Computing.Net > Forums > Security and Virus > Trojan Horse

Trojan Horse

Reply to Message Icon

Original Message
Name: Terry
Date: February 10, 2003 at 00:27:05 Pacific
Subject: Trojan Horse
OS: Win2000`
CPU/Ram: PII300
Comment:

I am running a Trojan scan from Sygate's online service and I got the following result:

Trojan 5000 OPEN Bubbel, Back Door Setup, Sockets de Troie

Can anyone help me with the following questions?
(1) Does that result mean that my computer has been hacked and my files on my computer might be stolen?
(2) What could be the reason that my computer has been affected with the above trojan horse?
(3) How to clean the above trojan horse? How to close port 5000? Any recommendation of Trojan Horse Removal program?

Thanks for your help in advance!


Report Offensive Message For Removal

Response Number 1
Name: Tom41
Date: February 10, 2003 at 01:49:21 Pacific
Subject: Trojan Horse
Reply: (edit)

1. It could mean you have a trojan..If so I doubt any of your files were stolen. If anything was stolen, most likely it would be your passwords.

2. If you have a trojan, it could have come from an e-mail attachment, IRC, file sharing etc...

3. Go here and run an online scan:
Housecall
Let me know the results..


Report Offensive Follow Up For Removal

Response Number 2
Name: Anne Marie
Date: February 10, 2003 at 13:16:18 Pacific
Subject: Trojan Horse
Reply: (edit)

Hi a free program to remove trojans is "Swat it" or free for so many days are Trojan remover (http://www.simplysup.com/tremover/details.html) and Anti-trojan. I had a trojan and they all spotted it. It doesn't seem to do any harm to have them all installed together either.


Report Offensive Follow Up For Removal

Response Number 3
Name: Jim Beau
Date: February 10, 2003 at 15:51:59 Pacific
Subject: Trojan Horse
Reply: (edit)

Terry.

You mentioned closing port 5000.
Go to www.grc.com(aka Shields Up!) and look for "Unplug and Pray".It's a small patch that is free and easy to install.It's also very easy to use.You can open or close that port with that program.
Let me guess,you have Windows XP too?
Hope this helps.JB


Report Offensive Follow Up For Removal

Response Number 4
Name: Terry
Date: February 11, 2003 at 01:12:20 Pacific
Subject: Trojan Horse
Reply: (edit)

Thank you all for your reply.

Tom41,
I have run the scan from Housecall and no trojan horse was found. I also run Trojan Removal, Anti-Trojan and TDS-3 and no trojan horse was found either, though port 5000 is open. Where can I find the password in my system, such as windows password file, yahoo or hotmail password if I choose remembering logging in info, some application password? Thanks!

Jim,
My OS is XP. Does port 5000 is open by default with backdoor program? I have not gone to grc.com yet.

Except for Trojan Horse, is there any other way that Hackers can attack my system and steal my files? Do they need to know the phone number where I dialed to the Internet or the phone number of the ISP I am dialing?

Thanks a lot for your help!



Report Offensive Follow Up For Removal

Response Number 5
Name: Tom41
Date: February 11, 2003 at 04:51:42 Pacific
Subject: Trojan Horse
Reply: (edit)

Hi Terry, Seeing that you are running XP, I doubt that you have a trojan. As Jim has indicated, It's Universal Plug and Play that is listening on that port.
You can either run the 'Unplug and Pray' utility or disable it manually.
To disable it manually, Click Start > Run > type services.msc and click OK
Scroll down and double click on Universal Plug and Play and first stop the service, then disable it.

Then run the Shields Up test at grc.com.
It should show port 5000 closed.



Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Trojan Horse

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software