That is good, maybe you are lucky. But, let think, are you only one persone on world using Win2000 with ZA? No. Does other people having similar configuration like you have a same problem? (downloading of malware during mentioned period)? I belive not, am I wrong? Why do you have? What is the reason? It does not have to be malware, but probability is high. Try to scan with some on-line scanner (Kaspersky is OK). You can also try to download
formatting link
rename it for example _root_dummy.exe and submit log to mentioned site. Best would be to ask somebody, who knows more than you, to check your hijackthis log and system for misconfiguration. Something is definetly wrong on your system. Are you running some server applicatons?
formatting link
this is interesting utility, you may find it usefull. Check running processes and listening ports.
NAT router will prevent dowloading of malware in future, but it will not fix your system, you have to do that.
Didn't find your answer? Ask the community — no account required.
Kerio is a good firewall, but it will anything permitted by the rules....
N
NoSpam
Dear Mr. Arnold,
No, I am not intimidated by trolls. They are easy to recognize by their in- ability to address a problem, their lack of good grammar and the absence of social grace.
You said in your mail:
The program Antivir Guard has the ability to scan "Laufende Prozesse", that is "Ongoing Processes". Is that in some way equivalent to Process Explorer? If no ongoing processes are found and maleware can turn itself on and off according to some algorithm, such a program might not be too valuable.
Greetings GR.
N
NoSpam
Dear Alf,
Other people with the same configuration may have the same problem and not recognize it! It occured only once during the vulnerable period and AntiVir Guard caught it. There were however some six of these files on my PC from earlier unrecognized events. I am sorry I erased them all and did not keep a copy.
I have observed with an earlier version of ZoneAlarm, that immediately after booting up, a ping comes in. It is either from the IPS or from some other scanner. So there is a way to find PC,s which have just booted up. This could be the reason why I have been hit with that malware, rather than by malware residing on my PC calling out for more malware.
Newer versions of ZoneAlarm have done away with this reporting be- cause it led to very frequent reports which were apparently a nuisance and not of concern.
To answer your question whether I am running a server: I do not.
Greetings and thanks GR.
A
alf
Hm, hm... I doubt.
Maybe I'm paranoid afterall. It is your system, you know better what is going on there. If you said it is clean, OK then it is clean. Now don't loose your time replying on this post. Configure your NAT router and keep on working normally.
Good luck.
A
Ansgar -59cobalt- Wiechers
"Running Processes" would be a more fitting translation. If I read this correctly, then AntiVir Guard scans the memory areas a program's code is loaded to while the program is being executed.
Process Explorer only lists processes, it doesn't scan them.
Malware doesn't turn itself on.
cu
59cobalt
N
NoSpam
Dear Ansgar, dear Mr. Arnold,
First: Win2k, my OS has the Task Manager. This program lists all running processes. It would be hard to discover malware among the various filenames it lists. Since Task Manager list running processes, Process Explorer would be superfluous, true?
Second: Does malware run all the time? Your post seems to indicate so. Task Manager indicates CPU usage. This would help to verify that malware is running!
Third: I do not know what exactly AntiVir Guard scans under Laufende Pro- zesse. All I know is that it says it scans "Laufende Prozesse".
I have done a scan with Kaspersky of the most sensitive area. The result showed
21 infected files and 2 Viruses. The final report lists the 21 files as not-a-virus AD files BUT it lists no virus.The Ad-files are like those I have located previously. They consists of a randomly selected sequence of 8 letters, the extension is .dll and they are in C:\\WINNT\\System32.
An example would be njmfgxfp.dll. They are all 124 436 bytes long and were created between June 15 and 18. Kaspersky calls them not-virus:AdWare.Win32. Virtumonde.ki with no other info available and their definitions were added to Kaspersky's list on 14 June. AntiVir Guard did not identify these 21 files nor any virus.
Why did Kaspersky not list the two Viruses they claim to have found?
Any comments?
Thank you GR.
A
Ansgar -59cobalt- Wiechers
Wrong, since Process Explorer shows *way* more (crucial) information about processes than the Windows Task Manager. These informations help identifying rogue processes.
Malware doesn't necessarily run all the time. However, it does not start all by itself, but needs some mechanism to be run. That can be the user, one of the many autorun-mechanisms Windows provides, the task scheduler or several other ways.
Usually virus scanners scan only files. As I said before "Laufende Prozesse" means "running processes", which would imply that AntiVir Guard scans not only files on your harddisk but also the processes in your RAM.
Because you configured it not to? Because it was manipulated by some malware? Because the stars are not right? There's no way to tell without a closer examination of your system.
However, apparently your system was compromised, and whatever did this had administrative privileges (because it was able to create files in %SystemRoot%\\system32). You can't trust anything any software running on a compromised system tells you. The only reasonable way to clean your system is to backup your data (expressly excluding any kind of executable), and then flatten and rebuild your system.
formatting link
cu
59cobalt
M
Mr. Arnold
No, it's not even in the ballpark with PE.
Malware likes to piggy back off of other processes that are running to hide or disguise itself, so that it's not easily spotted.
And Task Manager is no match for Process Explorer, because Task Manager only allows you to see the top process that's running.
PE allows you to not only to see a top process that's running, but it also allows you to look inside that top process and see the hidden processes that are being hosted by the top process, such as a possible malware process.
S
Sebastian G.
I'd title this post: "self-exposure of a troll"
S
Sebastian G.
But you're at least aware that you're either totally oversimplifying or talking utter bullshit?
M
Mr. Arnold
It's not read go away. You are a lunatic.
that's a soft logical .
M
Mr. Arnold
You read my other post. It applies to you here as well.
M
Mr. Arnold
One other thing here, you don't need to answer any of it, please.
Do you even notice what a nuisance you are in this NG, and how you have dragged this NG down?
Do you even notice how most of the regulars pretty much mind their own business and post to the OP while you in the meantime attack everyone with running up and down the threads?
This NG use to be a lot livelier with a mixture of professionals and non-professionals that frequent the NG seeking help, until you showed one day out from under a rock and started choking the NG out. :(
S
Sebastian G.
So far, I can only see this applying to you.
Oh, and would you please stop giving ill-advised suggestions that even you should know how wrong they are? This guy is about to actually buy a NAT router, which will just make everything fail again.
M
Mr. Arnold
You replied anyway, my God. When you're in this state of mind with pure lip dribbling, you know I am not reading it. :)
What a problem you have that you cannot control yourself with your postings in this NG.
N
Notan
If you'd pull your head from whatever holes it's currently in, you'd realize that your methods of "teaching" are anything but constructive.
S
Sebastian G.
Now what about one step after another? First deconstructing the nonsense, then thinking about the problem again, and then you'll start building a real solution.
Sorry for not suggesting a solution without even thinking about the problem again for figuring out what the actual problem is.
N
Notan
You just don't get it.
From what I've read, you've got a bunch of knowledge, but your attitude and method of presentation is so condescending, among other negative attributes, that it's all but wasted.
M
Mr. Arnold
He'll never get the message. He has not gotten the message to date, and it's been made obvious to him by a few people in this NG over a several months period.
It's really a shame about him. He obviously has great knowledge or seems to have the knowledge.
But he is so messed-up as Human Being that he is beyond help with his teaching methods, mannerisms, and in general, a lack of basic knowledge on how to treat people.
He has dragged the NG down to the point that no one wants to make a post in this NG, because he is liable to show and start going out of control. :(
S
Sebastian G.
The word you were searching for might have been "honest" or "direct". As you might understand, this is a place for discussing, not for cuddling and soft caressing. If some people have a problem with that, it's definitely not my fault.
BTW, isn't this getting a little bit offtopic?
Now, would someone please get a point that typical NAT router don't magically drop every packet with unknown target, but rather takes measure of guessing the target and forwarding it by chance? That's why Stephen's suggestion is so misguided, since it won't help at all with protecting a vulnerable system.
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.