View Single Post
Old 07-05-2004, 07:18 PM  
badmrfrosty
Confirmed User
 
Join Date: May 2003
Posts: 500
This is how i would get rid of it. I tried to ICQ you but you wouldnt authorize me lol :D

1) go to this URL:

http://www.foundstone.com/index.htm?...desc/fport.htm

2) Download F-port
3) Unzip Fport
4) start > run > cmd (enter)
5) cd \f-port2.0 (or whereever you unzipped it)

Look for anything that looks out of the ordinary listening on your system, it lists port numbers and their corresponding executable files.

after you get the name of the executable that is causing your headache

6) type exit
7) click start > run > type regedit (enter)
8) click edit > find
9) type in the name of the offending executable (or dll)
10) delete the key that is making the offending virus/trojan execute at boot time.
11) reboot your PC
12) delete the offending files

go to windowsupdate.com and keep your box patched, might be a good idea to keep antivirus software up to date as well.

Hope this helps, take care.

Actually I think everyone should have FPORT, its very useful, one can find all kinds of funny daemons running on their box, my girlfriend had a rogue webserver running on PORT 5000 that was letting people control her box.

BMF
badmrfrosty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote