Post #174,035
9/13/04 9:59:03 PM
|
Done!
As you suggested, had to re-install McAfee personal Firewall (which brought with it the now-useless AV stuff). We'll see what (if anything) happens....
jb4 shrub\ufffdbish (Am., from shrub + rubbish, after the derisive name for America's 43 president; 2003) n. 1. a form of nonsensical political doubletalk wherein the speaker attempts to defend the indefensible by lying, obfuscation, or otherwise misstating the facts; GIBBERISH. 2. any of a collection of utterances from America's putative 43rd president. cf. BULLSHIT
|
Post #174,215
9/14/04 1:49:23 PM
|
How'd it do for you?
Just wondering.
-- [link|mailto:greg@gregfolkert.net|greg], [link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @ iwetheyNo matter how much Microsoft supporters whine about how Linux and other operating systems have just as many bugs as their operating systems do, the bottom line is that the serious, gut-wrenching problems happen on Windows, not on Linux, not on Mac OS. -- [link|http://www.eweek.com/article2/0,1759,1622086,00.asp|source]Here is an example: [link|http://www.greymagic.com/security/advisories/gm001-ie/|Executing arbitrary commands without Active Scripting or ActiveX when using Windows]
|
Post #174,261
9/14/04 4:21:13 PM
|
Well....
Seemingly no change. After the install of the Firewall, I updated the firewall and utilities (apparently mcAfee won't allow you to keep your signature files updated after one year, but it will allow you to update the rest of the suite, the Shredder, the Firewall, et. al.) All during the download of the updates (which, at 36.0Kbps, was not fast), the firewall periodically notified me about attemtps to TFTP to someplace, which I continued to manually reject. (I don't want to set the firewall to automatically reject them, because I may actually need to do a TFTP sometime, and un-blocking something you've previously blocked is a pain-inna-arse.) The log gave no indication as to the target of the TFTP attempt -- hell, it wouldn't even log that an attempt took place. After about a half an hour of this, SVCHOST dutifully attempted an illegal access and crashed...taking the clipboard with it -- just as before.
However, I saw no evidence of the other problem, of the SVCHOST truing to UDP to someplace. so maybe It helped a bit. Further monitoring is needed to verify.
I'm tempted to let the TFTP go through, and then scan the snot out of my system to see if I can find out what is trying to be downloaded.
Thanks for asking!
jb4 shrub\ufffdbish (Am., from shrub + rubbish, after the derisive name for America's 43 president; 2003) n. 1. a form of nonsensical political doubletalk wherein the speaker attempts to defend the indefensible by lying, obfuscation, or otherwise misstating the facts; GIBBERISH. 2. any of a collection of utterances from America's putative 43rd president. cf. BULLSHIT
|
Post #174,262
9/14/04 4:23:36 PM
|
!!!
Why do you think you can magically avoid the solution that everyone else has to suffer with?
And you DO know that your contributing to Internet horror, right?
FIX IT ALREADY!
-drl
|
Post #174,267
9/14/04 4:42:06 PM
|
Not if it means that I have to go beyond W2K SP2!!!
Sorry, BillG(e) doesn't get implicit access to my machine! Sorry, BillG(e) doesn't get an inventory of the hardware and software of my machine! Sorry, BillG(e) doesn't get to deny me access to my machine because he may think I have a pirated version of his precious OS-surrogate!
I'll fucking give him the three-finger salute before that's going to happen.
And I'm contributing not one thing to the "Internet Horror" you so colorfully refer to (whatever the fuck that is...)
jb4 shrub\ufffdbish (Am., from shrub + rubbish, after the derisive name for America's 43 president; 2003) n. 1. a form of nonsensical political doubletalk wherein the speaker attempts to defend the indefensible by lying, obfuscation, or otherwise misstating the facts; GIBBERISH. 2. any of a collection of utterances from America's putative 43rd president. cf. BULLSHIT
|
Post #174,268
9/14/04 4:52:15 PM
|
Yes, you are.
The "internet horror" is the spread of worms (such as this little TFTP jobbie) that continues to infest computers that could otherwise be patched against it.
Migrate to Linux, go back to Win9x, or get the service packs.
At least stick yourself behind a hardware firewall, and turn off all port forwarding.
I've used this one to some success:
[link|http://www.newegg.com/app/ViewProductDesc.asp?description=33-122-008&depa=1|http://www.newegg.co...33-122-008&depa=1]
Powered by the Hammer of the Gods
|
Post #174,308
9/14/04 7:10:43 PM
|
Dude...I'm on DIALUP!
so how is a hardware firewall or doing anything with port forwarding going to help?
And go back to win9x?!? Riiiight...no chance for corruption there, nosiree!
Now, Linux...there's a solution. Once I get a distribution together (find a decent admin primer), I'm there. Might not be a bad idea to do all my internet prowling from within Linux....
But in the interim, a Three R's looks like it is in my future.
Note that all this started happening when I installed Real's spyware. I now have the "enterprise"/gold version that someone (possibly you) pointed me to, and I will install it once I get rid of this "problem".
jb4 shrub\ufffdbish (Am., from shrub + rubbish, after the derisive name for America's 43 president; 2003) n. 1. a form of nonsensical political doubletalk wherein the speaker attempts to defend the indefensible by lying, obfuscation, or otherwise misstating the facts; GIBBERISH. 2. any of a collection of utterances from America's putative 43rd president. cf. BULLSHIT
|
Post #174,318
9/14/04 8:45:49 PM
|
I used my D-Link DI-704P on dialup before I got cable...
You should have a hardware firewall. And not just to join the l337 who have one. :-) [link|http://z.iwethey.org/forums/render/content/show?contentid=50525|#50525].
There may not be a similar cheap firewall/switch box now for modems as external consumer modems are nearly at the Dodo end of the evolutionary stick. But check around.
Oh, and you should install SP4 too. MS says nothing about Activation being required and some web sites out there say that Win2k will never require Activation. [link|http://www.microsoft.com/windows2000/downloads/servicepacks/sp4/default.asp|SP4 home]. You should get the Network install version if you're paranoid, but use a non-infected machine to get it. It's 132 MB so you might want to see if someone at work has it and not try to do it over dial-up. ;-)
HTH. Luck!
Cheers, Scott.
|
Post #174,322
9/14/04 9:01:20 PM
9/14/04 9:01:39 PM
|
Yep...
If you want I know of someone that has an ISO image of W2K-SP3 that is bootable and installable with no requirement to ever be activated... ever.
-- [link|mailto:greg@gregfolkert.net|greg], [link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @ iwetheyNo matter how much Microsoft supporters whine about how Linux and other operating systems have just as many bugs as their operating systems do, the bottom line is that the serious, gut-wrenching problems happen on Windows, not on Linux, not on Mac OS. -- [link|http://www.eweek.com/article2/0,1759,1622086,00.asp|source]Here is an example: [link|http://www.greymagic.com/security/advisories/gm001-ie/|Executing arbitrary commands without Active Scripting or ActiveX when using Windows]
Edited by folkert
Sept. 14, 2004, 09:01:39 PM EDT
|
Post #174,325
9/14/04 9:05:47 PM
|
What he said. What I said.
-drl
|