[Dshield] SERV-Me Trojan horse?

David Bailey it1usnret at comcast.net
Wed Feb 5 08:18:03 GMT 2003


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Stupid question - what is the SERV-Me Trojan? Today was the first
time I have ever seen it. I use Norton Internet Security as my
firewall and going to Symantec Web Site, I could not find any
information on it. I get SubSeven trys all the time. I know what they
are but this one is throwing me for a loop. Any ideas?

Date: 2/4/03 Time: 12:05:09
Security alert displayed for rule Default Block SERV-Me Trojan horse.
Remote computer (200.158.168.72, 1581)

Date: 2/4/03 Time: 12:05:09
Rule "Default Block SERV-Me Trojan horse" blocked
(68.57.251.4,rmt(5555)).  Details:
Inbound TCP connection 
Local address,service is (68.57.251.4,rmt(5555))
Remote address,service is (200.158.168.72,1581)
Process name is "N/A"

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>

iQA/AwUBPkDIs0YMwZQxYr9pEQIq+ACfagnAtujWIMqyBiW71pnIWdM9n8sAoOif
SlFu24oUnZRsALVz/YzCXoMV
=rzxZ
-----END PGP SIGNATURE-----


More information about the list mailing list