, he is saying use Adaware to find the trojan.

Woops, I phrased that very bad... I thought adaware only finds hidden adware, not DoS trojans...
I'll try it anyways.

 

Mucman

Diamond Member
Oct 10, 1999
7,246
1
0
BKDR_ITERATOR.A is the culprit. Adaware didn't find it, but it did find lots of tracking crap my roomy
installed. That's the only machine I haven't converted to BSD, I attempted to a while back, but he
didn't like it... I might try again now that I am more familiar with getting all the browser plugins to work.