Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

explorer.exe opens udp port

Status
Not open for further replies.

nikky

Programmer
Feb 7, 2002
80
US
I know something is not right when the service "explorer" shows up in an fport listing running c:\winnt\explorer.exe on a udp port. Has anyone any idea what backdoor / remote control program might have been installed on this windows 2000 pc ? Explorer.exe itself looks to be uninfected.
 
You might want to check the machine for another copy of explorer.exe -- a clever trojan would take advantage of the fact that the PATH environmental variable is searched to find that program (unless you patched your registry to point explicitly at c:\winnt\).

Chip H.
 
I have looked, and they all seem to be the same - only 2 copies, exactly identical - one in winnt and the other in service packs.

Since then I have read that windows critical update notifcation opens up explorer.exe using a UDP port - perhaps this is the explanation.
 
Explorer is a great place to hide a trojan! Check the file sizes for each one. Are they the same?
Don't look at the timestamps as those can be faked.

You can also compare the MD5 Checksum from a known-good copy of explorer (one from a different machine) to verify file integrity.

I'll see your DMCA and raise you a First Amendment.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top