Computing.Net > Forums > Security and Virus > Have I got a virus? I'm baffled!

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Have I got a virus? I'm baffled!

Reply to Message Icon

Original Message
Name: J.Pullin
Date: December 11, 2002 at 10:51:09 Pacific
Subject: Have I got a virus? I'm baffled!
OS: XP Home
CPU/Ram: 1.3 GBs 256 MBs
Comment:

Hi,

I recently noticed that whenever I dial up, pretty soon by checking my firewall traffic log ( Sygate Pro 4.0 ), there's an outbound tcp connection made to a ftp site via the Internet Explorer program using various ports, even though I don't visit the site ( which is ftp.ox.ac.uk 163.1.2.79 ).

Almost instantly an incoming tcp connection is allowed, nearly always on port 21, sometimes port 20 from the same source. Also, every imcp probe from this same source, again on various ports, is allowed.

I've run two top notch anti trojan suites and Kaspersky antivirus 4.0 with full system scans and none report any infection.

I also continually run command prompts ( netstat -n ) and there never seems to be an active connection. So, I'm more than a little bemused.

If I use Opera ( which I find very slow ) as my browser, none of the above occurs.

I understand that some trojans once executed can attach themselves to a trusted program, usually Internet Explorer, to ' bypass ' firewalls. If I have one, then it's escaped detection.

Which begs the question, have I a virus or not? And if so, how to get rid of the pest?

Any advice will be gratefully received.


Report Offensive Message For Removal


Response Number 1
Name: capt
Date: December 11, 2002 at 11:20:14 Pacific
Reply: (edit)

You could do a search for that site. I would immediately use Sygate to deny it access, and to find out the program's name. Then do a search for that program, and take the appropriate action.


Report Offensive Follow Up For Removal

Response Number 2
Name: Latika
Date: December 11, 2002 at 11:56:01 Pacific
Reply: (edit)

It is the Oxford University Computing Dept. You should probably write to them and let them know that possibly someone is trying to access your machine.
ARIN whois:
OrgName: Oxford University Computing Service
OrgID: OUCS

NetRange: 163.1.0.0 - 163.1.255.255
CIDR: 163.1.0.0/16
NetName: OXFORD-UNIV
NetHandle: NET-163-1-0-0-1
Parent: NET-163-0-0-0-0
NetType: Direct Assignment
NameServer: DNS0.OX.AC.UK
NameServer: DNS1.OX.AC.UK
Comment:
RegDate: 1992-06-25
Updated: 1992-11-25

TechHandle: RT26-ARIN
TechName: Treweek, Roger
TechPhone: +44-1865-273251
TechEmail: roger.treweek@oucs.ox.ac.uk



Report Offensive Follow Up For Removal

Response Number 3
Name: michael2
Date: December 11, 2002 at 14:40:46 Pacific
Reply: (edit)

Do you have UPNP enabled ???
See my post from the security site...
http://www.computing.net/security/wwwboard/forum/942.html


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge
Poll History




Data Recovery Software