FORUMS
Remove All Ads from XDA

12346 Netbus Backdoor trojan showing up on my girlfriends phone.

107 posts
Thanks Meter: 16
 
Post Reply Email Thread
So I did a search and couldn't really find any info on what this is. today I was scanning everything attached to my network with Fing and her phone came up with a TCP 12346 netbus backdoor trojan. Not sure where to go from here to find and remove it. my guess is she got it from using mp3 music downloader. any help is much appreciated.
 
 
8th January 2012, 03:58 PM |#2  
xzombiex66's Avatar
OP Senior Member
Flag hamilton
Thanks Meter: 16
 
Donate to Me
More
Anyone????
8th January 2012, 04:14 PM |#3  
Turd Furguson's Avatar
Senior Member
Thanks Meter: 66
 
More
What did you use to scan it with?

Sent from my ADR6400L using Tapatalk
8th January 2012, 08:33 PM |#4  
xzombiex66's Avatar
OP Senior Member
Flag hamilton
Thanks Meter: 16
 
Donate to Me
More
Quote:
Originally Posted by Turd Furguson

What did you use to scan it with?

Sent from my ADR6400L using Tapatalk

look out security
5th March 2014, 01:58 PM |#5  
Junior Member
Thanks Meter: 0
 
More
Android NetBus backdoor trojan
Bump. I have seen this "12346 NetBus backdoor trojan" during a fing (overlooksoft) service scan. What does xda have to say about this?

Wikipedia gives a interesting article about theNetBus trojan horse.

The person that owns the phone claims that they clicked on a link in an email and the phone froze.

The only solution I have dug up is a factory reset. I did, ran another scan and it didnt change.

Ill be looking for feedback!
19th June 2015, 01:15 AM |#6  
Junior Member
Thanks Meter: 0
 
More
same 12346 netbus back Door trojan
Fing app tells me that my Phone has 12346 port open. Any advice? Thanks
5th July 2015, 07:30 PM |#7  
Junior Member
Thanks Meter: 1
 
More
For anyone still wondering
I also used Fing and found the same open port and it seems If you use the Rhapsody service then that is your answer if you dont then go fish, best of luck, hope this helps . . . . at least to anyone that uses Rhapsody
The Following User Says Thank You to DjOpps For This Useful Post: [ View ] Gift DjOpps Ad-Free
22nd January 2017, 05:13 AM |#8  
Junior Member
Thanks Meter: 0
 
More
I also have Rhapsody/Napster and I also did a scan with the Fing app, and got the same Netbus backdoor trojan in the running services when scanning with Fing. This is totally a guess but if its Napster then it would make sense that the app keeps a port open so it can block the service if your subscription is canceled or suspended. My experience is that if you force Napster into offline mode before its cancelled or suspended it wont block the service because its not actively searching for the network. I have done this with Napster a few times.
1st July 2017, 02:36 PM |#9  
Account currently disabled
Thanks Meter: 54
 
More
Install TWRP and reformat the drive... then re-flash the stock firmware.
Post Reply Subscribe to Thread

Guest Quick Reply (no urls or BBcode)
Message:
Previous Thread Next Thread
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes