Trojan

Monday, May 17, 2004 by Ande | Discussion: WinCustomize Talk

This is new for me. For the last couple of days my firewall is continually blocking "sockets de Trios v1 trojan horse" This is occuring every couple of minutes. Can anybody tell me what is going on
First Previous Page 1 of 3 Next Last
eieio
Reply #1 Monday, May 17, 2004 10:41 PM
Trying to come in? or trying to go out?
yrag
Reply #2 Monday, May 17, 2004 10:43 PM
My guess is it's trying to access port 5000. Disable Windows Plug and Play. Use this: http://grc.com/unpnp/unpnp.htm
Ande
Reply #3 Monday, May 17, 2004 11:24 PM
Had to go away sorry. Did that Gary, will wait and see.
Don't know Stephen, how do you tell. And that little statement will alert you how savvy I am. My knowledge is improving, I spend a little time trolling around after Yrag and Iplural taking notes
Ande
Reply #4 Monday, May 17, 2004 11:40 PM
Started again. The Security Alert says" Attempt to connect to local computer using the Sokets de Trois v1.Trojan Horse blocked, Threat level High Risk. At 1.28Pm on the 18/05/2004 the following communication was detected: Protocol: TCP (inbound)(there you go Stephen)
Remote Address: 202.138.41.172.4325 (this address changers each time it tries to access)
I don't know any Spanish, but what bloody bullfighter is trying to access my puter. >
Ande
Reply #5 Monday, May 17, 2004 11:40 PM
Started again. The Security Alert says" Attempt to connect to local computer using the Sokets de Trois v1.Trojan Horse blocked, Threat level High Risk. At 1.28Pm on the 18/05/2004 the following communication was detected: Protocol: TCP (inbound)(there you go Stephen)
Remote Address: 202.138.41.172.4325 (this address changers each time it tries to access)
I don't know any Spanish, but what bloody bullfighter is trying to access my puter. >
sig101
Reply #6 Monday, May 17, 2004 11:43 PM
Are you using Norton's firewall? It tends to ID portscans by the trojan known to use the port being scanned. Not too helpful really and sometimes scares newbies into thinking their firewall actually detected a trojan. As long as your firewall is doing its job (and presumably it is since it's giving you alerts) and blocks unsolicited communications from the net, I wouldn't concern myself with it. Too many port scans out there to worry about firewall alerts and logs unless you're a researcher looking for signs of new network infections that might be on the loose.

I'd ditto Yrag's recommendation to disable the Universal Plug & Play service.

Here's some info for home PC security from CERT, just in case you're interested. http://www.cert.org/homeusers/HomeComputerSecurity/
Ande
Reply #7 Monday, May 17, 2004 11:43 PM
Opps and there is another first. Double post
yrag
Reply #8 Monday, May 17, 2004 11:45 PM
Norton is known to pop an alert for this. It is blocking it (all the others do, they just don't tell you) and that's all you care about. There should be an option in Norton to not show this alert. Find it and then don't worry about it. If you want to worry about something, then worry about the other 500 or so scans your machine rejects daily with no alert...
yrag
Reply #9 Monday, May 17, 2004 11:48 PM
...Deb types a lot faster then me....

....anyway...what she said....
sig101
Reply #10 Monday, May 17, 2004 11:49 PM
By the way, perhaps the vast majority of port scans seen on he internet today are either automated scans or the result of infected PCs scanning through the internet looking for vulnerable machines to infect. That is, the idea that there is an actual hacker directing each portscan trying to specifically target you is probably almost never the case.

As long as you have a firewall that is blocking such scans people are usually advised not to be concerned. Some people go further and tell people to turn off the alerts since it doesn''t really do much good. If you maintain your firewall logs you might want to consider participating in a reporting service like mynetwatchman.com or dshield.org. Some related info in the BBR security forum FAQ: http://www.dslreports.com/faq/8226
[Message Edited]
sig101
Reply #11 Monday, May 17, 2004 11:50 PM
Great minds, Gary....
yrag
Reply #12 Monday, May 17, 2004 11:56 PM
...yup

Ande, if you want go here https://grc.com/x/ne.dll?bh0bkyd2 and scan your ports. It will tell you whats open...if anything and what to do to close it...

...That should keep him busy a while
IPlural
Reply #13 Monday, May 17, 2004 11:56 PM
Ande, you on broadband\internet?
Ande
Reply #14 Monday, May 17, 2004 11:57 PM
Gary I have had Norton Firewall(updated) for quite some time. And it does show these types of Alerts from time to time but not this continual pinging. However I have unticked the box for "enable access control alerts". Is that right? And if it is can I go out and play now.
Ande
Reply #15 Monday, May 17, 2004 11:59 PM
No IP, dial UP ???
yrag
Reply #16 Monday, May 17, 2004 11:59 PM
Yup......go play
Ande
Reply #17 Tuesday, May 18, 2004 12:27 AM
Yrag, done that test, pleased to say I am in full Stealth mode. Can you read this?
yrag
Reply #18 Tuesday, May 18, 2004 12:30 AM
Can you read this?


..Nope.
Jafo
Reply #19 Tuesday, May 18, 2004 12:47 AM
218985 intrusions blocked since install....5612 high rated.....someone out there really 'wants' me....
kona0197
Reply #20 Tuesday, May 18, 2004 2:24 AM
I feel sad. no one has tried to invade my PC. (Knock on wood) I used to use Sygate but It don't like Comcast HSI. So what other freeware firewalls of good reputabe ststus can I use?

Please login to comment and/or vote for this skin.

Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:

  • Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
  • Access to a great community, with a massive database of many, many areas of interest.
  • Access to contests & subscription offers like exclusive emails.
  • It's simple, and FREE!



web-wc01