Computing.Net > Forums > Security and Virus > Tracing trojan origins

Tracing trojan origins

Reply to Message Icon

Original Message
Name: Mike D
Date: November 15, 2003 at 21:53:31 Pacific
Subject: Tracing trojan origins
OS: Win 98
CPU/Ram: -
Comment:

I ran AVG today and it says it found a virus entitled NETBUS.EXE (More info: http://www.pestpatrol.com/PestInfo/N/NetBus.asp ). What I would like to know is if there is a log of any sort that can show me when that file was created and/or if from where did the command to create it come from?

Reason being for this is that I want to know if it's just some random person who placed it or was it placed by someone else who uses this computer.


Report Offensive Message For Removal

Response Number 1
Name: Tope
Date: November 20, 2003 at 22:53:16 Pacific
Subject: Tracing trojan origins
Reply: (edit)

if it really is netbus, it's a trojan. the most obvious answer to your question of "when that file was created " is to find the file (if it hasn't already been removed) and look at it's timestamp. (you know right click and go to properties and it says when it was created, modified, and accessed). the timestamp may have been tampered with ofcourse. if for some reason it hasn't been tampered with, you might be able to check your logs to see what user was logged in at the time. i've been working in XP for awhile now so that's the only OS i know where to find the logs for. if you only have one user then you're kinda outta luck. if you don't understand what i meant by checking the logs and the timestamp, you check the timestamp, and then look at the logs to see which user was using the computer at that time. i know this probably wasn't incredibly helpful, but no one else answered this post.


Tope


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Tracing trojan origins

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software