Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

What is Well-known TCP Port 999 for?

Status
Not open for further replies.

chucksel

IS-IT--Management
Sep 13, 2002
38
US
I noticed that I have port 999 open on a machine. What uses this port? I see that it is kisted as being for:

garcon 999/tcp
applix 999/udp Applix ac
puprouter 999/tcp
puprouter 999/udp


What are these apps/services?

Thanks! Chuck, MCSE
 
Assumng that you don't have Applix on the machine,
I would recommend virus scanning as this may likely be the keylogging service of the DeepThroat trojan.
Check also :6667 for trace of SubSeven.

Let me know if this proves useful.

 
WheeDoggy,

Thanks for the reply.

Well, I would hope that the latest engine and pattern (455) for my Trend Micro ServerProtect virus scanner that is running on this particular machine would catch this.

I am not running Applix on this Win2K server (at least I do not think so). What is Applix and how can I check? Chuck, MCSE
 
You can check out Applix here:

You might want to try some of the free online virus scans - Local virus scanners can become compromised and rendered ineffective. Trend Micro ( ) has a free online along with Symantec ( ) and McAfee FreeScan ( ).

I would advise firing up regedt32 and seeing if any strange programs are in the startup list (possibly systempatch.exe): HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Let me know how it goes.

Rgds
 
Nothing irregular in the HKLM\Software\Microsoft\Windows\CurrentVersion\Run hive.

Hmmmmmmmmmm. Chuck, MCSE
 
No Applix? If not you might want to block the tcp/udp 999 service with tcp filter/firewall as I am hard pressed to find any useful service other than Applix.

Have you tried the online virus scan yet?

FYI, other known SubSevens that use port 999 - f0replay & WinSatan.

Check the Run/RunServices keys in the reg under HKCU hive. Also check your CONFIG.SYS, AUTOEXEC.BAT, WINSTART.BAT, WIN.INI, for any strange apps loading.

Let us know........
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top