cancel
Showing results for 
Search instead for 
Did you mean: 

bla trojan port 1042 help needed

N/A

bla trojan port 1042 help needed

hi guys
annoying problem here it is EVERY time i connect to the net i get my norton internet security 2005 saying that it as blocked a recent attemp to connect to my computer on port 1042 by the trojan bla (which uses that port) and it always shows the ip address in the alert, but its always MY ip address in the alert, so im trying to connect to my own computer on port 1042 bla port ?.this is the alert below.

" 12/09/2005 12:03:21,"Rule ""Default Block Bla Trojan horse"" blocked (84.93.159.47,1042).","Rule ""Default Block Bla Trojan horse"" blocked (84.93.159.47,1042). Inbound UDP packet. Local address,service is (localhost,1042). Remote address,service is (84.93.159.47,1042). Process name is ""N/A""."."

all safety programs are upto date scans show up nothing computer running as normal useing xp pro,firefox,spybot, adaware, norton internet security 2005, hijack this, cwshreader,stinger, ps this alert is only on entering the net there is no repeat even if i stay on it all night
6 REPLIES
N/A

bla trojan port 1042 help needed

Backdoor bla runs when windows starts and continues in the background. Symantec solution will tell you how to remove it.

Ewido is very good and it has a free trial too, i run the free version occasionally, it often catches my trojans . (disable norton while you do it)
N/A

bla trojan port 1042 help needed

hi bluebellhouse
thanks for the responce, i have now added trojan remover to my computer as well, and still nothing picked up even after searching the registry for hours i cant find anything.

as i said before it is stange that a computer with MY ip address is trying to access my computer on port 1042. but only on entering the net not later. the firewall is doing its job but it is annoying.

delilah
N/A

bla trojan port 1042 help needed

Have you run a scan with Ewido and followed the Symantec advice?
Which Trojan Remover did you use?

If so, you need someone much more expert than me Sad

Just an idea, and i really don't know if it could cause your problem, it still would appear that you have an infection , but could it be that you have got file sharing on? XP has it enabled by default. If you don't want to files share:

To disable simple file sharing:
1. Click Start, and then click My Computer.
2. On the Tools menu, click Folder Options, and then click the View tab.
3. In the Advanced Settings section, clear the Use simple file sharing (Recommended) check box.
4. Click OK.
Nicky
N/A

bla trojan port 1042 help needed

hi bluebellhouse
i followed symantec advice but found nothing anywhere even in registry, im using trogan remover 6.4.2 with latest update, and as you said i have disabled the simple file sharing that was set as default as i dont share my files so will try for a while and see,

thanks for your help much appreciated

binzy
N/A

bla trojan port 1042 help needed

Binzy, you have done the usual tick list, so last ditch attempt.
Ewido in safe mode?
Trojan cleaner in safe mode?
Click here if you don't know how to get into safe mode
have a look here
http://www.stevengould.org/software/cleanup/download.html
that could help, but follow the instructions. (I haven't used it myself, but others recommend it).
Also, system restore must be off when you clean, otherwise you re-infect your machine everytime you start up.
How to turn off sys restore

For interest and oerhaps a bit of help, read this article;
http://www.anti-trojan-software-reviews.com/

C'mon anyone else cleverer than me got any ideas?
N/A

bla trojan port 1042 help needed

hi bluebellhouse

thanks for your patience, this is the latest so far with my searching, i updated my firefox from 1.06 to the new 1.07 and uninstalled amor screen capture from computer to try to see if that was infected. and so far so good but it is early yet so although hijack this and my other stuff picked up nothing i thought i would uninstall stuff one by one to see if i could pin point it. its only day one so far but all ok so far,will post later on after more time,

cheers binzy