norton AV is detecting a trojan attempt in alerts log for auto worm protection

Discussion in 'Software' started by jason1488, May 3, 2005.

  1. jason1488

    jason1488 Private E-2

    i have norton 2005 and in my alerts log i have a couple logged attempts and an ip.what is it that this means ?keeps saying (Rule "Default Block DeepThroat Trojan horse" blocked (81.83.33.31,6670).
    Inbound TCP connection.)help pls!!!!!!!!
    :eek:
     
  2. capn_caveman

    capn_caveman Sergeant

    It sounds to me like your firewall is blocking an incoming connection to a port that is known to be open when you have a trojan. This is normal and what appears to be happening is that someone on the internet is trying to do a random scan of IP addresses to check and see if anyone has this port open on their computer. Since your firewall blocked this attempt, you are in no danger. This type of traffic is actually quite common - there are plenty of hackers running port scans to check computers for open ports. I wouldn't worry about it.
     
  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  4. Matacumbie

    Matacumbie Rocky Top

  5. capn_caveman

    capn_caveman Sergeant

    I'm not all that familiar with Norton Firewall... but the post mentions an inbound attempt - not an outbound attempt. Does anyone else think this is probably some random port scan?
     
  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Most of the firewalls I have dealt with by default don't warn of random scans, otherwise you constantly get Alerts. Unless he lowered the Alert threshold, that was a definite attempt to contact his system.
     
  7. capn_caveman

    capn_caveman Sergeant

    I guess I'm more familiar with zone alarm pro which logs all inbound and outbound traffic. I get hundreds of hits per day, a half dozen of so of "high" importance where someone randomly scanned a known trojan port. I turn off all of the alerts so I don't have to see a message flash every 10 seconds.
     
  8. Matacumbie

    Matacumbie Rocky Top

    I think it has to do with how your firewall deals with streaming protocols.

    Steve
     
  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    I used ZoneAlarm for several years, before that I used Black Ice. Flirted with Norton and McAfee firewalls didn't like them. ZoneAlarm logs all inbound activity makes for exhaustive reading at times. I use Kerio Personal Firewall now, the log tells me exactly the type of attack , the source of the attack and the action taken.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds