identifying the virus in the network

raja53352

Disciple
Hi guys

I have more than 35 systems.Now i suspect some of the systems got affected by virus.Pls advise me the tool where i can find out virus by sitting in one machine and controllingf the same.I have major problem with sending the mail.I think that virus may block SMTP.
 
raja53352 said:
Hi guys

I have more than 35 systems.Now i suspect some of the systems got affected by virus.Pls advise me the tool where i can find out virus by sitting in one machine and controllingf the same.I have major problem with sending the mail.I think that virus may block SMTP.

Prolly what you need is this, haven't tried it meself but w t heck, give it a shot. Ohh but remember this will only tell you what virus/worm is infecting what system. It WONT give you a solution for it. Its kinda honeypot, it doesn't have any policies which it is to implement.

KFSensor free download KFSensor is a host based Intrusion Detection System (IDS). It acts as a honeypot to attract and detect hackers by simulating vulnerable system services and trojans. The system is highly configurable and features detailed loggin
 
@Aphro_EVO

i doubt a honeypot will be of any help to him. he has a basic virus problem not some outside attacker whom you need to trap or anything.

@raja53352

you might be better off with a good anti virus and scanning each system with it.
 
Late to respond to this.

But a honeypot is not to identify an attacker primarily. It is to check what all systems are infected in a particular network. It goes through all the open ports & matches the signatures of common attacks on the basis of port used for communication (both source & destination) & the frequency of attack.
 
Back
Top