You are welcome to subscribe to "New articles in Knowledge base" mailing list:

You are visiting our Support Website and we thank you in advance for your participation in this poll and your feedbacks.

Please vote honestly, we will analyze the results and will do our best to improve our service as soon as possible.

 Corporate Support Website Usability Survey:
Navigation quality*
Technical articles efficiency*
Relevance of the article(s) turned out by your query*
Ease of access to relevant information*
Comments

Read the same in:    English  Francais  Deutsch  Italiano  日本語  Polski  Русский  Español  Sweden  
Home / Business products /  Workstation protection /  Kaspersky Anti-Virus 6.0 for Windows Workstations MP2 (version 6.0.2.678, 6.0.2.690 /  Setting Anti-Hacker

 
Search :  
Search tips Article ID # :   
 

Kaspersky Anti-Virus 6.0 for Windows Workstations MP2 (version 6.0.2.678, 6.0.2.690

 
KLDump.exe: a utility for creation of network attack dump files
 ID Article: 772    Other languages:  Francais  Deutsch  Italiano  日本語  Polski  Русский  Español  Sweden      Views for 7 days 196    Last modified on 2009 Oct 07 18:00 Printable version

Applies to all Kaspersky Lab products for Windows

If your computer is being attacked by an unknown worm (you are using Kaspersky Anti-Virus with the last updates available and it does not detect suspicious objects) and you do not know how to protect your computer from the worm, use the utility kldump.exe. This utility creates dump files of network attacks. You can then send such dump files to Kaspersky Lab for analysis.

Use this link to download the utility:

http://support.kaspersky.com/downloads/utils/kldump.zip

Run the utility on the computer which is experiencing the unknown network attack. It is necessary to reproduce the situation on the same computer to get an adequate dump file.

Information If you run the utility without any switches, the full list of applicable switches will be displayed. It is strongly recommended to start the utility with one of the following switches: 

You can use the following command line switches to start the utility:

  • -f – network attack dump file name
  • -r : - remote address and port from which packages come (separated by a colon)
  • -l : - local address and port to which packages come (separated by a colon)
  • -p – network protocol to create the dump for: tcp, udp or icmp.
  • -b – log broadcasts into the dump file

    Example:

    kldump.exe -f dump139.dmp -l 139 -p tcp

    The utility will log packages coming to the local TCP port 139 into the file dump139.dmp



    After creating a network attack dump file, send it to the following e-mail address: newattack@kaspersky.com. Subject = New network attack. If your network attack dump file has registered a previously unknown network attack, its detection will be added to the Intrusion Detection System database.

  •  Did the provided info help you?

                           

     Give your detailed feedback.

     

    Kaspersky Lab

    Copyright © 1997 - 2009 Kaspersky Lab
    Site map  |   Contact us  |   International Support Service  |  Send us a suspected virus
    Login Your Personal Cabinet  |   Register  |   FAQ for Personal Cabinet