| Notices | Welcome to the Scale-Models forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact contact us. |  | |
17-01-2005
|
#1 (permalink)
| | Moderator
Join Date: Apr 2004 Location: Warwick,UK Real Name: Barry My Models: Aviation artifacts Visit wonwinglo's Gallery
Posts: 5,564
| Trojan attacks. Can anyone help here-
For the past few days my Nortons firewall has detected half hourly attacks which are reported as 'Default block Sokets de Trois V1 Trojan' the firewall blocks the port for 30 minutes,I then did a security check for network vulnerability port status which showed up 'open port' warning scan was able to make a connection with your computer.
I then did another check via Nortons firewall as follows-
Options>View statistics>One>Local column,I found alg.exe as the only executable in there which on checking is a legit c:\windows\System32 folder and disabling is not advised.
However a further check says that a similar file can hide itself away as spyware so I did a virus check which found nothing ?
The question is-Is the trojan trying to access via that open port and what can I do at this stage before any harm is done,it seems to have somehow latched onto my computer ?
Any help much appreciated.
__________________ 'And there I was oil on my goggles from a broken pipe,then I looked at the altimeter,all I could see was the makers name !' www.wonwinglo.scale-models.net/ |
| |
18-01-2005
|
#2 (permalink)
| | Scale Model Member
Join Date: Oct 2004 Location: Inverness Scotland Real Name: Iain My Models: i currently have a hpi nitro mt2 and a thundertiger ts4n Visit Phoenix's Gallery
Posts: 461
| close the port |
| |
18-01-2005
|
#3 (permalink)
| | Moderator
Join Date: Apr 2004 Location: Warwick,UK Real Name: Barry My Models: Aviation artifacts Visit wonwinglo's Gallery
Posts: 5,564
| Quote: |
Originally Posted by Phoenix close the port | *** Phoenix how do I do this ? |
| |
18-01-2005
|
#4 (permalink)
| | Scale Model Member
Join Date: Nov 2004 Location: Edinburgh Real Name: Iain Moffatt My Models: TID Tug, Admirals Barge, Crash Tender, Working on Brave Borderer & ASRL Visit IainM's Gallery
Posts: 106
| I routinely use a couple of programmes that, together, seem to keep my system clear of all the real nasties (touch wood)!
TrojanHunter, marketed by Mischel Internet Security in the USA does a marvelous job of scanning for Trojans and the like. Costs $48 but has excellent update functionality.
Ad-Aware, by Lavasoft, is available in a single user, personal, version as a freebe.
Its great at detecting and getting rid of the data miners and such like. Again, a very good update function is provided.
Quite amazing the stuff that creeps onto your PC when you are not looking :-( |
| |
18-01-2005
|
#5 (permalink)
| | Moderator
Join Date: Apr 2004 Location: Warwick,UK Real Name: Barry My Models: Aviation artifacts Visit wonwinglo's Gallery
Posts: 5,564
| Thanks Iain,could be worth purchasing this Trojan buster,nothing shows on a virus scan with Nortons ? has it parked something and feeding onto it ?
__________________ 'And there I was oil on my goggles from a broken pipe,then I looked at the altimeter,all I could see was the makers name !' www.wonwinglo.scale-models.net/ |
| |
18-01-2005
|
#6 (permalink)
| | Scale Model Member
Join Date: Oct 2004 Location: Inverness Scotland Real Name: Iain My Models: i currently have a hpi nitro mt2 and a thundertiger ts4n Visit Phoenix's Gallery
Posts: 461
| i dont use norton now so i cant remember how to do it i will let someone with more knowlege of norton tell you how to do it |
| |
18-01-2005
|
#7 (permalink)
| | Moderator
Join Date: Apr 2004 Location: Warwick,UK Real Name: Barry My Models: Aviation artifacts Visit wonwinglo's Gallery
Posts: 5,564
| Quote: |
Originally Posted by Phoenix i dont use norton now so i cant remember how to do it i will let someone with more knowlege of norton tell you how to do it | *** John can you help here ? how do I close a port with Nortons please ? |
| |
18-01-2005
|
#8 (permalink)
| | Moderator
Join Date: Apr 2004 Location: Warwick,UK Real Name: Barry My Models: Aviation artifacts Visit wonwinglo's Gallery
Posts: 5,564
| Just found this on the net-
First, the port isn't open, it's in Stealth Mode (actually not even open, but Norton doesn't advertise this--if it did, the distant end would know the computer existed and would run a port scan against it.)
The fact that you are getting the messages tells you that the firewall is actually working. That trojan horse attempts port 5000 by default.
You can copy the emoticons, but be aware that they are probably copyrighted, which means you can't use them. Check with the site owner.
So apparently their is no virus that shows on my computer because there is non,but why is this Trojan attempting attack every evening ? and is there a way that I can stop it ? will that Trojan Hunter programme help in this case ?
__________________ 'And there I was oil on my goggles from a broken pipe,then I looked at the altimeter,all I could see was the makers name !' www.wonwinglo.scale-models.net/ |
| |
19-01-2005
|
#9 (permalink)
| | Moderator
Join Date: Apr 2004 Location: Warwick,UK Real Name: Barry My Models: Aviation artifacts Visit wonwinglo's Gallery
Posts: 5,564
| Why does a firewall only block an offending port for only 30 minutes at a time ? surely if the firewall detects something like a Trojan it should block it altogether ?
__________________ 'And there I was oil on my goggles from a broken pipe,then I looked at the altimeter,all I could see was the makers name !' www.wonwinglo.scale-models.net/ |
| |
05-02-2005
|
#10 (permalink)
| | Scale Model Member
Join Date: Nov 2004 Location: Edinburgh Real Name: Iain Moffatt My Models: TID Tug, Admirals Barge, Crash Tender, Working on Brave Borderer & ASRL Visit IainM's Gallery
Posts: 106
| Ports are a bit like letter boxes in the front door.
All sorts of stuff needs to be able to come through them ... much of which is legitimate.
Trojans and the like spend their time 'polling' PCs connected to the web, looking for an unprotected port. ( a bit like cold calls from the call centre in timbucktoo ..pick it up and ..)
If they find one ... bingo, they are in and installing all sorts, most of which attempts to use the unprotected port as a way in/out of your PC.
If your Firewall NEVER reports any form of activity ... I'd get a wee bit worried whether or not it was working! At least you know it is when it blocks a port or a trojan etc.
If the firewall blocked the port permanently .. you'd soon not be able to connect to the internet at all!! |
| | | Thread Tools | | | | Display Modes | Linear Mode |
Posting Rules
| You may not post new threads You may not post replies You may not post attachments You may not edit your posts HTML code is Off | | | |