»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 02-25-2004, 09:27 PM   #1 (permalink)
Registered User
 
Join Date: Mar 2003
Posts: 57
v-a-m is on a distinguished road
My mind is blown...

I just got an attempted intrusion, detection from Norton Firewall. Said (when tried to trace) 127.0.0.0

I got this info....

Attempted Intrusion "BD_BUGBEAR" from your machine against 69.11.23.250 was detected and blocked
Intruder: localhost(3071)
Risk Level: High
Protocol: TCP
Attacked IP: 69.11.23.250
Attacked Port: socks(1080)

Any help??

v-a-m is offline   Reply With Quote
Old 02-25-2004, 09:29 PM   #2 (permalink)
Registered User
 
Join Date: Oct 2002
Posts: 179
bfcx is on a distinguished road
if it's just attempted then probably nothing happened, just a virus on someone elses computer scanning IP's and yours happened to be one it scanned. If you want to be safe update norton and do a full virus scan.
bfcx is offline   Reply With Quote
Old 02-25-2004, 09:29 PM   #3 (permalink)
Registered User
 
Join Date: Dec 2003
Posts: 1,045
HeadBand is on a distinguished road
could it just be a coincedince that this happend at the same time???
HeadBand is offline   Reply With Quote
Old 02-25-2004, 09:30 PM   #4 (permalink)
Registered User
 
golfcart's Avatar
 
Join Date: Oct 2001
Location: Michigan
Posts: 1,680
golfcart is on a distinguished road
If I'm reading it right, it looks like you are infected with the bugbear virus. Free removal tool and complete instructions can be found here
golfcart is offline   Reply With Quote
Old 02-25-2004, 09:33 PM   #5 (permalink)
Registered User
 
M_Six's Avatar
 
Join Date: Oct 2001
Location: Urbana, Illinois
Posts: 1,845
M_Six is on a distinguished road
Sounds like maybe your machine is infected and is trying to find other machines to infect. Hit one of the anti-virus sites like McAfee or Symantec and download a virus checker.

Try Stinger.
__________________
Mark}--->8-8->
If you're not the lead dog, the scenery never changes.
M_Six is offline   Reply With Quote
Old 02-25-2004, 10:31 PM   #6 (permalink)
Registered User
 
Join Date: Mar 2003
Posts: 57
v-a-m is on a distinguished road
--

I tried the symatec Bugbear fix, I followed the instructions to a t, and Bugbear was not found on my computer?!

Baffling.

It looked like an attack on me at first, as I was warned about an attrack. Then upon checking the Intrusion history, thats where I got the info posted above (where it looks as if my machine is attacking the other)
v-a-m is offline   Reply With Quote
Old 03-18-2004, 05:13 AM   #7 (permalink)
Registered User
 
Join Date: Mar 2004
Posts: 4
DVS_DVIT is on a distinguished road
Gaming an attempted attack from my machine with this BD_BUGBEAR?

Attempted Intrusion "BD_BUGBEAR" from your machine against 82.67.177.70 was detected and blocked
Intruder: localhost(4490)
Risk Level: High
Protocol: TCP
Attacked IP: 82.67.177.70
Attacked Port: socks(1080)
i had this in my norton log... and yes that is why i did a search on google to find out more about it, so i amnot the only person who has recieved this alert... so like it has been above meantioned, it looks like my computer has atempted to atack someone else, and i was shocked as i try to stay as up to date as possible, i am using norton internet security professional 2003 and windows xp pro, and have full subscription, and it is up to date, so im buggered if i can figure what this is all about. i will be checking this site for future developments... i went to symantec security site for info but found nothing helpful.
DVS_DVIT
DVS_DVIT is offline   Reply With Quote
Old 03-18-2004, 05:16 AM   #8 (permalink)
Registered User
 
Join Date: Mar 2004
Posts: 4
DVS_DVIT is on a distinguished road
I forgot to mention that this occured at 12.49 am on the 16 march 2004 guam(east australia time).

Last edited by DVS_DVIT; 03-18-2004 at 05:37 AM.
DVS_DVIT is offline   Reply With Quote
Old 03-18-2004, 05:27 AM   #9 (permalink)
Registered User
 
Join Date: Oct 2001
Posts: 6,533
John Prophet is on a distinguished road
Welcome to the forum!

there is a tool to remove bugbear http://securityresponse.symantec.com...ugbear@mm.html

I suppose the "BD" part means "backdoor" as in a trojan.

I see that the "symantec gateway security" has a patch that includes coverage for the BD_bugbear http://securityresponse.symantec.com...004.02.18.html

I would get that tool and try it out.

and/or also go to www.antivirus.com and do the free scan as a second opinion in case your symantec has somehow been compromised

here is a long article on bugbear, how it works etc http://216.239.51.104/search?q=cache...hl=en&ie=UTF-8

JP
__________________
"Even a fool is thought to be wise if he is silent"
John Prophet is offline   Reply With Quote
Old 03-19-2004, 07:46 PM   #10 (permalink)
Registered User
 
Join Date: Mar 2004
Posts: 4
DVS_DVIT is on a distinguished road
Gaming BD_BUGBEAR

Attempted Intrusion "BD_BUGBEAR" from your machine against 201.1.77.97 was detected and blocked
Intruder: localhost(4229)
Risk Level: High
Protocol: TCP
Attacked IP: 201.1.77.97
Attacked Port: socks(1080)

Attempted Intrusion "BD_BUGBEAR" from your machine against 201.1.77.97 was detected and blocked
Intruder: localhost(4192)
Risk Level: High
Protocol: TCP
Attacked IP: 201.1.77.97
Attacked Port: socks(1080)

two more.... waht to do... ive tried all advise mentioned so far....
DVS_DVIT
DVS_DVIT is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 06:20 PM.