Comteck Anti-Virus Information
  Home | Statistics | Encyclopedia | Online Resources | Software

Trojans and Firewalls

Protection from trojans can go a little further. The modern day Internet Trojan's primary purpose is to install a backdoor so that others can gain access to your PC across the Internet, WITHOUT your knowledge. What they can do, once there, is determined by what trojan they installed. The latest trojans allow the attacker almost unlimited control over your PC, including deleting files, editing the registry, executing programs, ftp files in/out, monitoring your actions, stealing password files and other sensitive information, and many other functions. Port scanners have been written that make it easy for even a novice (called script kiddies) to find if you have a trojan installed. They scan large numbers of IP address', extremely fast, looking for installed trojans. Firewalls like Zone Alarm and BlackICE, Port Monitors like NukeNabber, Attacker, and PortWatch, and Proxies are effective tools to help you detect and block access to your PC. Most antivirus software companies also make firewall products. Microsoft's XP comes with a built in firewall. If you install a monitoring tool, and you get warned of a scan by the program, don't get to excited. As I mentioned before, it is easy for a novice to scan thousands of IP address quickly. It happens all the time. A recent court ruling by the US District Court in Georgia, CIVIL ACTION FILE NO. 1:00-CV-434-TWT found that simply Port Scanning itself is not illegal, there was no damage or impairment, and any cost associated with investigation and prevention are not recoverable. Basically it's like someone walking through a parking lot checking car doors to see if they are locked. That act itself is not illegal. If they actually enter an unlocked car, at best it's trespassing. If they cause damage or theft, now that is illegal. With a computer it is much harder to prove damage and theft and trespassing is a misdemeaner. DO NOT call our tech support to report that you have been scanned, there is very little we can do. Like SPAM E-Mail, any attempt to block the person that scanned you, may also block ligitimate traffic from that ISP. You can find the ISP they belong to and send them a copy of your logs asking that they look into it. If they get enough compaints, and they can track it to the same individual, they will probably cancel their account.


Virus and Trojans
Most Common
Transmission
Protection
Firewalls
Current Threats
Hoaxes





 © 2002 Comteck of Indiana, Inc.

.