# Backdoor Trojan

**URL:** <https://boards.straightdope.com/t/backdoor-trojan/77174>\
**Category:** Factual Questions\
**Created:** [August 20, 2001, 4:47pm UTC](https://boards.straightdope.com/t/backdoor-trojan/77174 "2001-08-20T16:47:50Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![PlanMan](https://avatars.discourse-cdn.com/v4/letter/p/2bfe46/32.png) [@PlanMan](https://boards.straightdope.com/u/PlanMan)\
**Post date:** [August 20, 2001, 4:47pm UTC](https://boards.straightdope.com/t/backdoor-trojan/77174/1 "2001-08-20T16:47:50Z")

</div>

I have a Firewall on my cable connection. I get very frequent alerts for a “Default Block Backdoor/SubSeven Trojan”? What the heck is it, and why is it so frequent. Besides the very idea of a Trojan at my back door is unsettling.

At the risk of making this non-GQ, does anyone else get these, with frequency?

Thank You.

---

<div class="post-metadata">

**Author:** ![bernse](https://avatars.discourse-cdn.com/v4/letter/b/a9a28c/32.png) [@bernse](https://boards.straightdope.com/u/bernse)\
**Post date:** [August 20, 2001, 4:48pm UTC](https://boards.straightdope.com/t/backdoor-trojan/77174/2 "2001-08-20T16:48:46Z")

</div>

Heh. Backdoor trojan.

Heh. heh.

---

<div class="post-metadata">

**Author:** ![breaknrun](https://avatars.discourse-cdn.com/v4/letter/b/bbce88/32.png) [@breaknrun](https://boards.straightdope.com/u/breaknrun)\
**Post date:** [August 20, 2001, 4:57pm UTC](https://boards.straightdope.com/t/backdoor-trojan/77174/3 "2001-08-20T16:57:33Z")

</div>

Any computer on the Internet gets port scanned and probed frequently. Check out [http://www.sans.org/newlook/resources/IDFAQ/subseven.htm](http://www.sans.org/newlook/resources/IDFAQ/subseven.htm) for more info about subseven. Keep your firewall up to date and patch your systems regularly and you should be ok.

---

<div class="post-metadata">

**Author:** ![robby](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/robby/32/11048_2.png) [@robby](https://boards.straightdope.com/u/robby)\
**Post date:** [August 20, 2001, 5:00pm UTC](https://boards.straightdope.com/t/backdoor-trojan/77174/4 "2001-08-20T17:00:41Z")

</div>

Start with a [search](http://boards.straightdope.com/sdmb/showthread.php?threadid=76965)…

Has some info, including making fun of the term “backdoor trojan” (my contribution). 🙂

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [August 20, 2001, 5:00pm UTC](https://boards.straightdope.com/t/backdoor-trojan/77174/5 "2001-08-20T17:00:58Z")

</div>

Use a virus checker (they look for trojans, too) to see if you have one (try [http://housecall.antivirus.com](http://housecall.antivirus.com)). If you do, and Housecall doesn’t remove it, there are instructions at [Hackfix.](http://www.hackfix.org)

---

<div class="post-metadata">

**Author:** ![NotMrKnowItAll](https://avatars.discourse-cdn.com/v4/letter/n/6bbea6/32.png) [@NotMrKnowItAll](https://boards.straightdope.com/u/NotMrKnowItAll)\
**Post date:** [August 20, 2001, 5:19pm UTC](https://boards.straightdope.com/t/backdoor-trojan/77174/6 "2001-08-20T17:19:15Z")

</div>

For a fun read on how subseven can really screw up your day, go to [http://www.grc.com](http://www.grc.com) . Poor old Steve Gibson upset some thirteen year old and he launched a number of DDOS attacks on Gibson’s web site. Code Red II is pretty active, at least up to today (20th), I fear the hackers are going to spoil everything for everyone.

---

<div class="post-metadata">

**Author:** ![breaknrun](https://avatars.discourse-cdn.com/v4/letter/b/bbce88/32.png) [@breaknrun](https://boards.straightdope.com/u/breaknrun)\
**Post date:** [August 20, 2001, 5:19pm UTC](https://boards.straightdope.com/t/backdoor-trojan/77174/7 "2001-08-20T17:19:55Z")

</div>

Do not rely on virus checkers to catch trojans. The link I posted previously specifically mentions that a lot of virus checkers will not detect sub7. I’m not that familiar with Windows but in Unix, a lot of attacks involve replacing standard system binaries with compromised versions hide traces of the trojan. Eg. you can’t see a trojan process running because the binary that lists system processes was replaced with one that will not list the trojan.

---

<div class="post-metadata">

**Author:** ![Hanna](https://avatars.discourse-cdn.com/v4/letter/h/b3f665/32.png) [@Hanna](https://boards.straightdope.com/u/Hanna)\
**Post date:** [August 20, 2001, 6:19pm UTC](https://boards.straightdope.com/t/backdoor-trojan/77174/8 "2001-08-20T18:19:00Z")

</div>

The Cleaner, from [Moosoft](http://www.moosoft.com) can catch trojans. You can d/l a free 30 day trial.
