Ask the Expert

Information on Trojan backdoor g-1

My firewall has detected infection by Trojan backdoor-g-1. It uses port 1243. Neither Symntec nor McAfee has a definition or recognition of this Trojan. Have you heard of it? What do you know of it?

    Requires Free Membership to View

My general rule of thumb when confronted with a new virus, Trojan or worm, is to take a look at what a number of antivirus companies are saying about it.

Searching on Google is a good way to find out if someone has written something, and most antivirus and other malware-detection companies now offer online encyclopedias one can search. One problem that arises is that antivirus companies, after complaints from users for more than 10 years, still do not use the same name for each critter. Maybe the user community needs to start a petition?

In any case, you should be aware that antivirus software is not generally the best at detecting Trojans. There are more specialized companies working in this arena, such as PestPatrol and Spybot.

Not knowing which firewall you are using, it would seem that it has detected "Backdoor/SubSeven Trojan". Here is some info on it:

For more information on this topic, visit these other resources:
  • Ask the Expert: Removing Trojan not detected by antivirus software
  • Ask the Expert: Finding a Trojan horse on a home computer
  • Virus Prevention Tip: Backdoor Trojan making the rounds

    This was first published in February 2003

  • There are Comments. Add yours.

    TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

    REGISTER or login:

    Forgot Password?
    By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
    Sort by: OldestNewest

    Forgot Password?

    No problem! Submit your e-mail address below. We'll send you an email containing your password.

    Your password has been sent to: