On Fri, 15 Aug 2003 16:35:39 +0000 (UTC) in
<message-id:bhj24r$ado$(E-Mail Removed)>
"Eds" <(E-Mail Removed)> wrote:
> > As far as bolt-on firewalls go, IMO, it's one of the best ones for
> > windoze.. but the reason you haven't patched your box is?
> >
> >
> I don't have the same variant that everyone else seems to have got.
> It doesn't show up on any virus scans, but it was blocking the patch
> and windows update, as well as doing the 60 second shutdown thing.
> Can't find it in the registry or task manager either. I did install
> the patch, by opening the exe in winrar, so I don't get the shutdown
> message anymore. In fact everything appears normal, except I know I
> haven't killed it so what will happen tomorrow (attack MS day) is
> anyone's guess...
Hmm.. this sounds like you might have another trojan or something
separate to MSB.
Have you checked the following registry key:
HKEY_CLASSES_ROOT\exefile\shell\open\command
(Default)
This should be just:
""%1" %"
I have a suspicion you might have a trojan there that is affecting the
opening of .exe files (Sub7 for example used this technique).
Also, goto:
Start menu->run
type:
command.com
cd to your windows / winnt directory (IIRC) and type:
copy regedit.exe regedit.com
Then run:
regedit.com
to access the registry editor, as if I'm right (or it is indeed
something else that affects all .exe files), this will prevent any crash
as the file is no longer handled by that exefiles regkey (.com, .exe,
..scr etc are all types of executable extension).
>
> I just wanted to know whether I should be expecting Outpost to stop
> the worm doing its thing, once infected? If port whever it was was
> blocked, could the worm still trigger the auto shutdown thing?
It can of course trigger the shutdown part, as it's now inside / local.
What it _will_ prevent, is if you have all the MSB ports closed, further
attacks on your box.
>
> [Really up on my terminology today ;-)]
HTH Eds =)
Regards,
Ian
--
Ian.H [Design & Development]
digiServ Network - Web solutions
www.digiserv.net | irc.digiserv.net | forum.digiserv.net
Programming, Web design, development & hosting.