Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

determining the origin of a virus withing the company

Status
Not open for further replies.

blaine011

IS-IT--Management
Jul 4, 2003
95
CA
How can I tell from which computer in my company a virus is coming from. It seems to be spoofing the address. The virus is the w32.beagle.
 
According to Sarc, "Creates a listening thread on port 6777 that allows a remote attacker to connect".
Get a port scanner, and scan your domain for active connections on that port.
I recommend NMAP
There is a Windows version if you don't like command lines, it's called NMAPWin.


 
Thanks for the reply xemus, what would be the command line for nmap to listen to that port?
 
Something else you can do is check your router logs. Since beagle and most viruses now turn infected PCs into spamming machines, you will find one ip sending out an excessive number of packets. So the infected PC should be easy to find this way.
 
I have a cisco 1600 series router, do you know the command to check the logs, or where I can find the commands?
 
Hmm, I meant firewall logs there, sorry about the mental lapse. On the otherhand, a higher-end device such as a cisco might have a good logging feature. I'm only familar with the linksys, netgear,etc. devices and I don't know cisco devices. Anybody else know if the cisco blaine mentioned can log or detect this kind of activity?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top