Worm is making me go insane

Reaperkk

[H]ard|Gawd
Joined
Sep 30, 2000
Messages
1,949
Hello, basically I need a little help. I recently reformatted windows and I noticed right when reboated into windows (the first time) my road runner modem lights were going insane. So I run and net stat and a whole bunch of ports are listening and alot are also Syn_sent. Now I remembered that this was a worm last time I reformatted and I downloaded a patch to solve it. So I went and updated everything with windows, installed norton systemworks with internet security and nothing still. I'm fully updated but I still have this activity, with nortons firewall it keeps saying I have a possible hijack with buffer overflow message every 5 seconds. Ugh, this is so frustrating thanks to anybody that can help me out.
 

O[H]-Zone

[H]ard|Gawd
Joined
Mar 28, 2003
Messages
1,465
You got nailed almost as soon as you connected to the net. It's pretty "normal" for WinXP. Your best bet is to make a new WinXP CD with SP2 slipstreamed. Next-best is reformatting and re-installing windows, but before you plug into a network, install SP2. Google for "slipstream+SP2" to make the CD, otherwise downkoad SP2 and burn it to a disk.
 

SupaDupaNerd

Limp Gawd
Joined
Aug 12, 2003
Messages
213
First thing you should do upon a re-install is go to mozilla.com and download either the mozilla suite or firefox, or get some other alternative browser. Do not use IE because it is junk and you are much MUCH more secure running a different browser. Use that browser to download all your files that you need to get your computer up and running full steam again. Don't ever (ever) use IE unless you need to connect to windows update site (which will ONLY work with IE :mad: ). With great alternatives like Mozilla out there you don't need ie anymore

Less this, i would try running a virus scan and have it do a full scan, but only after updating your heuristicss files first. If you reformatted and you boot for the first time you might have gotten some kind of bug in the boot area of your hard drive or possibly have had someone access your computer upon first starting it (or possibly even during windows setup?? But i don't know if or how long windows might be connected to the internet while setting up.)
 

Direwolf20

2[H]4U
Joined
Mar 10, 2004
Messages
2,467
First, download the stand-alone installer for SP1 and SP2 from microsoft.com. Then reformat again, and **BEFORE** connecting to the internet, install the SP's.

Or slipstream, as mentioned above.
 

Phoenix86

Supreme [H]ardness
Joined
Mar 28, 2002
Messages
6,653
FIREWALL.

Any "always on" or "broadband" connection *should* require a hardware router/firewall. Yes, SP2 will prevent what your currently seeing, but SPs are not always current. When the next worm comes around that SP2 doesn't stop you will be just as vulnerable until you patch, and for an new systems you bring on the network until the new SP comes out (which can be a while). The only stop-gap measure is a firewall, and one external to the new machine is preffered because of new installs. A $40 soho router would fix this issue, and provide a lot of other features.

Think about the days just prior to SP2, and you see what I mean.
 

Fark_Maniac

2[H]4U
Joined
Feb 21, 2002
Messages
2,438
Direwolf20 said:
First, download the stand-alone installer for SP1 and SP2 from microsoft.com. Then reformat again, and **BEFORE** connecting to the internet, install the SP's.

Or slipstream, as mentioned above.
SP2 already has all the fixes SP1 had...you don't need SP1...just SP2
 

Direwolf20

2[H]4U
Joined
Mar 10, 2004
Messages
2,467
Fark_Maniac said:
SP2 already has all the fixes SP1 had...you don't need SP1...just SP2

Yea, I always forget they are cumulative because

A) I"m a dummy sometimes :)
B) I don't format ever :D.
 

Reaperkk

[H]ard|Gawd
Joined
Sep 30, 2000
Messages
1,949
Thanks for the help everyone, I did install SP1 and SP2 was acting really weird, it would seldom let me connect to the internet throught internet explorer. Anyways I tinked around with a few norton firewall settings and I got it to work. I appreciate everyones help.
 
Top