| General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun! |
| Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
 |
GNU/Linux Basic Guide
This 255-page guide will provide you with the keys to understand the philosophy of free software, teach you how to use and handle it, and give you the tools required to move easily in the world of GNU/Linux. Many users and administrators will be taking their first steps with this GNU/Linux Basic guide and it will show you how to approach and solve the problems you encounter.
Click Here to receive this Complete Guide absolutely free. |
|
 |
01-20-2006, 09:33 AM
|
#1
|
|
Member
Registered: Jul 2005
Location: Australia
Distribution: Debian
Posts: 113
Rep:
|
Intrusion Problem!!
Hello again,
I have an intrusion problem, it's to do with when I open firefox, it always connects to a site... namely msxsecurity.com on port 1028 and 1027. I do not know how to close it or get rid of what is doing it, can some one please give some support on this topic thanks.
Here is an image link to what I am seeing as I start up firefox.
http://putfile.com/pic.php?pic=1/1909321511.jpg&s=x12
Thanks Again 
|
|
|
|
01-20-2006, 04:31 PM
|
#2
|
|
Senior Member
Registered: Nov 2002
Location: Edmonton AB, Canada
Distribution: Gentoo x86; Gentoo PPC; Gentoo Sparc64; FreeBSD; OS X; Solaris
Posts: 3,731
Rep:
|
msxsecurity.com seems to be some sort of site for gaming cheats. Are you a gamer? Did you purchase a hack from this site? If not, looks like you may be part of someone's botnet...
A quick scan reveals:
Code:
PORT STATE SERVICE
1027/tcp filtered IIS
1028/tcp filtered unknown
1027 is not a registered port, but they seem to be running some sort of web server there. I could not connect when I attempted (it timed out).
Can you not set up your firewall to block these connections?
Last edited by bulliver; 01-20-2006 at 04:32 PM.
|
|
|
|
01-20-2006, 09:21 PM
|
#3
|
|
Member
Registered: Jul 2005
Location: Australia
Distribution: Debian
Posts: 113
Original Poster
Rep:
|
Is there a way I can block a port with cmd?
|
|
|
|
01-20-2006, 09:29 PM
|
#4
|
|
Senior Member
Registered: Mar 2003
Location: Following the white rabbit
Distribution: Slackware64 13.37 Android 4.0
Posts: 2,244
Rep:
|
Troj/AdClick-AV is a Trojan for the Windows platform that attempts to connect to various websites and then display selected banner advertisements.
Troj/AdClick-AV queries the www.msxsecurity.com in attempt to open redirect.php, a script file that contains redirect instructions.
You should be able to clean this with a decent AV app.
Last edited by masonm; 01-20-2006 at 09:30 PM.
|
|
|
|
01-24-2006, 02:37 PM
|
#5
|
|
Member
Registered: Jul 2005
Location: Australia
Distribution: Debian
Posts: 113
Original Poster
Rep:
|
I have another picture of what has happened but this time it's a picture of a BitDefender Firewall complaining about www.msxsecurity.com accessing the Internet. But the terrible thing is that when I don't allow it access, I can not use firefox, because it blocks the firefox.exe program and not just the ports that site is using.
Here is that picture of BitDefender Firewall complaining.
http://putfile.com/pic.php?pic=1/2314380743.jpg&s=x4
Some more help would be good... any recommendations on some good port blocking firewalls?
Last edited by InvisibleSniper; 01-24-2006 at 02:43 PM.
|
|
|
|
01-25-2006, 02:22 PM
|
#6
|
|
Member
Registered: Jul 2005
Location: Australia
Distribution: Debian
Posts: 113
Original Poster
Rep:
|
Hi again,
I tried to tracert LocalHost today... in other words I tried the command:
tracert 127.0.0.1 and for some reason the only traced path it gave me was www.msxsecurity.com. Can someone please tell me what is going on and how I can fix it please. Thanks All.
Also here is a screen shot of a cmd after I tried to tracert the local host.
http://putfile.com/pic.php?pic=1/2414210365.jpg&s=x4
|
|
|
|
01-26-2006, 08:45 AM
|
#7
|
|
Guru
Registered: May 2003
Location: London, UK
Distribution: Ubuntu 10.04, mostly
Posts: 6,002
|
InvisibleSniper,
Your screenshots show that you are running windows.
So why are you asking questions on a linux forum?
Edit: I realise that this is "General", but I think you'd get better advice from a windows forum.
Last edited by tredegar; 01-26-2006 at 08:51 AM.
|
|
|
|
01-26-2006, 09:31 AM
|
#8
|
|
Member
Registered: Mar 2005
Location: singapore
Distribution: puppy and Ubuntu and ... erh ... redhat(sort of) :( ... + the venerable bsd and solaris ^_^
Posts: 658
Rep:
|
if you wanted to , probably you can try these two app for xp if you had not came across them already ::
Starter
and
ProcessExplorer
the first one may show you some unwarranted startups in your machine(can choose to temp. disable or delete them) while the second one probably will help you in tracing the location of troublesome app/services but beware of the first one though ...
not really an answer but hope it helps ...
.
|
|
|
|
| Thread Tools |
Search this Thread |
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -5. The time now is 07:54 AM.
|
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|