Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Security > TROJ_AGENT.ALL

Reply
Thread Tools

TROJ_AGENT.ALL

 
 
Thund3rstruck_n0i
Guest
Posts: n/a
 
      01-30-2005
A friend of mine found TROJ_AGENT.ALL (As it is called on Trend Micro's
site) and ISTBAR on his PC. I've read up on istbar but Trend's site is
vague on how TROJ_AGENT.ALL is spread. Anyone know?

TIA

NOI

 
Reply With Quote
 
 
 
 
donnie
Guest
Posts: n/a
 
      01-30-2005
On Sat, 29 Jan 2005 21:29:50 -0500, Thund3rstruck_n0i
<> wrote:

> A friend of mine found TROJ_AGENT.ALL (As it is called on Trend Micro's
>site) and ISTBAR on his PC. I've read up on istbar but Trend's site is
>vague on how TROJ_AGENT.ALL is spread. Anyone know?
>
> TIA
>
> NOI

#################################
Most times the user clicked on an attachment but make sure file
sharing isn't enabled or that some service such as FTP isn't running.
donnie.
 
Reply With Quote
 
 
 
 
David H. Lipman
Guest
Posts: n/a
 
      01-30-2005
Trojans are spread by the stupidity of people downloading haphazardly crap off the Internet.
Trojans are NOT viruses and don't replicate.

--
Dave




"Thund3rstruck_n0i" <> wrote in message
newsyXKd.6250$...
| A friend of mine found TROJ_AGENT.ALL (As it is called on Trend Micro's
| site) and ISTBAR on his PC. I've read up on istbar but Trend's site is
| vague on how TROJ_AGENT.ALL is spread. Anyone know?
|
| TIA
|
| NOI
|


 
Reply With Quote
 
Thund3rstruck_n0i
Guest
Posts: n/a
 
      01-30-2005
David H. Lipman spilled my beer when they jumped on the table and proclaimed
in <XC_Kd.79$Xs6.49@trnddc01>

> Trojans are spread by the stupidity of people downloading haphazardly crap
> off the Internet. Trojans are NOT viruses and don't replicate.


Yeah...

Thanks Dave.

NOI


 
Reply With Quote
 
Thund3rstruck_n0i
Guest
Posts: n/a
 
      01-30-2005
donnie spilled my beer when they jumped on the table and proclaimed in
<>

> Most times the user clicked on an attachment but make sure file
> sharing isn't enabled or that some service such as FTP isn't running.
> donnie.


Thanks Donnie. I'll have him check for that.

NOI

 
Reply With Quote
 
ed
Guest
Posts: n/a
 
      01-30-2005
Dave wrote:


> Trojans are spread by the stupidity of people downloading haphazardly crap
> off the Internet.
> Trojans are NOT viruses and don't replicate.


Not entirely true, as I have a web server that has been compromised twice by
several back door Trojans. I do not download anything with the server and
can only presume it was hacked, which is the other way to get Trojans and
backdoors. It had all the MS OS updates applied, antivirus running, etc.

Since then, I have ran MS Baseline Security Analyzer on it and made all
possible changes

Also,

Applied an additional update to SQL Server
Applied an additional update to .Net
Changed the name of IUSR and IWAM Accounts
Removed the Admin account
Turned off NetBIOS

And still not sure if this will help, as I do not know how the server was
infected either time.


"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:XC_Kd.79$Xs6.49@trnddc01...
> Trojans are spread by the stupidity of people downloading haphazardly crap
> off the Internet.
> Trojans are NOT viruses and don't replicate.
>
> --
> Dave
>
>
>
>
> "Thund3rstruck_n0i" <> wrote in message
> newsyXKd.6250$...
> | A friend of mine found TROJ_AGENT.ALL (As it is called on Trend Micro's
> | site) and ISTBAR on his PC. I've read up on istbar but Trend's site is
> | vague on how TROJ_AGENT.ALL is spread. Anyone know?
> |
> | TIA
> |
> | NOI
> |
>
>



 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a
 
      01-30-2005
Servers are different. I should have stated user computers.

--
Dave




"ed" <> wrote in message news:vKbLd.582$...
| Dave wrote:
|
|
| > Trojans are spread by the stupidity of people downloading haphazardly crap
| > off the Internet.
| > Trojans are NOT viruses and don't replicate.
|
| Not entirely true, as I have a web server that has been compromised twice by
| several back door Trojans. I do not download anything with the server and
| can only presume it was hacked, which is the other way to get Trojans and
| backdoors. It had all the MS OS updates applied, antivirus running, etc.
|
| Since then, I have ran MS Baseline Security Analyzer on it and made all
| possible changes
|
| Also,
|
| Applied an additional update to SQL Server
| Applied an additional update to .Net
| Changed the name of IUSR and IWAM Accounts
| Removed the Admin account
| Turned off NetBIOS
|
| And still not sure if this will help, as I do not know how the server was
| infected either time.
|
|
| "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
| news:XC_Kd.79$Xs6.49@trnddc01...
| > Trojans are spread by the stupidity of people downloading haphazardly crap
| > off the Internet.
| > Trojans are NOT viruses and don't replicate.
| >
| > --
| > Dave
| >
| >
| >
| >
| > "Thund3rstruck_n0i" <> wrote in message
| > newsyXKd.6250$...
| > | A friend of mine found TROJ_AGENT.ALL (As it is called on Trend Micro's
| > | site) and ISTBAR on his PC. I've read up on istbar but Trend's site is
| > | vague on how TROJ_AGENT.ALL is spread. Anyone know?
| > |
| > | TIA
| > |
| > | NOI
| > |
| >
| >
|
|


 
Reply With Quote
 
winged
Guest
Posts: n/a
 
      02-02-2005
ed wrote:
> Dave wrote:
>
>
>
>>Trojans are spread by the stupidity of people downloading haphazardly crap
>>off the Internet.
>>Trojans are NOT viruses and don't replicate.

>
>
> Not entirely true, as I have a web server that has been compromised twice by
> several back door Trojans. I do not download anything with the server and
> can only presume it was hacked, which is the other way to get Trojans and
> backdoors. It had all the MS OS updates applied, antivirus running, etc.
>
> Since then, I have ran MS Baseline Security Analyzer on it and made all
> possible changes
>
> Also,
>
> Applied an additional update to SQL Server
> Applied an additional update to .Net
> Changed the name of IUSR and IWAM Accounts
> Removed the Admin account
> Turned off NetBIOS
>
> And still not sure if this will help, as I do not know how the server was
> infected either time.
>
>
> "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
> news:XC_Kd.79$Xs6.49@trnddc01...
>
>>Trojans are spread by the stupidity of people downloading haphazardly crap
>>off the Internet.
>>Trojans are NOT viruses and don't replicate.
>>
>>--
>>Dave
>>
>>
>>
>>
>>"Thund3rstruck_n0i" <> wrote in message
>>newsyXKd.6250$.. .
>>| A friend of mine found TROJ_AGENT.ALL (As it is called on Trend Micro's
>>| site) and ISTBAR on his PC. I've read up on istbar but Trend's site is
>>| vague on how TROJ_AGENT.ALL is spread. Anyone know?
>>|
>>| TIA
>>|
>>| NOI
>>|
>>
>>

>
>
>

Sure hope you did a clean build on the server else you probably are
still compromised. You should ensure your SQL server is constrained to
only talk to the web host and possibly admin terms and block SQL server
access at the firewall. Ideally the sq server is on a separate box else
wise run sq server on a virtual IP. It is not good practice to do
client side processing with exposed SQL services. .NET introduces a
whole gambit of security issues into the mix. For example there are a
number of calls where .NET works with client side MS apps where code can
be induced into the system. This usually requires an authenticated
user. This is why a number of major players in the .NET community have
been dumping .NET If the compromise is properly executed the "bad guy"
trojaned other connecting clients to make re-exploit easier. We have
found .NET can have significant issues if improperly implemented and
improperly restricted.

Winged
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off




Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57