hi all

Discussion in 'Malware Help (A Specialist Will Reply)' started by Flobynew, Dec 12, 2007.

  1. Flobynew

    Flobynew Private E-2

    Hi everyone ,

    Just thought I would say what a great site.
    Every one seems very friendly and helpfull.

    My email got hijacked by spammers at the weekend ,so I'm in the process of securing the computer.
    I intend to start with the basics first ie the malware removal guide.
    I have done a scan on my ports and ports 445 and 1028 are open ,1028 could be suspect , this may be a problem ?
    Any advise on this would be greatly appreciated .

    Cheers Flobynew
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Read this: http://www.grc.com/port_445.htm and this http://www.grc.com/port_1028.htm to Probe the ports and tell me what it says.

    To give you an example, when I click the Probe THIS Port button, I get stealth.

    Also what OS do you have?
    Do you have a router with a hardware firewall?
    Do you have a software firewall installed?
     
  3. Flobynew

    Flobynew Private E-2

    Hello Chaslang ,

    I probed the ports..

    445 stealth - microsoft ds
    1028 stealth - none

    Also what OS do you have? windows xp home
    Do you have a router with a hardware firewall? not sure its a sagem (service provider tiscali)
    Do you have a software firewall installed? yes standard windows

    Cheers Floby
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then they are not open.

    You will have to look up the specs on your model number or ask your ISP if it has a hardware firewall.

    The Windows firewall does not provide adequate protection. See the below:

    How to Protect yourself from malware!
     
  5. Flobynew

    Flobynew Private E-2

    Hi Chaslang ,
    I have replaced std windows firewall with COMODO .

    Quote:
    Originally Posted by Flobynew
    Do you have a router with a hardware firewall? not sure its a sagem (service provider tiscali)

    You will have to look up the specs on your model number or ask your ISP if it has a hardware firewall.

    I think I have a modem not a router ? its a ' SAGEM F@st™ ADSL modem '
    Do i still need to know if I have a hardware firewall?

    Sorry for the dumb *** questions

    Cheers Floby
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it looks like it is just an ADSL modem not a router. Thus you have no hardware firewall. In reality you could add a nice layer of protection by inserting a router inbetween your DSL modem and your PC.
     
  7. Flobynew

    Flobynew Private E-2

    Hi Chaslang,
    Many thanks for all the help so far ,
    I have probed port 135 and it says

    OPEN dcom service control manager

    Is this normal ?
    Should I close it ? (if so how? )

    Cheers Floby
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you had a hardware firewall that port would probably show up stealth by default. This port is often blocked by certain ISPs to begin with.

    Yes you should block the port unless you run software that requires it to be open. Some remote assistance tools make use of this port. Do you have remote assistance software installed? Are you sure of your answer? Did any get installed your ISP? Have you ever allowed anyone to help you remotely? Right click My Computer and select Properties. Then select the Remote tab. Is the Remote Assistance feature checked or unchecked. What about Remote Desktop?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds