Go Back   PCMech Forums > Help & Discussion > Internet, Web Applications, & The Cloud

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rating: Thread Rating: 3 votes, 5.00 average. Display Modes
Old 07-19-2000, 01:11 PM   #1
Member (6 bit)
 
Join Date: Aug 1999
Posts: 50
Post

I recently found a Netbus Trojan Program attached to a download I was doing. This would not normally be of a lot of interest, except it got in. This program, once in, broadcasts your IP address. That is how I found it, Norton Internet Security kept screaming that Netbus was broadcasting from my puter. How did it get by the AV program, Nortons, and how did I figure the infecting program?
Well, NAV must be loosing it, cus they don't detect what the Internet Security program can.
As to how I found the infecting program, this is important for those who download lots, it came in just after the part that it was attached to finished downloading, in a self-extracting file that looked like a zip, was only on the screen 1 second. Both the downloaded part and the drives scan clean, yet it did get in on that part, the way discribed.
I'm getting more AV protection, at least, and I have had to get a Trojan Cleaner just to get rid of it.
Watch your alerts on your Internet Security programs, if your getting Netbus, or anything else very regular, your probably infected and broadcasting, especially if the IP address indicated is yours!
Misdiagnosed is offline   Reply With Quote
Old 07-19-2000, 02:08 PM   #2
Member (13 bit)
 
Xayd's Avatar
 
Join Date: Jun 2000
Location: nowhere.com
Posts: 4,819
Send a message via AIM to Xayd
Post

Yeah, I had to go back to Zone Alarm from BlackIce due to a similar issue.

I like the automatic back trace of IP's that BlackIce has, but a virus such as the one you had would have to be damned sneaky to get something past Zone Alarm with all outgoing traffic restricted.

I've got a little hidden proggy that came with a chat client, for instance, that's been trying to send out my system info for two months now. ZA squishes the outgoing packet every time . I figured I could delete the executable, but what's the fun in that. Kinda like a pooch on a leash when it tries to run past ZA, I'm just gonna keep the proggy and call him Spot.

Xayd

[This message has been edited by Xayd (edited 07-19-2000).]
Xayd is offline   Reply With Quote
Old 07-19-2000, 02:17 PM   #3
Member (6 bit)
 
Join Date: Aug 1999
Posts: 50
Post

I never liked BlackIce cus it looked too much like a proggie written with VB 3.0.
I think it is way too over-rated. It misses scans and broadcasts that Norton Internet Security gets every time.

------------------
Your just jealous because the voices talk to ME.
Misdiagnosed is offline   Reply With Quote
Old 07-19-2000, 02:40 PM   #4
Member (13 bit)
 
Xayd's Avatar
 
Join Date: Jun 2000
Location: nowhere.com
Posts: 4,819
Send a message via AIM to Xayd
Post

I'm just inherently mistrusting of Norton products I guess, since that virus we got back at that ISP I worked for that caused Norton 2000 to quarantine Rundll32 for us. Was days of work putting about 5 or 6 NT workstations back together and getting them configured again.

Xayd
Xayd is offline   Reply With Quote
Old 07-19-2000, 03:06 PM   #5
Member (6 bit)
 
Join Date: Aug 1999
Posts: 50
Post

The Norton Internet security kernal was aquired from another company that went out of buisness. Someone else may remember the particulars. That is why it is so much better than Nortons other products.
Norton Utilities is junk, NAV misses infectants and and will no doubt give you the option of quarenteening a system file, which is the fastest way to a crash I know of. NAV, and all other AV programs, if they can't clean a system file, they should advise you that it is a system file that is infected, and give you proper method for fix.
I only use NAV for it's convienient updates. That may be a mistake.

------------------
Your just jealous because the voices talk to ME.
Misdiagnosed is offline   Reply With Quote
Old 07-19-2000, 11:53 PM   #6
Member (13 bit)
 
Xayd's Avatar
 
Join Date: Jun 2000
Location: nowhere.com
Posts: 4,819
Send a message via AIM to Xayd
Post

Yeah, you're probably right ya know.

Software with alot of functionality is great, I like software with lots of bells and whistles.

On the other hand, software with lots of bells and whistles in the hands of a user who barely knows how to double click is a Tech Support Nightmare.

NAV 2000 was just that. Not only did it give us fits (grumbles sales reps...) but caused quite a bit of a ruckuss with customers as well, since they call their ISP for anything they don't want to pay Microsoft for...

The old acronym does hold true in most cases, though....

Problem
Exists
Between
Keyboard
And
Chair

Xayd
Xayd is offline   Reply With Quote
Old 07-20-2000, 09:47 AM   #7
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,771
Post

The best Trojan scanner and cleaner I have found is The Cleaner from http://www.moosoft.com

*NO* antivirus program is really very effective at sniffing out trojans because they were not designed for that particular job.
glc is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 03:53 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2