CuteFTP attracting tons of trojans

Discussion in 'Malware Help (A Specialist Will Reply)' started by MistressRene, Apr 28, 2006.

  1. MistressRene

    MistressRene Private First Class

    Hi again.
    My cuteftp 7pro seems to be attracting every weird trojan in the book. I even tried to reinstall cuteftp cleanly and as soon as I started a download or upload the trojans started throwing themselves at my machine. Norton AV blocked every one!
    Now.. this is my question...
    What do I need to look for on my computer that would be attracting these. There is nothing showing with Hijackthis, and I am showing clean in virus scans too. Every type of scan that I run is clean. I'm lost.
    I will attach the log from Norton so you can see the names of these trojans.
    Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Read this about Shockrave Trojan: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=5456
    I don't think you have this unless something changed on your PC in the few days since last cleaning it.
    Also about TransScout see: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453083851

    All of the incoming ICMP message are just pings from your ISP and other valid locations that you access. Here is a list of who they all belong too:
    You may want to give this a read: http://kb.globalscape.com/Article.aspx?id=10132
     
  3. MistressRene

    MistressRene Private First Class

    Thanks Chaslang!
    I looked for information before I posted, but what I found was very very limited!
    The CuteFTP is going to drive me bonkers. I tried chaning the settings in my Norton
    SystemWorks2006, which is very similar to the Norton Internet Security 2005. I'll test it out later, and let you know if I still have the problem.
    Those trojans were being throw at me at 1 per second ACK!
    We will see :)

    I am also going to look for a new firewall. My subscription is coming for renewal, and I don't think itis doing its job very well!
    TY!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually your firewall was doing its job. It was blocking everything it detected which means no baddies were getting in or out. The question here is whether some of the things being blocked from CuteFtp were false positives or not.
     
  5. MistressRene

    MistressRene Private First Class

    I emailed globalscape, and they never even heard of such a thing.
    How do I test it, or is there a way. BTW This just started after my trojan fiasco.
    TY!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These could just be false positives from Symantec but you would expect that GlobalScape would know of problems like that.

    Did you check for the existence of the shockrave.exe file mentioned in the link I gave you?

    Do you recognize all of those IP address networks being mentioned. For example like the below:
    213.7.0.0
    212.7.0.0
    211.7.0.0
    210.7.0.0
    209.7.0.0
    208.7.0.0
    207.7.0.0
    189.7.0.0
    15.7.0.0
    64.6.0.0
    252.15.0.0
    92.8.0.0
    67.8.0.0
    231.7.0.0
    66.4.0.0

    This is a whole network range. Do any of them mean anything to you? Are they in some kind of list of sites that you have CuteFTP accessing?

    Do you use any kind of video conferencing?

    You could use a packet sniffing program like Ethereal to capture packets to/from your PC to find out what is really being sent and on what ports.
     
    Last edited: Apr 30, 2006
  7. MistressRene

    MistressRene Private First Class

    As I am typing a followup message I am looking for the fix for more trojans that have be throwing themselves at me this morning. Well guess what? I found the fix. Look below!
    Thank you again for ALL of your help, and your patience! :)
    -----------

    I FINALLY FOUND THE FIX!!! It's Gone! :D
    http://www.ftpplanet.com/ubb/Forum1/HTML/003236.html
    .
    Open Norton AntiVirus 2005 (OR 2006)
    - Click "Options"
    -- Click "Internet Worm Protection"
    --- Make sure "Enable Internet Worm Protection (recommended)" is checked.
    --- Click "Trojan Rules"
    ---- Uncheck "Unused Windows Services Block", (all the way at the bottom of the list)
    ---- "OK"
    --- "OK"
    .
    Connect to a site in WS-FTP. (OR CUTEFTP) (It'll work.)
    .
    Go back to Norton
    - Click "Options"
    -- Click "Internet Worm Protection"
    --- Click "Program Control"
    ---- You should see a new entry, "Microsoft Application Layer Gateway Service". It should be configured as "Automatic". This is what fixed the problem. (You don't have to make any changes here; this step was just to let you see the new entry.)(IF YOU DON'T SEE IT, AD IT windows\system32\alg.exe)
    ---- "OK"
    --- Click "Trojan Rules"
    ---- Put the checkmark back into "Unused Windows Services Block"
    ---- "OK"
    --- "OK"
    Close Norton
    .
    You should now be able to connect with WS-FTP (OR CUTEFTP) the same as you could before installing Norton AntiVirus 2005. (2006)
    .
    One other thing: if you have Windows XP Pro Service Pack 2 installed, you may at some point have to tell Windows Firewall to not block WS-FTP
    (OR CUTEFTP). To do so,
    .
    Open the Windows Control Panel
    - Click "Windows Firewall"
    -- Click the "Exceptions" tab
    --- Click "Add Programs"
    ---- Check "WS_FTP Pro" (OR CUTEFTP)
    ----- The Scope should be set to "Any computer (including those on the Internet)".
    .
    His environment is
    - Windows XP Pro, Version 5.1, Service Pack 2
    - Norton AntiVirus 2005, Version 11.0.11.4
    - WS-FTP 7.5 2002.02.28
    - Computer is an IBM 8433-94U

    My envoronment is windows XP home
    Norton system works 2006
    CuteFtp 7.1 Pro
    Generic IBM

    OH..I tried to download Ethereal from the Author's Site, and it timed out. You might want to check it.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think that may be similar to what was in the link I posted at the bottom of message # 2. However GlobalScape's Knowledgebase appears to be broken right now. It was readable at the time I posted that link.

    At anyrate this agrees with what I was saying....not malware.

    The Ethereal links all work fine for me and we cannot control the authors site anyway. If you tried the Majorgeek's links and they did not work....well that would be a different story. I don't think you need it anyway.
     
  9. MistressRene

    MistressRene Private First Class

    I couldn't get their link working either. I found the site with the fix by doing a search for one of the new 'trojans' that passed thru. One that was not there before :)
    Its working perfectly now! TYTYTY!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds