new firewall attacks

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mr Bananas, Jun 6, 2005.

  1. Mr Bananas

    Mr Bananas Private E-2

    I thought you clever bods at m.geeks could advise, as i have no idea about most things really.
    I just installed a new firewall (sygate personal pro), running in xp with avast antivirus. I am getting a few alerts and stuff which i have never had before, such as below.
    Is it anything t worry about?
    thanks for any enlightenment


    severity - critical - incoming - tcp
    [181.1] Inbound DCE BIND to potentially vulnerable RPC DCOM interface attempt detected

    and another is

    severity - mahor - incoming no protocol

    Traffic from IP address 81.174.209.211 is blocked from 06/05/2005 21:31:12 to 06/05/2005 21:41:12.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What firewall were you using before?

    Do you recognize the below
    Code:
     [url="http://samspade.org/t/whois?a=81-174-209-211.pth-as2.dial.plus.net;server=auto"][color=#800080]81-174-209-211.pth-as2.dial.plus.net[/color][/url] = [ [url="http://samspade.org/t/whois?a=81.174.209.211;server=auto"][color=#0000ff]81.174.209.211[/color][/url] ] 
     
    PlusNet Technologies Ltd 
    	 Technology Building Terry Street Sheffield S9 2BU 
    	 Sheffield S Yorkshir S9 2BU 
    	 GB 
    	 Domain Name: [url="http://samspade.org/t/whois?a=PLUS.NET;server=auto"][color=#0000ff]PLUS.NET[/color][/url] 
    	 Administrative Contact: 
    		 Plusnet Technologies Ltd [email="hostmaster@plus.net.uk"][color=#0000ff]hostmaster@plus.net.uk[/color][/email]
     
    		 Plusnet Technologies Ltd 
    		 Internet House Victoria Quays 
    		 Sheffield South York S47YA 
    		 GB 
    		 Phone: 01142200000 
    		 Fax: 
    
    What OS do you have?
    Have you run ALL the steps in the sticky thread below:
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
     
  3. Mr Bananas

    Mr Bananas Private E-2

    hello, thanks for the reply,

    running xp and sygate pro firewall, and no i dont recognise the address.
    My comp is free as far as i know from all baddies (checked regularly).
    mr bananas
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said you installed a new firewall. Did you have a different one before Sygate? Or did you really mean that you finally installed a firewall because you did not have one?

    What version of WinXP? SP1, SP1a, or SP2? Do you have all of your Windows Updates?

    Did you run the READ ME FIRST? You should go thru the steps below:


    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. Mr Bananas

    Mr Bananas Private E-2

    thanks for helping,

    i always used a firewall, the previos i think was outpost, and always a virus checker.

    I did all the tests and stuff u reccommended, but still getting messages of incoming attacks, although i have tested my computer and it is fully stealthed. I guess it is just the firewall doing its job and picking up scanners/hackers/bots out doing naughty things like port scanning and pop ups??. It is i am presuming just either more sensitive or reports more than the other i had previously.
    thats what i think but dont know!!!

    mr bananasas
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could just be, as you said, the firewall doing its job. If you want to be sure there are not other visible malware problems, you should post the HijackThis log I requested and I will look.
     
  7. Mr Bananas

    Mr Bananas Private E-2

    ok thankyou for lQQking, here is my hjack this file
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. Mr Bananas

    Mr Bananas Private E-2

    ok thanks, i will remove them
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds