Open Ports Killing Net Speed

  • Thread starter Thread starter News Groupie
  • Start date Start date
N

News Groupie

I ran netstat at command prompt because I noticed my web browsing getting
ridiculously slow. It came up with 270 connections to my computer. I know
this is not normal. I recognize the AIM, MSN, Trillian and similiar
connections. But most of the other connections established were to ports
"2119" and "http" and most were from foriegn hosts/ips (.fr, .se, .nl, .it,
etc.). I don't have a web server running and I have no clue what app or
service uses port 2119.

How do I fix this so my internet speed isn't boggled down? How do I prevent
this from happening again?

Thanks in advance

P.S. - Yes, I'm running WinXP SP2.
 
I ran netstat at command prompt because I noticed my web browsing
getting ridiculously slow. It came up with 270 connections to my
computer. I know this is not normal. I recognize the AIM, MSN,
Trillian and similiar connections. But most of the other connections
established were to ports "2119" and "http" and most were from foriegn
hosts/ips (.fr, .se, .nl, .it, etc.). I don't have a web server
running and I have no clue what app or service uses port 2119.

How do I fix this so my internet speed isn't boggled down? How do I
prevent this from happening again?

Thanks in advance

P.S. - Yes, I'm running WinXP SP2.

The link may help you in the furture. Your best bet is to wipeout it seems
like a badly compromised machine.

http://tinyurl.com/klw1

Duane :)
 
How do I fix this so my internet speed isn't boggled down? How do I prevent
this from happening again?

After you reformat and do a clean install of XP, don't disable the built in
firewall, don't open strange e-mail attachments, and read the EULA before
installing any software.
 
News said:
I ran netstat at command prompt because I noticed my web browsing getting
ridiculously slow. It came up with 270 connections to my computer. I know
this is not normal. I recognize the AIM, MSN, Trillian and similiar
connections. But most of the other connections established were to ports
"2119" and "http" and most were from foriegn hosts/ips (.fr, .se, .nl, .it,
etc.). I don't have a web server running and I have no clue what app or
service uses port 2119.

How do I fix this so my internet speed isn't boggled down? How do I prevent
this from happening again?

Thanks in advance

P.S. - Yes, I'm running WinXP SP2.

Do a thorough scan for malware. Are you running a firewall? One should
be active at all times when online.

Run these programs to check for spyware/malware. After installing
update them, then boot into safe mode and run them. You should update
and run them weekly.

Cwshredder
http://www.intermute.com/spysubtract/cwshredder_download.html

Ad-aware SE
http://www.lavasoftusa.com

Spybot Search and Destroy
http://www.safer-networking.org

Bazooka Adware and Spyware Scanner
http://download.com.com/3000-2144-10247783.html

Pest Patrol Free Pest Scanner
http://www.pestscan.com/ScanOrTrial.asp

If you’re still having problems after running these then run HijackThis
and post the log to one of the specialty forums, _NOT_ this one.

HijackThis
http://www.majorgeeks.com/download.php?det=3155

Forums to Interpret HijackThis Logs:

http://www.spywareinfo.com/forums/
http://forum.aumha.org/viewforum.php?f=30
http://forums.tomcoyote.org/
http://www.wilderssecurity.com/

After your system is clean use these programs to help keep it clean:

Spywareblaster
www.javacoolsoftware.com/sbdownload.html

Spywareguard
http://www.javacoolsoftware.com/sgdownload.html

IE-SPYAD
http://www.staff.uiuc.edu/~ehowes/resource.htm

For viruses, start with Trend Micro’s Sysclean. Download it and the
signature file. Turn off system restore, boot into safe mode and run
sysclean. Boot back into normal mode and run a full AV scan with your
normal AV program. Then turn system restore back on.

Trend Micro Sysclean
http://www.trendmicro.com/download/dcs.asp

Trend Micro Signature File
http://www.trendmicro.com/download/pattern.asp

You should also regularly run at least two of these online scans in
addition to your regular up to date AV program:

Online and Downloadable Virus Scanning:

Panda ActiveScan
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Bit Defender Online Virus Scan:
http://www.bitdefender.com/scan/license.php

Symantec Online Virus and Security Scan:
http://security.symantec.com/ssc/home.asp

TrendMicro:
http://housecall.trendmicro.com/housecall/start_corp.asp

McAfee Online Virus Scan:
http://www.mcafee.com/myapps/mfs/default.asp

RAV AntiVirus - Scan Online
http://www.ravantivirus.com/scan/

F-Secure:
http://support.f-secure.com/enu/home/ols.shtml

McAfee AVert Stinger Virus Removal Tool
http://vil.nai.com/vil/stinger/

[Note: Stinger looks only for a limited number of specific viruses.
It’s not intended for full strength virus scanning and removal, but it
can help eliminate enough threats to allow you to install and scan with
a full featured AV program.]

Make sure you have a firewall active at all times. If nothing else use
the one built into XP, but there are a variety of free third party ones
that do a better job from Sygate, Zone Alarm or Kerio.

Sygate Personal Firewall
http://smb.sygate.com/products/spf_standard.htm

Zone Alarm
http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp?lid=staticcomp_za

Kerio Personal Firewall
http://www.kerio.com/kpf_download.html

Lastly check your system for vulnerabilities. Make sure you have all
the latest security patches from Windows Update too.

Websites which will check for vulnerabilities:

Browser Security Tests:
http://www.jasons-toolbox.com/BrowserSecurity/

Symantec Security Check
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym

http://bcheck.scanit.be/bcheck/
https://testzone.secunia.com/browser_checker/
www.pcpitstop.com
 
WHOA!!! gawd damnnit. it's that serious?

What exactly caused this problem?

TIA


Rock said:
News said:
I ran netstat at command prompt because I noticed my web browsing getting
ridiculously slow. It came up with 270 connections to my computer. I know
this is not normal. I recognize the AIM, MSN, Trillian and similiar
connections. But most of the other connections established were to ports
"2119" and "http" and most were from foriegn hosts/ips (.fr, .se, .nl,
.it, etc.). I don't have a web server running and I have no clue what app
or service uses port 2119.

How do I fix this so my internet speed isn't boggled down? How do I
prevent this from happening again?

Thanks in advance

P.S. - Yes, I'm running WinXP SP2.

Do a thorough scan for malware. Are you running a firewall? One should
be active at all times when online.

Run these programs to check for spyware/malware. After installing update
them, then boot into safe mode and run them. You should update and run
them weekly.

Cwshredder
http://www.intermute.com/spysubtract/cwshredder_download.html

Ad-aware SE
http://www.lavasoftusa.com

Spybot Search and Destroy
http://www.safer-networking.org

Bazooka Adware and Spyware Scanner
http://download.com.com/3000-2144-10247783.html

Pest Patrol Free Pest Scanner
http://www.pestscan.com/ScanOrTrial.asp

If you’re still having problems after running these then run HijackThis
and post the log to one of the specialty forums, _NOT_ this one.

HijackThis
http://www.majorgeeks.com/download.php?det=3155

Forums to Interpret HijackThis Logs:

http://www.spywareinfo.com/forums/
http://forum.aumha.org/viewforum.php?f=30
http://forums.tomcoyote.org/
http://www.wilderssecurity.com/

After your system is clean use these programs to help keep it clean:

Spywareblaster
www.javacoolsoftware.com/sbdownload.html

Spywareguard
http://www.javacoolsoftware.com/sgdownload.html

IE-SPYAD
http://www.staff.uiuc.edu/~ehowes/resource.htm

For viruses, start with Trend Micro’s Sysclean. Download it and the
signature file. Turn off system restore, boot into safe mode and run
sysclean. Boot back into normal mode and run a full AV scan with your
normal AV program. Then turn system restore back on.

Trend Micro Sysclean
http://www.trendmicro.com/download/dcs.asp

Trend Micro Signature File
http://www.trendmicro.com/download/pattern.asp

You should also regularly run at least two of these online scans in
addition to your regular up to date AV program:

Online and Downloadable Virus Scanning:

Panda ActiveScan
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Bit Defender Online Virus Scan:
http://www.bitdefender.com/scan/license.php

Symantec Online Virus and Security Scan:
http://security.symantec.com/ssc/home.asp

TrendMicro:
http://housecall.trendmicro.com/housecall/start_corp.asp

McAfee Online Virus Scan:
http://www.mcafee.com/myapps/mfs/default.asp

RAV AntiVirus - Scan Online
http://www.ravantivirus.com/scan/

F-Secure:
http://support.f-secure.com/enu/home/ols.shtml

McAfee AVert Stinger Virus Removal Tool
http://vil.nai.com/vil/stinger/

[Note: Stinger looks only for a limited number of specific viruses. It’s
not intended for full strength virus scanning and removal, but it can help
eliminate enough threats to allow you to install and scan with a full
featured AV program.]

Make sure you have a firewall active at all times. If nothing else use
the one built into XP, but there are a variety of free third party ones
that do a better job from Sygate, Zone Alarm or Kerio.

Sygate Personal Firewall
http://smb.sygate.com/products/spf_standard.htm

Zone Alarm
http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp?lid=staticcomp_za

Kerio Personal Firewall
http://www.kerio.com/kpf_download.html

Lastly check your system for vulnerabilities. Make sure you have all the
latest security patches from Windows Update too.

Websites which will check for vulnerabilities:

Browser Security Tests:
http://www.jasons-toolbox.com/BrowserSecurity/

Symantec Security Check
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym

http://bcheck.scanit.be/bcheck/
https://testzone.secunia.com/browser_checker/
www.pcpitstop.com
 
WHOA!!! gawd damnnit. it's that serious?

What exactly caused this problem?

TIA

You should take a hard look at yourself in the mirror. That will give you a
*clue*.

Duane :)
 
News said:
WHOA!!! gawd damnnit. it's that serious?

What exactly caused this problem?

TIA


News said:
I ran netstat at command prompt because I noticed my web browsing getting
ridiculously slow. It came up with 270 connections to my computer. I know
this is not normal. I recognize the AIM, MSN, Trillian and similiar
connections. But most of the other connections established were to ports
"2119" and "http" and most were from foriegn hosts/ips (.fr, .se, .nl,
.it, etc.). I don't have a web server running and I have no clue what app
or service uses port 2119.

How do I fix this so my internet speed isn't boggled down? How do I
prevent this from happening again?

Thanks in advance

P.S. - Yes, I'm running WinXP SP2.

Do a thorough scan for malware. Are you running a firewall? One should
be active at all times when online.

Run these programs to check for spyware/malware. After installing update
them, then boot into safe mode and run them. You should update and run
them weekly.

Cwshredder
http://www.intermute.com/spysubtract/cwshredder_download.html

Ad-aware SE
http://www.lavasoftusa.com

Spybot Search and Destroy
http://www.safer-networking.org

Bazooka Adware and Spyware Scanner
http://download.com.com/3000-2144-10247783.html

Pest Patrol Free Pest Scanner
http://www.pestscan.com/ScanOrTrial.asp

If you’re still having problems after running these then run HijackThis
and post the log to one of the specialty forums, _NOT_ this one.

HijackThis
http://www.majorgeeks.com/download.php?det=3155

Forums to Interpret HijackThis Logs:

http://www.spywareinfo.com/forums/
http://forum.aumha.org/viewforum.php?f=30
http://forums.tomcoyote.org/
http://www.wilderssecurity.com/

After your system is clean use these programs to help keep it clean:

Spywareblaster
www.javacoolsoftware.com/sbdownload.html

Spywareguard
http://www.javacoolsoftware.com/sgdownload.html

IE-SPYAD
http://www.staff.uiuc.edu/~ehowes/resource.htm

For viruses, start with Trend Micro’s Sysclean. Download it and the
signature file. Turn off system restore, boot into safe mode and run
sysclean. Boot back into normal mode and run a full AV scan with your
normal AV program. Then turn system restore back on.

Trend Micro Sysclean
http://www.trendmicro.com/download/dcs.asp

Trend Micro Signature File
http://www.trendmicro.com/download/pattern.asp

You should also regularly run at least two of these online scans in
addition to your regular up to date AV program:

Online and Downloadable Virus Scanning:

Panda ActiveScan
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Bit Defender Online Virus Scan:
http://www.bitdefender.com/scan/license.php

Symantec Online Virus and Security Scan:
http://security.symantec.com/ssc/home.asp

TrendMicro:
http://housecall.trendmicro.com/housecall/start_corp.asp

McAfee Online Virus Scan:
http://www.mcafee.com/myapps/mfs/default.asp

RAV AntiVirus - Scan Online
http://www.ravantivirus.com/scan/

F-Secure:
http://support.f-secure.com/enu/home/ols.shtml

McAfee AVert Stinger Virus Removal Tool
http://vil.nai.com/vil/stinger/

[Note: Stinger looks only for a limited number of specific viruses. It’s
not intended for full strength virus scanning and removal, but it can help
eliminate enough threats to allow you to install and scan with a full
featured AV program.]

Make sure you have a firewall active at all times. If nothing else use
the one built into XP, but there are a variety of free third party ones
that do a better job from Sygate, Zone Alarm or Kerio.

Sygate Personal Firewall
http://smb.sygate.com/products/spf_standard.htm

Zone Alarm
http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp?lid=staticcomp_za

Kerio Personal Firewall
http://www.kerio.com/kpf_download.html

Lastly check your system for vulnerabilities. Make sure you have all the
latest security patches from Windows Update too.

Websites which will check for vulnerabilities:

Browser Security Tests:
http://www.jasons-toolbox.com/BrowserSecurity/

Symantec Security Check
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym

http://bcheck.scanit.be/bcheck/
https://testzone.secunia.com/browser_checker/
www.pcpitstop.com

Unsafe computing practices.
 
So basically, not having my firewall on and no spyware/malware/spam
proctection for 6 months will cause this problem?


Rock said:
News said:
WHOA!!! gawd damnnit. it's that serious?

What exactly caused this problem?

TIA


News Groupie wrote:

I ran netstat at command prompt because I noticed my web browsing
getting ridiculously slow. It came up with 270 connections to my
computer. I know this is not normal. I recognize the AIM, MSN, Trillian
and similiar connections. But most of the other connections established
were to ports "2119" and "http" and most were from foriegn hosts/ips
(.fr, .se, .nl, .it, etc.). I don't have a web server running and I have
no clue what app or service uses port 2119.

How do I fix this so my internet speed isn't boggled down? How do I
prevent this from happening again?

Thanks in advance

P.S. - Yes, I'm running WinXP SP2.

Do a thorough scan for malware. Are you running a firewall? One should
be active at all times when online.

Run these programs to check for spyware/malware. After installing update
them, then boot into safe mode and run them. You should update and run
them weekly.

Cwshredder
http://www.intermute.com/spysubtract/cwshredder_download.html

Ad-aware SE
http://www.lavasoftusa.com

Spybot Search and Destroy
http://www.safer-networking.org

Bazooka Adware and Spyware Scanner
http://download.com.com/3000-2144-10247783.html

Pest Patrol Free Pest Scanner
http://www.pestscan.com/ScanOrTrial.asp

If you’re still having problems after running these then run HijackThis
and post the log to one of the specialty forums, _NOT_ this one.

HijackThis
http://www.majorgeeks.com/download.php?det=3155

Forums to Interpret HijackThis Logs:

http://www.spywareinfo.com/forums/
http://forum.aumha.org/viewforum.php?f=30
http://forums.tomcoyote.org/
http://www.wilderssecurity.com/

After your system is clean use these programs to help keep it clean:

Spywareblaster
www.javacoolsoftware.com/sbdownload.html

Spywareguard
http://www.javacoolsoftware.com/sgdownload.html

IE-SPYAD
http://www.staff.uiuc.edu/~ehowes/resource.htm

For viruses, start with Trend Micro’s Sysclean. Download it and the
signature file. Turn off system restore, boot into safe mode and run
sysclean. Boot back into normal mode and run a full AV scan with your
normal AV program. Then turn system restore back on.

Trend Micro Sysclean
http://www.trendmicro.com/download/dcs.asp

Trend Micro Signature File
http://www.trendmicro.com/download/pattern.asp

You should also regularly run at least two of these online scans in
addition to your regular up to date AV program:

Online and Downloadable Virus Scanning:

Panda ActiveScan
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Bit Defender Online Virus Scan:
http://www.bitdefender.com/scan/license.php

Symantec Online Virus and Security Scan:
http://security.symantec.com/ssc/home.asp

TrendMicro:
http://housecall.trendmicro.com/housecall/start_corp.asp

McAfee Online Virus Scan:
http://www.mcafee.com/myapps/mfs/default.asp

RAV AntiVirus - Scan Online
http://www.ravantivirus.com/scan/

F-Secure:
http://support.f-secure.com/enu/home/ols.shtml

McAfee AVert Stinger Virus Removal Tool
http://vil.nai.com/vil/stinger/

[Note: Stinger looks only for a limited number of specific viruses. It’s
not intended for full strength virus scanning and removal, but it can
help eliminate enough threats to allow you to install and scan with a
full featured AV program.]

Make sure you have a firewall active at all times. If nothing else use
the one built into XP, but there are a variety of free third party ones
that do a better job from Sygate, Zone Alarm or Kerio.

Sygate Personal Firewall
http://smb.sygate.com/products/spf_standard.htm

Zone Alarm
http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp?lid=staticcomp_za

Kerio Personal Firewall
http://www.kerio.com/kpf_download.html

Lastly check your system for vulnerabilities. Make sure you have all the
latest security patches from Windows Update too.

Websites which will check for vulnerabilities:

Browser Security Tests:
http://www.jasons-toolbox.com/BrowserSecurity/

Symantec Security Check
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym

http://bcheck.scanit.be/bcheck/
https://testzone.secunia.com/browser_checker/
www.pcpitstop.com

Unsafe computing practices.
 
News Groupie said:
So basically, not having my firewall on and no spyware/malware/spam
proctection for 6 months will cause this problem?

Six months? I believe the latest figures for how quickly an unprotected
Windows XP box gets 0wned is around six *minutes*.

It's become so bad that some PC vendors will toss in a NAT router for free
when buying a system, because it saves the vendor support costs.
 
So basically, not having my firewall on and no spyware/malware/spam
proctection for 6 months will cause this problem?

Yeah, and trying to apply some kind of spyware removal software to resolve
the issues trying to clean it up and make it work is like dumping new oil
in a engine that has no oil pan and the engine has blown-up. You get
yourself a new engine. There's no telling what backdoors are buried so deep
on the computer that such detection software will ever be able to detect
it. If you have any common sense in your body, you'll wipeout that machine
and move on.

Duane :)
 
On Wed, 1 Dec 2004 22:26:11 -0500, Arthur Hagen spoketh
Six months? I believe the latest figures for how quickly an unprotected
Windows XP box gets 0wned is around six *minutes*.

It's become so bad that some PC vendors will toss in a NAT router for free
when buying a system, because it saves the vendor support costs.

The last reported number was 20 minutes. However, every time the story
gets referenced, the number keeps shrinking...


Lars M. Hansen
http://www.hansenonline.net
(replace 'badnews' with 'news' in e-mail address)
 
On Wed, 1 Dec 2004 22:26:11 -0500, Arthur Hagen spoketh


The last reported number was 20 minutes. However, every time the story
gets referenced, the number keeps shrinking...

Which is due to the fact that it's random. Script kiddies and worms
scan random blocks of IP addresses, and if your address happens to
be next in line the moment you connect a vulnerable system to the
internet, it can happen in seconds.
 
In message <[email protected]> Lars M. Hansen
The last reported number was 20 minutes. However, every time the story
gets referenced, the number keeps shrinking...

Reported by whom? I've seen boxes running XP RTM compromised within "a
few minutes" seen = witnessed myself.

I fired up an XP SP2 fresh install on a VPC at the beginning of this
thread, VLAN'd it outside my firewall (With it's own real IP), it has
yet to be compromised.
 
I fired up an XP SP2 fresh install on a VPC at the beginning of this
thread, VLAN'd it outside my firewall (With it's own real IP), it has
yet to be compromised.

Yea, it's amazing how lucky people can be for a while. In most cases,
when a machine is connected, unless it's subnet is in the middle of a
scan it could take minutes, hours, days, weeks, months, but it will get
compromised sooner or later.

I remember chaps that were running development stations on Dial-Up
accounts thinking they were safe since their IP changed all the time and
since they had to Dial-in to the ISP. It was funny, after about 3
months, they all started calling (all used the same ISP) and reporting
how they had strange things happening on their servers.... Turns out
that they had been compromised on a dial-up since they were not smart
enough to secure their machines - and it was not a windows file sharing
hack, it came through their unprotected IIS sites :)

In watching my subnet and what's going around it, due to what I see
hitting our IP's, I would suggest that any PC connected to a RR
connection in my area would last under 1 hour (I'm almost willing to bet
less than 5 minutes) before getting compromised.

You know, there is more than just viruses and trojans - there is
spyware. I just cleaned a machine that was running very slow, using
extra network traffic space, and seemed to just be wrong. When I opened
IE and got a screen full of windows I knew what it was. The interesting
thing was that it was behind a firewall, had good av software, but it
was using IE (something we don't let clients do any more), and had 8
different ad-delivery buggers installed, which installed even more of
the little buggers. It took about 30 minutes (over a remote connection)
to clean them without also disconnecting the machine (since I was
remote)....
 
Lars said:
On Wed, 1 Dec 2004 22:26:11 -0500, Arthur Hagen spoketh



The last reported number was 20 minutes. However, every time the story
gets referenced, the number keeps shrinking...
Hi

November 30, 2004
Unprotected PCs Fall To Hacker Bots In Just Four Minutes
http://www.techweb.com/wire/security/54201306

WinXP SP1 without any firewall protection had the poorest showing.
 
I blocked the http port (80) and port 2119 on my router and my internet
speed has been stable ever since.

May be just a temporary solution, but it saves me the trouble of a fresh
system install.

Rock said:
News said:
WHOA!!! gawd damnnit. it's that serious?

What exactly caused this problem?

TIA


News Groupie wrote:

I ran netstat at command prompt because I noticed my web browsing
getting ridiculously slow. It came up with 270 connections to my
computer. I know this is not normal. I recognize the AIM, MSN, Trillian
and similiar connections. But most of the other connections established
were to ports "2119" and "http" and most were from foriegn hosts/ips
(.fr, .se, .nl, .it, etc.). I don't have a web server running and I have
no clue what app or service uses port 2119.

How do I fix this so my internet speed isn't boggled down? How do I
prevent this from happening again?

Thanks in advance

P.S. - Yes, I'm running WinXP SP2.

Do a thorough scan for malware. Are you running a firewall? One should
be active at all times when online.

Run these programs to check for spyware/malware. After installing update
them, then boot into safe mode and run them. You should update and run
them weekly.

Cwshredder
http://www.intermute.com/spysubtract/cwshredder_download.html

Ad-aware SE
http://www.lavasoftusa.com

Spybot Search and Destroy
http://www.safer-networking.org

Bazooka Adware and Spyware Scanner
http://download.com.com/3000-2144-10247783.html

Pest Patrol Free Pest Scanner
http://www.pestscan.com/ScanOrTrial.asp

If you’re still having problems after running these then run HijackThis
and post the log to one of the specialty forums, _NOT_ this one.

HijackThis
http://www.majorgeeks.com/download.php?det=3155

Forums to Interpret HijackThis Logs:

http://www.spywareinfo.com/forums/
http://forum.aumha.org/viewforum.php?f=30
http://forums.tomcoyote.org/
http://www.wilderssecurity.com/

After your system is clean use these programs to help keep it clean:

Spywareblaster
www.javacoolsoftware.com/sbdownload.html

Spywareguard
http://www.javacoolsoftware.com/sgdownload.html

IE-SPYAD
http://www.staff.uiuc.edu/~ehowes/resource.htm

For viruses, start with Trend Micro’s Sysclean. Download it and the
signature file. Turn off system restore, boot into safe mode and run
sysclean. Boot back into normal mode and run a full AV scan with your
normal AV program. Then turn system restore back on.

Trend Micro Sysclean
http://www.trendmicro.com/download/dcs.asp

Trend Micro Signature File
http://www.trendmicro.com/download/pattern.asp

You should also regularly run at least two of these online scans in
addition to your regular up to date AV program:

Online and Downloadable Virus Scanning:

Panda ActiveScan
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Bit Defender Online Virus Scan:
http://www.bitdefender.com/scan/license.php

Symantec Online Virus and Security Scan:
http://security.symantec.com/ssc/home.asp

TrendMicro:
http://housecall.trendmicro.com/housecall/start_corp.asp

McAfee Online Virus Scan:
http://www.mcafee.com/myapps/mfs/default.asp

RAV AntiVirus - Scan Online
http://www.ravantivirus.com/scan/

F-Secure:
http://support.f-secure.com/enu/home/ols.shtml

McAfee AVert Stinger Virus Removal Tool
http://vil.nai.com/vil/stinger/

[Note: Stinger looks only for a limited number of specific viruses. It’s
not intended for full strength virus scanning and removal, but it can
help eliminate enough threats to allow you to install and scan with a
full featured AV program.]

Make sure you have a firewall active at all times. If nothing else use
the one built into XP, but there are a variety of free third party ones
that do a better job from Sygate, Zone Alarm or Kerio.

Sygate Personal Firewall
http://smb.sygate.com/products/spf_standard.htm

Zone Alarm
http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp?lid=staticcomp_za

Kerio Personal Firewall
http://www.kerio.com/kpf_download.html

Lastly check your system for vulnerabilities. Make sure you have all the
latest security patches from Windows Update too.

Websites which will check for vulnerabilities:

Browser Security Tests:
http://www.jasons-toolbox.com/BrowserSecurity/

Symantec Security Check
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym

http://bcheck.scanit.be/bcheck/
https://testzone.secunia.com/browser_checker/
www.pcpitstop.com

Unsafe computing practices.
 
On Thu, 02 Dec 2004 21:27:05 -0700, DevilsPGD spoketh

Reported by whom? I've seen boxes running XP RTM compromised within "a
few minutes" seen = witnessed myself.

Reported by a news organization. IRRC, the report in question was on
news.com. However, they only report. It is very possible that the actual
source was Gartner.


Lars M. Hansen
http://www.hansenonline.net
(replace 'badnews' with 'news' in e-mail address)
 
On Thu, 02 Dec 2004 21:27:05 -0700, DevilsPGD spoketh
Reported by whom? I've seen boxes running XP RTM compromised within "a
few minutes" seen = witnessed myself.

I should also add that this was an "average" time, not a fastest or
slowest, but an average of several tests. So, it is indeed possible that
a computer could be compromised in 4 minutes. It is also entirely
possible that the computer will not be compromised within 30 minutes...

Any type of device or software that blocks incoming connection attempts
are definitely a step in the right direction, and SP2 with it's default
firewall setting as "on" rather than "off" will definitely have an
impact on this (unless, of course, if you've got it disable in GP like I
do...)


Lars M. Hansen
http://www.hansenonline.net
(replace 'badnews' with 'news' in e-mail address)
 
In message <[email protected]> "News Groupie"
I blocked the http port (80) and port 2119 on my router and my internet
speed has been stable ever since.

May be just a temporary solution, but it saves me the trouble of a fresh
system install.

No it doesn't -- Your system is still compromised with unknown (but
obviously malicious) software.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top