Re: AdAware, SpyBot S &D, etc. + leave PC connected to Internet

From: curious (heyimjustcurious_at_yahoo.com)
Date: 01/31/04


Date: 30 Jan 2004 22:38:46 -0800

Sorry....I wrote something wrong..

 
> > > What ports are open?
> >
> > Ports 21, 25, 80, 1307 are 'OPEN' when Qucik Scan and Stealth Scan
> > were performed.
> >
> > Ports 21, 25, 80 for Trojan Scan.
>
> > Ports 21, 25, 80 for TCP scan. TCP scan seemed to have stopped at port
> > 1024.
>
> This isn't good.

Port 1307 (Source Port - the port used to communicate with the SyGate
web server) from Quick Scan & Stealth Scan is CLOSED. It's 443 (HTTPS)
that's OPEN along with

21 (FTP), 25(SMTP), and 80 (WEB).

I ran SWShredder; it was clean.
then Spybot S&D
then AdAware
Then, SpyBlaster. Success.

I just finished running trojanscans. No infection.

> Sometime while running a scan, run hiJackThis!
> (http://tomcoyote.org/hjt) and check your log results. It'll tell you
> what's running - it's more detailed than Task Manager. If you like,
> post or email the results. I don't see areason why Port 80 should be
> open. Actually, I don't see a reasonwhy any of those should show open
> because your firewall should stop it.

I wonder whether I should uninstall and reinstall SyGate (since I
didn't do "allow" or "Block" properly when installing) and perform
scanning and run hiJackthis at that time or just leave SyGate the way
it is and perform scanning and run hiJackThis!

In fact, I did run 'hiJackThis' earlier (from a site that also
provided CWShredder) but not with SyGate scanning. I didn't dare do
anything. I will read the "Intro", etc. in the link you gave and scan
from there.

Thanks for offering to email you. I will do that. I think I'll go
ahead and uninstall SyGate and reinstall once this trojanscanning is
done. It's just got done. Let me try SyGateuninstallation and
reinstallation ..

> Sometime when you have a lot of time and the above is taken care of,
> try using the online Nmap scanner at www.insecure.org. If you have a
> second PC, you can even download it. That's the best scanner
> available.

O.K.



Relevant Pages

  • Re: Security Updates BROKE Sygate
    ... We thought you'd replaced Sygate Firewall a month ago? ... Reinstall Sygate. ... understands how these latest security updates work, ...
    (microsoft.public.windowsxp.general)
  • Re: Sygate help
    ... am a new user to Sygate and really like it so far. ... > applications to let in/out what I want. ... I think it's major if someone is SCANNING my ports that I don't ... Nothing, no email/IM's/or Internet Exporer. ...
    (comp.security.firewalls)
  • Re: Sygate help
    ... The Sygate firewall? ... scanning you unless you asked them to. ... looking for an open proxy. ... Oh, and shieldsup.grc.com gets their IP from Verio, too. ...
    (comp.security.firewalls)
  • Re: Differing results?
    ... Sygate was scanning the proxy while the GRC scan was initiated using Steve's IP agent so ... or problems by running both the XP built in firewall and Sygate at the same time? ...
    (comp.security.firewalls)
  • Sygate help
    ... am a new user to Sygate and really like it so far. ... applications to let in/out what I want. ... I think it's major if someone is SCANNING my ports that I don't know. ... Nothing, no email/IM's/or Internet Exporer. ...
    (comp.security.firewalls)