Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Applications > trojan on my machine?

trojan on my machine?
Thread Tools
Fresh-Faced Recruit
Join Date: Jun 2002
Location: detroit
Status: Offline
Reply With Quote
Nov 2, 2003, 11:12 AM
 
hello,

i just got netbarrier for my mac and in the log i found the tcpwrappers trojan sending out through some port that sohuld have been off. in the antivandal feature i turned trojan blocking on for all of them and put the offender on the stop list.

i'm a little freaked out though, i didn't think macs had trojans. my brother had been into downloading stuff on the machine but i've gotten busier with it and i wanted to be secure from the wild...

any advice or explanations would be deeply appreciated.

thanx
     
Gus
Fresh-Faced Recruit
Join Date: Oct 2001
Location: Belgium
Status: Offline
Reply With Quote
Nov 2, 2003, 12:09 PM
 
Are you sure about this?
A virus on MOSX? Finally!

Gus
     
elucid  (op)
Fresh-Faced Recruit
Join Date: Jun 2002
Location: detroit
Status: Offline
Reply With Quote
Nov 2, 2003, 01:53 PM
 
no not a virus, a trojan is not a virus
     
Posting Junkie
Join Date: Dec 2000
Status: Offline
Reply With Quote
Nov 2, 2003, 03:56 PM
 
Ouch. What version of Mac OS X are you running?

Did you see the trojan program running in top? What was the path it installed itself to?

Ticking sound coming from a .pkg package? Don't let the .bom go off! Inspect it first with Pacifist. Macworld - five mice!
     
Grizzled Veteran
Join Date: May 2002
Location: UK
Status: Offline
Reply With Quote
Nov 2, 2003, 04:32 PM
 
where can i find info aobut this, cant seem to get much relervent stuff from google
     
Dedicated MacNNer
Join Date: Jan 2001
Location: Badfort
Status: Offline
Reply With Quote
Nov 2, 2003, 04:40 PM
 
Huh? I just googled for tcp wrappers trojan. The tcpwrappers trojan was released in Jan 1999, and didn't use a specific port, it was triggered by calling a tcpwrappers run service from source port 421. Are you saying there's another one? Does your brother have admin rights? Does Jaguar even have tcpwrappers, i thought it only used xinetd?
You see, my friends, pirates are the key. - thalo
     
elucid  (op)
Fresh-Faced Recruit
Join Date: Jun 2002
Location: detroit
Status: Offline
Reply With Quote
Nov 2, 2003, 06:48 PM
 
wow i don't know anything about all this.
i just got netbarrier as it was well recommended, and after installing i went to the log and was astounded to see how much was actually going on. apparently edonkey was running and he had somehow set it in terminal to run in the background. i then freaked out and switched firewall to no network, shutting everything off. ran antivirus and left overnight. next day i was checking the firewall logs and found a couple of lines that blocked connection to tcpwrappers port 2#$%#. i haven't seen it since. i put ip on stop list and turned trojan blocking on in firewall. i don't know the port#, i don't know anything about networks and such. neither, really, does my brother who had adm priveledges. i haven't noticed anything weird on the machine and i really don't know what to do?

sorry for rambling and thanks for the responses...
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 06:10 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2