View Full Version : Whats port 13139
Man is ther a new virus like code red out cuz my cable modem is going crazy and i keep geting ZA stops on 13139 what ports that and at time it gets so bad when ZA is off it makes my pc reboot :( any ideas ?
Could you maybe be infected with Sircam?
It could be a Korean attack led on your computer.
Can you find the origination address so I can find out who it belongs too?
yea ther from dif ips....
The firewall has blocked Internet access to your computer (UDP Port 13139) from 66.123.169.185 (UDP Port 35964)
(UDP Port 13139) from 12.224.66.8 (UDP Port 1025).
(ICMP Unreachable) from 204.255.168.85.
(UDP Port 13139) from 65.80.143.53 (UDP Port 12531).
UDP Port 13139) from 61.75.158.156 (UDP Port 13139).
(UDP Port 13139) from 210.104.130.66 (UDP Port 18088).
(UDP Port 13139) from 209.102.67.26 (UDP Port 13139).
Thers way more but thers a few
I dont know mabye infected with sir cam but i dont open any email and have norton and just reinstall os like 2 weeks ago so i dunno i could tho
pc been on bout a hour and iv got hit 62 times :(
209.102.67.26 is Rock Island Internet.
210.104.130.66 is SUNLIN KR (Seoul).
61.75.158.156 is Korea Telecom.
65.80.143.53 is BellSouth at Charlotte U.S.
204.255.168.85 is UUNET Technologies, Inc. U.S.
12.224.66.8 is AT&T Corp.
12.224.66.8 is also AT&T
With complements of Neotrace Express and....
Croc.
thank you croc
Its realy slowen me down any others haven za hits?
I'm not seeing anything for 13139.
Why don't you go ahead and run the Sircam removal tool, just in case. I can't think of any other idea as far as why your being targeted.
http://www.symantec.com/avcenter/venc/data/w32.sircam.worm@mm.removal.tool.html
Do you play any online games?
13139 for some game engines is used for custom UDP pings.
yea but still geting this when not playing
ran sir cam remover and nope didnt have it
I didn't think you did, but figured it wouldn't hurt to try it.
I just don't have any other Idea's at the current time.
GreEd, how about you?
These are the current listings for ports used in the 13000 range that are used by trojans. 13139 is not listed. The list is from Neohapsis which is supposed to be the most up to date one around.
13000 tcp SennaSpy [trojan] Senna Spy
13010 tcp HackerBrasilHBR [trojan] Hacker Brasil - HBR
13160 tcp i-zipqd I-ZIPQD
Croc.
After Googling "Port 13139" (inc." ") and a quick read check out if you have one of those internet dialers installed.
Crocedit.
I wouldn't worry much about it. Try and take note of what time the probes are occuring, and log it. Once you get the probes in some type of pattern check the ip's for activity.
Of the ip's, I would take note of 65.80.143.53 and 204.255.168.85, I ran a small audit on these two ip's and they seemed the most suspicious. I'm also waiting for a reply from dshield to see if either have been logged as "attacking" ip's.
regards,
greEd
Thank you guys so much :D it seem to slow down some but still geting them every so ofton
Take that back just got hit 50 times on that port all being dif ip
vBulletin® v3.7.3, Copyright ©2000-2008, Jelsoft Enterprises Ltd.