Computing.Net > Forums > Security and Virus > Backdoor/SubSeven and Norton...HELP

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Backdoor/SubSeven and Norton...HELP

Reply to Message Icon

Name: Concerned One
Date: October 21, 2002 at 05:28:11 Pacific
OS: WinXP Pro
CPU/Ram: P4 1.6/512
Comment:

I've been getting a message a couple to few times a day from Norton Internet Security 2002 which tells me a hack has been attempted, and each time it is the Subseven Trojan (I'm running winXP Pro with Norton Antivirus as well).

Here is a sample detail:

Date: 10/21/2002 Time: 4:59:40
Rule "Default Block Backdoor/SubSeven Trojan horse" blocked (ag(66.122.135.130),27374). Details:
Inbound TCP connection
Local address,service is (ag(66.122.135.130),27374)
Remote address,service is (67.209.60.187,1790)
Process name is "N/A"

I wish I saved more to compare the detail and see if they always looked the same. But for now, my questions are:

1) Does this mean that the trojan is already on my machine and Norton AV/IS is catching it trying to communicate out? If so, I checked the registry and system.ini and win.ini that Norton says to look at to see if it is on your system and nothing there.

2) If this is not on my system, it's wierd that over the last 5 days someone is cleary trying to put it on my system. No other trojan or virus hacker alerts come up, just this one.

Keep in mind I just rebuilt my machine one week ago with a bunch of different stuff.

Also, every once in a while I get a millisecond worth of like a window popping up or something and it dissappears almost instantly. I keep assuming it's just some wierd artifact of WinXP and my video card maybe, but now I'm really wondering...

Any advice/suggestions? Oh yeah the local address in the above details is mine.

Thanks!




Sponsored Link
Ads by Google

Response Number 1
Name: Concerned One
Date: October 21, 2002 at 05:31:19 Pacific
Reply:

BTW, I forgot to add that I have already scanned my entire system multiple times as well and nothing is found. I also ran something called Tauscan (sp?) which found nothing.


0

Response Number 2
Name: capt
Date: October 21, 2002 at 09:44:29 Pacific
Reply:

It sounds like you are secure and that Norton is being diligent. If you have scanned with 2003 and Tauscan and found nothing and the probes are external reports, and not outgoing requests for access there should not be a problem. If the request is for you to grant access to an outgoing program. Then you know that a trojan is on your system, and more searching is required. Have you ran the scans at the PC Flank website to see how your firewall is performing. Norton makes a pretty nice antivirus program, but they are not the greatest firewall makers. You will see what I mean at the firewall reviews at PC Flank. Take care and all the best!


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Backdoor/SubSeven and Norton...HELP

Backdoor/Subseven Trojan www.computing.net/answers/security/backdoorsubseven-trojan/6930.html

Backdoor SubSeven trojan www.computing.net/answers/security/backdoor-subseven-trojan/6018.html

Backdoor Subseven - Virus cont.... www.computing.net/answers/security/backdoor-subseven-virus-cont/315.html