LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices


Reply
  Search this Thread
Old 08-05-2003, 04:07 AM   #1
ksoma
Member
 
Registered: Jun 2003
Location: Austin,TX most of the year...in Euless,TX the rest of it
Distribution: RH 9.0
Posts: 154

Rep: Reputation: 30
CTRL-ALT-DEL Problems...i know its windoze..but any help is appreciated


This just started maybe an hour ago....I push CTRL-ALT-DEL...and the window pops up..and then automatically closes immediately...does the same when i type the commands "msconfig" or "regedit" in the Run box... I did a virus scan because I figured maybe that was the problem....no problem there...but whenever I restarted..there was this new file called TFTP1496 sitting in my startup with an .exe file called "webdav"....i went ahead and deleted them....they both were created a few hours ago today when i looked at their properties....and that's when the problems seemed to start happening..dont know where the hell they came from or what they are. If anyone has any clue what they are or anywhere I can go to see if any changes have been made...I'd appreciate it. Thanks.
 
Old 08-05-2003, 04:21 AM   #2
slakmagik
Senior Member
 
Registered: Feb 2003
Distribution: Slackware
Posts: 4,113

Rep: Reputation: Disabled
Well, don't freak because I could be wrong but I think it may have something to do with the nimda worm. How up to date is your scanner - and how good is it?

Quote:
What is WebDAV?
Briefly: WebDAV stands for "Web-based Distributed Authoring and Versioning". It is a set of extensions to the HTTP protocol which allows users to collaboratively edit and manage files on remote web servers.
Quote:
61-219-34-242.hinet-ip.hinet.net ...
... Found PE_NIMDA.E. Deleted. C:\Inetpub\scripts\TFTP1488 --> Found PE_NIMDA.E. Deleted. C:\Inetpub\scripts\TFTP1496 --> Found PE_NIMDA.E. Deleted. C:\Inetpub\scripts\TFTP1508 --> Found PE_NIMDA.E. Deleted. C:\Inetpub\scripts ...
http://61-219-34-242.hinet-ip.hinet.net/REPORT.LOG - 32 KB
Unfortunately, I couldn't follow that link to find out what it was about.

Sounds like someone hacked your box. You definitely shouldn't have crap like that materializing in places like that. If you don't have something like Sygate, download it now, I guess.
 
Old 08-05-2003, 04:23 AM   #3
qanopus
Senior Member
 
Registered: Jul 2002
Location: New York
Distribution: Slackware
Posts: 1,358

Rep: Reputation: 45
I don't understand your situation. You started getting strange recations from your windows box, went hunting and found those files. Is that right? And when you delete those files, they come back again. Is that correct?
Where exactally were those files, in the root dir of C: ?
If I were you, I would update my virus scanner and thoroughly check your drives.
 
Old 08-05-2003, 04:33 AM   #4
slakmagik
Senior Member
 
Registered: Feb 2003
Distribution: Slackware
Posts: 4,113

Rep: Reputation: Disabled
That's a good point. Did you do a cursory scan? Because you should set it for the slowest and most thorough. And try more than one, as they use different databases and methods.

I used to use McAfee some, AVG a lot, and F-Prot, even.

Incidentally, Sygate's a firewall, in case you thought I was talking anti-virus, but it helps lock down a system - sounds like someone's trying to create an entryway into your computer. So you'd also need something like that.
 
Old 08-05-2003, 05:14 AM   #5
ksoma
Member
 
Registered: Jun 2003
Location: Austin,TX most of the year...in Euless,TX the rest of it
Distribution: RH 9.0
Posts: 154

Original Poster
Rep: Reputation: 30
Schatoor,
I deleted the files...but they didn't come back or anything...but I'm not sure if they are causing the problem I'm having right now(w/ windows closing after opening them...only with Windows apps like "regedit", msconfig, and ctrl-alt-del) ...i'm just assuming that may have something to do with it.

I hope no one hacked into my comp but I figure it would be considerably hard considered I'm behind a router as well....I'm thinking it could be some music file i may have downloaded through kazaa lite...or maybe some harmful ad-ware i picked up from some sites...

Right now, I'm scanning the comp using Housecall...so maybe i'll get something else..
 
Old 08-05-2003, 05:50 AM   #6
ksoma
Member
 
Registered: Jun 2003
Location: Austin,TX most of the year...in Euless,TX the rest of it
Distribution: RH 9.0
Posts: 154

Original Poster
Rep: Reputation: 30
Ok, got two trojans with housecall...one called troj kbman.exe...it puts a .dll file on your comp that tracks your keystrokes...i deleted that...and there's another one called TROJ SENAMAKR1..or something like that....it puts a file called TEMP.EXE with an IRC client pic on it ....i've gotten this one in the past...it always seems to be in the C://WINDOWS directory....the other one was in the C://WINDOWS/slog/ directory...
 
Old 08-05-2003, 05:52 AM   #7
dalek
Senior Member
 
Registered: Jul 2003
Location: Mississippi USA
Distribution: Gentoo
Posts: 2,058
Blog Entries: 2

Rep: Reputation: 79
Exclamation Kazaa

I think you were asking for trouble. My understanding is that kazaa is like opening the door and putting out a welcome sign. You really really really need to get some software that looks for trojans and such and run it. They are out there but since I run Linux only I don't know where they are. Goto the screensavers.com and see if you can find something. They talk about it on TV all the time.

Whatever you do, do something. Also check your MS updates thingy.

Good luck

 
Old 08-05-2003, 03:37 PM   #8
ksoma
Member
 
Registered: Jun 2003
Location: Austin,TX most of the year...in Euless,TX the rest of it
Distribution: RH 9.0
Posts: 154

Original Poster
Rep: Reputation: 30
Does anyone know the name of the .dll file or patch that I would need from the microsoft site to fix that app?....Thanks.
 
Old 08-05-2003, 04:27 PM   #9
qanopus
Senior Member
 
Registered: Jul 2002
Location: New York
Distribution: Slackware
Posts: 1,358

Rep: Reputation: 45
If I were you, I would start using kazaa lite, instead of plain kazaa. Same user base, no spyware.
 
Old 08-06-2003, 04:51 AM   #10
ksoma
Member
 
Registered: Jun 2003
Location: Austin,TX most of the year...in Euless,TX the rest of it
Distribution: RH 9.0
Posts: 154

Original Poster
Rep: Reputation: 30
Yea, i'm using kazaa lite...sorry for abbrev. that. I think I do have something.....i didn't get exactly what the message said because I was watching tv when it happened..but my comp just decided to go ahead and restart itself.
 
Old 08-06-2003, 05:10 AM   #11
dalek
Senior Member
 
Registered: Jul 2003
Location: Mississippi USA
Distribution: Gentoo
Posts: 2,058
Blog Entries: 2

Rep: Reputation: 79
Exclamation Doesn't sound normal

Here's a couple of links for you to check out.
http://securityresponse.symantec.com/
http://www.grisoft.com/us/us_dwnl_trial.php

If you look around you will probably find someone else having the same problems. You got a little rat running around in there somewhere, you need a mouse trap. Ha ha ha

Good luck hunting, it's there somewhere.

 
Old 08-06-2003, 05:19 AM   #12
dalek
Senior Member
 
Registered: Jul 2003
Location: Mississippi USA
Distribution: Gentoo
Posts: 2,058
Blog Entries: 2

Rep: Reputation: 79
Another link

http://download.com.com/3120-20-0.ht...search=+Go%21+

Maybe this will help.

 
Old 08-06-2003, 05:26 AM   #13
ksoma
Member
 
Registered: Jun 2003
Location: Austin,TX most of the year...in Euless,TX the rest of it
Distribution: RH 9.0
Posts: 154

Original Poster
Rep: Reputation: 30
*Location service (loc-srv). This port is used to direct RPC (Remove Procedure Calls) services to the appropriate dynamically mapped ports. Hackers can use this to determine which port is used by several Windows services. This port should not be visible from the Internet.

*Windows NT / 2000 SMB. A standard used to exchange Server Message Blocks, and can be exploited in multiple ways, including gaining your passwords.


Those are the two ports open...ports 135 and 445, respectively. Need help on how to close these ports. Thanks.
 
Old 08-06-2003, 05:30 AM   #14
ksoma
Member
 
Registered: Jun 2003
Location: Austin,TX most of the year...in Euless,TX the rest of it
Distribution: RH 9.0
Posts: 154

Original Poster
Rep: Reputation: 30
Also, basic info about my comp was able to be seen according to the symantec security check....that's what i used to see which ports were open as well....The basic info was the name of my comp, the workgroup, and the mac address of my comp.
 
Old 08-06-2003, 05:36 AM   #15
ksoma
Member
 
Registered: Jun 2003
Location: Austin,TX most of the year...in Euless,TX the rest of it
Distribution: RH 9.0
Posts: 154

Original Poster
Rep: Reputation: 30
One more thing, according to that symantec thing....its safe from trojans....im doing their virus scan right now though...maybe it'll pull something up. I got the files infected with trojans off the comp yday....maybe that took care of them....or maybe this security check isnt that up to par.

BTW, thanks for those links dalek...appreciate it.

Last edited by ksoma; 08-06-2003 at 05:37 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ctrl + Alt + Del ? funkenbooty Linux - Newbie 7 04-26-2007 06:20 AM
ctrl-alt-del on tightvnc cck23 Linux - Software 2 07-06-2004 08:16 AM
ctrl+alt+del for linux? webazoid Linux - Software 9 06-30-2004 11:19 PM
ctrl.alt.del. in man9.2??? krome Mandriva 3 01-15-2004 11:31 PM
ctrl, alt, del hornet74 Linux - Software 8 01-13-2004 08:06 PM

LinuxQuestions.org > Forums > Non-*NIX Forums > General

All times are GMT -5. The time now is 10:37 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration