Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Strange firewall alert - trojan?

 
   Security Forums (Home) -> General Discussions RSS
Next:  Trojan Horse Downloader.Agent (GJW, GBY) and Troj..  
Author Message
steve0029

External


Since: Dec 06, 2006
Posts: 1



(Msg. 1) Posted: Wed Dec 06, 2006 2:32 am
Post subject: Strange firewall alert - trojan?
Archived from groups: alt>comp>anti-virus (more info?)

Hi all,

I was wondering if I could get some of your opinions on what just
happened to me a little while ago.

I booted up my computer, and connected to the Internet. Upon connecting
My Avast AV program began to download updates as it normally does. Then
something odd happened that's never happned to me before.

I got an alert from my Sygate firewall (v5.6) that said:

---------
C:\Program Files\Alwil Software\Avast4\Setup\avast.setup - A Trojan
horse application has been detected on your computer. It has been
blocked by Sygate Personal Firewall

Trojan horse "IntrusePack 1.27b" detected in C:\Program Files\Alwil
Software\Avast4\Setup\avast.setup, process id: 3780
Description: Fail to terminate the process.
---------

Does this mean my firewall thought Avast was acting as a trojan? I do
scans for viruses and trojans regularly.. and did a few scans
immediately after I got this prompt and they all came up clean. I'm no
expert by any means, but this seems like a false positive to me. Has
anyone here had this happen to them? I'd greatly appreciate any and all
input.

Thank you,
--steve

Here are a few more details..

File Description : C:\Program Files\Alwil
Software\Avast4\Setup\avast.setup
File Path : C:\Program Files\Alwil Software\Avast4\Setup\avast.setup
Process ID : 0xEC4 (Heximal) 3780 (Decimal)

Connection origin : local initiated
Protocol : TCP
Local Address : 4.158.132.190
Local Port : 1069
Remote Name : download22.avast.com
Remote Address : 70.86.99.98
Remote Port : 80 (HTTP - World Wide Web)

 >> Stay informed about: Strange firewall alert - trojan? 
Back to top
Login to vote
Dr. Abraham van Helsing

External


Since: Dec 06, 2006
Posts: 1



(Msg. 2) Posted: Wed Dec 06, 2006 11:23 am
Post subject: Re: Strange firewall alert - trojan? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

70.86.99.98

http://www.arin.net/index.shtml

Enter the IP into the Whois Search Box, find out who it is, and then
make a determination, if the contact is malicious or not.

Google can give you information about the company, you can even call the
company.

I suspect it's Sygate and its Application Control whining about nothing.
All personal FW(s) that have App Control, tend to make the end-user
paranoid with much to do about nothing in most cases.

 >> Stay informed about: Strange firewall alert - trojan? 
Back to top
Login to vote
David H. Lipman

External


Since: Jul 04, 2003
Posts: 1727



(Msg. 3) Posted: Wed Dec 06, 2006 10:12 pm
Post subject: Re: Strange firewall alert - trojan? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: <steve0029 DeleteThis @gmail.com>

| Hi all,
|
| I was wondering if I could get some of your opinions on what just
| happened to me a little while ago.
|
| I booted up my computer, and connected to the Internet. Upon connecting
| My Avast AV program began to download updates as it normally does. Then
| something odd happened that's never happned to me before.
|
| I got an alert from my Sygate firewall (v5.6) that said:
|

< snnip >

False Positive.

It is misiterpreting Alwil Avast's communication with its respective update server.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm
 >> Stay informed about: Strange firewall alert - trojan? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Strange virus/trojan not detected - I didn't get any answer to this message nor it appeared within my message list. Probably lost. I'd appreciate to get additional information. Sorry for the length! After the first post I performed Internet scans with TrojanScan and Symantec. They didn't...

My firewall is not stopping trojan horse viruses - Hi everyone, I have a Windows 2000 PC set up as an FTP server, running the WS_FTP Server software. This PC does not have a floppy disk. Email access and Internet browser have been disabled. So the ONLY access to this PC from the outside world is thru...

My firewall is not stopping trojan horse viruses - Hi everyone, I have a Windows 2000 PC set up as an FTP server, running the WS_FTP Server software. This PC does not have a floppy disk. Email access and Internet browser have been disabled. So the ONLY access to this PC from the outside world is thru...

Virus: Firewall and antivirus, trojan scanners, .. disable.. - For any reason, Zone Alarm didn't rename a .PIF file attached to a message. Confusing it with a .TIF, and quite sure the work was correctly done by the firewall, I confidently clicked on the attachment and within the following microsecond I realized my....

Comments from users of Road Runners AV, Firewall and Spywa.. - > Road Runner Internet Security Package now includes Anti-Spyware > > Spyware is software that tracks online activity and often slows down computer performance. Anti-Spyware detects and removes a wide variety of spy...
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]