ViewTCP is a network monitoring tool that examines TCP/IP activity on Windows-based systems. It lists all TCP and UDP endpoints on a PC and the remote addresses to which they connect. With this user-friendly software, users can also determine the processes that are bound on various ports on their PC and the remote network addresses accessed by suspicious applications, says Manoj Mansukhani, head technology and marketing, MicroWorld Technologies.
ViewTCP is designed to give the details of the process that is associated with a TCP/IP address and port at any given point of time. Since the process name along with the name of its makers can be viewed, it becomes easier finding out the specific task performed by it, and thereby spotting harmful ones, the company says.
Network monitoring is critical for computers connected to Internet, as most Worms, Bots, Trojans and Backdoors are remote controlled by attackers sitting in faraway hideouts.
For example, the original Sobig worm was used in spreading a Proxy Server Trojan. It went on to become one of the most successful worms as hundreds of thousands of Proxy Servers were surreptitiously installed on computers worldwide. The purpose of this proxy network was to serve spammers by giving them a way to hide their true IP addresses while they spewed spam all over the globe.
On the other hand, a Backdoor can harvest system information, stop and start processes, take screenshots of the desktop and send them to the attacker, download files from the net and execute them, capture network user information, log off current user, search disks for files, create and move directories and restart the victim's machines and more, all by working through TCP ports or IRC channels.
|