Notices
ScoobyNet General General Subaru Discussion

Something weird going in ... ZoneAlarm might be good idea :(

Thread Tools
 
Search this Thread
 
Old Aug 9, 2001 | 10:41 PM
  #1  
EvilBevel's Avatar
EvilBevel
Thread Starter
Scooby Regular
 
Joined: Oct 1999
Posts: 3,491
Likes: 0
Unhappy

No scaremongering, but ...

I had about 3000 alarms in the last 3 days from my PC being scanned.

Looks like another trojan becoming active ...

Just make sure that you have some kind of protection on your PC. ZoneAlarm is pretty good and free, but others may be equally useful.

See
Reply
Old Aug 9, 2001 | 10:50 PM
  #2  
kryten's Avatar
kryten
Scooby Regular
 
Joined: May 2000
Posts: 869
Likes: 0
Post

Its good to keep reminding people!

Had a consultant at work this week who complained about a lot of data being sent down his dialup link (which he left connected all day).

It had transferred over 100mb -
netstat -na revealed over 5000 open ports. On reboot, over 2000 ports were opened immediately.

He had a trojan, hadn't updated the virus files in 6 weeks and had no personal firewall. Told him to talk to his IT dept who told him that the laptops were 'self managing' ie he had to do it himself!!!

Regularly updated virus checker plus personal firewall and regular patching isn't just for those of us who run servers....
Reply
Old Aug 9, 2001 | 10:51 PM
  #3  
Richard Askew's Avatar
Richard Askew
Scooby Regular
 
Joined: Dec 2000
Posts: 9,400
Likes: 0
From: A land of lap-dancers and Lanson Black Label
Post

nah ur ok theo - not scared....
Reply
Old Aug 9, 2001 | 11:05 PM
  #4  
EvilBevel's Avatar
EvilBevel
Thread Starter
Scooby Regular
 
Joined: Oct 1999
Posts: 3,491
Likes: 0
Post

OK, just to update ... all scans seem to go to port 80, so it may be the Code Red thing relaunching.

If you are not running IIS, you don't have to worry about this one. Still, recommendation of a personal firewall still holds.

Theo
Reply
Old Aug 9, 2001 | 11:50 PM
  #5  
boomer's Avatar
boomer
Scooby Senior
 
Joined: Feb 2000
Posts: 5,763
Likes: 0
From: West Midlands
Exclamation

Theo,

it is not so much a <I>relaunch</I>, rather just a continuation of the damage that Code Red II is doing. See
Reply
Old Aug 10, 2001 | 01:32 AM
  #6  
kryten's Avatar
kryten
Scooby Regular
 
Joined: May 2000
Posts: 869
Likes: 0
Post

most of the connections to port 80 at the moment will be code red, or one of its variants/children.

i'm seeing &gt;50 attempts per day.

depends on your ip address: a mate's server is getting 200 attempts per day.

oh well, only 10 days of it to go (until the 1st Sept, anyway).

cleanup of code red 1 is easy as its memory based only: reboot, then patch to stop re-infection.

code red 2 is a bit more tricky....plenty of sites with the info needed though.
Reply
Old Aug 10, 2001 | 01:52 AM
  #7  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Post

Reading some of the MS Private newsgroups, Code Red seems to stop the MS Proxy services on BackOffice SBS servers at random.

Interesting side effect...

ChrisB.
Reply
Old Aug 10, 2001 | 12:46 PM
  #8  
Ian Griffiths's Avatar
Ian Griffiths
Scooby Regular
 
Joined: Dec 2000
Posts: 302
Likes: 0
Post

*Groan*

Editted as I read the help file

[This message has been edited by Ian Griffiths (edited 10 August 2001).]
Reply
Old Aug 10, 2001 | 12:54 PM
  #9  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Post

So tonight was a good time to change over to my hardware firewall then?
Reply
Old Aug 10, 2001 | 05:11 PM
  #10  
Viagraman's Avatar
Viagraman
Scooby Newbie
 
Joined: Sep 2001
Posts: 6
Likes: 0
Post

i have had zone alarm and norton av for a while now and i am extremely happy with both.
ZA is certainly good for a freebie !

VM
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Mattybr5@MB Developments
Full Cars Breaking For Spares
20
Oct 22, 2015 06:12 AM
jobegold@hotmail.co.uk
ScoobyNet General
43
Sep 24, 2015 02:16 PM
RAGGY DOO
General Technical
6
Sep 18, 2015 09:18 PM
Adam Kindness
ScoobyNet General
0
Sep 15, 2015 03:31 PM
blackandz
General Technical
0
Sep 12, 2015 07:01 PM




All times are GMT +1. The time now is 08:57 PM.