The Mudcat Café TM
Thread #97933   Message #1932920
Posted By: JohnInKansas
11-Jan-07 - 12:20 AM
Thread Name: Tech: Problem with a Mudcat thread
Subject: RE: Tech: Problem with a Mudcat thread
One more vote for nothing wrong with the thread. It opened normally for me (the whole thread rather than paging it) in IE7, with Norton Internet Security, and Microsoft XP firewall finding nothing wrong.

Back Door (BD) Bladerunner is an old trojan that should be blocked by Norton since sometime way back in 2000. with a signature update in 2002. It is possible that it might have gotten on your machine in something that was saved, and wasn't turned loose until the file that contained it was opened.

The warning you saw might have indicated that the trojan somewhere on your machine was attempting to open port 5400 to "talk to its master" - i.e. that the suspect action was from the inside of your machine rather than the from the outside via the thread(?).

Norton Tech Sheet has some info.

If you're confident enough, you can look in Regedit for the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

If the trojan is on your machine it will have added a value there:

System-Tray    <path to the server file>

The "path to the server file" will tell you where the bad file is located on your machine so that you can go delete the file. The key value should also be deleted from the registry.

Norton should be able to do all the "fixing" for you if you run a full system scan with current updates if this trojan is actually there. A warning sometimes will pop up if the infected file was deleted but the registry key value wasn't cleared when the file was deleted, so you may have to do some "interpreting" to clean things up manually.

The tech file page (link above) also has a link (on the right) to the online system scan by Norton that you might want to run, since it may be more thorough than the Norton you have installed if yours isn't one of the advanced versions.

John