es que creo que ese troyano se conecta via http
por cierto, algun dato del cabronazo
Starting nmap V. 3.00 (
www.insecure.org/nmap )
Interesting ports on jesus.and.moses.are.super-jew.net (66.98.xxxxxx):
(The 1590 ports scanned but not shown below are in state: closed)
Port State Service
21/tcp open ftp
22/tcp open ssh
80/tcp open http
113/tcp open auth
135/tcp filtered loc-srv
139/tcp filtered netbios-ssn
445/tcp filtered microsoft-ds
539/tcp filtered apertus-ldp
6667/tcp filtered irc
6969/tcp open acmsoda
7000/tcp open afs3-fileserver
Remote operating system guess: Linux Kernel 2.4.0 - 2.5.20
Uptime 130.341 days (since Fri Aug 22 19:18:00 2003)
Nmap run completed -- 1 IP address (1 host up) scanned in 57 seconds