View previous topic :: View next topic |
Author |
Message |
viper
Guest
|
Posted: Mon Feb 10, 2003 3:44 pm Post subject: Nerte 7.8.1 Trojan |
|
|
I got a warning message after the scan. What is this please help
Warning: fsockopen() [function.fsockopen]: unable to connect to 217.128.142.30:31 in /home/www/computercops/modules/Trojan_TCP_Scan/ccspTrojans.php on line 137
Connection Refused: Port 31 used by Master Paradise.
ESTABLISHED CONNECTION: Possible Nerte 7.8.1 Trojan found on port 80. |
|
Back to top |
|
|
Paul
Admin
Joined: Feb 22, 2002
Posts: 5719
Location: USA
|
Posted: Mon Feb 10, 2003 3:57 pm Post subject: |
|
|
Are you running any firewalls or anti-virus programs?
_________________
I love my wife. |
|
Back to top |
|
|
Guest
|
Posted: Sun Feb 16, 2003 6:51 pm Post subject: |
|
|
Paul wrote: |
Are you running any firewalls or anti-virus programs? |
i to also got this msg
Possible Nerte 7.8.1 Trojan found on port 21.
im running zone alarm pro firewall on xp pro
|
|
Back to top |
|
|
jaykaykay
Captain
Premium Member
Joined: Feb 25, 2002
Posts: 477
Location: USA
|
Posted: Tue Feb 25, 2003 9:52 pm Post subject: |
|
|
Anonymous wrote: |
Paul wrote: |
Are you running any firewalls or anti-virus programs? |
i to also got this msg
Possible Nerte 7.8.1 Trojan found on port 21.
im running zone alarm pro firewall on xp pro
|
How about an AV or Anti Trojan scanner. I believe that this is one of those Backdoor goodies according to Google.
|
|
Back to top |
|
|
Paul
Admin
Joined: Feb 22, 2002
Posts: 5719
Location: USA
|
Posted: Tue Feb 25, 2003 9:59 pm Post subject: |
|
|
An online scanner here?
_________________
I love my wife. |
|
Back to top |
|
|
jaykaykay
Captain
Premium Member
Joined: Feb 25, 2002
Posts: 477
Location: USA
|
Posted: Tue Feb 25, 2003 10:11 pm Post subject: |
|
|
Paul wrote: |
An online scanner here? |
Looks like it to me...
"Warning: fsockopen() [function.fsockopen]: unable to connect to 217.128.142.30:31 in /home/www/computercops/modules/Trojan_TCP_Scan/ccspTrojans.php on line 137
Connection Refused: Port 31 used by Master Paradise.
ESTABLISHED CONNECTION: Possible Nerte 7.8.1 Trojan found on port 80."
Perhaps I am not reading your question right though.
|
|
Back to top |
|
|
Paul
Admin
Joined: Feb 22, 2002
Posts: 5719
Location: USA
|
Posted: Tue Feb 25, 2003 11:29 pm Post subject: |
|
|
Oh I thought you meant adding an AV scanner or something.
_________________
I love my wife. |
|
Back to top |
|
|
slofs
Guest
|
Posted: Sun Apr 06, 2003 12:35 pm Post subject: |
|
|
i alsso had Nerte warning
i run AGV and Sygate firewhal
ESTABLISHED CONNECTION: Possible Nerte 7.8.1 Trojan found on port 80. |
|
Back to top |
|
|
Paul
Admin
Joined: Feb 22, 2002
Posts: 5719
Location: USA
|
Posted: Mon Apr 07, 2003 10:25 am Post subject: |
|
|
Try running "netstat -an" , post your findings.
_________________
I love my wife. |
|
Back to top |
|
|
ehask
Guest
|
Posted: Thu Apr 17, 2003 11:55 pm Post subject: Nerte 7.8.1 Trojan |
|
|
Make sure your not running a webserver on your box. I also got this message but I am on the LAN side of a Linux firewall that is hosting 5 domains (port 80)
I believe the fact that a webserver responds triggers the scanner as a possible Trojan
Paul nice site!!
Eric H
A+,Linux+,MCSE,CCNA
www.pctechs2go.net |
|
Back to top |
|
|
Guest
|
Posted: Tue Jul 22, 2003 3:44 pm Post subject: heres what netstat -an says |
|
|
http://freeozlotto.com/Clipboard01.gif
i also have the nerte rthing being reported |
|
Back to top |
|
|
Paul
Admin
Joined: Feb 22, 2002
Posts: 5719
Location: USA
|
Posted: Tue Jul 22, 2003 8:32 pm Post subject: |
|
|
Try an "netstat -an" does it show anything listening on that port?
_________________
I love my wife. |
|
Back to top |
|
|
Guest
|
Posted: Wed Jul 23, 2003 2:00 am Post subject: |
|
|
0.0.0.0:1960 0.0.0.0:0 LISTENING
127.0.0.1:1792 0.0.0.0:0 LISTENING
127.0.0.1:5180 0.0.0.0:0 LISTENING
127.0.0.1:3698 0.0.0.0:0 LISTENING
127.0.0.1:3716 0.0.0.0:0 LISTENING
203.29.136.155:12082 0.0.0.0:0 LISTENING
203.29.136.155:31825 0.0.0.0:0 LISTENING
203.29.136.155:3697 207.46.106.38:1863 ESTABLISHED
203.29.136.155:3713 205.188.9.77:5190 ESTABLISHED
203.29.136.155:3723 64.12.200.226:5190 ESTABLISHED
203.29.136.155:1958 205.188.165.121:80 TIME_WAIT
203.29.136.155:1960 207.46.108.49:1863 ESTABLISHED
203.29.136.155:1962 64.12.174.121:80 TIME_WAIT
203.29.136.155:11465 0.0.0.0:0 LISTENING
0.0.0.0:1029 *:*
0.0.0.0:3696 *:*
127.0.0.1:1792 *:*
127.0.0.1:3698 *:*
127.0.0.1:3716 *:*
203.29.136.155:31825 *:*
203.29.136.155:11465 *:* |
|
Back to top |
|
|
savagegoose
Cadet
Joined: May 14, 2003
Posts: 2
Location: Australia
|
Posted: Wed Jul 23, 2003 2:31 am Post subject: |
|
|
well that last guest posts was mine, i narrowed down all progs running and still had this
Proto Local Address Foreign Address State
TCP 0.0.0.0:1029 0.0.0.0:0 LISTENING
TCP 203.29.136.155:2063 205.188.165.121:80 TIME_WAIT
UDP 0.0.0.0:1029 *:*
i did a trace route and got this
1 203.12.165.50 201ms 202ms 220ms TTL: 0 (adl-ts1-2600.tpgi.com.au ok)
2 203.12.165.33 223ms 206ms 199ms TTL: 0 (adl-7204.tpgi.com.au ok)
3 202.7.183.34 222ms 202ms 230ms TTL: 0 (adl-adlpow-gw.tpgi.com.au ok)
4 202.7.162.101 294ms 214ms 239ms TTL: 0 (syd-adl-pow-gw.tpgi.com.au ok)
5 203.192.130.221 220ms 220ms 221ms TTL: 0 (No rDNS)
6 203.192.160.101 222ms 221ms 222ms TTL: 0 (No rDNS)
7 203.192.136.106 375ms 361ms 380ms TTL: 0 (pos2-1-155M.cr1.LAX1.gblx.net ok)
8 66.185.148.49 376ms 378ms 361ms TTL: 0 (pop2-las-P5-1.atdn.net bogus rDNS: host not found [authoritative])
9 66.185.137.160 427ms 385ms 406ms TTL: 0 (bb1-las-P1-0.atdn.net bogus rDNS: host not found [authoritative])
10 66.185.137.160 407ms 393ms 392ms TTL: 0 (bb1-las-P1-0.atdn.net bogus rDNS: host not found [authoritative])
11 66.185.152.37 405ms 381ms 379ms TTL: 0 (bb2-pho-P1-0.atdn.net bogus rDNS: host not found [authoritative])
12 66.185.152.37 416ms 420ms 428ms TTL: 0 (bb2-pho-P1-0.atdn.net bogus rDNS: host not found [authoritative])
13 66.185.152.106 452ms 435ms 448ms TTL: 0 (bb2-hou-P6-0.atdn.net bogus rDNS: host not found [authoritative])
14 66.185.152.184 442ms 431ms 442ms TTL: 0 (bb1-atm-P7-0.atdn.net bogus rDNS: host not found [authoritative])
15 66.185.152.184 479ms 442ms 437ms TTL: 0 (bb1-atm-P7-0.atdn.net bogus rDNS: host not found [authoritative])
16 66.185.152.29 428ms 431ms 425ms TTL: 0 (bb1-vie-P10-0.atdn.net bogus rDNS: host not found [authoritative])
17 66.185.152.158 436ms 456ms 432ms TTL: 0 (bb1-dtc-P11-0.atdn.net bogus rDNS: host not found [authoritative])
18 66.185.152.158 484ms 436ms 441ms TTL: 0 (bb1-dtc-P11-0.atdn.net bogus rDNS: host not found [authoritative])
19 66.185.145.2 432ms 435ms 434ms TTL: 0 (ow1-dr2-S0-2-0.atdn.net bogus rDNS: host not found [authoritative])
20 66.185.145.2 440ms 463ms 448ms TTL: 0 (ow1-dr2-S0-2-0.atdn.net bogus rDNS: host not found [authoritative])
21 172.18.126.98 456ms 471ms 441ms TTL: 0 (No rDNS)
22 205.188.165.121 447ms 461ms 432ms TTL: 50 (ads.web.aol.com ok)
should i be worried? |
|
Back to top |
|
|
Jamming
Colonel
Premium Member
Joined: Jun 22, 2002
Posts: 1874
|
Posted: Wed Jul 23, 2003 7:13 pm Post subject: |
|
|
Download the TrojanHunter trial it detects and removes the Nerte 781 Trojan. Make sure you update the definitions. Using the trial version of TrojanHunter, please see http://www.misec.net/support/trojanhunter/updating/ for instructions on how to update to the latest ruleset. |
|
Back to top |
|
|
|