altavista_traversal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by fangy, Jul 2, 2005.

  1. fangy

    fangy Private E-2

    My Norton fire wall keeps alerting me to high risk attacks on port 9000, It says it's an Altavista_Traversal kind. It also says that the attacks coming from my own IP address. Could anyone tell me what this is?
    Thanks.
    Fangy.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here is some info on what port 9000 has been found to be used for:

    9000 tcp Netministrator, W32.Randex

    9000 udp Asheron's Call - This port is used in Microsoft's massively- multiplayer game called "Asheron's Call". The game can continue to contact the player even after the player has logged out.

    Do you use Altavista's search engine?

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. fangy

    fangy Private E-2

    We dont use any of the things you mentioned on port 9000.
    I have completed all the steps in your read me first thread, nothing found.
    But I am unable to attach my hijack this log. Nothing happens when I click on the manage attachment button.
    What should I do now?
    cheers
    Fangy
     
  4. fangy

    fangy Private E-2

    I've got Ad-ware, spybot, with Spyware blaster running in the back ground, my AV is Norton 2004 with Firewall. I up date every thing about once a week. Other than my firewall alerting me to these atacks I can't find anything wrong. I'm still unable to attach a HJT log, does anyone know why?
     
  5. fangy

    fangy Private E-2

    I couldn't get my HJT log to upload while I was using Firefox, worked ok with IE.
    Fangy.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Fangy,

    Your HJT log is clean. But is does not look like you ran the online scanners. Why?

    Please follow the steps below.

    Bitdefender online scan
    RavAntivirus online scan <-- select Auto Clean then click Scan My PC
    TrojanScan online scan

    If that does not help, run the below:

    Download this virus checker tool from Microworld Antivirus Toolkit Utility

    1. Save it to a folder.
    2. Reboot into safe mode
    3. Double click the Mwav.exe file.(This is a stand alone tool and NOT just a virus checker......so it won't install anything)
    4. Leave the all default settings accept change it to Scan All Files instead of just Program Files. Then click SCAN and when it is completed, anything found will be displayed in the lower pane.
    5. Click the View Log button which will bring up the log in a Notepad window. Save the log and then upload it here (as an attachment) when you come back. Note this mwav.log file may be too large to upload as it is. You may have to compress it into a ZIP file using a program like WinZip and then upload the compressed file.

    *Note* If prompted that a Virus was found and you need to purchase the product to remove the malware, just close out the prompt and let it continue scanning.

    We just want to use it to try to identify anything that is bad.
     
  7. fangy

    fangy Private E-2

    I done the scans I had missed, the Bit Defender found nothing.
    The Rav AV found nothing infected but 5 suspicious files, all of them were to do with my Winrar, it mentioned a Poebot.E worm,and the trojan scan found nothing. I read somewere that to get rid of this Poebot.E worm you have to click on start/ run/ and type regedit/enter, make a back up of you registry by clicking on "export registry file"In the "export range" panel click "all" then save your registry as a back up. Then locate the...
    HKEY_LOCAL_MACHINE entry and delete ...
    HKLM\software\microsoft\windows\current version\run windows dll loader%windows%\system32\radeonfx.exe. Is this the right thing to do?
    I also done the Microworld AV scan in safe mode, it found 2 things so I've rar'd the log and attached them with this.
    Thanks again for all the help.
    Fangy.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you ran ALL of the READ ME FIRST. I see quite a bit of files in Temp folders that should have been cleaned up by CCleaner.

    Do you know what the below file is? If not,, make sure it is deleted.
    C:\DOCUME~1\fangy\LOCALS~1\Temp\ypsr_setup_full_bt_uk.exe


    Do you use Beat Blender? If so, the warning about Altavista_Traversal is probably a false alarm from Norton.

    See:
    http://translate.google.com/translate?hl=en&sl=de&u=http://wap.tutorials.de/t-153207.html&prev=/search%3Fq%3DBeat%2BBlender%2B%252Btraversal%26hl%3Den%26lr%3D

    http://mellowave.com/chat/
     
  9. fangy

    fangy Private E-2

    I ran everything you said, the CCleaner is left on the default settings, I know what the file is you mentioned, it's BT anti spy. I've never heard of Beat Blender, don't know what it's for? Do you think the Poebot.E or the 2 things found by Microworld AV are anything to worry about?
    Thanks again.
    Fangy.
    I don't get the link to the radio station?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The items reported by MWAV are not problems. I believe it always reports an Altnet problem.

    Your HJT log showed no signs of the file associated with Poebot.E

    You could look in your registry manually using regedit to double check.
    Also look for c:\windows\system32\radeonfx.exe but I doubt that it is there.
     
  11. fangy

    fangy Private E-2

    Thanks for your help.
    Fangy.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds