XP Firewall Suddenly Turned Off

J

JohnG

This morning I got an alert warning about 2 issues:

.. a trojan backdoor:
http://go.microsoft.com/fwlink/?linkid=37020&name=Backdoor:WinNT/Nuwar.D!sys&threatid=2147597707
.. a trojan downloader:
http://go.microsoft.com/fwlink/?lin...Downloader:Win32/Renos.AS&threatid=2147610970

I immediately removed them.

A little later, when I logged on, I got a warning that my firewall was off,
& I turned it back on.

I looked through the system log & saw ForeFront warnings about changes to
system configuration & autostart for SVCHost:

.. Microsoft Forefront Client Security Real-Time Protection agent has
detected changes. Microsoft recommends you analyze the software that made
these changes for potential risks. You can use information about how these
programs operate to choose whether to allow them to run or remove them from
your computer. Allow changes only if you trust the program or the software
publisher. Microsoft Forefront Client Security can't undo changes that you
allow.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=74409
Scan ID: {CBEDFA11-54C6-4DC4-82E4-B82FAFCDBAE8}
Agent: Auto Start
User: DAD2002\John
Name: Unknown
ID:
Severity: Not Yet Classified
Category: Not Yet Classified
Path Found:
regkey:HKCU@S-1-5-21-1690843657-2136417557-4012481799-1006\Software\Microsoft\Windows\CurrentVersion\Run\\SVCHOST.EXE;runkey:HKCU@S-1-5-21-1690843657-2136417557-4012481799-1006\Software\Microsoft\Windows\CurrentVersion\Run\\SVCHOST.EXE;file:C:\WINDOWS\system32\drivers\svchost.exe
Alert Type: Unclassified software
Process Name:
Detection Type:
Status:

.. Microsoft Forefront Client Security Real-Time Protection agent has
detected changes. Microsoft recommends you analyze the software that made
these changes for potential risks. You can use information about how these
programs operate to choose whether to allow them to run or remove them from
your computer. Allow changes only if you trust the program or the software
publisher. Microsoft Forefront Client Security can't undo changes that you
allow.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=74409
Scan ID: {798D8A3D-3D01-4FD2-BBF6-A2731F43B974}
Agent: System Configuration
User: DAD2002\John
Name: Unknown
ID:
Severity: Not Yet Classified
Category: Not Yet Classified
Path Found:
regkey:HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\SYSTEM32\DRIVERS\svchost.exe;firewallokfile:HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\SYSTEM32\DRIVERS\svchost.exe;file:C:\WINDOWS\SYSTEM32\DRIVERS\svchost.exe
Alert Type: Unclassified software
Process Name:
Detection Type:
Status:

Are these changes valid or could they be related to my firewall being turned
off?

Thanks,
John
 
J

JohnG

I just downloaded a new signature file & Forefront detected a trojan
downloader - svchost.exe - that answers my question.
 
B

Bill Sanderson

Good--the real svchost.exe should never be detected as unknown.

I would recommend scanning your system with several different full-service
scanners--use the online versions.

It looks like you've caught this quickly, but although the component that
allows control of your machine has been caught, it is difficult to be sure
that nothing has, in fact, been downloaded that might not have been
detected.

So--in lieu of rebuilding from scratch, do some careful scanning now, and
probably weekly for several weeks out--just to be sure something is not in
place that is later added to detections.

The other question is: How did it get in? If your OS is fully patched to
date, you should be looking at third-party apps (or, perhaps, other users
who clicked on something they should not have?)

I'd recommend the PSI scanner at www.secunia.com

http://secunia.com/vulnerability_scanning/

If this is a personal machine, hit the middle button on that page and
download PSI. Once you have scanned and corrected most of what it finds,
change the setting to only show easily corrected issues, and see if you can
fix the rest-use the buttons for technical details to see where the items it
is detecting are found--often they are, for example, outdated examples of
Adobe Reader installed with specific apps.

You should be able to get a system down to all patched and maybe one or two
end-of-life, with some effort.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top