Go Back   Scale Models > General Chat > Computer Help!

Notices

Reply
 
LinkBack Thread Tools Display Modes
Old 17-01-2005   #1 (permalink)
Moderator
 
wonwinglo's Avatar
 
Join Date: Apr 2004
Location: Warwick,UK
Real Name: Barry
My Models: Aviation artifacts
Visit wonwinglo's Gallery
Posts: 5,564
Images: 49
Trojan attacks.

Can anyone help here-
For the past few days my Nortons firewall has detected half hourly attacks which are reported as 'Default block Sokets de Trois V1 Trojan' the firewall blocks the port for 30 minutes,I then did a security check for network vulnerability port status which showed up 'open port' warning scan was able to make a connection with your computer.
I then did another check via Nortons firewall as follows-
Options>View statistics>One>Local column,I found alg.exe as the only executable in there which on checking is a legit c:\windows\System32 folder and disabling is not advised.
However a further check says that a similar file can hide itself away as spyware so I did a virus check which found nothing ?
The question is-Is the trojan trying to access via that open port and what can I do at this stage before any harm is done,it seems to have somehow latched onto my computer ?
Any help much appreciated.
__________________
'And there I was oil on my goggles from a broken pipe,then I looked at the altimeter,all I could see was the makers name !'
www.wonwinglo.scale-models.net/
wonwinglo is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 18-01-2005   #2 (permalink)
Scale Model Member
 
Phoenix's Avatar
 
Join Date: Oct 2004
Location: Inverness Scotland
Real Name: Iain
My Models: i currently have a hpi nitro mt2 and a thundertiger ts4n
Visit Phoenix's Gallery
Posts: 461
close the port
Phoenix is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 18-01-2005   #3 (permalink)
Moderator
 
wonwinglo's Avatar
 
Join Date: Apr 2004
Location: Warwick,UK
Real Name: Barry
My Models: Aviation artifacts
Visit wonwinglo's Gallery
Posts: 5,564
Images: 49
Quote:
Originally Posted by Phoenix
close the port
*** Phoenix how do I do this ?
wonwinglo is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 18-01-2005   #4 (permalink)
Scale Model Member
 
Join Date: Nov 2004
Location: Edinburgh
Real Name: Iain Moffatt
My Models: TID Tug, Admirals Barge, Crash Tender, Working on Brave Borderer & ASRL
Visit IainM's Gallery
Posts: 106
Images: 40
I routinely use a couple of programmes that, together, seem to keep my system clear of all the real nasties (touch wood)!
TrojanHunter, marketed by Mischel Internet Security in the USA does a marvelous job of scanning for Trojans and the like. Costs $48 but has excellent update functionality.

Ad-Aware, by Lavasoft, is available in a single user, personal, version as a freebe.
Its great at detecting and getting rid of the data miners and such like. Again, a very good update function is provided.

Quite amazing the stuff that creeps onto your PC when you are not looking :-(
IainM is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 18-01-2005   #5 (permalink)
Moderator
 
wonwinglo's Avatar
 
Join Date: Apr 2004
Location: Warwick,UK
Real Name: Barry
My Models: Aviation artifacts
Visit wonwinglo's Gallery
Posts: 5,564
Images: 49
Thanks Iain,could be worth purchasing this Trojan buster,nothing shows on a virus scan with Nortons ? has it parked something and feeding onto it ?
__________________
'And there I was oil on my goggles from a broken pipe,then I looked at the altimeter,all I could see was the makers name !'
www.wonwinglo.scale-models.net/
wonwinglo is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 18-01-2005   #6 (permalink)
Scale Model Member
 
Phoenix's Avatar
 
Join Date: Oct 2004
Location: Inverness Scotland
Real Name: Iain
My Models: i currently have a hpi nitro mt2 and a thundertiger ts4n
Visit Phoenix's Gallery
Posts: 461
i dont use norton now so i cant remember how to do it i will let someone with more knowlege of norton tell you how to do it
Phoenix is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 18-01-2005   #7 (permalink)
Moderator
 
wonwinglo's Avatar
 
Join Date: Apr 2004
Location: Warwick,UK
Real Name: Barry
My Models: Aviation artifacts
Visit wonwinglo's Gallery
Posts: 5,564
Images: 49
Quote:
Originally Posted by Phoenix
i dont use norton now so i cant remember how to do it i will let someone with more knowlege of norton tell you how to do it
*** John can you help here ? how do I close a port with Nortons please ?
wonwinglo is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 18-01-2005   #8 (permalink)
Moderator
 
wonwinglo's Avatar
 
Join Date: Apr 2004
Location: Warwick,UK
Real Name: Barry
My Models: Aviation artifacts
Visit wonwinglo's Gallery
Posts: 5,564
Images: 49
Just found this on the net-
First, the port isn't open, it's in Stealth Mode (actually not even open, but Norton doesn't advertise this--if it did, the distant end would know the computer existed and would run a port scan against it.)

The fact that you are getting the messages tells you that the firewall is actually working. That trojan horse attempts port 5000 by default.

You can copy the emoticons, but be aware that they are probably copyrighted, which means you can't use them. Check with the site owner.

So apparently their is no virus that shows on my computer because there is non,but why is this Trojan attempting attack every evening ? and is there a way that I can stop it ? will that Trojan Hunter programme help in this case ?
__________________
'And there I was oil on my goggles from a broken pipe,then I looked at the altimeter,all I could see was the makers name !'
www.wonwinglo.scale-models.net/
wonwinglo is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 19-01-2005   #9 (permalink)
Moderator
 
wonwinglo's Avatar
 
Join Date: Apr 2004
Location: Warwick,UK
Real Name: Barry
My Models: Aviation artifacts
Visit wonwinglo's Gallery
Posts: 5,564
Images: 49
Why does a firewall only block an offending port for only 30 minutes at a time ? surely if the firewall detects something like a Trojan it should block it altogether ?
__________________
'And there I was oil on my goggles from a broken pipe,then I looked at the altimeter,all I could see was the makers name !'
www.wonwinglo.scale-models.net/
wonwinglo is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-02-2005   #10 (permalink)
Scale Model Member
 
Join Date: Nov 2004
Location: Edinburgh
Real Name: Iain Moffatt
My Models: TID Tug, Admirals Barge, Crash Tender, Working on Brave Borderer & ASRL
Visit IainM's Gallery
Posts: 106
Images: 40
Ports are a bit like letter boxes in the front door.
All sorts of stuff needs to be able to come through them ... much of which is legitimate.

Trojans and the like spend their time 'polling' PCs connected to the web, looking for an unprotected port. ( a bit like cold calls from the call centre in timbucktoo ..pick it up and ..)
If they find one ... bingo, they are in and installing all sorts, most of which attempts to use the unprotected port as a way in/out of your PC.
If your Firewall NEVER reports any form of activity ... I'd get a wee bit worried whether or not it was working! At least you know it is when it blocks a port or a trojan etc.

If the firewall blocked the port permanently .. you'd soon not be able to connect to the internet at all!!
IainM is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 04:48.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
© 2004 - 2008 Scale Model Forums
Magazine Subscriptions | Mortgage Loans | Mortgages | Betway Bonus | Mortgage Calculator
ServInt Internet Services