Shields Up security scans show that at various times of
the day my port 25 is open. Other times it is closed. My
isp is AOL and i use the AOL e-mail program.I also have a
Hotmail account but can only recieve Hotmail,I can not
send it because Outlook Express does not work with AOL. I
have scanned for trojans and found none(NORTON).I also
use Zone Alarm as my firewall.What could be causing port
25 to open and how do I close it. Thanks

Re: Port 25 open by Lanwench

Lanwench
Mon Apr 19 09:10:34 CDT 2004

It would be a setting in zone alarm. But I'd be concerned if your
workstation had something listening on port 25 - that's used for SMTP mail
traffic, and your workstation OS shouldn't have an SMTP server installed
unless you deliberately put one there. I'd do another scan at
http://housecall.antivirus.com for a second opinion.

On your computer, if you go to a command prompt and type

telnet localhost 25 <enter>

do you get a banner in reply?


Alan wrote:
> Shields Up security scans show that at various times of
> the day my port 25 is open. Other times it is closed. My
> isp is AOL and i use the AOL e-mail program.I also have a
> Hotmail account but can only recieve Hotmail,I can not
> send it because Outlook Express does not work with AOL. I
> have scanned for trojans and found none(NORTON).I also
> use Zone Alarm as my firewall.What could be causing port
> 25 to open and how do I close it. Thanks



Re: Port 25 open by N

N
Mon Apr 19 15:44:03 CDT 2004

In article <0e3501c42604$58e39110$a401280a@phx.gbl>,
anonymous@discussions.microsoft.com says...

> Shields Up security scans show that at various times of
> the day my port 25 is open. Other times it is closed.

That is suspicious.

> My isp is AOL and i use the AOL e-mail program.

Even more so because, AFAIK, AOL does not install any program which would be
listening on port 25.

> I also have a Hotmail account but can only recieve Hotmail,
> I can not send it because Outlook Express does not work with AOL.

MSOE requires HTTP access to the Hotmail servers for sending, as well as
receiving. Outgoing Hotmail messages don't go anywhere near port 25 when
using MSOE. Not really relevant to your problem, but I don't know why it
shouldn't work with AOL.

> I have scanned for trojans and found none(NORTON).

Norton? As in anti virus? Because I am not aware that Norton can find all
Trojans. And it certainly can't find proxies, which this is starting to look
like.

> I also use Zone Alarm as my firewall.

And ZA doesn't pop up a permission window when port 25 is active? Try
resetting ZA so it starts asking for permissions again, and pay close
attention to what is requesting server rights.

> What could be causing port 25 to open and how do I close it.

Not having access to your system, I can't say exactly. But it sounds like it
could be some kind of hijack of your system. If you can find the process
which is opening port 25, you can either kill it, if it is just a part of
the WinOS, or remove it, if it is something else.

If it really does appear to be a Trojan hijack, your best course is probably
to salvage your data and rebuild your system from scratch. Learn how you
were compromised so you can secure your rebuilt system.

--
Norman
~Win dain a lotica, En vai tu ri, Si lo ta
~Fin dein a loluca, En dragu a sei lain
~Vi fa-ru les shutai am, En riga-lint

Re: Port 25 open by Lem

Lem
Mon Apr 19 16:59:54 CDT 2004

Good information Norman. Thanks from all of us. I have a similar problem
on one of my computers, but Sheilds up always shows port 25 open. I am
using a Linksys router with NAT, so it shouldn't be a problem, just
wondering why port 25 should be open like that.. any ideas?

Thanks again for your knowledgable answers

N. Miller wrote:
> In article <0e3501c42604$58e39110$a401280a@phx.gbl>,
> anonymous@discussions.microsoft.com says...
>
>
>> Shields Up security scans show that at various times of
>>the day my port 25 is open. Other times it is closed.
>
>
> That is suspicious.
>
>
>>My isp is AOL and i use the AOL e-mail program.
>
>
> Even more so because, AFAIK, AOL does not install any program which would be
> listening on port 25.
>
>
>>I also have a Hotmail account but can only recieve Hotmail,
>>I can not send it because Outlook Express does not work with AOL.
>
>
> MSOE requires HTTP access to the Hotmail servers for sending, as well as
> receiving. Outgoing Hotmail messages don't go anywhere near port 25 when
> using MSOE. Not really relevant to your problem, but I don't know why it
> shouldn't work with AOL.
>
>
>>I have scanned for trojans and found none(NORTON).
>
>
> Norton? As in anti virus? Because I am not aware that Norton can find all
> Trojans. And it certainly can't find proxies, which this is starting to look
> like.
>
>
>>I also use Zone Alarm as my firewall.
>
>
> And ZA doesn't pop up a permission window when port 25 is active? Try
> resetting ZA so it starts asking for permissions again, and pay close
> attention to what is requesting server rights.
>
>
>>What could be causing port 25 to open and how do I close it.
>
>
> Not having access to your system, I can't say exactly. But it sounds like it
> could be some kind of hijack of your system. If you can find the process
> which is opening port 25, you can either kill it, if it is just a part of
> the WinOS, or remove it, if it is something else.
>
> If it really does appear to be a Trojan hijack, your best course is probably
> to salvage your data and rebuild your system from scratch. Learn how you
> were compromised so you can secure your rebuilt system.
>



Re: Port 25 open by Lanwench

Lanwench
Tue Apr 20 10:38:46 CDT 2004

Did you see my reply and my suggestion that you telnet to localhost on port
25 to see what's listening?

Lem Lo wrote:
> Good information Norman. Thanks from all of us. I have a similar
> problem on one of my computers, but Sheilds up always shows port 25
> open. I am using a Linksys router with NAT, so it shouldn't be a
> problem, just wondering why port 25 should be open like that.. any
> ideas?
>
> Thanks again for your knowledgable answers
>
> N. Miller wrote:
>> In article <0e3501c42604$58e39110$a401280a@phx.gbl>,
>> anonymous@discussions.microsoft.com says...
>>
>>
>>> Shields Up security scans show that at various times of
>>> the day my port 25 is open. Other times it is closed.
>>
>>
>> That is suspicious.
>>
>>
>>> My isp is AOL and i use the AOL e-mail program.
>>
>>
>> Even more so because, AFAIK, AOL does not install any program which
>> would be listening on port 25.
>>
>>
>>> I also have a Hotmail account but can only recieve Hotmail,
>>> I can not send it because Outlook Express does not work with AOL.
>>
>>
>> MSOE requires HTTP access to the Hotmail servers for sending, as
>> well as receiving. Outgoing Hotmail messages don't go anywhere near
>> port 25 when using MSOE. Not really relevant to your problem, but I
>> don't know why it shouldn't work with AOL.
>>
>>
>>> I have scanned for trojans and found none(NORTON).
>>
>>
>> Norton? As in anti virus? Because I am not aware that Norton can
>> find all Trojans. And it certainly can't find proxies, which this is
>> starting to look like.
>>
>>
>>> I also use Zone Alarm as my firewall.
>>
>>
>> And ZA doesn't pop up a permission window when port 25 is active? Try
>> resetting ZA so it starts asking for permissions again, and pay close
>> attention to what is requesting server rights.
>>
>>
>>> What could be causing port 25 to open and how do I close it.
>>
>>
>> Not having access to your system, I can't say exactly. But it sounds
>> like it could be some kind of hijack of your system. If you can find
>> the process which is opening port 25, you can either kill it, if it
>> is just a part of the WinOS, or remove it, if it is something else.
>>
>> If it really does appear to be a Trojan hijack, your best course is
>> probably to salvage your data and rebuild your system from scratch.
>> Learn how you were compromised so you can secure your rebuilt system.



Re: Port 25 open by Ozone

Ozone
Wed Apr 21 12:21:28 CDT 2004

IIS 5 installs the SMTP service if selected during the install of IIS. This
could be what is listening on that port. Also, take a look at active ports
http://www.webattack.com/get/activeports.shtml
to see what process is using that port.

HTH
Ozone
"Lanwench [MVP - Exchange]"
<lanwench@heybuddy.donotsendme.unsolicitedmail.atyahoo.com> wrote in message
news:uKeHt7uJEHA.232@TK2MSFTNGP12.phx.gbl...
> Did you see my reply and my suggestion that you telnet to localhost on
port
> 25 to see what's listening?
>
> Lem Lo wrote:
> > Good information Norman. Thanks from all of us. I have a similar
> > problem on one of my computers, but Sheilds up always shows port 25
> > open. I am using a Linksys router with NAT, so it shouldn't be a
> > problem, just wondering why port 25 should be open like that.. any
> > ideas?
> >
> > Thanks again for your knowledgable answers
> >
> > N. Miller wrote:
> >> In article <0e3501c42604$58e39110$a401280a@phx.gbl>,
> >> anonymous@discussions.microsoft.com says...
> >>
> >>
> >>> Shields Up security scans show that at various times of
> >>> the day my port 25 is open. Other times it is closed.
> >>
> >>
> >> That is suspicious.
> >>
> >>
> >>> My isp is AOL and i use the AOL e-mail program.
> >>
> >>
> >> Even more so because, AFAIK, AOL does not install any program which
> >> would be listening on port 25.
> >>
> >>
> >>> I also have a Hotmail account but can only recieve Hotmail,
> >>> I can not send it because Outlook Express does not work with AOL.
> >>
> >>
> >> MSOE requires HTTP access to the Hotmail servers for sending, as
> >> well as receiving. Outgoing Hotmail messages don't go anywhere near
> >> port 25 when using MSOE. Not really relevant to your problem, but I
> >> don't know why it shouldn't work with AOL.
> >>
> >>
> >>> I have scanned for trojans and found none(NORTON).
> >>
> >>
> >> Norton? As in anti virus? Because I am not aware that Norton can
> >> find all Trojans. And it certainly can't find proxies, which this is
> >> starting to look like.
> >>
> >>
> >>> I also use Zone Alarm as my firewall.
> >>
> >>
> >> And ZA doesn't pop up a permission window when port 25 is active? Try
> >> resetting ZA so it starts asking for permissions again, and pay close
> >> attention to what is requesting server rights.
> >>
> >>
> >>> What could be causing port 25 to open and how do I close it.
> >>
> >>
> >> Not having access to your system, I can't say exactly. But it sounds
> >> like it could be some kind of hijack of your system. If you can find
> >> the process which is opening port 25, you can either kill it, if it
> >> is just a part of the WinOS, or remove it, if it is something else.
> >>
> >> If it really does appear to be a Trojan hijack, your best course is
> >> probably to salvage your data and rebuild your system from scratch.
> >> Learn how you were compromised so you can secure your rebuilt system.
>
>



Re: Port 25 open by Lem

Lem
Wed Apr 28 20:26:48 CDT 2004

Thanks, I will try that. I also am using AOL as the ISP and both of the
computers I am using show port 25 open using SHIELDS UP.

Has anyone else seen problems AOL and port 25 being open?

Lanwench [MVP - Exchange] wrote:
> Did you see my reply and my suggestion that you telnet to localhost on port
> 25 to see what's listening?
>
> Lem Lo wrote:
>
>>Good information Norman. Thanks from all of us. I have a similar
>>problem on one of my computers, but Sheilds up always shows port 25
>>open. I am using a Linksys router with NAT, so it shouldn't be a
>>problem, just wondering why port 25 should be open like that.. any
>>ideas?
>>
>>Thanks again for your knowledgable answers
>>
>>N. Miller wrote:
>>
>>>In article <0e3501c42604$58e39110$a401280a@phx.gbl>,
>>>anonymous@discussions.microsoft.com says...
>>>
>>>
>>>
>>>>Shields Up security scans show that at various times of
>>>>the day my port 25 is open. Other times it is closed.
>>>
>>>
>>>That is suspicious.
>>>
>>>
>>>
>>>>My isp is AOL and i use the AOL e-mail program.
>>>
>>>
>>>Even more so because, AFAIK, AOL does not install any program which
>>>would be listening on port 25.
>>>
>>>
>>>
>>>>I also have a Hotmail account but can only recieve Hotmail,
>>>>I can not send it because Outlook Express does not work with AOL.
>>>
>>>
>>>MSOE requires HTTP access to the Hotmail servers for sending, as
>>>well as receiving. Outgoing Hotmail messages don't go anywhere near
>>>port 25 when using MSOE. Not really relevant to your problem, but I
>>>don't know why it shouldn't work with AOL.
>>>
>>>
>>>
>>>>I have scanned for trojans and found none(NORTON).
>>>
>>>
>>>Norton? As in anti virus? Because I am not aware that Norton can
>>>find all Trojans. And it certainly can't find proxies, which this is
>>>starting to look like.
>>>
>>>
>>>
>>>>I also use Zone Alarm as my firewall.
>>>
>>>
>>>And ZA doesn't pop up a permission window when port 25 is active? Try
>>>resetting ZA so it starts asking for permissions again, and pay close
>>>attention to what is requesting server rights.
>>>
>>>
>>>
>>>>What could be causing port 25 to open and how do I close it.
>>>
>>>
>>>Not having access to your system, I can't say exactly. But it sounds
>>>like it could be some kind of hijack of your system. If you can find
>>>the process which is opening port 25, you can either kill it, if it
>>>is just a part of the WinOS, or remove it, if it is something else.
>>>
>>>If it really does appear to be a Trojan hijack, your best course is
>>>probably to salvage your data and rebuild your system from scratch.
>>>Learn how you were compromised so you can secure your rebuilt system.
>>
>
>



Re: Port 25 open by Lem

Lem
Wed Apr 28 20:29:02 CDT 2004

Thanks Ozone. I will try webattack. How is it different from SHIELDS UP?

This was a new computer out of the box with AOL added. IIS is not
running as far as I can tell.

Any other ideas?

Ozone wrote:
> IIS 5 installs the SMTP service if selected during the install of IIS. This
> could be what is listening on that port. Also, take a look at active ports
> http://www.webattack.com/get/activeports.shtml
> to see what process is using that port.
>
> HTH
> Ozone
> "Lanwench [MVP - Exchange]"
> <lanwench@heybuddy.donotsendme.unsolicitedmail.atyahoo.com> wrote in message
> news:uKeHt7uJEHA.232@TK2MSFTNGP12.phx.gbl...
>
>>Did you see my reply and my suggestion that you telnet to localhost on
>
> port
>
>>25 to see what's listening?
>>
>>Lem Lo wrote:
>>
>>>Good information Norman. Thanks from all of us. I have a similar
>>>problem on one of my computers, but Sheilds up always shows port 25
>>>open. I am using a Linksys router with NAT, so it shouldn't be a
>>>problem, just wondering why port 25 should be open like that.. any
>>>ideas?
>>>
>>>Thanks again for your knowledgable answers
>>>
>>>N. Miller wrote:
>>>
>>>>In article <0e3501c42604$58e39110$a401280a@phx.gbl>,
>>>>anonymous@discussions.microsoft.com says...
>>>>
>>>>
>>>>
>>>>>Shields Up security scans show that at various times of
>>>>>the day my port 25 is open. Other times it is closed.
>>>>
>>>>
>>>>That is suspicious.
>>>>
>>>>
>>>>
>>>>>My isp is AOL and i use the AOL e-mail program.
>>>>
>>>>
>>>>Even more so because, AFAIK, AOL does not install any program which
>>>>would be listening on port 25.
>>>>
>>>>
>>>>
>>>>>I also have a Hotmail account but can only recieve Hotmail,
>>>>>I can not send it because Outlook Express does not work with AOL.
>>>>
>>>>
>>>>MSOE requires HTTP access to the Hotmail servers for sending, as
>>>>well as receiving. Outgoing Hotmail messages don't go anywhere near
>>>>port 25 when using MSOE. Not really relevant to your problem, but I
>>>>don't know why it shouldn't work with AOL.
>>>>
>>>>
>>>>
>>>>>I have scanned for trojans and found none(NORTON).
>>>>
>>>>
>>>>Norton? As in anti virus? Because I am not aware that Norton can
>>>>find all Trojans. And it certainly can't find proxies, which this is
>>>>starting to look like.
>>>>
>>>>
>>>>
>>>>>I also use Zone Alarm as my firewall.
>>>>
>>>>
>>>>And ZA doesn't pop up a permission window when port 25 is active? Try
>>>>resetting ZA so it starts asking for permissions again, and pay close
>>>>attention to what is requesting server rights.
>>>>
>>>>
>>>>
>>>>>What could be causing port 25 to open and how do I close it.
>>>>
>>>>
>>>>Not having access to your system, I can't say exactly. But it sounds
>>>>like it could be some kind of hijack of your system. If you can find
>>>>the process which is opening port 25, you can either kill it, if it
>>>>is just a part of the WinOS, or remove it, if it is something else.
>>>>
>>>>If it really does appear to be a Trojan hijack, your best course is
>>>>probably to salvage your data and rebuild your system from scratch.
>>>>Learn how you were compromised so you can secure your rebuilt system.
>>>
>>
>
>



Re: Port 25 open by S

S
Thu Apr 29 05:56:47 CDT 2004

There are numerous online port scanners - they all are pretty much the same.
But using netstat -an from local computer or telnetting to local TCP port
(telnet your_IP_address 25 for SMTP), as indicated by Lanwench , is a good
start. Or you can run a port scanner agains yourself!

--
Svyatoslav Pidgorny, MVP, MCSE
-= F1 is the key =-

"Lem Lo" <asdf@asdf.com> wrote in message news:40905A5E.9050602@asdf.com...
> Thanks Ozone. I will try webattack. How is it different from SHIELDS UP?
>
> This was a new computer out of the box with AOL added. IIS is not
> running as far as I can tell.
>
> Any other ideas?
>
> Ozone wrote:
> > IIS 5 installs the SMTP service if selected during the install of IIS.
This
> > could be what is listening on that port. Also, take a look at active
ports
> > http://www.webattack.com/get/activeports.shtml
> > to see what process is using that port.
> >
> > HTH
> > Ozone
> > "Lanwench [MVP - Exchange]"
> > <lanwench@heybuddy.donotsendme.unsolicitedmail.atyahoo.com> wrote in
message
> > news:uKeHt7uJEHA.232@TK2MSFTNGP12.phx.gbl...
> >
> >>Did you see my reply and my suggestion that you telnet to localhost on
> >
> > port
> >
> >>25 to see what's listening?
> >>
> >>Lem Lo wrote:
> >>
> >>>Good information Norman. Thanks from all of us. I have a similar
> >>>problem on one of my computers, but Sheilds up always shows port 25
> >>>open. I am using a Linksys router with NAT, so it shouldn't be a
> >>>problem, just wondering why port 25 should be open like that.. any
> >>>ideas?
> >>>
> >>>Thanks again for your knowledgable answers
> >>>
> >>>N. Miller wrote:
> >>>
> >>>>In article <0e3501c42604$58e39110$a401280a@phx.gbl>,
> >>>>anonymous@discussions.microsoft.com says...
> >>>>
> >>>>
> >>>>
> >>>>>Shields Up security scans show that at various times of
> >>>>>the day my port 25 is open. Other times it is closed.
> >>>>
> >>>>
> >>>>That is suspicious.
> >>>>
> >>>>
> >>>>
> >>>>>My isp is AOL and i use the AOL e-mail program.
> >>>>
> >>>>
> >>>>Even more so because, AFAIK, AOL does not install any program which
> >>>>would be listening on port 25.
> >>>>
> >>>>
> >>>>
> >>>>>I also have a Hotmail account but can only recieve Hotmail,
> >>>>>I can not send it because Outlook Express does not work with AOL.
> >>>>
> >>>>
> >>>>MSOE requires HTTP access to the Hotmail servers for sending, as
> >>>>well as receiving. Outgoing Hotmail messages don't go anywhere near
> >>>>port 25 when using MSOE. Not really relevant to your problem, but I
> >>>>don't know why it shouldn't work with AOL.
> >>>>
> >>>>
> >>>>
> >>>>>I have scanned for trojans and found none(NORTON).
> >>>>
> >>>>
> >>>>Norton? As in anti virus? Because I am not aware that Norton can
> >>>>find all Trojans. And it certainly can't find proxies, which this is
> >>>>starting to look like.
> >>>>
> >>>>
> >>>>
> >>>>>I also use Zone Alarm as my firewall.
> >>>>
> >>>>
> >>>>And ZA doesn't pop up a permission window when port 25 is active? Try
> >>>>resetting ZA so it starts asking for permissions again, and pay close
> >>>>attention to what is requesting server rights.
> >>>>
> >>>>
> >>>>
> >>>>>What could be causing port 25 to open and how do I close it.
> >>>>
> >>>>
> >>>>Not having access to your system, I can't say exactly. But it sounds
> >>>>like it could be some kind of hijack of your system. If you can find
> >>>>the process which is opening port 25, you can either kill it, if it
> >>>>is just a part of the WinOS, or remove it, if it is something else.
> >>>>
> >>>>If it really does appear to be a Trojan hijack, your best course is
> >>>>probably to salvage your data and rebuild your system from scratch.
> >>>>Learn how you were compromised so you can secure your rebuilt system.
> >>>
> >>
> >
> >
>
>



Re: Port 25 open by Lanwench

Lanwench
Tue May 04 14:36:14 CDT 2004

Lem Lo wrote:
> Thanks, I will try that. I also am using AOL as the ISP and both of
> the computers I am using show port 25 open using SHIELDS UP.
>
> Has anyone else seen problems AOL and port 25 being open?

No - port 25 is used for SMTP communication, and AOL doesn't even use that
for your own outbound mail. If something on your computer is listening on
port 25, it's an SMTP server and you can perhaps find out what it is by
telnet as I suggested.
>
> Lanwench [MVP - Exchange] wrote:
>> Did you see my reply and my suggestion that you telnet to localhost
>> on port 25 to see what's listening?
>>
>> Lem Lo wrote:
>>
>>> Good information Norman. Thanks from all of us. I have a similar
>>> problem on one of my computers, but Sheilds up always shows port 25
>>> open. I am using a Linksys router with NAT, so it shouldn't be a
>>> problem, just wondering why port 25 should be open like that.. any
>>> ideas?
>>>
>>> Thanks again for your knowledgable answers
>>>
>>> N. Miller wrote:
>>>
>>>> In article <0e3501c42604$58e39110$a401280a@phx.gbl>,
>>>> anonymous@discussions.microsoft.com says...
>>>>
>>>>
>>>>
>>>>> Shields Up security scans show that at various times of
>>>>> the day my port 25 is open. Other times it is closed.
>>>>
>>>>
>>>> That is suspicious.
>>>>
>>>>
>>>>
>>>>> My isp is AOL and i use the AOL e-mail program.
>>>>
>>>>
>>>> Even more so because, AFAIK, AOL does not install any program which
>>>> would be listening on port 25.
>>>>
>>>>
>>>>
>>>>> I also have a Hotmail account but can only recieve Hotmail,
>>>>> I can not send it because Outlook Express does not work with AOL.
>>>>
>>>>
>>>> MSOE requires HTTP access to the Hotmail servers for sending, as
>>>> well as receiving. Outgoing Hotmail messages don't go anywhere near
>>>> port 25 when using MSOE. Not really relevant to your problem, but I
>>>> don't know why it shouldn't work with AOL.
>>>>
>>>>
>>>>
>>>>> I have scanned for trojans and found none(NORTON).
>>>>
>>>>
>>>> Norton? As in anti virus? Because I am not aware that Norton can
>>>> find all Trojans. And it certainly can't find proxies, which this
>>>> is starting to look like.
>>>>
>>>>
>>>>
>>>>> I also use Zone Alarm as my firewall.
>>>>
>>>>
>>>> And ZA doesn't pop up a permission window when port 25 is active?
>>>> Try resetting ZA so it starts asking for permissions again, and
>>>> pay close attention to what is requesting server rights.
>>>>
>>>>
>>>>
>>>>> What could be causing port 25 to open and how do I close it.
>>>>
>>>>
>>>> Not having access to your system, I can't say exactly. But it
>>>> sounds like it could be some kind of hijack of your system. If you
>>>> can find the process which is opening port 25, you can either kill
>>>> it, if it is just a part of the WinOS, or remove it, if it is
>>>> something else.
>>>>
>>>> If it really does appear to be a Trojan hijack, your best course is
>>>> probably to salvage your data and rebuild your system from scratch.
>>>> Learn how you were compromised so you can secure your rebuilt
>>>> system.