//flex table opened by JP

Click to See Complete Forum and Search --> : Hack attempts


Hola hoop
07-15-2004, 02:22 PM
Hello all, wondering if anyone can help with this.
I recently dl a port scanner from http://www.atelierweb.com/pscan/

After analyzing over 5800 ports there were at least 300 with entries like

Backdoor_az
Backdoor_nightmare
Worm....
Worm...

midnight caller..
ihatewin...

I didnt bring with me the full extensions but i know what ones were virus's ect. I have done scans with all of the spyware, shredders, trojan removers, Av, adaware ect ect. Didnt find any,
The software i dl gave u option to make inactive or kill the process. I did about 50 but too many to sit there for hours.

My question is that the backdoor_az type things, are these active trogans or hack attemtps??
Also i know that some of the worms it found, including blaster-b are not active anymore but yet they are running an active process. Firewall wont block these port users and i am not sure the best way of handling them. If the virus or worm is inactive then it should not need a port for communication?
Nothing is actually wrong with the comp, and im very aware of "if it aint broke then dont fix it" but 300????
If non of the software finds ANY of these 300 entries then what can i do?

Hearie
07-15-2004, 02:56 PM
I think that it is just telling you that you may be vunerable to those types of trojans/exploits. I could download the program and check it out, but first why don't you see if you can tell if it is just warning you or if it's actually an active trojan. Understand?

Hola hoop
07-15-2004, 04:02 PM
All the program will do is show you all active ports and what application is using them. There is a box that you can check/uncheck to stop the process. This is what makes me think it is active otherwise why would it give you the option of switching it off?
At the same time, some on the virus variants it shows are using a port are viruses that had a expiration date of feb 2004 for example so you know that virus is no longer a threat yet it still shows up as bing on your system as a port user!
Im just at a bit of a loss. 3 different virus scans done, Norton 2003 fully updated, Avast antivirus fully updated and AVG fully updated...they found nothing.
To add i ahve had fully upto date virus definations from day 1 so comp wasnt infected before virus got there, and isnt norton supposed to pick up polymorphic virus to?

Hearie
07-15-2004, 05:04 PM
If yer OS is XP/2k, download/install/update/scan with Ewido. Its a trojan scanner. Find it at www.ewido.net it's free

Hola hoop
07-16-2004, 09:19 AM
OP sys is XP home edition.
DL the ewido program, ran it and it didnt find anything. Has anyoone else tried the program i linked before from altierweb?

If so what were your results?

Hearie
07-17-2004, 01:02 AM
I d/l'd the program and installed it, but don't see where to "scan" the machine. Do you click "Local" and then "Ports"?