Suspected Attack

From: Alan UK (bigal_1302_at_hotmail.com)
Date: 09/01/03


Date: Mon, 1 Sep 2003 01:38:16 -0700


I am running W2k pro with Norton System Works AV (with
Live Update) and a Sygate Personal Firewall (freeware
version) and have an ADSL connection- although not left on
24/7.
After the MSBlast virus I scheduled a weekly Windows
Update and have all the latest bit and pieces.
I recently noticed a lot of attempts (throught the
firewall log) for sites trying to access the internet
using existing software- ie "site.com is trying to access
the internet through Norton Speed Disk" sort of thing.
Although I blocked all I could later the PC went a bit
barmy and kept showing Explorer.exe errors.
After a reboot and every scan (AV, Spyware etc) I could
muster I noticed that the Sygate firewall had gone awol.
The .exe file and Readme.txt were in the folder, but all
the rest had gone- and I discovered them all in the
Recycle bin.
I restored them, but is this a virus/trojan attack to
disbale the firewall or could this have happened during
the Explorer.exe errors? (I realise that could have been
part of any attack too)
Any information would be greatly appreciated, and
particularly any information about further (cost-
effective) methods of protecting the pc short of shutting
it off or disabling so much as to make the internet a
waste of time...I know its a compromise.
:-(



Relevant Pages

  • Re: Just when you think youd seen it all.....
    ... WinXP Pro SP1 installed, Norton system works, AOL 9.0, ... AVG Anti-Virus Free Edition and Spybot Search & Destroy. ... I started the Windows Firewall so she would have basic ...
    (alt.sys.pc-clone.dell)
  • Invalid page fault in module VBA332.DLL
    ... Publisher 97 on the system. ... got to the point of using Publisher to write my letters, ... I have Norton System Works 2003 with Virus Checker and Firewall and update ... I already have to keep the Firewall ...
    (microsoft.public.word.docmanagement)
  • Re: unused ports, firewall, and trojanhorse
    ... The exact build of the software firewall (from Properties ... Three add-on utilities for NIS/NPF that you may wish to check out: ... security from Norton System Works would be Norton Anti-Virus. ... Almost all electrons used in the creation of this message were recycled. ...
    (microsoft.public.security)
  • Re: Symantec Common Client update prevents OE retrieving mail
    ... Just did a live update and IE stopped accessing web pages. ... "To restore the default General and Trojan Horse firewall rules." ... version 2005 and downloaded ISRIRstr.exe This is on the Symantec web page. ... > work (because the trigger to prompt you for the "new" upgraded component ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • what is tfswctrl.exe?
    ... I'm running Win XP home, MSIE 6.0, Outlook Express 6.0. ... Norton System Works 2004, including Antivirus and ... Internet Security (my firewall). ... only way to undo it is to use the power button! ...
    (microsoft.public.windowsxp.general)