»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 02-18-2004, 01:42 AM   #1 (permalink)
Registered User
 
Join Date: Feb 2004
Posts: 2
chris8852 is on a distinguished road
TransScout Trojan Horse?

On Norton Personal Firewall 2003 I get attacked by dozens, if not hundreds, of different IPs by the 'TransScout Trojan Horse'... I get attacked every second, literally, and I think it's using a consistent amount of my system resources (It reports over 500,000 recent intrusion attempts). I'm wondering if there is a way I can turn the reporting off without turning blocking off, or if it is a major threat if I do turn it off, or some other fix.. It's quite annoying.

P.S. I'm on a cable modem (Dynamic IP that never changes... What's the point?)


Last edited by chris8852; 02-18-2004 at 01:48 AM.
chris8852 is offline   Reply With Quote
Old 02-18-2004, 01:56 AM   #2 (permalink)
Registered User
 
nochay's Avatar
 
Join Date: Aug 2002
Location: Las Vegas NV USA
Posts: 477
nochay is on a distinguished road
Send a message via ICQ to nochay Send a message via AIM to nochay Send a message via Yahoo to nochay
Re: TransScout Trojan Horse?

Quote:
Originally posted by chris8852
On Norton Personal Firewall 2003 I get attacked by dozens, if not hundreds, of different IPs by the 'TransScout Trojan Horse'... I get attacked every second, literally, and I think it's using a consistent amount of my system resources (It reports over 500,000 recent intrusion attempts). I'm wondering if there is a way I can turn the reporting off without turning blocking off, or if it is a major threat if I do turn it off, or some other fix.. It's quite annoying.

P.S. I'm on a cable modem (Dynamic IP that never changes... What's the point?)
then you must have a static ip address. unplug yourself from the net, then reconnect. does it change then? If not, then it is static. Are you keeping up to date on all your security patches? Do the ip addresses change? try blocking the ip addresses.

Dane
__________________
Seti@Home Work Unit Processor
Member Of Team Art Bell

2 Computers Processing The Units:

HP Pavilion 8276
300 MHZ Pentium II Processor
256 Megs Of Ram

Dell Optiplex GX1
350 MHZ Pentium II Processor
256 Megs Of Ram

Both Use The Command Line Version Of Seti@Home, And Complete A Unit In About 16-17 Hours.
nochay is offline   Reply With Quote
Old 02-18-2004, 02:45 AM   #3 (permalink)
Registered User
 
doddsy's Avatar
 
Join Date: Nov 2003
Location: Banbridge, N.Ireland
Posts: 219
doddsy is on a distinguished road
these may not actually be attacks, i got loads of warnings about sub 7 trojans with nis 2003. you can stop the alertes from appearing without affecting your security.

open norton firewall
and click configure (my firewall is part of NIS 2003 so the route to configure might be slightlydifferent)


click the advanced tab

click trojan horse rules

find transcout in the list and hightlight it (don't uncheck the box)

now with transcout highlighted click the modify button

now click the tracking tab

and uncheck the two "notify me" boxes

then click ok-ok-ok.............no more alerts.....security unaffected...

doddsy
__________________
:D
doddsy is offline   Reply With Quote
Old 02-18-2004, 12:52 PM   #4 (permalink)
Registered User
 
Join Date: Feb 2004
Posts: 2
chris8852 is on a distinguished road
Thanks!
Question though... If they are not attacks... What are they?
chris8852 is offline   Reply With Quote
Old 02-18-2004, 02:15 PM   #5 (permalink)
Registered User
 
doddsy's Avatar
 
Join Date: Nov 2003
Location: Banbridge, N.Ireland
Posts: 219
doddsy is on a distinguished road
i read somewhere............can't remember where ............that lots of attack alerts of the same kind may actually be legitimate traffic, even your own isp, but using the port at which that particular attack is expected...............this may or may not be fact.........but lots of alerts is a nuisance.............so disabling the alerts while maintaing security seemed to be a good course of action.

i take it this has worked for you.

welcome to techimo!

__________________
:D
doddsy is offline   Reply With Quote
Old 02-18-2004, 02:40 PM   #6 (permalink)
Registered User
 
Join Date: Jul 2003
Location: PA
Posts: 1,609
butch81385 is on a distinguished road
Send a message via AIM to butch81385
i ran into the same problem on my university connection. apparently the university would check to see if we were online (they monitored our bandwidth) and when they checked NIS thought it was a sub7
butch81385 is offline   Reply With Quote
Old 02-18-2004, 09:02 PM   #7 (permalink)
Registered User
 
nochay's Avatar
 
Join Date: Aug 2002
Location: Las Vegas NV USA
Posts: 477
nochay is on a distinguished road
Send a message via ICQ to nochay Send a message via AIM to nochay Send a message via Yahoo to nochay
Quote:
Originally posted by doddsy
i read somewhere............can't remember where ............that lots of attack alerts of the same kind may actually be legitimate traffic, even your own isp, but using the port at which that particular attack is expected...............this may or may not be fact.........but lots of alerts is a nuisance.............so disabling the alerts while maintaing security seemed to be a good course of action.

i take it this has worked for you.

welcome to techimo!


yes, that is true. alot of trojans use common ports, like port 80,21, & so on. We know these are web server and ftp server ports, so NIS would go crazy with these!
__________________
Seti@Home Work Unit Processor
Member Of Team Art Bell

2 Computers Processing The Units:

HP Pavilion 8276
300 MHZ Pentium II Processor
256 Megs Of Ram

Dell Optiplex GX1
350 MHZ Pentium II Processor
256 Megs Of Ram

Both Use The Command Line Version Of Seti@Home, And Complete A Unit In About 16-17 Hours.
nochay is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 06:06 PM.