New User? Click here to register! Feel free to read this for beginners help.

Computer Cops
image image image image image image image image
Prime Choice
· Head Lines
· Dnld of the Week!
· Find a Cure!

· Ian T's (Article 12)
· Marcia's (Op8)
· Paul's (Article 3)

· Ian T's Archive
· Marcia's Archive
· Paul's Archive
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Security Central
· Home
· Wireless
· Bookmarks
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· Recommend Us
· RegChat
· Reviews
· Search
· Sections
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
Donations
image
Search

image
Survey
Which Anti-Virus product do you use?

Computer Associates
Eset (NOD32)
F-Secure
Frisk (F-Prot)
Grisoft (AVG)
Kaspersky
Network Associates (McAfee)
Panda
Sophos
Symantec (NAV)
Trend Micro
Other



Results
Polls

Votes: 8614
Comments: 80
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Am I at risk?
Goto page 1, 2  Next
 
Post new topic   Reply to topic       Computer Cops Forum Index -> Site Toolkit
View previous topic :: View next topic  
Author Message
hally44
Trooper
Trooper



Joined: Jan 09, 2004
Posts: 13
Location: Uk

PostPosted: Tue Jan 20, 2004 3:26 pm    Post subject: Am I at risk? Reply with quote

I have just run the trojan test and its stating ive got 3 possible trojans. Am I at risk at all? I have Norton Antivirus, Zone alarm and run spybot perodically.

ESTABLISHED CONNECTION: Possible TruvaAti 1.2 beta Trojan found on port 23.
ESTABLISHED CONNECTION: Possible Nerte 7.8.1 Trojan found on port 80.
ESTABLISHED CONNECTION: Possible CANCER 1.0 Trojan found on port 8080.
3 possible trojans were detected on your system. Recommended solution: update your anti-virus or anti-trojan definitions immediately and then scan your system. For further help, please visit the CCSP Toolkit Forum

Output from netstat -a is :
Proto Local Address Foreign Address State
TCP ?????:0 ?????:0 LISTENING
TCP ?????:2071 ?????:0 LISTENING
TCP ?????:6543 ?????:0 LISTENING
TCP ?????:1030 ?????:0 LISTENING
TCP ?????:1116 ?????:0 LISTENING
TCP ?????:2143 ?????:0 LISTENING
TCP ?????:137 ?????:0 LISTENING
TCP ?????:138 ?????:0 LISTENING
TCP ?????:nbsession ?????:0 LISTENING
UDP ?????:2071 *:*
UDP ?????:6543 *:*
UDP ?????:1030 *:*
UDP ?????:2143 *:*
UDP ?????:nbname *:*
UDP ?????:nbdatagram *:*

Any advice much appreciated
Back to top
View users profile Send private message
Paul
Admin
Admin



Joined: Feb 22, 2002
Posts: 4548
Location: USA

PostPosted: Tue Jan 20, 2004 6:55 pm    Post subject: Reply with quote

Have you run any updated trojan or anti-virus scanners on your system lately>
_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
Guest







PostPosted: Tue Jan 20, 2004 7:15 pm    Post subject: Reply with quote

I have got Norton antiVirus which is up to date and run frequently. Does this not also highlight trojans or is this something seperate?
Back to top
Paul
Admin
Admin



Joined: Feb 22, 2002
Posts: 4548
Location: USA

PostPosted: Tue Jan 20, 2004 10:23 pm    Post subject: Reply with quote

Ok, step one is good then if your updated scanner reveals nothing. Next question, do you have a firewall?
_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
hally44
Trooper
Trooper



Joined: Jan 09, 2004
Posts: 13
Location: Uk

PostPosted: Fri Jan 23, 2004 11:28 am    Post subject: Reply with quote

Yes i have the free Zone alarm running. Have also scanned system for spyware with spybot and all appears ok.
Back to top
View users profile Send private message
Acheton
Forums Admin
Forums Admin
Premium Member
Premium Member


Joined: Sep 04, 2003
Posts: 1717
Location: Uk

PostPosted: Fri Jan 23, 2004 2:38 pm    Post subject: Reply with quote

I suggest that you download, install and update a trial version of TrojanHunter (www.misec.net). Then reboot your machine and run a full scan using TH without connecting to the new. Then post back with your findings. At the moment it is difficult to tell whether your browser has the ports open, or whether it is something more nefarious.

thanks,

ach
Back to top
View users profile Send private message
hally44
Trooper
Trooper



Joined: Jan 09, 2004
Posts: 13
Location: Uk

PostPosted: Mon Jan 26, 2004 10:45 am    Post subject: Reply with quote

I have downloaded the trojanhunter and run with the result that no trojans were detected. I have also installed Diamond port explorer and the only pertinent thing it came up with was I had inetinfo.exe running on port 6543 though IIS service was stopped so do not think this was a problem. When removed with highjackthis so that it doesnt run anymore still showing ports 23, 80 and 8080 as possible trojans using the test on this site.
Port Explorer does not show anything listening on these ports so I am a liitle confused on why the test says theres a problem.
Really do appreciate all the advice given as Id like to understand what is happening here. Many thanks.
Back to top
View users profile Send private message
hally44
Trooper
Trooper



Joined: Jan 09, 2004
Posts: 13
Location: Uk

PostPosted: Tue Jan 27, 2004 6:31 pm    Post subject: Reply with quote

Just a thought but when running the test the IP address is not my real address. My Service provider uses a proxy server and this address is the one being reported at the start of the scan.
Is the scan scanning the proxy server for trojans and not my pc?
Back to top
View users profile Send private message
Paul
Admin
Admin



Joined: Feb 22, 2002
Posts: 4548
Location: USA

PostPosted: Tue Jan 27, 2004 6:36 pm    Post subject: Reply with quote

Yes that's correct, the proxy. Run this:

http://computercops.biz/modules.php?name=Reveal_IP

Is it accurate?

_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
hally44
Trooper
Trooper



Joined: Jan 09, 2004
Posts: 13
Location: Uk

PostPosted: Tue Jan 27, 2004 7:39 pm    Post subject: Reply with quote

Yes that is it I think - its scanning the proxy server as 'reveal my ip' shows two ips and the actual ip address is accurate and its not scanning this.
Silly question now but if 'reveal your ip' knows the real ip address can't the scan be directed at this instead of the proxy server?
Also I take it that I must be more secure and less prone to trojans with the proxy setup?
Many thanks for all the advice given
Back to top
View users profile Send private message
Paul
Admin
Admin



Joined: Feb 22, 2002
Posts: 4548
Location: USA

PostPosted: Tue Jan 27, 2004 7:45 pm    Post subject: Reply with quote

Yes, I'll modify this in a moment.
_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
Paul
Admin
Admin



Joined: Feb 22, 2002
Posts: 4548
Location: USA

PostPosted: Tue Jan 27, 2004 7:55 pm    Post subject: Reply with quote

Ok I changed the code for all the TCP/Trojan/UDP scanners. Can you test and let me know? I'll be back after dinner.
_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
hally44
Trooper
Trooper



Joined: Jan 09, 2004
Posts: 13
Location: Uk

PostPosted: Wed Jan 28, 2004 12:59 pm    Post subject: Reply with quote

Yes problem solved - Seems to be scanning my real IP address now and no Trojans detected.
Many Thanks
Back to top
View users profile Send private message
Paul
Admin
Admin



Joined: Feb 22, 2002
Posts: 4548
Location: USA

PostPosted: Wed Jan 28, 2004 8:13 pm    Post subject: Reply with quote

Great! I've been meaning to hop on this for some time now, and was finally able to purchase free time. icon_wink.gif
_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
outkast-central
Cadet
Cadet



Joined: Feb 28, 2004
Posts: 2
Location: Australia

PostPosted: Sat Feb 28, 2004 1:27 am    Post subject: Reply with quote

I've got Norton Antivirus and BitDefender Virus Scanners and i reckon that BitDefender is way better than Norton Antivirus because i update my Norton Antivirus scanner everyday. But BitDefender is way better because i havent updated it yet and it detects Win32.parite.B , this DyFuCa Trojan and many more that Norton Cannot detect. I suggest that you try every virus scanner to see which one truly is the best
Back to top
View users profile Send private message Send email
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> Site Toolkit All times are GMT - 5 Hours
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8 © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops