[Dshield] Is there a legitimate service named doom?

FS bastiji at gmail.com
Thu Jun 23 18:10:05 GMT 2005


http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&subcontent=/resources/proddesc/fport.htm
or http://tinyurl.com/d3yap will map the port to the application. That
might be a good start...

Faisal

On 6/23/05, securityguy at dslextreme.com <securityguy at dslextreme.com> wrote:
> Troubleshooting a windows 2k server, a netstat showed a protocol named
> "doom" listening on port 1035.  The latest virus scans show no infection
> (symantec, mcafee stinger, and trendmicro's housecall) all report clean.
> There's been (so far as I can tell) no slow down in service, increase in
> disk size, or anything out of the ordinary.  It possible that this is a
> normal service as opposed to someone running a game?  How would I track
> down what is spawning this service?
> 
> - SG
> 
> 
> 
> 
> _______________________________________________
> send all posts to list at lists.dshield.org
> To change your subscription options (or unsubscribe), see: http://www.dshield.org/mailman/listinfo/list
>



More information about the list mailing list