Restoring WindowsXP SP2 Firewall service after malicious software attack



Hello!

My computer (WinXP SP2 fully patched - including yesterdays patches)
was compromised today with brand new attack vector which has done the
following:

1. Disabled built in WinXP firewall
2. Downloaded several trojans
3. Crashed system with bluescreen of death
4. After system reboot several applications were infected with trojans
5. Permanently damaged WinXP firewall by uninstalling its service
6. Damaged internet connection sharing service

This new vector was send to KasperskyLabs and confirmed to be new
malicious software (lab singature [KLAB-1097372]).

I am still trying to recover full system functionality after attack and
have performed several scans with:

1) rootkit detectors,
2) anitvirus software.
3) sfc tool which was used to restore original windows files

Tried to reinstall SP2 as well (orirginal system was SP1) but it did
not help in restoring firewall and internet connection sharing
services.

Anyone have an idea how to restore original firewall/internet
connection services? MS documentation is obviously missing in that area
and I would prefer to avoid system reinstallation or repair
installation.

.



Relevant Pages

  • RE: fedora-list Digest, Vol 16, Issue 287
    ... >> can't get the winXP box online through the Fedora box. ... or the "middle man" has to do address translation for him. ... -- serve as a NAT router. ... If you use XP's Internet Connection Sharing, it's going to do this for you. ...
    (Fedora)
  • Re: Starting up a new HP computer recommendations?
    ... In case that there is WinXP RTM (Gold) or WinXP SP1 installed, ... enable the WinXP firewall before going online. ...
    (microsoft.public.windowsxp.general)