Viral oddness

Configure and optimize you computer for Audio.
Post Reply New Topic
RELATED
PRODUCTS

Post

Weird problems.
I'm on ADSL, my modem is also a router/firewall (100% stealth according to Shields Up).
Nonetheless, I have my PCcillin filewall switched on, set to highest security.
Every once in a while, it will panic a little and say stuff like

Code: Select all

Cloaking,19:03:47,IN,ICMP,xx.xx.xxx.xx,N/A,xx.x.x.xxx,N/A,Cloaking,
but nothing else happens.
Tonight, however, it said this

Code: Select all

Trojan backdoor blocking,22:33:54,OUT,TCP,xx.x.x.xxx,2552,xx.xx.xxx.xxx,31339,Net Spy,
three times in a row, and also

Code: Select all

Trojan backdoor blocking,22:45:22,OUT,TCP,xx.x.x.xxx,2830,xxx.xxx.xx.xxx,27374,Sub Seven,
Now a firewall blocking trojans is pretty regular. Blocking trojans from getting out can be seen as bad news.
So, I fired up PCcillin (latest pattern-files, engine, latest anything) and scanned my whole machine.
Nothing.
Hmmm.
Went straight to Housecall.
Scanned everything. Again.
Nothing. Again.
Hmmm. Again.
All the while I had Netstat running to monitor traffic, but it saw nothing out of the ordinary.

Is anyone aware of stealth-virii out there? Trend issued no warnings regarding these, don't know if such a thing even exists anymore.

Any pointers?
False alarm?

Groet, Erik
Pop music delenda est.
Image

Post

You have sub seven trojan on computer. Outside user is trying to enter into computer with this. Subseven allows person to control the computer you are using as they wish. Run antivirus software quickly! They can find ways around firewall, and find ways into your computer.

Subseven is very old trojan. This emulate netbus software in bad way. Many children use this to play pranks on friends. Many grown ups act like children too. :(
Image
Soon to release my new album! Alive in Chernobyl - "Dead Inside"

Post

Alive In Chernobyl wrote:You have sub seven trojan on computer. Outside user is trying to enter into computer with this. Subseven allows person to control the computer you are using as they wish. Run antivirus software quickly!
I have (Trend's PCcillin is my scanner).
Nothing found.
I know there's virii that alter/bypass pattern files, so I tried Housecall (Trend's online scanner) as well. Again, nothing was found.
I also checked for any recently updated (hidden) files and folders, but I could find nothing out of the ordinary.
No odd running tasks, either, and Netstat registered no weird connections.
They can find ways around firewall, and find ways into your computer.

Subseven is very old trojan.
Yes, it has been around for at least 3 years.
This is why I reckoned it would be picked up by the virusscanners.
This emulate netbus software in bad way. Many children use this to play pranks on friends. Many grown ups act like children too. :(
Yes.
I have no intention of letting my computer be used as a spambot or attack-zombie.
I get the feeling a full format+install is in order.
Battle-stations!

Groet, Erik
Pop music delenda est.
Image

Post

On a sidenote, does anyone know if it's possible to kill a specific outgoing connection with a command-line? Like the *nix "kill" command to end a process.
I'm on win2k, by the way.

Groet, Erik
Pop music delenda est.
Image

Post

Netbus and Subseven can be thought of as real program by some scanner.

Try Grisoft AVG. Also try Free web scanner that exist. Remember netbus is made as a real network admin programm, and subseven was too for some time.
Image
Soon to release my new album! Alive in Chernobyl - "Dead Inside"

Post

tetraplan wrote:
Alive In Chernobyl wrote:You have sub seven trojan on computer. Outside user is trying to enter into computer with this. Subseven allows person to control the computer you are using as they wish. Run antivirus software quickly!
I have (Trend's PCcillin is my scanner).
I don't know much about PCcillin, but I know that a lot of good (now really ?) anti-virus software is not that good when it comes to Trojans...

McAfee has a free tool specifically made for Trojans, it's called Stinger.
You can download it here:
http://vil.nai.com/vil/stinger/

Otherwise, give a try to 'Anti-Trojan' ot 'The Cleaner'.

Post

Kullervo wrote:
tetraplan wrote:
Alive In Chernobyl wrote:You have sub seven trojan on computer. Outside user is trying to enter into computer with this. Subseven allows person to control the computer you are using as they wish. Run antivirus software quickly!
I have (Trend's PCcillin is my scanner).
I don't know much about PCcillin, but I know that a lot of good (now really ?) anti-virus software is not that good when it comes to Trojans...

McAfee has a free tool specifically made for Trojans, it's called Stinger.
You can download it here:
http://vil.nai.com/vil/stinger/

Otherwise, give a try to 'Anti-Trojan' ot 'The Cleaner'.
Problem is that neither of this programs is trojan. They are real software being used in a bad way. Trojan are naturally made to do something bad, or do something annoying. If trojan scanner found this then they should also find quicktime and realplayer. These are software that do bad things, but are not made to be bad.
Image
Soon to release my new album! Alive in Chernobyl - "Dead Inside"

Post

OK, thanks for the tips.
Everything is eerily quiet on ports 31339 and 27374.
Downloading stinger as I type this.
It may not find Net Spy and Subseven, but it can't hurt to try.
I really don't see how any malware could have made it to my system, but, well.

Groet, Erik
Pop music delenda est.
Image

Post

tetraplan wrote:OK, thanks for the tips.
Everything is eerily quiet on ports 31339 and 27374.
Downloading stinger as I type this.
It may not find Net Spy and Subseven, but it can't hurt to try.
I really don't see how any malware could have made it to my system, but, well.

Groet, Erik
This programs often added into fake updates for software. Many people with no permissions to post software of companies adds this into companies software. Be careful downloading softwares from a third party!
Image
Soon to release my new album! Alive in Chernobyl - "Dead Inside"

Post

Alive In Chernobyl wrote:This programs often added into fake updates for software. Many people with no permissions to post software of companies adds this into companies software. Be careful downloading softwares from a third party!
OK, thanks.

Groet, Erik
Pop music delenda est.
Image

Post

try installing and scanning with this

http://www.nai.com/us/downloads/beta/vse/VSE80i.htm

next generation AV software with intrusion prevention and buffer over flow protection

ive been testing it for over a month now and its served me well!

Post

simonw wrote:try installing and scanning with this

http://www.nai.com/us/downloads/beta/vse/VSE80i.htm

next generation AV software with intrusion prevention and buffer over flow protection

ive been testing it for over a month now and its served me well!
I'm not really a fan of McAffee's stuff, but I'll give this one a try.
Thanks for the tip.
//note to self: make testing-environment

In the meantime: Apart from entries in PCcillin's log on the 23rd, I have seen no more activity on these ports.
Odd.

Groet, Erik
Pop music delenda est.
Image

Post Reply

Return to “Computer Setup and System Configuration”