<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Virus infected PC on network - how to stop in Archive</title>
    <link>https://business.forums.bt.com/t5/Archive/Virus-infected-PC-on-network-how-to-stop/m-p/75522#M8736</link>
    <description>&lt;P&gt;Today I checked the Event Log in the BT Hub Manager for my BT Business Hub 5 and found something rather odd.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that every few seconds a UDP connection was being opened and then immediately closed from our static IP at port 16660 that originates at my PC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first thing I did was Google port 16660 and check what it might have been associated with. The first page that showed was&amp;nbsp;&lt;A target="_self" href="http://www.auditmypc.com/tcp-port-16660.asp"&gt;this&lt;/A&gt;, looks like malware named '&lt;SPAN&gt;Stacheldraht'&amp;nbsp;&lt;/SPAN&gt;that perhaps makes me part of a botnet or something similar.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran a malware scan using Malwarebytes, found something but was unrelated, followed by an AVG scan that found nothing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My PCs firewall is enabled, I don't know what would happen if I started deleting existing rules (not sure whether they'd respawn again so don't want to start throwing my hammer at it).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A target="_self" href="http://pastebin.com/feh7hv3C"&gt;Here&lt;/A&gt;&amp;nbsp;is what the log shows in just 20 seconds. Any ideas how&amp;nbsp;to get around this? If I'm part of a botnet and have a trojan/malware on my PC that's not being picked up by two of the top anti malware/anti virus protection programs, what chance have I got?&lt;/P&gt;</description>
    <pubDate>Sun, 28 Jun 2015 22:53:28 GMT</pubDate>
    <dc:creator>jskidd3</dc:creator>
    <dc:date>2015-06-28T22:53:28Z</dc:date>
    <item>
      <title>Virus infected PC on network - how to stop</title>
      <link>https://business.forums.bt.com/t5/Archive/Virus-infected-PC-on-network-how-to-stop/m-p/75522#M8736</link>
      <description>&lt;P&gt;Today I checked the Event Log in the BT Hub Manager for my BT Business Hub 5 and found something rather odd.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that every few seconds a UDP connection was being opened and then immediately closed from our static IP at port 16660 that originates at my PC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first thing I did was Google port 16660 and check what it might have been associated with. The first page that showed was&amp;nbsp;&lt;A target="_self" href="http://www.auditmypc.com/tcp-port-16660.asp"&gt;this&lt;/A&gt;, looks like malware named '&lt;SPAN&gt;Stacheldraht'&amp;nbsp;&lt;/SPAN&gt;that perhaps makes me part of a botnet or something similar.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran a malware scan using Malwarebytes, found something but was unrelated, followed by an AVG scan that found nothing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My PCs firewall is enabled, I don't know what would happen if I started deleting existing rules (not sure whether they'd respawn again so don't want to start throwing my hammer at it).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A target="_self" href="http://pastebin.com/feh7hv3C"&gt;Here&lt;/A&gt;&amp;nbsp;is what the log shows in just 20 seconds. Any ideas how&amp;nbsp;to get around this? If I'm part of a botnet and have a trojan/malware on my PC that's not being picked up by two of the top anti malware/anti virus protection programs, what chance have I got?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jun 2015 22:53:28 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Virus-infected-PC-on-network-how-to-stop/m-p/75522#M8736</guid>
      <dc:creator>jskidd3</dc:creator>
      <dc:date>2015-06-28T22:53:28Z</dc:date>
    </item>
  </channel>
</rss>

