Suspicious files

Discussion in 'Software' started by thripston, Jul 2, 2004.

  1. thripston

    thripston Private First Class

    Should there be files in the windows/debug folder called:

    oakley.log
    oakley.log.sav
    PASSWD.LOG
    Netsetup.log

    (I'm using Windows XP Pro)

    The last one has loads of stuff like:

    07/02 13:13:54 NetpValidateName: checking to see if 'WORKGROUP' is valid as type 2 name
    07/02 13:13:54 NetpCheckNetBiosNameNotInUse: for 'WORKGROUP' returned: 0x858
    07/02 13:13:54 NetpCheckNetBiosNameNotInUse for 'WORKGROUP' [ Workgroup as MACHINE] returned 0x858
    07/02 13:13:54 NetpValidateName: name 'WORKGROUP' is valid for type 2

    Which has me wondering whether someone has hacked me.

    I do use a router (without a built in firewall) and a software firewall but I'm not entirely confident that all my ports are closed off. I still think there are ways I could improve my defences, especially where hacking and port intrusions/worms are concerned, any free software I can get to improve my situation?

    Cheers
     
  2. highly_volatile

    highly_volatile Private First Class

    The files in your debug folder are fine. I'm to using xp pro and have the same files
     

    Attached Files:

  3. thripston

    thripston Private First Class

    Thanks, guess this PC is just being cranky as usual.
     
  4. alanc

    alanc MajorGeek

  5. Adrynalyne

    Adrynalyne Guest

    dcpromo.log in the debug folder is usually not an ok file ;) Sasser puts that file in there to get in.

    Just to expand on that a bit ;)
     
  6. thripston

    thripston Private First Class

    Spyware and viruses - If only it was that simple! No, I never find either of those at the root of my problems, it's something far more strange and unusual.

    I have software to tackle those. They are pretty standard kit, what I need is something to handle whatever Zone Alarm, Ad Aware, Spybot S&D and AVG Anti-Virus can't.

    J
     
  7. Adrynalyne

    Adrynalyne Guest


    Seems to me you shoould wait until you have a problem to tackle it?

    I still don't see any real issue you are having.

    Please expand on this if you are indeed having a problem.
     
  8. thripston

    thripston Private First Class

    You are advising me to deal with the stable door after the horse has bolted, I don't think that's the best strategy to tackle any potential problems that my current suite of software isn't designed for. I just want peace of mind that I have a secure system. Maybe I do and I don't realise it. I was expecting someone to advise me to get x because Zone Alarm, AVG etc can't protect me from x or to say what I've got pretty much covers all the essential bases. It's a pretty straight question so I don't understand why I'm not getting a straight answer.
     
  9. Adrynalyne

    Adrynalyne Guest

    We can't help you fix a problem that you don't have. :confused:

    You aren't getting a straight answer because you aren't giving a straight question.

    You posed the question about suspicious files, we told you they were normal.

    You also said this,
    Once again, I don't see what problem you are having?

    Tell us, if there is one. Otherwise, you will not get a satisfactory answer. Your question is so vague, I've got no idea what you are really talking about. I reckon I am not alone, or more people would have replied to this thread.
     
  10. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    In this day and age I wish it was simple enough to have software that could protect you against all nastys that are out on the big bad internet BUT sadly its not going to happen, someone will always think its clever to exploit a weak spot in any OS ( and i mean any OS ) as you really need to think of them all as working betas.

    you can however try to protect yourself which I see you are already doing, if you havnt read this FAQ then please do and get yourself SpywareBlaster as it will help protect against most spyware being installed in the first place http://forums.majorgeeks.com/showthread.php?t=25834

    do visit windows update and MS security websites for all upto date info and patches
    http://www.microsoft.com/security/default.mspx



    read up on potental coming or new alerts
    http://www.cert.org/nav/index_main.html
    http://www.securityfocus.com/
    http://www.sans.org/


    Like Adryn said you have done what you can to protect yourself hardware and software wise.... what do you need to protect yourself against? enjoy the intenet rather that being suspicious of every little file or folder, learn to know what your PC acts like and what running processes should be in the task manager, look at what your firewall has in its programs list... if anything out of the ordinary then recearch it.

    if you truely want to be safe then sorry to say this but... disconnect from the internet!


    the guys here at MGs have been through all these issues that may affect your PC but sadly we cannot predict the future ( me for one if I could I certainly wouldnt be typing this now I'd be on a beach with a cold drink in hand sunning myself ) we can just pass on our experiences... again the FAQ section will help.
     
  11. Just Playin

    Just Playin MajorGeek

    Try SpywareBlaster ans SpywareGuard (in the spyware tools downloads page) to help block much of spyware from installing. I use both myself. I hope this is more geared to what you are looking for.
     
  12. thripston

    thripston Private First Class

    I already have Spyware Guard and if it has blocked anything dubious it hasn't told me. It doesn't seem to catch all the crap that Adaware nets when I run it which always has me wondering if it's doing its job. I think I tried Spyware Blaster and for some reason didn't get on with it, if it's a little technical that's probably why. I'll give it another try anyway it might make more sense this time around.

    I'm not as paranoid about all this as I might be coming over I just had a nagging feeling there was somethng I was missing. My answer to the question 'what am I protecting myself against' is, 'I don't know you tell me' basically. Which is the question I felt I was fairly clearly asking though obviously not clearly enough for some people.

    I appreciate that knowledge is power and MS updates are a wise course of action etc etc, I also appreciate that you are never entirely safe whatever you do. What I'm after here is something to complement what I already have. The consensus seems to be that, other than Spyware Blaster, there isn't anything specific out there I'm lacking.
     
  13. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    the easy answer to that question is we don't know! well we dont until and exploit or vunerbility has been found/anounced,

    If you have not been hit with anything, like myself & others here who have not had Virii/Spyware then great.. you have done all you can until the next big exploit but the next one may well hit everyone not just the ones who are not savvy to security issues.

    again I read these security based sites for forthcomming issues ( even they may miss exploits until its too late ) as some smart people on the net are always looking in to security issues with all OSes.


    http://www.cert.org/nav/index_main.html
    http://www.securityfocus.com/
    http://www.sans.org/ ( updates site http://isc.incidents.org/ )
    http://www.microsoft.com/security/default.mspx
    http://xforce.iss.net/xforce/alerts
    http://www.w3.org/Security/Faq/
    http://www.windowsecurity.com/



    and by reading Sans this morning I noticed that there is another Another Russian Bank Scam If the victim is using Internet Explorer and the browser is not patched for the .chm exploit, the victim's browser is directed to download several files including executables from a web hosting site in Atlanta.

    so with this info in hand I will double check I have relevent patches in place.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds