Worm in XP that kills updates, etc

From: Kurt Loba (anonymous_at_discussions.microsoft.com)
Date: 08/05/04


Date: Thu, 5 Aug 2004 06:20:15 -0700

Hi Guys

I have spent most of this week trying to kill the worm, or
whatever it is that may be troubling some of you. The
symptoms I had: no task manager display (it flashes up and
disappears), massive uncontrolled/unwanted data flow in and
out of my PC, complete waste of hours and hours downloading
anti-virus/spyware software.

Short of booting from a dics that has a stinger in it,
seems pretty much impossible to kill it off. There is
hope, however!!

Get the Trend Micro Firewall/PCCillin free download, or if
you have a firewall installed, check your settings. The
virus allows hackers, or whatever the sons of slime who
created these things are called, to get into PCs through
Port 443. If you set your firewall to maximum protection,
and look at your port settings, you can Disable port 443.

Sites like this one use Port 443 for secure links into PCs,
and MicroTrend alerts you whenever yon connect, so it's not
as though you can't access https:// sites anymore. It just
means the worm can't communicate with its farty breathed
masters.

Hope this helps. I knew nothing about any of this until
four days ago. Firewalls and stingers rule!!

PS. If this makes no difference at all to the problem you
are facing, sorry I couln't make it better.

CHeers

klobs



Relevant Pages

  • Re: Lan Computer shows intruder attempt
    ... This is due to an http scanner, script, or worm trying to exploit ... Did this also show in the gateway computers firewall ... or to a port which is being forwarded to the second machine? ...
    (comp.security.firewalls)
  • Re: Controlling ports used by natd
    ... >>How is this problem confined to NAT? ... > firewall can't trust it not to be infected just because it's inside. ... it'd retry and would get another port the next time. ... > but so that a worm that's gotten into the system is detected. ...
    (freebsd-net)
  • Re: How did it get through?
    ... >The router is not going to stop a worm from coming down any port. ... if the port is already in use so that SPI will think it is OK. ... >router with a *true* firewall. ...
    (comp.security.firewalls)
  • Re: Controlling ports used by natd
    ... firewall can't trust it not to be infected just because it's inside. ... it'd retry and would get another port the next time. ... With NAT, there's a bigger problem: the firewall that's doing NAT may ... but so that a worm that's gotten into the system is detected. ...
    (freebsd-net)
  • Re: keeping ports open
    ... If a port is open, it means that 1) a software or service is running on your ... and 2) you're not using a firewall or your firewall isn't ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ...
    (microsoft.public.security)