You are viewing an obsolete version of the DU website which is no longer supported by the Administrators. Visit The New DU.
Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Reply #13: I've been trying to figure this out, too [View All]

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
Ivory_Tower Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 11:12 PM
Response to Original message
13. I've been trying to figure this out, too
I understood the headaches I went through at work today since our network is like a sieve, but at home:

I have an up-to-date AV data file, plus a firewall on my router, PLUS ZoneAlarm. (I'm running Win2K, btw.) I've run the "Probe My Ports" test and all that, and theoretically, my network is invisible to the outside world. I checked the log on my router and port 135 is constantly getting pounded. I check the log on ZoneAlarm and didn't see any attempts to reach Port 135 (or any port, for that matter since the router firewall seems to be working). And yet, when I checked my PC, I saw the same symptoms as the ones I saw at work! So, either the symptom I'm seeing isn't really a sympton and I'm safer than I thought (I don't tend to think that way, though), or my computer got infected by some other method (but the only method I've read about is unauthorized exploits through port 135).

The symptom I had was watching tftp.exe "miraculously" restore itself in the system32 directory after I rename it or delete it. I didn't see it active in Task Manager, either, so I'm not sure who restored it.

Once I ran the updates and patches, I was able to delete the restored instances of tftp.exe without having them return, so I'm pretty confident that I was attacked. But I'll be damned if I can figure out how.
Printer Friendly | Permalink |  | Top
 

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC