Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hi!!
my pc was HP pavalion with XP home edition P4 1.8 Ghz...for security i m currently using nortan antivirus 2002 that was provided with pc when I bought it..but i don't have other internet security sofwares..just using default settings...a few days ago I looked the report from nortan..it shown that detected backdoor. trojan and says can't access to file and access is denied...next 2 days later..my mouse pointer moving itself up down slowly and some keys from keyboard is death..I scanned again and again but nothin is found nothin..but i think this problem is more worse than a day by day...I think somebody is attacking from yahoo messenger by sending infected files...and that f---ing freak said IP attack ??? i don't know what's that?? and can attack to somebody using their IP addresses....I'm freak out ... any ideas...but lool my nortan antiVirus subscription is expired for a month ago..I still haven't renew it..of course I checked the updates nearly everyday...Pls help me..hey I also found the virus named "cybertech"..
regard..Fred.

You can download Trojan Hunter (30 day free trial) and scan your system.
You can get a free firewall (Zone Alarm)
and also run Ad-aware.
I think that they will help you.
You can even have free online virus scan
http://security2.norton.com/ssc/home.asp?

hi fred,
listen stop freaking out you have been trojaned.
do the following:
to find out what ports are opened go to www.thepublicworks.com security section and click on the following:
to find out what ports are opened go to either link- shields up and then go to pcflank to scan for open ports and trojans on your computer.
when you get results go to wilders.org and download free 30 day trial of Trojan Hunter and scan your machine.
download free firewall such as zone alarm or any fine free firewall, and make sure your ports are in stealth, then download the following:
regprot, free registry monitor, and from sysinternals download TDImon, and Procmon- free port and process monitors
if you can not scan your machine with norton download free AVG virus scanner and update virus definitions first, then scan.
next delete all peer to peer programs on your computer such as messanger, icq, kaaza audio galaaxy etc.... these programs are known virus and trojan carriers.
O.K.
all the best,
murve

My recomendation is to stop all internet activity on that computer tillyou have it straightened out. here's what you do
1. Unplug your modem, dsl, cable from their respective lines.
2. Buy one of your friends lunch and ask them to lend you their computer to download a few things.
3. Download "Zone Alarm/Zone Alarm PRO" and also "The Trojan Remover" or another good trojan removale program.
Once you have these programs, burn them on a CD and take them back to your computer. WITH YOUR COMPUTER STILL DISCONNECTED FROM THE PHONE/CABLE LINE install these 2 programs. Once Zone Alarm is installed turn your "internet" and "trusted" zones to "HIGH" setting and go ahead and connect your modem/cable DSL back on. Log on to the net and when zone alarm asks you whether or not to let certain programs get internet access click on "NO" EXCEPT ON THOSE PROGRAMS THATS YOU KNOW ARE FOR A FACT YOUR LEGIT PROGRAMS ACCESSING THE INTERNET. If you get a weird program trying to access the internet deny access. One you're on the net Update your Trojan Remover and udpate your Anti Virus Scanner. Once they are both updated run both scans on your computer (not simultaneously) What you have is a "Sub7/Back Door, Back Orifice Trojan" Those are easily fixed by most Trojan Removers these days.

Hi! murve,
Hi! Lakeshow,
Hi! georgesI tried Shield Up! tested and shown all the ports are stealth!! But result for Stealth test from Pcflank shown this following:
We have sent following packets to TCP:1 port of your machine:
TCP ping packet
TCP NULL packet
TCP FIN packet
TCP XMAS packet
UDP packetand all the statuses for particular one are non-stealthed!!!!
and then I did Trojan Test shown ports 1243 and 12345 are stealthed..and the rest are closed..and i scanned with TrojanHunter 2.54, only one file C:\WINDOWS\bwunin-6.1.0.153.exe has warned because of double extensions..actually this file is uninstall program but it's make me confusing that would be Trojan or somethin..?? yesterday..I installed sygate personal firewall 5.0 and currently running this one. and I also got AVG and that "cybertech" viruses detected by AVG so it recommended me to send them to virus vault..so I did that..but I'm still using messenger and ICQ sometimes...KaZaa was uninstalled...but one thing Im still confusing is that my pc's security is tighten up or not??? another one thing is can I make security for P2P connection like messenger or ICQ or whatever?? any ideas about keyboard's key death and mouse movin' itself???? sygate and Zone Alram which one should I choose???Anyway..Thanx for all responses...u guys are doing real great job :) thanx again..take care
regards......Fred.

hi fred,
delete the trojan C:\WINDOWS\bwunin-6.1.0.153.exe with anti-trojan trojan hunter.get rid of icq and messanger they are known virus and trojan horse carriers. install zone alarm free or sygate, whichever one is easiest for you to work with, and scan your computer again with your anti-virus and trojan hunter and delete any virus and or trojan horse that they find. don't open up any e-mail from person's you don't know and uncheck in your e-mail program in the Read tab the box that says automatically open up emails with attachments. go to www.thepublicworks.com security section and download Regprot, free registry monitor and read all you can about trojans, trojan ports,etc.
all the best,
murve

Hi..Murve,
I deleted the trojan C:\WINDOWS\bwunin-6.1.0.153.exe..and I installed both sygate and ZoneAlarm...they're working really great...but 2 firewalls ?? that would be happen something or is that would be a problem...and i scanned my system 2 times which didn't detect infected files...but I'm not so sure that one program is trying to do as a server everytime in startup...that program file full path is C:\program files\hp center\137903\program\BackWeb-137903 . this one is virus or spyware ??? I'm confusing that I would let that program through the firewall or not..anyway..I am so appreciated ur suggestions.And for Firewall which one I should Uninstalled..sorry for my poor knowledge :)..Thanx
Fred.

Hi..Murve
One thing I forgot...I downloaded and Installed Regprot already....and I did scanned with projan hunter but nothin found !! Thanx..Fred.

Murve, what's guy icq and any instant messangers are not carriers they are used as chat tools even though most hackers go to ICQ to spead there devistation. meaning the person on the receiving in should be taught about how to avoid issues. like downloading a file from someone they never knew. so what you are saying in theory is get read of email, chat software because they are carriers of infection? you have to teach people about security before anything happens. this would be the first step . not to bash on you or anything just thoughti would get everyone advice from a exhacker.

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |