Trojan
Monday, May 17, 2004 by Ande | Discussion: WinCustomize Talk
Reply #22 Tuesday, May 18, 2004 7:22 AM
http://www.kerio.com/kpf_download.html
Reply #23 Wednesday, May 19, 2004 1:37 AM
If this is the norm OK. Life goes on. But I am having trouble comprehending this. To me this incessant blocking of the same type of Trojan is not normal. My Firewall has never acted the way before. Ok pl someone, please put my mind at rest. >

Reply #24 Wednesday, May 19, 2004 1:46 AM
There should be an option in Norton somewhere to 'not' show alerts thru the tray icon and just show the normal icon.
Reply #25 Wednesday, May 19, 2004 1:51 AM
Reply #26 Wednesday, May 19, 2004 1:53 AM

Reply #27 Wednesday, May 19, 2004 1:57 AM
Reply #28 Wednesday, May 19, 2004 2:23 AM
Reply #29 Wednesday, May 19, 2004 2:27 AM
[Message Edited]
Reply #30 Wednesday, May 19, 2004 2:46 AM

Reply #31 Wednesday, May 19, 2004 2:50 AM
Reply #32 Wednesday, May 19, 2004 2:55 AM
Brian, #1 : you''re safe. #2 : there should be a setting to disable that icon from flashing.....it''s been so long that I used Norton, I just can''t remember where it''s at. You could just hide the icon in the system tray, then you''ll know it''s running and, more importantly, you won''t see it all the time.
[Message Edited]
Reply #34 Wednesday, May 19, 2004 4:38 PM
I would suggest ive.... just because

Reply #35 Wednesday, May 19, 2004 5:53 PM
If you applied Gibson's Unplug n Pray app that would disable the service and close the port within the OS. http://grc.com/unpnp/unpnp.htm
I previously posted a link to the BBR Security FAQ...lots of info there if you want to read up and learn.

Reply #36 Wednesday, May 19, 2004 9:05 PM
added May 18
US-CERT has received reports of scanning activity directed at port 5000/tcp. This port is used by the Microsoft Windows Universal Plug and Play service (UPnP). Some of this activity can be attributed to two worms: W32/Bobax and W32/Kibuv. These worms scan for systems with port 5000/tcp open to identify machines running Windows XP (which enables the UPnP service by default), prior to attempting to exploit these systems.
Now see if i've got this right. These two ground crawlers are hitching a lift in the Trojan, Sokets de trios v1, to bombard my port 5000 (the firewall confirms this) to stuff up my puter. I'm safe because i'm behind a firewall and the three disabling programs i downloaded. Also because i've run a security check on ALL port to confirm i am in full stealth mode. Some lowlife somewhere is making these bullets and firing at ramdom for kicks or financial gain?
Acording to reports i've read there is very high activity in port 5000 taraffic. Thanks Deborah I did a little reading
Have i got the gist of it
Reply #38 Wednesday, May 19, 2004 10:05 PM
Yes, you have a good understanding of what is happening and what isn't. Norton, unlike most, is just telling you that it was blocked. The one thing you have to remember is that it's only telling you that, not the scanner. When you run in full Stealth, for all intents and purposes, nothing scanning the internet knows you're there. If, on the other hand, Norton was to react to the actual scan (other then the alert to you) by bouncing it back to the source then the scan would know your presence...have I confused you enough?
Reply #39 Wednesday, May 19, 2004 10:12 PM

Reply #40 Wednesday, May 19, 2004 10:15 PM
Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!







Reply #21 Tuesday, May 18, 2004 2:34 AM