Oh no please not a trojan!

General Network security, firewalls, port filtering/forwarding, wireless security, anti-spyware, as well as spam control and privacy discussions.
Post Reply
touser3
Regular Member
Posts: 151
Joined: Wed Dec 06, 2000 12:00 am

Oh no please not a trojan!

Post by touser3 »

hi guys i just noticed something on my link logger and according to it, it is a trojan, but i wanted your guys's opinions as The Cleaner didnt find anything :( i am running winXP pro, tiny personal firewall,the proxomitron, and kasper sky antivirus.thanks in advance :)
Image
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

It certainly looks like it is doing it's thing. I can't get through to Moosoft to see if they have it in their database, but Anti-Trojan 5.5 does! Get a trial copy of it and scan ahttp://www.anti-trojan.net/at.asp?l=en&t=downloadgain.

Hopefully, it will clean you up. Hope this helps. :)
touser3
Regular Member
Posts: 151
Joined: Wed Dec 06, 2000 12:00 am

Post by touser3 »

thank oyu blebs99 your awsome as usual :) what i just dont understand is why tiny didnt stop it :( and now anti-trojan is coeing up saying all these different ports are open! when i have a block all rule for tiny, and all the security sites said they where closed..hrmm ok anti-trojan finished and here was its report

Port 135 open.
Port 139 open.
Port 445 open.
Port 1025 open.
Port 1037 open.
Port 1067 open.
Port 1462 open.
Port 5000 open. Possible Trojans. Sockets de Troie, Blazer 5
Port 8080 open.
Port 17604 open.
Port 44334 open.
no trojans where found on this system, buit while it was performing the search my wonderful kasper sky antivirus poped up and said iy found something and deleted it! the file it found was JS.Trojan.Seeker-Based, that must have been it :) what i dont understand is how all those ports are open
touser3
Regular Member
Posts: 151
Joined: Wed Dec 06, 2000 12:00 am

Post by touser3 »

EEK link logger is showing this now right after i supposedly got rid of the trojan..now ere my questioon..this is reading the loggs from the router..meaning this guy has gotten past my router but does this mean he is also getting past tiny?
Image
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

These sneaky people are incorporating was to temporarily shutdown firewalls to allow the nasty to get in. This may not be the case with you, but it is something to think about.
How well do you understand Tiny's Rulesets? I know that I got terribly frustrated trying to understand them and opted for Zone Alarm instead. I don't have a real working knowledge of Tiny, so it might be best to let Fredra or greEd answer your port open questions. I just hope that all is now cleaned up. Keep an I on the logs. ;)
touser3
Regular Member
Posts: 151
Joined: Wed Dec 06, 2000 12:00 am

Post by touser3 »

well this guy has been hitting me all day according to link logger, i have at least 50 hits all going to port 80 from all different ip's but with the same intent and some from the same cx #, my question is sence i have so many hits does this mean that he is trying to get in over and over and is only able to get passed my router and is stopped by tiny, or is it that he has gotten in and is making commands? thanks in advance :)
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

Port 80 hits I would not worry about unless your firewall log is showing traffic going out. The darn Code Red Worm and it's buddies are still looking for servers to infect. I'm getting the same deal here.
touser3
Regular Member
Posts: 151
Joined: Wed Dec 06, 2000 12:00 am

Post by touser3 »

thanks blebs, say does anyone know where i can get a free version of something like link logger that is free? because i dont have $21 to spend on it :(
drdoug99
SG Elite
Posts: 6471
Joined: Tue Nov 28, 2000 12:00 am
Location: ohio

Post by drdoug99 »

what is link logger? it looks complicated,lol

EDIT: ah, looks like it's only if you have a linksys routter, which I do not. :(
SoWhat
Member
Posts: 82
Joined: Thu Jun 29, 2000 12:00 am
Location: Tulsa, Oklahoma

Post by SoWhat »

Please do not show your @home I.D. touser3
Some people can make good use of it.



c-ya
Windoze probs!!!!!!!!
Format c: /u
SoWhat
Member
Posts: 82
Joined: Thu Jun 29, 2000 12:00 am
Location: Tulsa, Oklahoma

Post by SoWhat »

My bad. That was the offender. scolled to fast.





c-ya
Windoze probs!!!!!!!!
Format c: /u
SoWhat
Member
Posts: 82
Joined: Thu Jun 29, 2000 12:00 am
Location: Tulsa, Oklahoma

Post by SoWhat »

I think that its its possible that applications are opening the ports
but tiny is blocking data. port 44334 is tiny, 8080 is proxy for
those @home people or http servers. You can find more info from internal scans than through external(via web).



c-ya
Windoze probs!!!!!!!!
Format c: /u
Post Reply