Trojan Infection WinXP

Discussion in 'malware problems & news' started by JV, Jan 9, 2003.

Thread Status:
Not open for further replies.
  1. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,491
    Location:
    Netherlands
    Hi JV,

    If it is spyware, Spybot S&D will tackle it. Read through the help file how to make the program ignore certain elements (You can find Aureate in the Excludes > Spybots.sbi tab) and make sure that the backup options under Settings > Settings > Main settings are checked.
    That should help in case anything you need gets deleted.

    Regards,

    Pieter
     
  2. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Pest Patrol is a security program, a scanner for many viruses and trojans, worms, spyware, so there was not any reason to delete or unisntall that one.
    It has the ability to even look into texts possibly containing suspicious text inside (nice for parents, partners or administrators to check what is on a computer they have supervision on)
     
  3. JV

    JV Registered Member

    Joined:
    Jan 9, 2003
    Posts:
    9
    Location:
    Annapolis, MD USA
    Thank you all for helping me. I am now Virus and Trojan free. (fingers crossed) There was only one Trojan, a low risk called Morpheus1.9.

    I have reloaded and run Pest Patrol and deleted all Spyware and Cookies, etc. they are all gone. I think that is how Gator disappeared two days ago. I deleted it and did not realize it. I installed SpywareBlaster and set it to block all but Aureate until I can get my mailing lists copied.

    I have run scans from Symantec and Sygate. Symantec says I am in Stealth mode on all Ports. Sygate says Port 53 is closed but can be accessed, this is with the Norton firewall.

    Who do I believe and how do I find out for sure?

    Also, when I went to Symantec to run the test, the site would not load. BUT, when I used the scan mode from my Norton Firewall to test, the scan went thru with no trouble. Why? I went in and configured the ActiveX and script by Norton's directions so that did not stop it.

    I have tried these tests with each firewall, one at a time. If the setting's are OK for Norton to do a scan from the Symantec site then why won't Zonealarm and Sygate load and run the scans from the Symantec site?

    AND, I can get none of the scans to run from the Sygate site with any of the firewalls except ZoneAlarm and that to says Port 53 is closed but can be accessed. I know this sounds confusing...sorry. Seems that Sygate does not like my Port 53. :D

    I followed the thread for Blaze and the Start-up and with the URL Pierre sent me I am going to cut out a lot of unnecessary programs from my start-up menu. I may need some more help with that. But let's get my Ports closed first. :D
     
  4. JV

    JV Registered Member

    Joined:
    Jan 9, 2003
    Posts:
    9
    Location:
    Annapolis, MD USA
    I forgot to ask if I should go ahead and get the Port
    Explorer or wait until we get these things fixed first.
    Thanks
     
  5. LowWaterMark

    LowWaterMark Administrator

    Joined:
    Aug 10, 2002
    Posts:
    18,278
    Location:
    New England
    Hi JV,

    "Who do you believe?" Well, go with the majority. If you do a couple different virus or trojan scans, and they say clean, you are probably clean. If most online scans say you are mostly stealth, and if not stealth, all is closed, then you are fine. Only if they say you are open would you be unsecure.

    I just realized from your last couple posts that you have multiple firewalls installed on your system at the same time. (I had incorrectly thought from yesterday's posts that you had moved from one firewall to another over time, but now I see you actually have multiple installed.)

    Your StartupList seems to show both ZA and NIS running at the same time, is that ture? But in any case, even having more than one packet filtering software firewall installed on a single system at the same time can cause all kinds of problems. (No, not the open ports, but the problems you are having with differing scan results and the inability to scan with a certain firewall / scan site combo.)

    If you read at many firewall sites or in their manuals, many will tell you to deinstall any other firewalls before installing theirs. You may want to think about settling on one, deinstalling all, doing a full registry cleanup of all firewall references and than a clean install of only the one you have chosen. It might be better that way, than the possible conflicts that could be occurring between them all, including conflicts that you are not even aware of, but could be happening in the background.

    By the way, with the cleanup you've done so far, after a clean reboot, what ports are listening in a "netstat -an" now? Is it less than before?

    Regards,
    LowWaterMark
     
  6. JV

    JV Registered Member

    Joined:
    Jan 9, 2003
    Posts:
    9
    Location:
    Annapolis, MD USA
    I do have three firewalls installed but I only run one at a time. All the port checks I have run today, regardless of which firewall I had in operation have come back Stealth. In addition, I found one Trojan on my computer. Morpheus 1.9 and deleted it with Pest Patrol. Not a big infestation I would say. LOL

    I think I am going to delete Anti-Trojan. I just ran it and it said I had a Trojan, Netspy on Port 1033. I have Port Explorer running and it says Port 1033 is aol.exe/listening. It is listed in the list I just sent you on IM. If I am missing something please let me know.

    I am now working on my Startup list. I only have Norton on the Startup list now so the other two firewalls are not in operation. I have chosen Norton for one reason only. On my last computer I tried to uninstall Norton Security and it was a nightmare. Plus the fact that it takes forever to get a tech to answer you and when they do, they have forgotten you question completely. I do not want to go thru that again and Norton seems to be working fine so I will leave it.

    I really appreciate all the help everyone has given me. I have really learned a lot and I am still learning. The best part beside meeting some really smart people here is I did not have to reload XP. For that, I am really grateful.
    :D
     
  7. LowWaterMark

    LowWaterMark Administrator

    Joined:
    Aug 10, 2002
    Posts:
    18,278
    Location:
    New England
    Hey JV, :)

    Well, your listening ports look fine, all the usual things you'd expect on an Windows XP system considering the software you are running. As for the warning from Anti-Trojan saying "...Trojan, Netspy on Port 1033", that is just what many such scanning products do. If you have some program listening on a port that is sometimes used by a known Trojan, they give you a warning like that just so you'll check it out and be sure you know what it is.

    In this case, as you said, it was just AOL and not a problem. These types of warnings can be a pain, but, if you got a warning at some point, looked with Port Explorer, and found a real Trojan, then the warning would have been helpful.

    As for the startuplist, it'd be good to reduce out any things you don't really need to start. It will certainly speed your system up some and it'll make reviewing your system less complex.

    Regards,
    LowWaterMark
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.