afterdawn.com  > forums  > software, operating systems and more  > windows - virus and spyware problems  > worm intursion  
											
												
	
	
						 				 	
	
	
	
		
			
			
			
		 
	
												 
															
															
	
			
			
				
					worm intursion
				 
				
				
					
				 
				
			 
			
			
			
				
					
					
				 
			
			
			
			
			
				
				
					
				
				
				
				
					
						
							
								JAHMAX
							
							
								Newbie
								
									
								
							
							 
						6. April 2006 @ 17:20 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Being constantly attacked by this worm like so many others. The worm is portscan 1920168.0.1 (domain(53)) and it attacks many different ports.  We have down loaded Hijackthis and did a scan and created a log that we pasted below.  Can someone please assist us in eliminating this really annoying pest?  Thank you.
http://www.dell.com http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/... http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/... http://yahoo.sbc.com/dsl http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/... http://rd.yahoo.com/customize/sbcy/defaults/*http://yahoo.sbc.com/dial http://go.microsoft.com/fwlink/?linkid=39204 http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/... http://a19.g.akamai.net/7/19/7125/4056/ftp.coupons.com/r3302/Coup...  
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
					
						
							Advertisement
							 
						 
					
						
							
							
						 
					 
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						6. April 2006 @ 20:24 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Ok, the worm propably is not in your computer and it is attacking from outside. The good thing is that you have Norton's firewall protecting you. 
http://www.ewido.net/en/download/ Cleaning instructions: 
HijackThis .exe into its own folder C:\HJT
HijackThis  and fix these entries (if found): (Do a system scan only, check entries, close all other windows, press Fix checked) 
http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/... http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/... http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/... http://rd.yahoo.com/customize/sbcy/defaults/*http://yahoo.sbc.com/dial http://a19.g.akamai.net/7/19/7125/4056/ftp.coupons.com/r3302/Coup...  
HijackThis  log and Ewido's log to here so we can see if your computer is clean.
 
							
						 
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								JAHMAX
							
							
								Newbie
								
									
								
							
							 
						8. April 2006 @ 08:08 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Here is the requested ewido log file:
HijackThis  report
 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								JAHMAX
							
							
								Newbie
								
									
								
							
							 
						8. April 2006 @ 08:13 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Here is our log file from HijackThis  and thank you:
HijackThis  v1.99.1
http://www.dell.com http://yahoo.sbc.com/dsl WinZIP  Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
http://go.microsoft.com/fwlink/?linkid=39204 http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...  
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								JAHMAX
							
							
								Newbie
								
									
								
							
							 
						8. April 2006 @ 08:18 Link to this message 
								  
								 
					
					
					
						
						
						
							
							FYI: Here is the response I got from Symantec.
http://service1.symantec.com/Support/nav.nsf/docid/20040914131335...  
http://www.checkdomain.com/  
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						8. April 2006 @ 21:46 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Hi, your log looks clean. 
 
							
						
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								JAHMAX
							
							
								Newbie
								
									
								
							
							 
						9. April 2006 @ 06:40 Link to this message 
								  
								 
					
					
					
						
						
						
							
							We did all recommended fixes yesterday and the worm in question hit us once so far.  We always would reboot when it hit and did so again out of habit without seeing if it would slow us down as usual. We won't get a real test until it hits again and we don't reboot.  To answer you question the worm would always hit Explorer when starting it or while using it and often.  The attacks were less frequent on the weekends.  Ewido just downloaded an upgrade and I will do another scan.  Thanks again for your help. Jahmax 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						9. April 2006 @ 21:14 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Ok, you're welcome =)
 
							
						
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								JAHMAX
							
							
								Newbie
								
									
								
							
							 
						10. April 2006 @ 20:02 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Hi there! Please explain.  Is it possible internet explorer is blocking traffic from my router?  How do I determine this? 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
					
						
							Advertisement
							 
						 
					
						
							
							  
					 
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						11. April 2006 @ 04:15 Link to this message 
								  
								 
					
					
					
						
						
						
							
							No I ment that have adjusted Norton's settings so that it allows Internet Explorer to connect to internet.  
							
						
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
						 
					 
				
				
			
			
			
			
			
		
		
	
			
			
		
	 
 
					
						
							afterdawn.com  > forums  > software, operating systems and more  > windows - virus and spyware problems  > worm intursion