Track down activity from ports 3120, 3466, 3470

  • Thread starter Thread starter Harvey Colwell
  • Start date Start date
H

Harvey Colwell

there is a better group for this to be posted to, please let me know.

I have McAfee AntiVirus Enterprise version installed. It is updated daily
and is configured to scan "All" files. I run SpyBot Search & Destroy on a
weekly. I have Windows XP firewall enabled. Our corporate LAN is behind a
Cisco router with the IOS firewall installed.

I just installed "Intrusion Catcher 2" and every time I open the web browser
I get several hits from various remote sites, port 80, trying to open a
connection to port 3120, 3466, or 3470 on my PC. All of these ports are
related to various backdoor Trojans.

I feel that my PC is clean, but I don't know how these remote sites would be
alerted that I'm going on-line unless I have some rouge program running on
it. I've used both TCPView and FPort to list the open ports and none of the
above ports are in use.

Is this a threat? Do I have a Trojan on my PC? How can I protect our PCs
from this attack/probe?

I'll put a packet sniffer on it as soon as I get some more time.


--
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Harvey Colwell --- SDS, Inc
Web: http://www.sds400.com/
Eml: (e-mail address removed)
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
 
It is normal for a web page with content from several domains to have
various IP addresses connecting back to your machine on your high
numbered ports. The ads usually come from different servers than the
main page.

Be suspicious of open listening high numbered ports on your system that
don't correspond to known Windows processes or other network
applications you have installed (like a web server). Those could be
trojans.
 
I finally got the time to put a packet sniffer on it. The main culprit was a
Domino Internet Explorer Tool Bar that was going out checking for an updated
configuration file. The rest seem to be normal web site sessions, that just
happen to be using the same ports as some Trojan programs.

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Harvey Colwell --- SDS, Inc
Web: http://www.sds400.com/
Eml: (e-mail address removed)
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
 
Back
Top