Discussion in 'Trojan Defence Suite' started by tutankamon, Oct 20, 2003.
port 1030 shows as being BBN AID ( RAT Clandestine
should I be worried about this?
Depends on where/when you see it used and by whom for which function.
Tried to see with PE?
What was the application that held onto that port? Does it hold onto the same port when you launch it after a reboot? If yes, this is definitely something that you should be worried about but my guess is that the port will be different after a reboot. (If the port is different then it is probably just a normal use of ephemeral ports.)
Port Explorer, as Jooske suggested, is the surest way to gauge whether this is something that needs to be further scrutinized.
Thanks for the replies, I was using TDS3 netstat tool,
I have not seen it again on the last 3 occasions that I have started up.
Separate names with a comma.