The Cellar

The Cellar (http://cellar.org/index.php)
-   Technology (http://cellar.org/forumdisplay.php?f=7)
-   -   The Annoying svchost.exe problem!!!! (http://cellar.org/showthread.php?t=5923)

perth 06-02-2004 09:48 AM

*Can* suggest you have the Blaster worm, not categorically prove it.
Quote:

Its not a virus coz i got up to date protection and it didnt find one,
Now, I've spoken to end-users who think "up-to-date" means "within the past couple months", so I probably shouldn't be operating on assumption here, but I took Pirate's statement to mean that he ran the lastest virus defs and it came up clean. As far as I know the big scanners cannot clean it, only quarantine it, but they're still gonna report it.

So the big question here is, what exactly does Pirate mean when he says "up-to-date" in the context of his virus protection? And for good measure, which application is he using?

pirate 06-02-2004 10:34 PM

[quote]Originally posted by perth
*Can* suggest you have the Blaster worm, not categorically prove it.

Now, I've spoken to end-users who think "up-to-date" means "within the past couple months", so I probably shouldn't be operating on assumption here, but I took Pirate's statement to mean that he ran the lastest virus defs and it came up clean. As far as I know the big scanners cannot clean it, only quarantine it, but they're still gonna report it.

So the big question here is, what exactly does Pirate mean when he says "up-to-date" in the context of his virus protection? And for good measure, which application is he using?
[/QUOTE



What I mean is my virus scanning program Norton AntiVirus 2003 updated virus defs every time i access the internet. I have a seperate virus searcher that is tuned to the blaster worm and will exterminate any possible traces of it.

perth 06-02-2004 11:44 PM

Then it's reasonably safe to say you're not infected. I would start using support.microsoft.com and groups.google.com to start narrowing down possibillities. :)

mbpark 06-03-2004 11:40 AM

either that or Kerio :)
 
Either that or get Kerio or ZoneAlarm, as the fact that it's letting MSRPC traffic in is a BAD thing.

Also, avoid BlackICE like the plague. If you use a few different types of nmap scans, nmap 3.5 makes it completely invisible.

Mitch


All times are GMT -5. The time now is 01:42 PM.

Powered by: vBulletin Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.