Strange behavior ... New trojan?

Strange behavior ... New trojan?

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Strange behavior ... New trojan? Bobby 05-06-2004
Posted by Bobby on May 6, 2004, 7:57 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I was observing strange behavior in my computer recently.
I am running Windows Me with Outpost firewall. On the Open Ports
page of Outpost firewall I see that Internet Explorer sequentially
tries to open ports. For example

IExplorer.exe 1017
IExplorer.exe 1018
IExplorer.exe 1019

A few seconds later I see

IExplorer.exe 1020
IExplorer.exe 1021
IExplorer.exe 1022

Then

IExplorer.exe 1023
IExplorer.exe 1024
IExplorer.exe 1025

And so on. The Outpost is in Block Most mode. In addition to that I defined
rules that block all well known ports like 135-139, 389, 445, 593, 636,
3368-3369, 1025, 1720, 1503 and 443 (both TCP and UDP, both inbound and
outbound).

Besides that I used DCOMBobulator utility from grc.com web site to shut
down DCOM.

Does anyone encounter similar behavior?

Any ideas why is it happening?

Might it be new trojan?

May be the IExplorer.exe was infected/modified by some virus/trojan?

I did check my computer regularly and neither Spybot, nor Adaware, nor Norton
Antivirus find any viruses/trojans.

Thanks in advance


Posted by Steve Horsley on May 6, 2004, 9:29 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Bobby wrote:
> I was observing strange behavior in my computer recently.
> I am running Windows Me with Outpost firewall. On the Open Ports
> page of Outpost firewall I see that Internet Explorer sequentially
> tries to open ports. For example
>
> IExplorer.exe 1017
> IExplorer.exe 1018
> IExplorer.exe 1019
>
> A few seconds later I see
>
> IExplorer.exe 1020
> IExplorer.exe 1021
> IExplorer.exe 1022
>
> Then
>
> IExplorer.exe 1023
> IExplorer.exe 1024
> IExplorer.exe 1025
>
> And so on. The Outpost is in Block Most mode. In addition to that I defined
> rules that block all well known ports like 135-139, 389, 445, 593, 636,
> 3368-3369, 1025, 1720, 1503 and 443 (both TCP and UDP, both inbound and
outbound).
>
> Besides that I used DCOMBobulator utility from grc.com web site to shut
> down DCOM.
>
> Does anyone encounter similar behavior?
>
> Any ideas why is it happening?
>
> Might it be new trojan?
>
> May be the IExplorer.exe was infected/modified by some virus/trojan?
>
> I did check my computer regularly and neither Spybot, nor Adaware, nor Norton
> Antivirus find any viruses/trojans.
>
> Thanks in advance

I suspect that this is just IE doing its thing. It is making several outgoing
calls,
using sequential source port numbers. This is normal. The only question is: do
you
expect IE to be making calls at this time? Does it have a page open that needs to
be refreshed occasionally (including adverts)?

Steve



Similar ThreadsPosted
WS Trojan Scanner March 30, 2005, 7:14 am
trojan horse Canada December 1, 2004, 8:07 pm
World Cup email is a Trojan May 30, 2006, 3:27 pm
Trojan ByteVerify Question December 9, 2007, 6:40 pm
Re: Trojan from using VNC Viewer Software April 2, 2007, 5:38 am
Help me,my computer maybe at risk with some trojan. April 9, 2008, 12:43 pm
Trojan hides in 'Amazon' email May 30, 2006, 3:31 pm
Fake Microsoft emails hide Trojan spy May 30, 2006, 3:25 pm
strange requests sent to my WWW April 12, 2006, 4:06 pm
Strange Error Log, then FBI? June 15, 2006, 6:55 pm

The site map in XML format XML site map

Contact Us | Privacy Policy