M
MickKi
Perhaps I'm getting paranoid for no reason, but this is how it looks like
from here:
PART 1
Installed new Kerio PF on fully patched XP. Also running Nod32 on trial.
While browsing on this nsg I got a nasty netdex 10 backdoor trojan! Nod32
stopped it (or so it said). I quarantined it, and then deleted it. A
full machine Nod32 scan did not reveal anything untoward. Quick check
around the registry (told you I'm paranoid) revealed that "PostNotCached
repost.html" was added to the registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs which I
promptly deleted.
Marvellous, I thought, there must be more . . . but I could not find any
other tell-tale signs of this trojan on my machine.
PART 2
After rebooting I keep getting a little fellow trying to dial up! I
believe that this happens when I right-click on the Kerio icon in the tool
tray. The pop-up says something along the lines: "A program or you have
requested connection to 213.121.147.208" If I do not react the same pop-up
is replaced by 213.121.147.209. Both IP addresses seem to belong to BT
Public Internet Service (BT-MDIP). I have disabled Kerio from automatic
updates so I don't know what's causing it. Any ideas?
The log shows: "ICMP Destination Unreachable (Communication
Administratively Prohibited)", Direction: In
Remote Address: 213.121.147.209
Attack Class: misc-activity
Priority: Low
Action: permitted (this particularly worries me ;-)
The same entry has also been logged for 213.121.147.208.
PART 3
A quick check on HijackThis doesn't reveal much. A couple of entries I am
not sure about are:
O2 - BHO: (no name) - {--- binary code is written here ---} -
C:\WINDOWS\System32\nzdd.dll
O10 - Broken Internet access because of LSP provider 'imon.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
Any advice much appreciated. TIA.
Regards,
Mick
from here:
PART 1
Installed new Kerio PF on fully patched XP. Also running Nod32 on trial.
While browsing on this nsg I got a nasty netdex 10 backdoor trojan! Nod32
stopped it (or so it said). I quarantined it, and then deleted it. A
full machine Nod32 scan did not reveal anything untoward. Quick check
around the registry (told you I'm paranoid) revealed that "PostNotCached
repost.html" was added to the registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs which I
promptly deleted.
Marvellous, I thought, there must be more . . . but I could not find any
other tell-tale signs of this trojan on my machine.
PART 2
After rebooting I keep getting a little fellow trying to dial up! I
believe that this happens when I right-click on the Kerio icon in the tool
tray. The pop-up says something along the lines: "A program or you have
requested connection to 213.121.147.208" If I do not react the same pop-up
is replaced by 213.121.147.209. Both IP addresses seem to belong to BT
Public Internet Service (BT-MDIP). I have disabled Kerio from automatic
updates so I don't know what's causing it. Any ideas?
The log shows: "ICMP Destination Unreachable (Communication
Administratively Prohibited)", Direction: In
Remote Address: 213.121.147.209
Attack Class: misc-activity
Priority: Low
Action: permitted (this particularly worries me ;-)
The same entry has also been logged for 213.121.147.208.
PART 3
A quick check on HijackThis doesn't reveal much. A couple of entries I am
not sure about are:
O2 - BHO: (no name) - {--- binary code is written here ---} -
C:\WINDOWS\System32\nzdd.dll
O10 - Broken Internet access because of LSP provider 'imon.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
Any advice much appreciated. TIA.
Regards,
Mick