Results 1 to 15 of 15

Thread: Trojan?

  1. #1
    ricmitch_uk
    Guest

    Question Trojan?

    A few days back, my firewall picked up krnl386.exe trying to access the net. I checked this out and the program's version info seems authentic enough, but should my Windows Kernel Core be accessing the net?
    Norton Firewall keeps blocking something with the:
    "Default block Subseven/Backdoor trojan" rule. I checked the registry, and msconfig.exe but I can't find anything incriminating.
    Does anyone have any info?

  2. #2
    Fanatic Member zmerlinz's Avatar
    Join Date
    May 2000
    Location
    in a world where the sun always shines on the bloody tv!!
    Posts
    604
    My computers firewall picks up kernel386 quite often but i don't think that it is doing any harm, programs like messanger or my virus checker when it needs to update send that through first

    Some people have told me they don't think a fat penguin really embodies the grace of Linux, which just tells me they have never seen a angry penguin charging at them in excess of 100mph. They'd be a lot more careful about what they say if they had.
    -- Linus Torvalds

    [Galahtech.com] | [My Site] | [Fishsponge] | [UnixForum.co.uk]

  3. #3
    Jethro
    Guest
    Damn l thought this was going to be a thread about condoms

    This one time at band camp.....

  4. #4
    ricmitch_uk
    Guest
    Originally posted by Jethro
    Damn l thought this was going to be a thread about condoms

    This one time at band camp.....
    Why??

  5. #5
    ricmitch_uk
    Guest
    Whatever this thing is my firewall's blocking it's using port:
    27374

  6. #6
    PowerPoster
    Join Date
    Jul 1999
    Posts
    5,923
    I have Norton too and it also seems the Win Kernal wants t access the internet (sometimes it says Explorer) . I made a rule telling it to disallow every time with no adverse effects. I occasionally get an app called "@x$%&" or something like that trying to do the same, I always say no to that.

  7. #7
    Fanatic Member Illspirit's Avatar
    Join Date
    Mar 2001
    Location
    Blackpool, England
    Posts
    815
    BEWARE!!! 27374 is the default Sub7 port!!!!

    Try running the exe when your offline, and if nothing happens, check the size of the exe. If its about 380kb then i think you should get rid of it!
    Illspirit - [email protected]

    SmartBarXP Lead Developer
    SmartBarXP - The leading desktop sidebar application for Microsoft Windows XP

  8. #8
    ricmitch_uk
    Guest
    The port number it uses is the reason it's being blocked. However it is not the krnl386.exe that is causing these alerts, it is another program which I haven't determined yet. (krnl386.exe is about 120KB)

  9. #9
    lord_dude
    Guest
    Instead of potentially deleting something needed by windows, y not just get a virus scanner. They also detect trojans.

  10. #10
    ricmitch_uk
    Guest
    I have Norton AV but I wasn't sure whether it would pick it up. It didn't get Kak, I used my own personal skills to spot that and remove it.

  11. #11
    lord_dude
    Guest
    Thats very odd. Norton is supposed to be one of the best. Did u have all the lattest updates?

  12. #12
    ricmitch_uk
    Guest
    Yeah. I update every month. I'm no fool when it comees to virii. I also enable the detect unknown virii thing as well. AV and Firewall are constantly running on my system, since I've been on certain websites, attacks have increased 2 fold.

  13. #13
    Fanatic Member
    Join Date
    Apr 2000
    Location
    Whats a location?
    Posts
    516
    Why is it that somebody like me (no firewall, virus scanner or security features of any sort) never gets a virus?

    I feel left out. It is as if they don't care about me
    Courgettes.

  14. #14
    PowerPoster
    Join Date
    Jul 1999
    Posts
    5,923
    Nope, you're just VERY lucky never to have been probed. Don't push your luck anymore though.

  15. #15
    lord_dude
    Guest
    Originally posted by V(ery) Basic
    Why is it that somebody like me (no firewall, virus scanner or security features of any sort) never gets a virus?

    I feel left out. It is as if they don't care about me
    A firewall is most important. Viruses can usually be avoided by being careful what you download and by not using outlook or outlook express. I agree with chrisjk. zonealarm is free from www.zonelabs.com.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  



Click Here to Expand Forum to Full Width