Re: Sockets De Trois V1

From: optikl (optikl.spamtrap(remove)_at_comcast.net)
Date: 10/31/03


Date: Fri, 31 Oct 2003 12:23:26 GMT


"Gary Brett" <globalg2001@yahoo.co.uk> wrote in message
news:5b221b4d.0310310207.4cc9bac0@posting.google.com...
> After running GSNetScan I discovered I had a "Sockets De Trois V1"
> trojan on all my LAN XP Pro machines. I have since closed port 5000 on
> the Firewall and have disabled "SSDP Discovery Service" in WinXP
> Services. This seems to have stopped the Trojan, but do you know how
> it entered the LAN and what it actaully does when inside. Presumably I
> have not destroyed it by closing the ports, just halted its progress?
>
> Thanx for your time..
>
> Gary

Are you certain it said you actually had the trojan on your system, or just
that with port 5000 open, it's possible one reason could be Sockets de Trois
?
What does your AV software tell you? Try using Trend's on line housecall
service to scan your system.



Relevant Pages

  • Sockets De Trois V1
    ... I have since closed port 5000 on ... the Firewall and have disabled "SSDP Discovery Service" in WinXP ... This seems to have stopped the Trojan, ... it entered the LAN and what it actaully does when inside. ...
    (comp.security.firewalls)
  • Re: My Game Needs a Port Listed as Trojan Port
    ... > my games uses this port. ... The trojan has to be installed on your machine, ... > that my virus scan knows that this game is ok to use this port although it ... Antivirus shouldn't have anything to do with it: but for a firewall it will. ...
    (comp.security.firewalls)
  • Re: netstat finds something strange?
    ... I dunno about heuristics or viruses or trojans, ... should have your PC name as the name listening on each different port. ... > The free pest patrol scanner just looks for port numbers that are open ... >> What the heck kind of virus or trojan does this. ...
    (microsoft.public.win2000.security)
  • Re: What does this log file mean- Intrusion, Noise, or ISP?
    ... NAV2002 with updates and just scanned with ANTS trojan scanner (from ... but I may contact Charter and let them know about the IP of concern. ... >>NIS 2002 constantly blocks the remote IP below trying to connect to Port ... > other machines to infect. ...
    (comp.security.firewalls)
  • Re: svchost.exe
    ... Svchost.exe is tied in with RPC somehow and win2k needs it. ... If you did a netstat -an in the DOS command prompt, ... the process list and port 135 is closed and it no longer shows up on ... The trojan was listening on port ...
    (microsoft.public.windowsxp.security_admin)