# Virus/Trojan Horse question

**URL:** <https://boards.straightdope.com/t/virus-trojan-horse-question/129210>\
**Category:** Factual Questions\
**Created:** [September 23, 2002, 2:14am UTC](https://boards.straightdope.com/t/virus-trojan-horse-question/129210 "2002-09-23T02:14:08Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Omniscient](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/omniscient/32/3290_2.png) [@Omniscient](https://boards.straightdope.com/u/Omniscient)\
**Post date:** [September 23, 2002, 2:14am UTC](https://boards.straightdope.com/t/virus-trojan-horse-question/129210/1 "2002-09-23T02:14:08Z")

</div>

Hey computer geeks. I just installed Norton Internet Security 2002 (formerly Norton Personal Firewall) on my machine here. Its running Win2K Pro on a always-on cable modem without any physical firewall.

Anyways, since I’ve had it on I get an alert warning of “Default Block Backdoor/SubSeven Trojan horse”. It seems to happen almost constantly.

I’ll be the first to admit that while I’m somewhat used to the basics of computers and the internet I know absolutely nothing about networks and the concept of internet security.

What is this alert for? Should I be concerned? I haven’t been able to really learn anything from my web searches or from the Symantec site. Any advice or thoughts from you folks?

---

<div class="post-metadata">

**Author:** ![Duckster](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/duckster/32/1244_2.png) [@Duckster](https://boards.straightdope.com/u/Duckster)\
**Post date:** [September 23, 2002, 2:44am UTC](https://boards.straightdope.com/t/virus-trojan-horse-question/129210/2 "2002-09-23T02:44:31Z")

</div>

> [@](#):
>
> \*Originally posted by Omniscient \*  
> What is this alert for? Should I be concerned? I haven’t been able to really learn anything from my web searches or from the Symantec site. Any advice or thoughts from you folks?

Look harder. Found this in no time.

See [http://securityresponse.symantec.com/avcenter/venc/data/backdoor.subseven.22.a.html](http://securityresponse.symantec.com/avcenter/venc/data/backdoor.subseven.22.a.html)

You should be concerned: “Backdoor.Subseven.22.a acts as the server application that allows a remote user to control and retrieve information from your system. Some of the capabilities include searching, retrieving, and sending files, stealing passwords, changing the colors and resolution, playing sounds, and changing the date and time.”

---

<div class="post-metadata">

**Author:** ![Omniscient](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/omniscient/32/3290_2.png) [@Omniscient](https://boards.straightdope.com/u/Omniscient)\
**Post date:** [September 23, 2002, 5:36am UTC](https://boards.straightdope.com/t/virus-trojan-horse-question/129210/3 "2002-09-23T05:36:49Z")

</div>

Hmmm, thanks. Not sure what my problem was.

Anyways, this seems like what I ws seeing. I’ve scanned my computer a few times and it never reports finding any trojans. But it looks like the alert I’m getting is the the firewall blocking it from being downloaded. Which is good news since _I think_ I’m not infected, just trying to be infected.

> [@](#):
>
> Additional information:
> 
> Norton Internet Security/Norton Internet Protection users  
> If you are using either of these Symantec firewall programs, the name that is used by the Trojan Block rule to prevent the Trojan from being downloaded to your computer is different from the name that is used by Norton AntiVirus to detect the same threat if it were actually run on your computer or received in email.
> 
> Norton Internet Security/Norton Internet Protection will block Backdoor.SubSeven.22.a from being downloaded to your computer using the Block Rule Backdoor/SubSeven.

Though it makes me wonder, I was running for months without any security, and I must have been getting hit with these attempts. If so, why would I not be infected?

---

<div class="post-metadata">

**Author:** ![cls](https://avatars.discourse-cdn.com/v4/letter/c/e68b1a/32.png) [@cls](https://boards.straightdope.com/u/cls)\
**Post date:** [September 23, 2002, 8:19am UTC](https://boards.straightdope.com/t/virus-trojan-horse-question/129210/4 "2002-09-23T08:19:18Z")

</div>

The scans are people looking for computers that are _already_ infected with Subseven. If you aren’t infected with Subseven, they can’t do anything.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [September 23, 2002, 12:32pm UTC](https://boards.straightdope.com/t/virus-trojan-horse-question/129210/5 "2002-09-23T12:32:32Z")

</div>

My first thought would be that you have a trojan on your machine. Norton’s firewall can only block it; it doesn’t remove it. If it’s blocking it “contantly,” the odds are that it’s on your machine. Also, if the trojan is on your machine and running, Norton antivirus can’t clean it.

You can find information on how to clean it at [http://virusall.com/trojanclean.html](http://virusall.com/trojanclean.html)

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [September 23, 2002, 12:32pm UTC](https://boards.straightdope.com/t/virus-trojan-horse-question/129210/6 "2002-09-23T12:32:43Z")

</div>

My first thought would be that you have a trojan on your machine. Norton’s firewall can only block it; it doesn’t remove it. If it’s blocking it “constantly,” the odds are that it’s on your machine. Also, if the trojan is on your machine and running, Norton antivirus can’t clean it.

You can find information on how to clean it at [http://virusall.com/trojanclean.html](http://virusall.com/trojanclean.html)

---

<div class="post-metadata">

**Author:** ![Alereon](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@Alereon](https://boards.straightdope.com/u/Alereon)\
**Post date:** [September 23, 2002, 3:19pm UTC](https://boards.straightdope.com/t/virus-trojan-horse-question/129210/7 "2002-09-23T15:19:14Z")

</div>

Just to agree with **cls** , you are not infected. Those who wish to compromise other computers will generally scan large IP ranges constantly in search for infected machines. Machines that are infected will be logged for exploitation at a later date, nothing happens to those that aren’t. The same person will often scan frequently, and there are many people simultaneously running the same scans. This leads to a large number of probes every day. In conclusion, as long as you aren’t infected, these probes are harmless.

---

<div class="post-metadata">

**Author:** ![Omniscient](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/omniscient/32/3290_2.png) [@Omniscient](https://boards.straightdope.com/u/Omniscient)\
**Post date:** [September 23, 2002, 9:14pm UTC](https://boards.straightdope.com/t/virus-trojan-horse-question/129210/8 "2002-09-23T21:14:20Z")

</div>

I think the hamsters are getting up in years, I’ve been losing alot of posts lately.

**RealityChuck** , just to be safe I checked that website, and none of the registry keys they list in the removal instructions exist on my machine. Hopefully, I’m not infected. Why do you say that NAV wouldn’t be able to clean this? On the NAV website, the first step in their cleaning procedure is to run NAV to wipe it out.

All those probes certainly are annoying, I always get a IP address from the machine attempting to access me, should I do anything with that or report it to anyone?

---

<div class="post-metadata">

**Author:** ![Alereon](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@Alereon](https://boards.straightdope.com/u/Alereon)\
**Post date:** [September 24, 2002, 1:38am UTC](https://boards.straightdope.com/t/virus-trojan-horse-question/129210/9 "2002-09-24T01:38:36Z")

</div>

No, just ignore it. While technically port scanning is a crime, no one cares. The government doesn’t care enough to prosecute, and their ISP doesn’t care enough to stop taking their money. You’ll just have to get used to it.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [September 24, 2002, 1:43am UTC](https://boards.straightdope.com/t/virus-trojan-horse-question/129210/10 "2002-09-24T01:43:10Z")

</div>

> [@](#):
>
> \*Originally posted by Omniscient \*  
> \*\ ***RealityChuck** , just to be safe I checked that website, and none of the registry keys they list in the removal instructions exist on my machine. Hopefully, I’m not infected. Why do you say that NAV wouldn’t be able to clean this? On the NAV website, the first step in their cleaning procedure is to run NAV to wipe it out.  
> \*\*

If the trojan is running, antivirus software can’t clean it until you remove the registry keys and reboot. Windows doesn’t allow you to delete a running file.
