HELP: My computer is spewing packets into the world... particpating in maybe a trojan initated DDOS?

AccruedExpenditure

Diamond Member
May 12, 2001
6,960
7
81
My ethernet send light is on solid. 90 million packets sent in 12 hours. I believe that my computer has been infected by a trojan. I've ran an updated norton AV but it can't catch it. I've also download the stinger tool and it can't detect anything.

Any suggestions...

I've installed a packet sniffer to see what kind of outbound traffic my computer is sending, it looks like UDP packets directed towards 200.230.118.2
=/
 

ViRGE

Elite Member, Moderator Emeritus
Oct 9, 1999
31,516
167
106
The best thing to do would be to shut off every last application that isn't nessisary, and then fire up the packet sniffer of choice, and see what's being sent, and where.
 

AccruedExpenditure

Diamond Member
May 12, 2001
6,960
7
81
Originally posted by: ViRGE
The best thing to do would be to shut off every last application that isn't nessisary, and then fire up the packet sniffer of choice, and see what's being sent, and where.

That's the thing, I think the trojan disabled my task manager... anytime I control alt delete to get to my win2k task manager, it the console box disappears and I return to my previous window :confused:
 

illusion88

Lifer
Oct 2, 2001
13,164
3
81
Originally posted by: Gnote
Originally posted by: ViRGE
The best thing to do would be to shut off every last application that isn't nessisary, and then fire up the packet sniffer of choice, and see what's being sent, and where.

That's the thing, I think the trojan disabled my task manager... anytime I control alt delete to get to my win2k task manager, it the console box disappears and I return to my previous window :confused:

you could try booting into safe mode. That might help, might not.
 

AccruedExpenditure

Diamond Member
May 12, 2001
6,960
7
81
Originally posted by: illusion88
Originally posted by: Gnote
Originally posted by: ViRGE
The best thing to do would be to shut off every last application that isn't nessisary, and then fire up the packet sniffer of choice, and see what's being sent, and where.

That's the thing, I think the trojan disabled my task manager... anytime I control alt delete to get to my win2k task manager, it the console box disappears and I return to my previous window :confused:

you could try booting into safe mode. That might help, might not.

tried it, no avail, no internet in safemode either.
 

tranceport

Diamond Member
Aug 8, 2000
4,168
1
81
www.thesystemsengineer.com
I would format your box. You most likely have subseven installed on your machine. We recently were the target of about 400 machines hitting our mailserver with a syn attack. Most of the machines I reverse scanned had subseven on them. Most of the machines were also in .nl .sk .ca and a few cox and bellsouth boxes. Also check out what Savij posted.
 

AccruedExpenditure

Diamond Member
May 12, 2001
6,960
7
81
Thanks sajiv and tranceport. I tried your link sajiv and it couldn't find the slammer virus on my hd. I'm pretty sure what I have is some variant of the sub7 trojan on my computer. Short of reformating, does anyone have any ways for me to remedy my issue.
 

WannaFly

Platinum Member
Jan 14, 2003
2,811
1
0
Originally posted by: Gnote
Thanks sajiv and tranceport. I tried your link sajiv and it couldn't find the slammer virus on my hd. I'm pretty sure what I have is some variant of the sub7 trojan on my computer. Short of reformating, does anyone have any ways for me to remedy my issue.

Eww, sub7 - I had to deal with that one a few times - it never does REALLY go away - if you can spare, reformat. Its a bitch, you think you have it gone, then 2 days later it comes back, and it just repeats over and over.
 

beatmix01

Golden Member
Jun 22, 2001
1,008
1
0
yeah i got a msg on my machine today backdoor.trojan in my serv-u daemom exe... bizarre...nothing was running...uninstalled the app deleted the norton quarantined item hope im good.
 

Anubis

No Lifer
Aug 31, 2001
78,712
427
126
tbqhwy.com
Originally posted by: beatmix01
yeah i got a msg on my machine today backdoor.trojan in my serv-u daemom exe... bizarre...nothing was running...uninstalled the app deleted the norton quarantined item hope im good.

funny i got the same thing today when i did a norton scan. same virus. norton quarantined it and i killed it. no idea what it was or now i got it. im behind a huge hardware FW and i run norton and a SW firewall