Firewall Alert for Virus ! - Page 2

Created

Last reply

Replies

25

Views

2.1k

Users

5

Likes

13

Frequent Posters

Ishan. thumbnail
18th Anniversary Thumbnail Stunner Thumbnail + 8
Posted: 15 years ago
#11
Screen Shots of my Alerts !!




Posted: 15 years ago
#12

Originally posted by: hardik_kansagra

i know what you says but there's no need to add security patches cause in mine one i have microsoft windows vista service pack 2(OEM Addition) With all Security Patches In My Dell Leptop And Stil I Am Receiving This Alerts Here Are The Pictures.

Picture 1 :
Picture 2(While Pressed View Detail Link In Alert) :
Frequency Of Message : Each 10 Minit While Surfing(Not Just India-Forums But At All Sites).
And I Do Not Think That Norton Is Bed Software Cause Norton internet Security, McAfee, Quick Heal,AVG, Kaspersky Internet Security Are The Top 5 High Reated Softwares For Protection To Virus And Hack Attacks.
By
Hardik Kansagra



Hey,

If you watch the IP and its location you will notice that its coming from the same IP range starting with 117.232.xxx.xxx and it has nothing to do with any website but your network.

So first thing I would suggest if you are on a cable internet or something then disable Windows File Sharing.

Posted: 15 years ago
#13

Originally posted by: ishan.k

Screen Shots of my Alerts !!






Hey can you let me know where you got this alert as this is coming through some "GIF" file ddfapey.gif

So if you can tell me more about it may be I can find the source of the problem.

Cheers,
Vijay
Posted: 15 years ago
#14

Originally posted by: vijay



Hey can you let me know where you got this alert as this is coming through some "GIF" file ddfapey.gif

So if you can tell me more about it may be I can find the source of the problem.

Cheers,
Vijay



On further studying more about this particular worm:

Win32/Conficker.B starts an HTTP server on the affected system by opening a random port, shown below. This allows a copy of the worm to be downloaded by systems vulnerable to MS08-067.

The downloaded files usually have the following file extensions:

.BMP
.GIF
.PNG
.JPG


So either your system is compromised or its trying to download the file from one of those affected systems. So lets find more about it.

BTW do you know Microsoft has put an award of 5 Million dollars to the person who helps in finding the author or group who is spreading this worm. 😊

Edited by vijay - 15 years ago
Ishan. thumbnail
18th Anniversary Thumbnail Stunner Thumbnail + 8
Posted: 15 years ago
#15

Originally posted by: vijay



Hey can you let me know where you got this alert as this is coming through some "GIF" file ddfapey.gif

So if you can tell me more about it may be I can find the source of the problem.

Cheers,
Vijay



I really don't know that. What to check , I am confused !! 😕 Can u tell me wat i should let u ??
Ishan. thumbnail
18th Anniversary Thumbnail Stunner Thumbnail + 8
Posted: 15 years ago
#16

Originally posted by: vijay


On further studying more about this particular worm:

Win32/Conficker.B starts an HTTP server on the affected system by opening a random port, shown below. This allows a copy of the worm to be downloaded by systems vulnerable to MS08-067.

The downloaded files usually have the following file extensions:

.BMP
.GIF
.PNG
.JPG


So either your system is compromised or its trying to download the file from one of those affected systems. So lets find more about it.

BTW do you know Microsoft has put an award of 5 Million dollars to the person who helps in finding the author or group who is spreading this worm. 😊



Wow thanks for letting me know this !! So i can find anti virus for this worm on Microsoft site ??

hehehe 5 million dollars ?? 😲😲😲 I wish i could find that author of this worm 😆

Posted: 15 years ago
#17

Originally posted by: ishan.k

Screen Shots of my Alerts !!






Well on further checking I feel that this is NOT coming from any website cause:

Your alert shows that its trying to download the file in the following Folder:

C:\Documents and Settings\Network Service

Where as all the temporary internet files are normally stored in:

C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\


And normally this particulr Worm spreads through LAN using ill formatted RPC calls or USB Drives (through autorun.inf)

Hope this helps you find more about the same.

Regards,
Vijay
baz786 thumbnail
16th Anniversary Thumbnail Sparkler Thumbnail + 2
Posted: 15 years ago
#18

Originally posted by: vijay



Well on further checking I feel that this is NOT coming from any website cause:

Your alert shows that its trying to download the file in the following Folder:

C:\Documents and Settings\Network Service

Where as all the temporary internet files are normally stored in:

C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\


And normally this particulr Worm spreads through LAN using ill formatted RPC calls or USB Drives (through autorun.inf)

Hope this helps you find more about the same.

Regards,
Vijay



Vijay

this conficker virus has been around a while

one thing to do is keep anti-virus upto-date

also one can disable the Auto Play feature of any usb device, dvd or cd

this will help reduce chance of infection

n keep windows updates running the patch for this virus is KB958644 from MS

but just wait until windows installs it by itself thru update

most will probably have it all ready

the way to check is go to add-remove programs n click show updates

Vijay can u plz fill in if ive made any error in explanation n also tell members how to disable autoplay function i knew how to do it but have forgotten
Posted: 15 years ago
#19
On McAfee site they are reporting Global Threat Condition to : Critical

Which means:

Systems worldwide are being widely targeted, or may become widely targeted by an active and available exploit or threat. An extreme global security incident is taking or may imminently take place.


And this is affecting a lot of people using "Internet Explorer"

Microsoft has today released a very "Critical Update" which you should not ignore and install it immediately.

https://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx

This security update resolves seven privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The more severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Be safe!
baz786 thumbnail
16th Anniversary Thumbnail Sparkler Thumbnail + 2
Posted: 15 years ago
#20

Originally posted by: vijay

On McAfee site they are reporting Global Threat Condition to : Critical

Which means:

Systems worldwide are being widely targeted, or may become widely targeted by an active and available exploit or threat. An extreme global security incident is taking or may imminently take place.


And this is affecting a lot of people using "Internet Explorer"

Microsoft has today released a very "Critical Update" which you should not ignore and install it immediately.

https://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx

This security update resolves seven privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The more severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Be safe!



thats true Vijay

it appears the virus has been around for years

apprecraite u giving link

i know im safe fully updated n patched on Vista SP2

Related Topics

Top

Stay Connected with IndiaForums!

Be the first to know about the latest news, updates, and exclusive content.

Add to Home Screen!

Install this web app on your iPhone for the best experience. It's easy, just tap and then "Add to Home Screen".