republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » A super trojan?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
May never go back to IE for regular use »
« HJT Log..... Downloader.Trojan  
AuthorAll Replies


zmaugy

join:2003-05-24
Slovenia


1 edit
reply to kpatz
Re: A super trojan?

Zone alarm. And my IE is not hijacked and the system is always patched, AV (NAV2004) is always updated, from time to time the system is checked with KAV 4.5 on demand, system is Spybot1.3 immunized and checked, running from behind a router with stateful packet inspection, also ZaPRO is installed and running - every application has to ask to connect (except IE6, OE6, NAV2004, ZaPRO). The only pages I'm surfing with the machine is my ISP's webmail, no other than business software is running.
How the hell could I be infected? And my ISP checks email for viruses...
--
French fries.

kpatz
MY HEAD A SPLODE
Premium
join:2003-06-13
Manchester, NH

Did Zone Alarm say what application was hitting that IP?

As mentioned here: »www.geocities.com/technofundo/te···fip.html

quote:
Class D - This is a class meant for multicasting only, for sending multicast messages to other groups of host machines.

First Octet - - The first octet is between 224 to 239. (Starts with binary bits - 1110).

The class D is a special purpose reserved class, and addresses in this range are not assigned as IP addresses on an IP network, including Internet.
In other words, 239.255.255.250 isn't even a routable address on the Internet.
--
Robert Tappan Morris, Jr., got six months in jail for crashing 10% of the computers that Bill Gates made $100 million crashing last weekend.


zmaugy

join:2003-05-24
Slovenia

said by kpatz See Profile:
Did Zone Alarm say what application was hitting that IP?

Generic host process for win32 services. And it's logged only when automatic lock on ZA is turned on.
--
French fries.

kpatz
MY HEAD A SPLODE
Premium
join:2003-06-13
Manchester, NH

said by zmaugy See Profile:
Generic host process for win32 services. And it's logged only when automatic lock on ZA is turned on.
Bingo... when ZA is locked, it blocks all traffic. Windows uses TCP/IP internally for certain interprocess communication (this traffic never goes out over the network), but Zone Alarm sees it, and blocks it when it's locked. Windows is likely using the 239. IP range for this purpose.

I've seen instances, where when I was having network issues, and didn't have a valid IP, that certain Windows services would cause Zone Alarm prompts (the Spooler Subsystem is prone to doing this). I'm at work now so I can't see what IP it was trying to use though, but I wouldn't be surprised if it was a 239.* IP.
--
Robert Tappan Morris, Jr., got six months in jail for crashing 10% of the computers that Bill Gates made $100 million crashing last weekend.


zmaugy

join:2003-05-24
Slovenia
Thanks, I know my question was off topic:), anyway I'm going to go step by step through the procedure just in case.
--
French fries.
Forums » Up and Running » Security » SecurityMay never go back to IE for regular use »
« HJT Log..... Downloader.Trojan  


Tuesday, 08-Dec 20:08:51 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [193] Sprint Sued For Distracted Driving Death
· [81] 3G Network Test Says AT&T Is Tops
· [71] Mediacom Unveils 105 Mbps Pricing
· [57] Sprint Poised For A Turnaround?
· [49] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [44] Microwaving Your Innards Is Not 'Extreme'
· [43] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [39] Verizon LTE: 5-12 Mbps Downstream
· [18] Verizon Settles With NJ Over Misleading FiOS Marketing
Most people now reading
· Servers UP!!! [World of Warcraft]
· Comcast Customers: Would You Prefer Metered Billing? [Comcast HSI]
· Windows 7 boot manager editing questions [Microsoft Help]
· CRTC Response to ME: You will be Band F FOREVER!!! [TekSavvy]
· Account Hacked With Authenticator [World of Warcraft]
· World of Warcraft Client Patch 3.3 (12-8-2009) [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· World of Warcraft Client Patch 3.3.0 (12-08-2009) [World of Warcraft]
· Top 10 things to do while servers are down! [World of Warcraft]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]