View Full Version : wsftp_pro getting hammered by trojans
jazzylee77
March 11th, 2005, 12:37 PM
I've been doing long uploads the past couple days. (35,000 html pages)
wsftp_pro slows way down and I start getting NAV messages about blocked incoming trojan attempts one after another.
Names of trojans too numerous to mention...
At first they were most transcout trojans and now I see everything.
Would this just be a symptom of running my ftp program over a long period?
It's gettting to be a nuisance as I think it is causing occaisional errors interrupting the uploads.
I wonder if the slowdown is done my my host...it starts fast and gradually slows down to a trickle.
I've run avast virus cleaner and norton, checked for transcout related files. Nothing.
How can I be sure a trojan isn't getting through?
Just make me nervous with all the attacks. Usually around 6 of them one after another every few minutes. Others more randomly.
Also I had intended to switch my new computer over to Avast soon when the NAV trial expires...but since Norton seems to be blocking trojans...(or maybe it isn't !) I'm hesitant to remove it.
looking forward to all clues to ftp security ...please spare me the ftp is a terrible protocol lecture...I want to know what I can do about it. :)
jazzylee77
March 11th, 2005, 12:41 PM
one other thing...and this makes me very suspicious...
sometimes Zone Alarm alerts that wsftp_pro is requesting to run as a server. I deny and it continues to function normally. Could just be an update function, but sounds trojan-like to me.
Firecat
March 11th, 2005, 12:41 PM
If your using NAV for Trojan detection its possible that some of them have successfully entered your PC. NAV is really not that good in Trojan detection.
jazzylee77
March 11th, 2005, 12:49 PM
I'd be interested in hearing about good additional trojan protection...I was going to switch to Avast, somethihng I'm familiar with...is it any better in this department or should I run a specific trojan tool? recommendations appreciated.
Firecat
March 11th, 2005, 12:54 PM
Y'see the main problem with Norton is that it will DETECT most of the Trojans, but all that is through a generic signature. Moreover, those types of signatures in Symantec database do not remove the assosciated startup keys, registry entries, browser helper objects etc.
PLEASE NOTE THAT THE ABOVE INFORMATION MAY ONLY FULLY APPLY TO NAV 2004 AND UP!
I recommend you back up NAV with an Anti-Trojan such as A-Squared or Ewido Free and an On-Demand AV like BitDefender Free 7.2
For best overall malware protection KAV seems to be the best, and ArcaVir is coming out on second for me...
Firecat
jazzylee77
March 11th, 2005, 12:56 PM
ok...I'm catching up on threads in the "other anti trojan" forum. I'll settle on one of those mentioned often there and give it a spin. Looks like I should have posted in that area...oops
jazzylee77
March 11th, 2005, 04:05 PM
I've added BoClean and bit defender, so far
Firecat
March 11th, 2005, 04:09 PM
That should be good enough...You can also add A-Squared Free and Ewido Free (Ewido's among the best ATs I think).
snapdragin
March 11th, 2005, 04:32 PM
-{ Quote: "ok...I'm catching up on threads in the "other anti trojan" forum. I'll settle on one of those mentioned often there and give it a spin. Looks like I should have posted in that area...oops" }-Hi jazzylee77,
I've moved your thread over into the "Other Anti-trojan Software" forum as it is a more suitable forum for your topic. ;)
Regards,
snap
Blackcat
March 11th, 2005, 04:42 PM
-{ Quote: " NAV is really not that good in Trojan detection." }-
Not too bad with these recent results; http://www.av-comparatives.org/ ;)
Not as good as KAV, but Norton's on-demand scanner even beat well-known trojan slayers, Dr Web and McAfee in trojan/backdoor detection in the above test.
Overall, layered defense is recommended; an AV and AT combined; http://www.techsupportalert.com/free-vs-paid-av.htm
bellgamin
March 12th, 2005, 02:29 PM
BOClean is superb AT protection. Good move!
I wonder if WSFTP has been directly attacked -- infected or corrupted? Have you considered uninstalling it, then using a registry cleaner to ensure ALL of it is gone, then re-installing it? Pain in the nether regions, but might be worth it.
jazzylee77
March 13th, 2005, 02:40 AM
Registry cleaner? That does sound like a pain, I'll think about it tommorrow! I've used registry mechanic on another system...willl that do the trick? I was even thinking of removing ftp pro and getting a different ftp program altogether since I'm only guessing whether it is clean or not.
A trojan was found...ByteVerify. Java class junk. It doesn't sound like it would be related to the ftp program. I've seen no alerts since running all the extra stuff. I have ewido on now too. Bit defender picked up a couple threats that the others had missed. I feel a little more secure now...if I only knew why! :)
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums