Forum Home
Press F1
 
Thread ID: 42582 2004-02-15 14:52:00 Viri infected pc °° toxicbass (4045) Press F1
Post ID Timestamp Content User
215771 2004-02-15 14:52:00 Hello!

My pc (1 . 6ghz athlon with xp pro (formatted only 45days ago) was restarting by itself when
1) i turn it on and it gets to windows
2) when i double click the net icon and the modem relay goes 'click'-and it would restart right at that moment

So i treid the confuzled micro$oft site,found the auto scan thinge to see what i needed-too bad i needed ten thousand files,no chance of that thanks!

So i just downloaded the msblast fix- which wouldnt run until i had all those files

So just now am scanning with symantec w32 . blaster . worm removal tool . . .
fixblast . exe ( . symantec . com/avcenter/FixBlast . exe" target="_blank">securityresponse . symantec . com)



All this trouble started btw , when my zone alarm ran out,20seconds on the net ,and RPC time! woah thanks ,and just to top it off,u cant even take a screenshot of ur RPC for future laughs about how Xp security is!
:-@
i found this running- and i run spybot and ad aware weekly . . when i format this pc il make sure we DONT install kazaa . . . and get ZONE ALARM


"WinTasks Process Library



teekids - teekids . exe - Process Information
Process File: teekids or teekids . exe
Process Name: Teekids
Description: Indication of the Lovesan worm . This worm scans several IP networks to get access to port 135 (COM) . The worm sends a buffer overrun request to vulnerable computers . The newly infected computer then initiates the command shell on TCP port 4444 . Lovesan runs the thread that opens the connection on port 4444 and waits for the FTP 'get' request from the victim computer . The worm then forces the victim computer to send the 'FTP get' request . Thus the victim computer downloads the worm from the infected computer and runs it . The victim computer is now infected .
Company: N/A
System Process: No
Security Risk ( Virus/Trojan/Worm/Adware/Spyware ): Yes
Common Errors: N/A

[url]http://www . liutilities . com/products/wintaskspro/processlibrary/teekids/ (]http://homepages . paradise . net . nz/quadroph/hahah . JPG[/url)


the symantec thing just completed,took ~20min

Cheers!
toxicbass (4045)
215772 2004-02-15 14:54:00 when i format this pc il make sure we DONT install kazaa...and get ZONE ALARM


i mean, Not the demo version which runs out resulting in viri infection
toxicbass (4045)
215773 2004-02-15 15:02:00 also note that the Picture URL infect sends you to pcworld :P

image -

homepages.paradise.net.nz

i wish there was an edit function to edit posts within 15min of posting them!
for 3am munters!
Cheers!
toxicbass (4045)
215774 2004-02-15 15:02:00 also note that the Picture URL infect sends you to pcworld :P

image -

homepages.paradise.net.nz

i wish there was an edit function to edit posts within 15min of posting them!
for 3am munters!
Cheers!
toxicbass (4045)
215775 2004-02-15 19:40:00 If you enable Windows XP's firewall prior to going online for the first time you will be protected from incoming attacks until you are able to download your updates and a third party firewall. tommy (2826)
215776 2004-02-15 20:35:00 Why not do this next time it occurs:
Click Start
Click Run
type:
shutdown /a

And the error should go away :-)

Then get to the removal of it :-)


Chill.
Chilling_Silently (228)
215777 2004-02-15 23:06:00 shutdown /a

so whats the /a command actually do?

il try it when i get home

And yes i did get this weird problem with the xp firewall on- perhaps i turned it off once to transfer a file on msn mess,allowing bugs onto pc
:-(

Thanks
toxicbass (4045)
215778 2004-02-15 23:42:00 Shutdown /a
Translates to:
Abort shutdown


Chill. :-)
Chilling_Silently (228)
1