Trojan

Monday, May 17, 2004 by Ande | Discussion: WinCustomize Talk

This is new for me. For the last couple of days my firewall is continually blocking "sockets de Trios v1 trojan horse" This is occuring every couple of minutes. Can anybody tell me what is going on
First Previous Page 2 of 3 Next Last
yrag
Reply #21 Tuesday, May 18, 2004 2:34 AM
http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp?lid=zadb_zadown
eieio
Reply #22 Tuesday, May 18, 2004 7:22 AM
This is also a good one
http://www.kerio.com/kpf_download.html
Ande
Reply #23 Wednesday, May 19, 2004 1:37 AM
Back again. Yrag or anyone with knowledge. I have had Norton Firewall for some years now, with the "enable alert" option on. Nothing has ever got through and still hasn't. From time to time it very politely advised me when an intrusion attempt happened. I am aware of and have been advised that trojan invasion is a common occurrence. But even with the "Alert Options" disabled an "exclamation mark" is flashing on the Norton Firewall icon in the system tray and its very annoying. Ok you might say remove the subject icon. But I like to know that the Firewall is enabled when I boot up. The minute I log onto the internet this paticular Trojan (Described in post 5) does not let up for a moment, it is constant.

If this is the norm OK. Life goes on. But I am having trouble comprehending this. To me this incessant blocking of the same type of Trojan is not normal. My Firewall has never acted the way before. Ok pl someone, please put my mind at rest. >
yrag
Reply #24 Wednesday, May 19, 2004 1:46 AM
For Norton, it is normal....


There should be an option in Norton somewhere to 'not' show alerts thru the tray icon and just show the normal icon.
yrag
Reply #25 Wednesday, May 19, 2004 1:51 AM
I do have two questions...when you scanned your ports over at the grc site, did you scan the 'Service ports' and do you have 'Messenger Service' disabled?
Ande
Reply #26 Wednesday, May 19, 2004 1:53 AM
Thanks Mate will look. But how come its just started this type of behavior??
yrag
Reply #27 Wednesday, May 19, 2004 1:57 AM
There's no real answer for that....could just be a scanner that just happened to pick on your ISP...next week, it'll be somebody elses turn. I still think you might find a service port listening and it's rejecting the scan. Let me know what the 'Service Ports' scan shows.
Ande
Reply #28 Wednesday, May 19, 2004 2:23 AM
Scanned all service ports up to 1056. No problems. I think Messenger service is disabled never used it where is it
yrag
Reply #29 Wednesday, May 19, 2004 2:27 AM
Go back to grc http://grc.com/default.htm and download the 2 apps. for disabling Dcom and Messenger Service ( you all ready did the PnP one). If either say thet''re running then disable them using those apps.










[Message Edited]
Ande
Reply #30 Wednesday, May 19, 2004 2:46 AM
Both downloaded, both were enabled, now disabled, re booted and after a minute of loging on the Trojans back, the alerts come every minute. Have not found that other disable alert thingy yet. Looks like i'm stuck with it. No figure though.
Essencay
Reply #31 Wednesday, May 19, 2004 2:50 AM
Ande...if your ISP has another dial-up number to use try it. Sometimes, at least for me, the other number isn't being scanned. I bounce back and forth between a couple of numbers here, to get away from the annoyance of the alert message from Norton's
yrag
Reply #32 Wednesday, May 19, 2004 2:55 AM
That''s a good idea Stephen...I forgot all about you have that option in dial up.....

Brian, #1 : you''re safe. #2 : there should be a setting to disable that icon from flashing.....it''s been so long that I used Norton, I just can''t remember where it''s at. You could just hide the icon in the system tray, then you''ll know it''s running and, more importantly, you won''t see it all the time.


[Message Edited]
Ande
Reply #33 Wednesday, May 19, 2004 2:55 AM
I'll check that out with my ISP Stephen, thanks.
IPlural
Reply #34 Wednesday, May 19, 2004 4:38 PM
Norton 2004 auto blocks a site which is seen to attempt to run an invalid script or to attempt a TCP/IP attack for 30 minutes, you can over ride it in the configuration, over all or ively.

I would suggest ive.... just because
sig101
Reply #35 Wednesday, May 19, 2004 5:53 PM
Go back to GRC.com Shield's Up and run the test for common ports. http://grc.com/default.htm Port 5000 (UnPnP) I believe is not included in the service portscan which covers the first 1056 ports. Port 5000 is the port Norton says you're getting scanned on so that would be the one in particular you'd want to check. As long as the port is not open I wouldn't waste time worring about it.

If you applied Gibson's Unplug n Pray app that would disable the service and close the port within the OS. http://grc.com/unpnp/unpnp.htm

I previously posted a link to the BBR Security FAQ...lots of info there if you want to read up and learn.



Powered by SkinBrowser!
Ande
Reply #36 Wednesday, May 19, 2004 9:05 PM
Increased scanning of 5000/tcp
added May 18
US-CERT has received reports of scanning activity directed at port 5000/tcp. This port is used by the Microsoft Windows Universal Plug and Play service (UPnP). Some of this activity can be attributed to two worms: W32/Bobax and W32/Kibuv. These worms scan for systems with port 5000/tcp open to identify machines running Windows XP (which enables the UPnP service by default), prior to attempting to exploit these systems.

Now see if i've got this right. These two ground crawlers are hitching a lift in the Trojan, Sokets de trios v1, to bombard my port 5000 (the firewall confirms this) to stuff up my puter. I'm safe because i'm behind a firewall and the three disabling programs i downloaded. Also because i've run a security check on ALL port to confirm i am in full stealth mode. Some lowlife somewhere is making these bullets and firing at ramdom for kicks or financial gain?

Acording to reports i've read there is very high activity in port 5000 taraffic. Thanks Deborah I did a little reading

Have i got the gist of it
Ande
Reply #37 Wednesday, May 19, 2004 9:51 PM
bump Yrag
yrag
Reply #38 Wednesday, May 19, 2004 10:05 PM
yrag likes a good bumpin'..

Yes, you have a good understanding of what is happening and what isn't. Norton, unlike most, is just telling you that it was blocked. The one thing you have to remember is that it's only telling you that, not the scanner. When you run in full Stealth, for all intents and purposes, nothing scanning the internet knows you're there. If, on the other hand, Norton was to react to the actual scan (other then the alert to you) by bouncing it back to the source then the scan would know your presence...have I confused you enough?
Ande
Reply #39 Wednesday, May 19, 2004 10:12 PM
Yes. What prompts the firewall to react, i.e. bouncing it back to source. Is that a setting?.
yrag
Reply #40 Wednesday, May 19, 2004 10:15 PM
No setting...a good firewall is set that way as a default. The idea (and it's a good one) is that a scanner can't scan what it can't find.....

Please login to comment and/or vote for this skin.

Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:

  • Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
  • Access to a great community, with a massive database of many, many areas of interest.
  • Access to contests & subscription offers like exclusive emails.
  • It's simple, and FREE!



web-wc01