Problems with security and direct cable connection

From: Snuffles (nospam@noplace.com)
Date: 02/19/03


From: Snuffles <nospam@noplace.com>
Date: Wed, 19 Feb 2003 10:32:56 -0500


First, I will apologize in advance for being a newbie in this area,
but I would really appreciate any help or suggestions on some issues
that I'm having.

About 2 months ago, I downloaded KaZaA Gold and used it for a couple
of weeks. Then I decided to remove it. I did this with what
appeared to be no problem. But it's been well over a month since I
removed the programs, and I am getting hundreds of hits on port 1214
that are being blocked by my firewall. Many hits are coming from a
few individuals, and so it didn't seem to me as if they were trying
to hack me. Is there somewhere in all the stuff concerning KaZaA
that tracks your IP address in some manner and then retains it so
that others unkowningly keep attempting to access my system again?

Secondly, I have always kept my Symantec Anti-virus up to date, but
until recently, did not realize that I needed something else to pick
up the trojans, adware and possible spyware on my system. For
trojans, I ran the trail version of TDS-3, which I don't believe,
has a current list of trojans that can be added to the trial
version. But it did find 4 instances of SubSeven 2.2b and 1
instance of Mosucker Dropper 1.1. I removed them all and figured
I'd gotten my problems resolved. I also ran a The Cleaner, by
Moosoft and it found nothing.

I've cleaned up my adware by running both the current version of
Ad-aware and Spybot Search & Destroy.

But a couple of times before I removed the trojans and now, twice
since I've removed them, I have an unusual situation. I have a
packet sniffer program that checks all traffic on port 25 that is
not from my ISP's mail server. What I found was that there seems to
be something that accesses port 25 through my connection and
attempts to access and send some type of mail to an ISP in China.
The email it attempts to send is not going to the same address each
time. And the IP it uses varies usually by the last digit of the
address each time. The packets so far indicate that these user id's
no longer exist on China's ISP.

Does anyone know what could be causing this? This attempt to send
info to the China ISP only happens within a second or two and so I
don't think there is anything that will show a program running at
the time it's happening, that would still show as running once I

I'm using Window's XP.

Any help would be greatly appreciated.

Snuffles



Relevant Pages

  • Problems with security on cable connection
    ... and I am getting hundreds of hits on port 1214 ... up the trojans, adware and possible spyware on my system. ... attempts to access and send some type of mail to an ISP in China. ... info to the China ISP only happens within a second or two and so I ...
    (alt.computer.security)
  • Re: How do I disable a port>
    ... > Port 1033 open. ... Possible trojans. ... malicious hackers install. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Firewalls VS MS TCP/IP filtering
    ... The thing about the HW firewall, to me anyway, is that while it limits ... trojans that actually come in thru the ... Port 25 OPENED. ... a product tailored to protect Internet ...
    (comp.security.firewalls)
  • Re: Best Practices Denying Outbound Traffic
    ... Most of the newer trojans these days ... And if it is a commonly used port such as http the same ... network exponentially more secure by restricting outbound access. ... I would probably be thinking about getting a new firewall management company ...
    (comp.security.firewalls)
  • Re: What does this log file mean- Intrusion, Noise, or ISP?
    ... ANTS and NAV find no trojans. ... alert was always from the same IP and it was from the same ISP as mine. ... >> NIS 2002 constantly blocks the remote IP below trying to connect to Port ... Trend Micro's OfficeScan products may ...
    (comp.security.firewalls)

Quantcast