Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > HijackThis Log Help
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

HijackThis Log Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help.

Closed Thread
 
Thread Tools
Old 07-01-2004, 11:43 PM   #1 (permalink)
Registered User
 
Sutto's Avatar
 
Join Date: Jul 2004
Posts: 15
OS: XP Pro


Bla Trojan Horse

Ok i think i may have this trojan.. Twice i turn on my pc and get this message from norton antivirus

Details: Rule "Default Block Bla Trojan horse" blocked (64.4.12.201,1042)
Inbound UDP packet
Local address,service is (NONE(10.0.0.8),1042)
Remote address,service is (64.4.12.201,7001)
Process name is "N/A"

2 days in a row and havn't had it today (got it yesterday and day before.) I have ran Adaware Pro, Norton Antivirus, Pestcontrol, Trojan Hunter 3.8 (without update)... And all found nothing.. I think it may have got in and made itself invisible, or does that norton thing mean it tried to get on my pc but never made it on?


Also a CCproxy.exe is taking up alot of my cpu space (hasn't normally)


Help appreciated..
Sutto is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 07-02-2004, 02:14 AM   #2 (permalink)
Troubled
 
Lobos's Avatar
 
Join Date: Apr 2004
Location: California
Posts: 943
OS: Windows XP


I believe it was telling you it blocked it

Default Block Bla Trojan horse" blocked (64.4.12.201,1042)
Inbound UDP packet


Do you use nortons firewall that looks like a firewall

im not familar with antivirus telling you it blocked something


Lobos
Lobos is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 07-02-2004, 02:30 AM   #3 (permalink)
Registered User
 
Sutto's Avatar
 
Join Date: Jul 2004
Posts: 15
OS: XP Pro


thats what i thought... Yes its a firewall

Ive talked to a variety of people on msn who know computers quite well and some have told me that the trojan is on my pc trying to connect but got blocked, some are telling me it tried to get on but norton canned it before it made it on... Also is that IP address it came with, is that the person who sent it to me or a hacker or what..
Sutto is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 07-02-2004, 08:16 AM   #4 (permalink)
Old Timer
 
jgvernonco's Avatar
 
Join Date: Sep 2003
Location: Northern Arizona
Posts: 7,957
OS: Vista Home Premium, SP 27


You will note that it identifies the UDP packet as inbound, which means that it is being blocked on the way in, not out.

The addy is not registered, which means it is part of a network set up by the bad guys.

After they get done sweeping your little patch of the web, things will settle back down.
jgvernonco is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 07-02-2004, 11:31 PM   #5 (permalink)
Registered User
 
Sutto's Avatar
 
Join Date: Jul 2004
Posts: 15
OS: XP Pro


Well i have 2 firewalls installed on my pc (norton, and sygate) and sygate logs, show that "Somebody is scanning your computer" and it has that log about 20 times... and then after each one an address that was blocked!!! My is my computer being screwed with! :no:
Sutto is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 07-03-2004, 07:48 AM   #6 (permalink)
Old Timer
 
jgvernonco's Avatar
 
Join Date: Sep 2003
Location: Northern Arizona
Posts: 7,957
OS: Vista Home Premium, SP 27


"Barbarians at the Gate".

I have been through a couple of periods like this, myself. As a matter of fact, I finally set my firewall to NOT notify me about these things, as it was getting monotonous.

I am going to close this thread. If you have any further problems, please feel free to start another one.

Drop by anytime!
jgvernonco is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 05:58 AM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81