Re: identifying malware process
"Voytek Eymont" <[email protected]>
| Newsgroups | gmane.org.user-groups.slug.chat |
|---|---|
| Message-ID | <[email protected]> |
On Mon, November 17, 2008 1:51 pm, Matthew Hannigan wrote: > On Mon, Nov 17, 2008 at 10:15:09AM +1100, Voytek Eymont wrote: >> when I clicked on the balloon, > > Don't click on balloons :-) thanks, Matt that was a deliberate click to identify malware process and files; I then killed the process before it concluded >> also, it cleaned up, BUT, I still get strange traffic on port 21260 to >> hosts all over the place, that I can not identify what it is > > You're still buggered then. the strange port 21260 traffic turned out to be from a dns component of bittorrent client > You should probably re-install, > but first you might avail yourself of the free downloads of real > antivirus, or malware removers, from say eset.com.au. I'll try that. I still have an executable in temp directory that I suspect started it all; so far Norton failed to identify it, I'll try the eset app -- Voytek -- SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/ Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html