Author |
Topic: VTOT Trogan |
Recluse
From: Cleveland, Ohio, USA
|
Posted 23 Jul 2001 9:44 am
|
|
Help. I have been probed many times by
DNS:VTOT.proxy.aol.com
IP:205.188.146.146
It seems they put temporary trogan horse program on my machine and try to get some information. Black Ice Defender picks it up and tells me I have a Trojan Horse response then the machine locks. Norton Anti-Virus with the latest updates can not find any evidence of a virus. I have to restart to get the machine to run properly.
Any one know who the above address belongs to and any tips on how to stop them.
Your help will be greatly appreciated.
Thank You |
|
|
|
Jack Stoner
From: Kansas City, MO
|
Posted 23 Jul 2001 10:08 am
|
|
Dump the Black Ice and install Zone Alarm. It will block it and just give you an alert that it tried to access.
I've read several reviews on Black Ice and it didn't score well on any of the reviews.
Zone Alarm is available for free at www.zonealarm.com |
|
|
|
Jeff Agnew
From: Dallas, TX
|
Posted 23 Jul 2001 12:56 pm
|
|
Query: 205.188.146.146
Registry: whois.arin.net
Results:
America Online, Inc (NETBLK-AOL-DTC)
22080 Pacific Blvd
Sterling, VA 20166
US
Netname: AOL-DTC
Netblock: 205.188.0.0 - 205.188.255.255
Coordinator:
America Online, Inc. (AOL-NOC-ARIN) domains@AOL.NET
703-265-4670
Domain System inverse mapping provided by:
DNS-01.NS.AOL.COM 152.163.159.232
DNS-02.NS.AOL.COM 205.188.157.232
Record last updated on 27-Apr-1998.
Database last updated on 21-Jul-2001 23:13:10 EDT.
The IP itself is a dialup number in AOL's netblock but it's almost certainly spoofed. You should file a complaint with AOL, including a copy of your logs if available.
Also, an anti-virus program won't eliminate a trojan. Use an anti-trojan program like The Cleaner, or BOClean which is one of the best on the market. |
|
|
|
Recluse
From: Cleveland, Ohio, USA
|
Posted 27 Jul 2001 5:38 am
|
|
Not solved yet but you have sent me in tne right direction. Thanks for the help. |
|
|
|
Rich Paton
From: Santa Maria, CA.,
|
Posted 28 Jul 2001 5:29 pm
|
|
I recently upgraded to ZoneAlarm v. 2.6, which seems to be improved in handling local server (my PC, that is) issues. I just had a warning that "reg scan" wanted to access the internet.
Anyone have a take on this? I suspect it was my Netscape registry, but if on the other hand it was my W98SE's "regscan" app, I find that unsettling. What's the scoop on this, ye firewall gurus? |
|
|
|