I have been geeting chronic port scan attacks from remote
address 127.0.0.1 port 20480 ever since I did Christmas
shopping.How do I stop this and who do I report this to?I
have a firewall that has intercepted all so far as I know
but sooner or later???Thanks so much for any help.

Re: port scan attacks by PA

PA
Fri Feb 27 21:33:01 CST 2004

tom c. wrote:
> I have been geeting chronic port scan attacks from remote
> address 127.0.0.1 port 20480 ever since I did Christmas
> shopping.How do I stop this and who do I report this to?I
> have a firewall that has intercepted all so far as I know
> but sooner or later???Thanks so much for any help.

Check your system for "hijackware":

Dealing with Hijackware
http://mvps.org/winhelp2002/unwanted.htm
http://www.mvps.org/inetexplorer/Darnit.htm#tshoot
http://aumha.org/a/parasite.htm

CoolWebSearch Chronicles
http://www.merijn.org/cwschronicles.html

You *must* seek updates for Ad-Aware, Spybot, etc., before each and every
use, even "right out of the box". But even then, they can't catch
everything. When all else fails, HijackThis
(http://www.merijn.org/files/hijackthis.zip) is the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware. **Post
your files to http://forums.spywareinfo.com/ or the Spyware forum at
http://forum.aumha.org/ for expert analysis, not here.**

Also update your virus definitions and then run a full system scan. From
now on, do both daily.

[Many anti-spyware sites continue to suffer from a week-long DoS attack.
Alternative download pages for Ad-Aware, Spybot, HijackThis and CWShredder
may be found on this page: http://aumha.org/a/parasite.htm.]

So How Did I Get Infected Anyway?
http://boards.cexx.org/viewtopic.php?t=957
--
HTH - Please Reply to This Thread

~Robear Dyer (PA Bear)
MS MVP-Windows (IE/OE), AH-VSOP

AumHa Forums
http://forum.mvps.org/

Protect Your PC
http://www.microsoft.com/security/protect


Re: port scan attacks by N

N
Sat Feb 28 03:28:03 CST 2004

In article <381a01c3fda2$09df1510$a301280a@phx.gbl>, goodfeelintoknow@msn
says...
> I have been geeting chronic port scan attacks from remote
> address 127.0.0.1 port 20480 ever since I did Christmas
> shopping.How do I stop this and who do I report this to?I
> have a firewall that has intercepted all so far as I know
> but sooner or later???Thanks so much for any help.

Just an F.Y.I. (I can't improve upon PA Bear's advice; he is just too good
for me!), IP address 127.0.0.1, a.k.a. "localhost", is actually on your
computer. Also called the "loopback", it is used when some application is
doing something akin to talking to itself; that connection is not going to
the Internet. This doesn't negate the advice to check for spyware/adware,
but not all loopback connections are malicious. I have at least two programs
which loopback normally; Mozilla 1.6, the "other browser", and Kerio
Personal Firewall 2.1.5.

Again, apparently PA Bear knows something suspicious about that port number,
20480. It is not familiar to me, and my loopback apps don't use it. So that
must be the suspicious sign which triggered the spyware removal advice. But
I just wanted to point out that you need to know at least a little about
things that can happen on your computer.

--
Norman
~Win dain a lotica, En vai tu ri, Si lo ta
~Fin dein a loluca, En dragu a sei lain
~Vi fa-ru les shutai am, En riga-lint

port scan attacks by John

John
Sun Feb 29 00:34:15 CST 2004


>-----Original Message-----
>I have been geeting chronic port scan attacks from remote
>address 127.0.0.1 port 20480 ever since I did Christmas
>shopping.How do I stop this and who do I report this to?I
>have a firewall that has intercepted all so far as I know
>but sooner or later???Thanks so much for any help.
>.
I did a search on MSN (prot 20480) and this came up.
(LiveVault TSCON PICI utility)

LiveVault Is a firewall are you using it ??

If you are type (prot 20480) in MSN search and hit enter
to read about it.

RE: port scan attacks by anonymous

anonymous
Sun Feb 29 15:01:09 CST 2004

As Miller said, loopback address. 127*.*.* addresses are usually nothing to worry about.

But I can say that TCP port 20480 is used by trojan "Trojan.Adnap". You should have a file on your system partition called FPanda.exe. Your autoexec.bat is also modified
An updated AV should detect and remove it. If not there are plenty of sites taking you through the steps of removing it manually.