PDA

View Full Version : Detecting Trojan Horse



Ryall
October 1st, 2002, 05:47 PM
Hey everyone... a bit ago Trojan Horses came up and someone mentioned a good download to scan for them... I was wondering what it is - I think on of my computers may be under attack!!:(

I hope I can find out... IP, IP, IP :evil:

Peace

lostinbeta
October 1st, 2002, 05:52 PM
Yeah, it was a program called "The Cleaner" from www.moosoft.com

It is great. It found 2 trojans on my comp. Definitey think you should download it. It is a 30 day free trial.

Ryall
October 1st, 2002, 05:54 PM
thanks Lost... I'll check it out!

Peace

lostinbeta
October 1st, 2002, 05:58 PM
Oh yeah, and to add to those stats, it found 20 trojans on my friends computer and 34 on his girlfriends.

This program rocks. Not only can it find them, but it can clean them!

flex
October 1st, 2002, 06:10 PM
http://www.kirupaforum.com/showthread.php?s=&threadid=6454

Make sure you do the moolive update often - to get the latest build and trojan defs. Also, XP has some probs with the TCActive - which monitors in real time current processes on your PC, but the other one, TCMonitor - is very useful, it watches the registries for trojans putting themselves in keys used to run an app on load (run, runOnce, runService, etc.) and also your system files. It can also disable dodgy scripts and repair the reg if it gets a bit confused.

Scanning with the "scan inside compressed files" takes longer but is worthit - also beware of norton and cleaner clashes.

You can get apps on the net (if you haven't got decent firewall) that watch what's trying to get out from your pc. You'd be VERY surprised at what tries to connect TO it (mainly microsof(ten doesn't work)) and what tries to get out - like the lexmark software.

flex
October 1st, 2002, 06:15 PM
Also go to www.samspade.org and use the online utilities or better still download samspade the app. It's excellent - trace ip's to their domains, "dig" servers, finger, whois, check an email address if it's valid, etc.

BlackIce is good - except doesn't block ICMP. They suggest you block it at the router level - but it's wicked - if the othe guy has file and print, or BlackIce can get you the NetBIOS info - you get the everything, from the pc name, workgroup, ip address and right down to the MAC address!

You can do this manually using nbtstat - but you can't do it to every ip address you get - too tedious.

bcogswell11
October 1st, 2002, 07:03 PM
OMG, 3% done and already ten trojans found! It looks like I'm in trouble! I just delete them all correct?

-brad-:cowboy:

flex
October 1st, 2002, 07:06 PM
Yes - delete them all! http://www.kirupa.com/forums/smileys_files/ar15firing.gif

flex
October 1st, 2002, 07:31 PM
Also try www.bitdefender.com

eilsoe
October 1st, 2002, 07:35 PM
I'm gonna try this one too, just in case...

I found an I-worm/Nimda vira not too long ago muttering around my documents...

hate that...

eilsoe
October 1st, 2002, 08:17 PM
Oh boy.. 24 trojans... good thing i DL'ed this prog.

flex
October 1st, 2002, 08:32 PM
Phil - What's the name of the trojan? Did it pick it up? If all else fails then I'm afraid - it's wipe clean time.

minimalistik
December 16th, 2003, 08:52 PM
why dont you just get norton internet security?

hahaha ppl from places in euro have tried to hack me with all sorts of viruses... and have failed , dont noe why they bother lolz

rysolag
December 17th, 2003, 03:05 AM
are there viruses that slow network speed?