cancel
Showing results for 
Search instead for 
Did you mean: 

Backdoor / Subseven trojan

N/A

Backdoor / Subseven trojan

My Norton Firewall alerts me several times every day that my PC has been attacked by the Backdoor / Subseven Trojan. Checking the symantec site it only tells me that I should run Norton Antivirus to make sure that the Trojan isn't residing on my PC. I've scanned all my drives with the latest definition files and nothing shows up. This only started a few days ago, anyone know what is causing this?

tom
6 REPLIES
N/A

Backdoor / Subseven trojan

I have had about 10 alerts in the last 2 days.
Not sure what is going on as normally there were only a handful of alerts per month.
Just a coincidence ? or something a bit more sinister.
N/A

Backdoor / Subseven trojan

It say's here a spanish email
Run through the list of their recommendations and also run
Ad Aware.
Community Veteran
Posts: 3,181
Thanks: 19
Fixes: 2
Registered: 31-07-2007

Backdoor / Subseven trojan

if your firewall is blocking it then its doing its job. But do the necessary online virus/trojan checks but your firewall is doing its job.

One question, do you use online IRC/ICQ etc at all? If you do then you are more likely to get those probes as people harvest IP's from IRC etc and scan the IP blocks they find. So if say you use the sub7 capital irc aka quakenet you will get scanned every night your on and probably for a couple of weeks after until they move on to a new block of IP's.
Unvalued customer since 2001 funding cheap internet for others / DSL/Fibre house move 24 month regrade from 8th May 2017
N/A

Backdoor / Subseven trojan

Guess I'm not the only one then. Have not received the spanish e-mail, in fact haven't received any spam or virus e-mail for a good while now as I kill these on the server. Don't use ICQ or IRC, not even MSM.

Have run through Symantec's recommendations, as well as Adaware and Spybot S&D (highly recommended btw).

tom
N/A

Backdoor / Subseven trojan

i may be mistaken but i think the virus can be set by its creator to start doing things after a certain date
N/A

Backdoor / Subseven trojan

It is quite likely that the warnings are just reports of someone scanning your host on the usual Sub7 ports, but for safetys sake I would run a full scan off your system anyway.