How to report a new worm.

  • Thread starter Thread starter robert
  • Start date Start date
R

robert

I've got what I think might be a new worm.
Where do I report this?

I have the latest xp software patches etc.
I have the latest norton antivirus software
I have the latest sygate firewall

My system is sending out thousands of packets to U.S. Homeland Security
computers.

any help would be appreciated.
armstrong
 
adaware spywareguard etc

I've run hijackthis and submitted it to
a few websites that help with that kind of stuff.

I'm seeing this through the firewall.

I've tried calling Norton they want 75.00 buck to talk with them.

sigh...
 
Email the Anti-Virus companies McAfee and Symantec for starters, i think
they can help.
 
You are on our "suspected Terrorist" list, there is a big black car parked
outside your home too.

Testy
Director
U.S. Homeland Security
 
do you know the program that is sending the packets? Because it sounds like
you got infected by some adware/Trojan that has been setup to DOS the US
homeland security. Also never heard of sygate, try zonealarm. Its free and
will ask for each program that is asking to connect to your internet
connection also figuring out what program is sending the packets.
 
Jeremy


The computer sends out data
using ICMP protocol using Remote Port/ICMP Type 8 under DLLHOST.exe

armstrong
 
You do realize that there is a difference between
a rogue application that is DoSing somewhere and
a virus or worm that is attempting to spread itself.
If you have evidence of the spreading behavior,
can capture its on-the-network footprint and include
this with what files it is residing in, and can package
this up then the AV companies will probably tell you
what existing known virus/worm it is.
 
It honestly sounds like the Welchia worm. Because it basically ping floods
when looking for new machines to infect. Get Symantec Welchia worm removal
tool.
http://securityresponse.symantec.com/avcenter/venc/data/w32.welchia.worm.removal.tool.html
Run it see if it finds anything. Because all the hosts that were infected
on our system the DLLHOST.exe was the file was infected and needed to be
deleted by the worm removal tool. Also mcafee wouldn't remove it only
Symantec's tool with mcafee turned off cleaned it completely.
 
Back
Top