Personal computing discussed

Moderators: renee, Flying Fox, Ryu Connor

 
Crayon Shin Chan
Minister of Gerbil Affairs
Topic Author
Posts: 2313
Joined: Fri Sep 06, 2002 11:14 am
Location: Malaysia
Contact:

Help! Deep Throat (no not pr0n) infection on Windows XP!!!

Fri Jun 13, 2003 4:21 am

While browsing lazily through PC-cillin 2002's features, I stumbled upon a personal firewall log which logged two instances of Deep Throat trying to send a message through.
I checked Deep Throat out, but the websites all said something about it infecting Win95, 98 and ME versions of Windows only. BTW, the files listed on the website that should be removed are not found in my system directory!
Help will be appreciated very much!!!!!
Mothership: FX-8350, 12GB DDR3, M5A99X EVO, MSI GTX 1070 Sea Hawk, Crucial MX500 500GB
Supply ship: [email protected], 12GB DDR3, M4A88TD-V EVO/USB3
Corsair: Thinkpad X230
 
etilena
Gerbil Jedi
Posts: 1674
Joined: Wed Jun 12, 2002 7:43 am
Location: .ozziefied.

Fri Jun 13, 2003 12:25 pm

Well, it did say 'try' to send messages through. If you haven't been visiting dodgy sites or downloading and executing viruses of late, there shouldn't be a problem.

Probably someone was probing your ports and tried to hack into it.
*yawn*
 
phelt
Gerbil
Posts: 22
Joined: Tue Mar 26, 2002 7:00 pm

Fri Jun 13, 2003 4:07 pm

It's important to know whether the communication attempts were inbound (someone on the net trying to send packets to your machine) or outbound (something on your machine trying to "dial home"). If they're inbound, it sounds like your firewall is blocking and logging them, so no big deal. Lots of idjits use vulnerability scanners to try and find exploitable boxes. As long as your firewall is handling it, don't sweat it.

But if they're outbound packets, something on your machine is possibly trojaned. I say "possibly" because sometimes regular communications happen to occur on ports that are known to be used by trojans. This seems less likely since one would expect that a firewall/antivirus package that recognizes the trojan ports should alert you to an app that is a trojan or has been compromised. It also seems likely that there would be more than 2 logged instances - it's unlikely that a trojan would simply give up after a couple of attempts.
 
just brew it!
Administrator
Posts: 54500
Joined: Tue Aug 20, 2002 10:51 pm
Location: Somewhere, having a beer

Fri Jun 13, 2003 5:05 pm

Yes, see if the log entry indicates what direction the attempted communication was going -- inbound or outbound. As a guess, it is probably just someone else with an infected machine, that is randomly probing blocks of IP addresses for additional vulnerable PCs to infect.
 
Crayon Shin Chan
Minister of Gerbil Affairs
Topic Author
Posts: 2313
Joined: Fri Sep 06, 2002 11:14 am
Location: Malaysia
Contact:

Sat Jun 14, 2003 3:35 am

It said out, that means it's an outbound packet. I'm scared. Would Kazaa have anything to do with this? (it's always trying to send out from port 1214, and Kazaa uses 1214).
Mothership: FX-8350, 12GB DDR3, M5A99X EVO, MSI GTX 1070 Sea Hawk, Crucial MX500 500GB
Supply ship: [email protected], 12GB DDR3, M4A88TD-V EVO/USB3
Corsair: Thinkpad X230
 
Forge
Lord High Gerbil
Posts: 8253
Joined: Wed Dec 26, 2001 7:00 pm
Location: Gone

Sat Jun 14, 2003 4:18 am

It's most likely a coincidence. Kazaa sent out some packets that looked 'Deep Throat-like'. If you're really worried, fire kills all virii. Apply it directly to the hard disk's platters for greatest effect.
 
Crayon Shin Chan
Minister of Gerbil Affairs
Topic Author
Posts: 2313
Joined: Fri Sep 06, 2002 11:14 am
Location: Malaysia
Contact:

Sat Jun 14, 2003 5:35 am

brings out flamethrower...
:D
Mothership: FX-8350, 12GB DDR3, M5A99X EVO, MSI GTX 1070 Sea Hawk, Crucial MX500 500GB
Supply ship: [email protected], 12GB DDR3, M4A88TD-V EVO/USB3
Corsair: Thinkpad X230

Who is online

Users browsing this forum: No registered users and 1 guest
GZIP: On