Flux rss
Bookmark Bookmark & Share
Introduzione ai cavalli di Troia Introdução aos cavalos de Tróia Einführung von den Pferden von Troja Introduction aux chevaux de Troie Introducción a los Troyanos

Trojan horses

A Trojan horse is a computer program which carries out malicious operations without the user's knowledge. The name "Trojan horse" comes from a legend told in the Iliad (by the writer Homer) about the siege of the city of Troy by the Greeks.

Legend has it that the Greeks, unable to penetrate the city's defences, got the idea to give up the siege and instead give the city a giant wooden horse as a gift offering.

The Trojans (the people of the city of Troy) accepted this seemingly harmless gift and brought it within the city walls. However, the horse was filled with soldiers, who came out at nightfall, while the town slept, to open the city gates so that the rest of the army could enter.

Thus, a Trojan horse (in the world of computing) is a hidden program which secretly runs commands, and usually opens up access to the computer running it by opening a backdoor. For this reason, it is sometimes called a Trojan by analogy to the citizens of Troy.

Like a virus, a Trojan horse is a piece of harmful code placed within a healthy program (like a false file-listing command, which destroys files instead of displaying the list).

A Trojan horse may, for example:

  • steal passwords;
  • copy sensitive date;
  • carry out any other harmful operations;
  • etc.

Worse, such a program can create an intentional security breach within your network, so as give outside users access to protected areas on the network.

The most common Trojan horses open machine ports, allowing their designer to gain entry to your computer over the network by opening a backdoor or backorifice.

A Trojan horse is not necessarily a virus, as its goal is not to reproduce itself to infect other machines. On the other hand, some viruses may also be Trojan horses; that is, they might spread like viruses and open ports on infected machines!

Detecting such a program is difficult because you must be able to determine whether an action is being carried out by the Trojan horse or by the user.

Symptoms of infection

Infection by a Trojan horse usually comes after opening a contaminated file containing the Trojan horse (see the article on protecting yourself from worms) and is indicated by the following symptoms:

  • Abnormal activity by the modem, network adapter or hard drive: data is being loaded without any activity from the user;
  • Strange reactions from the mouse;
  • Programs opening unexpectedly;
  • Repeated crashes.

Principle of a Trojan horse

As a Trojan horse is usually (and increasingly) intended to open a port on your machine so that a hacker can gain control of it (such as by stealing personal data stored on the hard drive), the hacker's goal is to first infect your machine by making you open an infected file containing the Trojan and then to access your machine through the opened port.

However, to be able to infiltrate your machine, the hacker normally has to know its IP address. So:

  • Either you have a fixed IP address (as with businesses, or with individuals with a cable or similar connection, etc.) in which case your IP address can easily be discovered;
  • or your IP address is dynamic (reassigned each time you connect), as with modem connections; in which case the hacker must scan IP addresses at random in order to detect those which correspond to infected machines.

Protect yourself from Trojans

Installing a firewall (a program which filters data entering and leaving your machine) is enough to protect you from this kind of intrusion. A firewall monitors both data leaving your machine (normally initiated by the programs you are using) and data entering it. However, the firewall may detect unknown outside connections even if a hacker is not specifically targeting you.. They may be tests carried out by your Internet service provider, or a hacker randomly scanning a range of IP addresses.

For Windows systems, there are two free high-performance firewalls:

In case of infection

If a program whose origins you are unsure of attempts to open a connection, the firewall will ask you to confirm it before initiating the connection. It is important to not authorise connections for a program you don't recognise, because it might very well be a Trojan horse.

If this reoccurs, it may be helpful to check that your computer isn't affected by a Trojan, by using a program that detects and deletes them (called an anti-Trojan).
One example is The Cleaner, which can be downloaded from http://www.moosoft.com.

List of ports commonly used by Trojans

Trojan horses commonly open a port on the infected machine and wait for a connection to open on that port, so that hackers will be able to gain total control over the computer. Here is a (non exhaustive) list of the most common ports used by Trojan horses (source: Site de Rico):

port Trojan
21 Back construction, Blade runner, Doly, Fore, FTP trojan, Invisible FTP, Larva, WebEx, WinCrash
23 TTS (Tiny Telnet Server)
25 Ajan, Antigen, Email Password Sender, Happy99, Kuang 2, ProMail trojan, Shtrilitz, Stealth, Tapiras, Terminator, WinPC, WinSpy
31 Agent 31, Hackers Paradise, Masters Paradise
41 Deep Throat
59 DMSetup
79 FireHotcker
80 Executor, RingZero
99 Hidden port
110 ProMail trojan
113 Kazimas
119 Happy 99
121 JammerKillah
421 TCP Wrappers
456 Hackers Paradise
531 Rasmin
555 Ini-Killer, NetAdmin, Phase Zero, Stealth Spy
666 Attack FTP, Back Construction, Cain & Abel, Satanz Backdoor, ServeU, Shadow Phyre
911 Dark Shadow
999 Deep Throat, WinSatan
1002 Silencer, WebEx
1010 to 1015 Doly trojan
1024 NetSpy
1042 Bla
1045 Rasmin
1090 Xtreme
1170 Psyber Stream Server, Streaming Audio Trojan, voice
1234 Ultor trojan
port 1234Ultors Trojan
port 1243BackDoor-G, SubSeven, SubSeven Apocalypse
port 1245VooDoo Doll
port 1269Mavericks Matrix
port 1349 (UDP)BO DLL
port 1492FTP99CMP
port 1509Psyber Streaming Server
port 1600Shivka-Burka
port 1807SpySender
port 1981Shockrave
port 1999BackDoor
port 1999TransScout
port 2000TransScout
port 2001TransScout
port 2001Trojan Cow
port 2002TransScout
port 2003TransScout
port 2004TransScout
port 2005TransScout
port 2023Ripper
port 2115Bugs
port 2140Deep Throat, The Invasor
port 2155Illusion Mailer
port 2283HVL Rat5
port 2565Striker
port 2583WinCrash
port 2600Digital RootBeer
port 2801Phineas Phucker
port 2989 (UDP)RAT
port 3024WinCrash
port 3128RingZero
port 3129Masters Paradise
port 3150Deep Throat, The Invasor
port 3459Eclipse 2000
port 3700portal of Doom
port 3791Eclypse
port 3801 (UDP)Eclypse
port 4092WinCrash
port 4321BoBo
port 4567File Nail
port 4590ICQTrojan
port 5000Bubbel, Back Door Setup, Sockets de Troie
port 5001Back Door Setup, Sockets de Troie
port 5011One of the Last Trojans (OOTLT)
port 5031NetMetro
port 5321FireHotcker
port 5400Blade Runner, Back Construction
port 5401Blade Runner, Back Construction
port 5402Blade Runner, Back Construction
port 5550Xtcp
port 5512Illusion Mailer
port 5555ServeMe
port 5556BO Facil
port 5557BO Facil
port 5569Robo-Hack
port 5742WinCrash
port 6400The Thing
port 6669Vampyre
port 6670Deep Throat
port 6771Deep Throat
port 6776BackDoor-G, SubSeven
port 6912Shit Heep (not port 69123!)
port 6939Indoctrination
port 6969GateCrasher, Priority, IRC 3
port 6970GateCrasher
port 7000Remote Grab, Kazimas
port 7300NetMonitor
port 7301NetMonitor
port 7306NetMonitor
port 7307NetMonitor
port 7308NetMonitor
port 7789Back Door Setup, ICKiller
port 8080RingZero
port 9400InCommand
port 9872portal of Doom
port 9873portal of Doom
port 9874portal of Doom
port 9875portal of Doom
port 9876Cyber Attacker
port 9878TransScout
port 9989iNi-Killer
port 10067 (UDP)portal of Doom
port 10101BrainSpy
port 10167 (UDP)portal of Doom
port 10520Acid Shivers
port 10607Coma
port 11000Senna Spy
port 11223Progenic trojan
port 12076Gjamer
port 12223Hack´99 KeyLogger
port 12345GabanBus, NetBus, Pie Bill Gates, X-bill
port 12346GabanBus, NetBus, X-bill
port 12361Whack-a-mole
port 12362Whack-a-mole
port 12631WhackJob
port 13000Senna Spy
port 16969Priority
port 17300Kuang2 The Virus
port 20000Millennium
port 20001Millennium
port 20034NetBus 2 Pro
port 20203Logged
port 21544GirlFriend
port 22222Prosiak
port 23456Evil FTP, Ugly FTP, Whack Job
port 23476Donald Dick
port 23477Donald Dick
port 26274 (UDP)Delta Source
port 27374SubSeven 2.0
port 29891 (UDP)The Unexplained
port 30029AOL trojan
port 30100NetSphere
port 30101NetSphere
port 30102NetSphere
port 30303Sockets de Troie
port 30999Kuang2
port 31336Bo Whack
port 31337Baron Night, BO client, BO2, Bo Facil
port 31337 (UDP)BackFire, Back Orifice, DeepBO
port 31338NetSpy DK
port 31338 (UDP)Back Orifice, DeepBO
port 31339NetSpy DK
port 31666Bo Whack
port 31785Hack´a´Tack
port 31787Hack´a´Tack
port 31788Hack´a´Tack
port 31789 (UDP)Hack´a´Tack
port 31791 (UDP)Hack´a´Tack
port 31792Hack´a´Tack
port 33333Prosiak
port 33911Spirit 2001a
port 34324BigGluck, TN
port 40412The Spy
port 40421Agent 40421, Masters Paradise
port 40422Masters Paradise
port 40423Masters Paradise
port 40426Masters Paradise
port 47262 (UDP)Delta Source
port 50505Sockets de Troie
port 50766Fore, Schwindler
port 53001Remote Windows Shutdown
port 54320Back Orifice 2000
port 54321School Bus
port 54321 (UDP)Back Orifice 2000
port 60000Deep Throat
port 61466Telecommando
port 65000Devil


Last update on Thursday October 16, 2008 02:43:16 PM.This document entitled « Introduction to Trojan horses » from Kioskea (en.kioskea.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the licence, as this note appears clearly.
Prevent viruses, trojan horse, malware, worm Hello, i am from Pakistan.... i want to know about the registry files which is effected by the viruses, malware, spyware, trojan horses and how can i stop the viruses manulay to reappearing again by editing in window registry. there is some upcoming... en.kioskea.net/forum/affich-110129-prevent-viruses-trojan-horse-malware-worm
Download Trojan Remover Description: Especially designed to eliminate trojans (also called Trojan horses) as well as the intruders of ad ware and spy ware types, Trojan remover will help you to fight effectively against any sorts of spy software raging on... en.kioskea.net/telecharger/telecharger-1307-trojan-remover
Trojan horse clicker there is trojan horse clicker ico in my computer i dont know whwat to do please help to delete this trojan .i have avg anti virus en.kioskea.net/forum/affich-4649-trojan-horse-clicker
Getting rid of Vundo TrojanGetting rid of Vundo Trojan What is a Vundo Trojan? How to remove a Vundo Trojan Manually Step 1: Locate the Trojan Step 2: Use Registry Editor to eliminate Registry Values Step 3: Using Command Prompt for Vundo unregistration Download... en.kioskea.net/faq/sujet-259-getting-rid-of-vundo-trojan
No open port = no TrojanNo open port means No trojan Myth Leaving no ports open on my PC , I'm sure I will not have any Trojan on my computer. Reality FALSE. Explanations An open port is not necessary to control a computer on which there is... en.kioskea.net/faq/sujet-2146-no-open-port-no-trojan
Online antivirusOnline antivirus Intro Bitdefender Computer Associates F-Secure Trend Micro(Housecall) Symantec Pandasecurity Intro These online tools mainly allow computer viruses, including worms and Trojan horses. Such programs may... en.kioskea.net/faq/sujet-1764-online-antivirus
How to get rid of trojan virusHello, i have a mischievous virus it is trojan n i cant get rid of it can someone tell me step mby step how its done please;-) en.kioskea.net/forum/affich-65559-how-to-get-rid-of-trojan-virus
How to remove trojan virus manuallyHello, there's a flashing trojan message which took over my desktop, I have a virus software running, but it still shows up. I have ran my virus scan but each time I turn on the machine, I get the flashing trojan again. Can you please let me know how... en.kioskea.net/forum/affich-80298-how-to-remove-trojan-virus-manually
Trojan horse virusHello, My messenger is sending a virus to all my contacts. How can I clean my messenger ??? Thanks en.kioskea.net/forum/affich-94565-trojan-horse-virus
Download The CleanerThe Cleaner must not be confused with CCleaner, and was originally written to counter trojan Back Orifice. In a very short time, it detects quickly thousands of hostile programs and continues to do it nowadays. . This version is not a shareware... en.kioskea.net/telecharger/telecharger-1306-the-cleaner
Download AntiVir PersonalAntiVir is a free antivirus software designed for private use. Efficient and reliable, the program lists over 1,300,000 viruses, Trojan horses and worms. It analyzes each file created or read on the computer in order to detect any infection trying to... en.kioskea.net/telecharger/telecharger-36-antivir-personal
Download Spybot - Search & DestroySpybot - Search & Destroy is an adware, spyware, dialers, keyloggers, trojans detection and removal tool. It scans your computer hard disk and/or RAM for malicious software. It can also immunise your system against over 400 different spies and... en.kioskea.net/telecharger/telecharger-37-spybot-search-destroy
Hi-tech 'Trojan horse' can kill cancer cells: researchersTwo women look at prostate cancer cells under a microscope. Australian researchers are set to begin human trials of a tiny nano-cell that acts as a "Trojan horse" against cancer cells, a breakthrough they say may curb the need for debilitating... en.kioskea.net/actualites/hi-tech-trojan-horse-can-kill-cancer-cells-researchers-13144-actualite.php3
Online Valentine cards may contain Internet worm, FBI warnsHeart illuminations for Valentine's Day. Valentine's Day e-greetings from a stranger could deliver more than the recipient bargained for in the shape of a destructive "Trojan horse" that hijacks computers, the FBI warned Tuesday. Valentine's Day... en.kioskea.net/actualites/online-valentine-cards-may-contain-internet-worm-fbi-warns-10099-actualite.php3
Iexplore - iexplore.exeiexplore - iexplore.exe iexplore.exe (iexplore stands for Internet Explorer) is a Windows process which corresponds the web browser Internet Explorer. The process iexplore is not in any way a virus, a worm, a Trojan horse, spyware, or adware. It is... en.kioskea.net/contents/processus/iexplore-exe.php3
Msoobe - msoobe.exemsoobe - msoobe.exe msoobe.exe (msoobe stands for Windows Product Activation) is a Windows XP generic process which activates product licences. The process msoobe is not in any way a virus, a worm, a Trojan horse, spyware, or adware. It is a system... en.kioskea.net/contents/processus/msoobe-exe.php3
Cmd - cmd.execmd - cmd.exe cmd.exe (cmd signifiant Windows Command Prompt) is a Windows NT/2000/XP generic process which opens a text-mode console for running programs using a command line. The process cmd is not in any way a virus, a worm, a Trojan horse,... en.kioskea.net/contents/processus/cmd-exe.php3