PC
Sysinternals helps uncover Troj/IRCBot-TK Trojan
I've been using Process Explorer,one of a set of tools created by Mark Russinovich, for some time now and have found it very useful to see exactly what processes are being run at any moment on my pc.
An overview of Sysinternals tools is available as a free video download here
By monitoring my system with this tool, I recently found an svchost process that gradually ate up all my spare processing time causing everything to go slower and slower. Double-clicking on the process pops up a tabbed window in which I can see attached remote addresses. In this case I found ,under the Tcp/IP tab, connections to IRC networks including Undernet. Switching to the Image tab showed the path as C:\WINDOWS\system32\scif\svchost.exe. A search on Google revealed that this is one of the files installed by the Troj/IRCBot-TK trojan !


Recent comments
41 weeks 1 day ago
1 year 16 weeks ago