Re: a few basic simple questions

From: Douglas Pichardo (vbnova@myrealbox.com)
Date: 01/30/02


From: Douglas Pichardo <vbnova@myrealbox.com>
To: "Enquiries" <Enquiries@globalart4u.com>, <security-basics@securityfocus.com>
Date: Wed, 30 Jan 2002 15:16:59 -0500


> How do you know when you are infected by a trojan or someone has control of
> your pc from a backdoor?
The simplest way to see if you are infected by an active trojan is to run
netstat -an from a DOS window. That will show you open internet connections.
You might also want to try a packet sniffer to examine incoming/outgoing
packets; I recommend Ethereal (http://ethereal.zing.org).
> Is it when your windows update's always continuously refuse to update from
> the microsoft site, including the ever popular critical updates to patch
> security holes?
The Windows Update site has been down for a little while I think... some
problem with the setup (I think there was a news item about it, but I don't
remember). Also, that just happens sometime; it happenned to me, and I was
clean (in Windows 98).
> When trying to update IE from microsoft it does not work?
That happenned to me a few times... see above.
> When you discover every so often that the hard drive when wiped clean
> suddenly becomes a 1gb hard drive instead of a 20 gb hard drive - has
> happened several times to me?
Sometimes your BIOS and/or DOS/Windows see large drives in a messed up way.
Some BIOSes can report incorrect info about the hard drive, and sometimes
fdisk messes up when reporting partition size when you actually partition it.
> when the firewalls (zonealarm) every so often is disabled while surfing?
...this is the only one I see as really a hint there might be a problem. You
should get some anti virus software and scan your computer. If you find
anything, unplug your computer from the internet (or disconnect if on
dialup), and clean up.
> How does one detect what the problem is and cure it, especially when you
Well, netstat is useful in finding out open connections you have to foreign
computers. Under Start Menu/Programs/Accessories/System Tools (I THINK, not
sure...) you can find a prog called System Information, and a tab in that
shows you all running processes and the locations of the files that are
running - this is very useful. But most of all, get some antivirus software -
if not Norton's or McAfee's, try... umm, I forget the name, maybe someone can
provide a link - it's free though... sorry, brain fart.
> are a beginner? If using a trojan to fight a trojan to cure the problem
> how does you know which ones to trust, as I have found there seems to be a
> lot of programmes out there saying they can find this that and the other
> but what if it is something really specialised?
...don't use a trojan to fight a trojan... I don't see a trojan could fight
another, and also you are not sure the one you purposefully use is not
malicious to you.

DoPo



Relevant Pages

  • Re: Removing CoolWebSearch (spyware)
    ... without taking the trojan along with it? ... having to boot Windows on the same drive. ... dirty it's tons easier to clean a not-booted drive. ... Reload Windows from CD ...
    (alt.guitar)
  • Re: repairing services.exe
    ... and the computer is clean. ... the trojan works like the sasser worm. ... You might also try clean-boot troubleshooting to possibly see what is ... Clean boot in Windows XP - http://support.microsoft.com/kb/310353 ...
    (microsoft.public.windowsxp.general)
  • Re: Security POP update
    ... So run antivirus and anti-spyware in regular mode. ... runsrv32.exe seems to be a trojan. ... Name Troj/Spyre-A ... Affected operating systems Windows ...
    (microsoft.public.windowsxp.security_admin)
  • SYMANTEC doesnt detect TROJAN, !!WARNING TROJAN ATTACHED!! - first_3sum.wri (0/1)
    ... ATTACHED FILE IS INFECTED WITH A TROJAN. ... me some advise on how to completely remove the infection. ... My OS is Windows ME. ... I am using Norton Internet Security2002. ...
    (comp.security.firewalls)
  • Re: operating error
    ... You may have a Backdoor Trojan that creates randomly generated names. ... When you get to a C: prompt, type: CD windows and hit enter. ... Open the registry editor ... Ron Badour, MS MVP W95/98 Systems ...
    (microsoft.public.windows.inetexplorer.ie6.browser)