• Want to help us with this year's BoS Trials?
    Let us know before 30 June. See this thread for details
  • Looking for HSC notes and resources?
    Check out our Notes & Resources page

Antivirus (1 Viewer)

Winston

Active Member
Joined
Aug 30, 2002
Messages
6,128
Gender
Undisclosed
HSC
2003
Ian... why don't you guys say if there's no announcements and its vacant annoucements, and when there's a big virus outbreak, you guys make a global annoucement with steps to remove the virus and prevent yourself from being infected etc, so that all the BOS members are informed of any latest virus outbreaks.
 

fatmuscle

Active Member
Joined
Jul 6, 2002
Messages
3,707
Location
Hornsby
Gender
Male
HSC
2001
nah, then people won't bother posting when they have problems.

it's good to have people posting!!!


besides, that's what Symantec is for :p
 

lillaila

clear as ice
Joined
Feb 26, 2003
Messages
424
Location
muahahhahaha
Gender
Female
HSC
2003
i heard or read somewhere that Telstra Bigpond Broadband people or smthng are safe from the sasser virus thing cos they blocked the port.....is this right? i hope so
 

Comedy_Al

Member
Joined
Aug 28, 2003
Messages
109
Location
Newcastle
Damn microsoft......
Sassar and all the similar ones are classic microsoft stupidity. Alot of people already know this, and if i get it wrong let me know, but this is my understanding...
Sassar itself doesn't make your computer restart, its a byproduct of its geting on.
What happens is with welchand most similar ones, is theres a service in windows called "Remote Precudure Calls" or RPC which allows a series of computers to do parrallel processing, in theory, by letting another computer call code in an activex program on that computer.
Yes, it is actually designed to allow someone to excicute code on your computer. I have never heard of it ever being used, and its dodgy as all hell anyways, so its basically useless. All welch, or w32.blast, or any other virus like that have to do is make RPC 'fall over', so it stops checking the commands and just executes them.
This was as easy as just flooding it, sending a couple of thousand messages and poof! your computer is icomepletely open. Now where the real stupidity comes in is when RPC dies, windows cant restart it for whatever reason. So instead of continueing running without a comepletly useless service, it decides that the only way to restart RPC is to restart the computer-hence the stupid 1 minuet timer.
Incidently for any of you suffering from this you can normally go Start -> Run -> cmd (for win2k and xp, command for 98 & me) and type shutdown -a (for abort), and this normally kills the shutdown timer. Sassar seems to target Isass.exe, which windows also forces a reboot for.
Microsoft :chainsaw:

Go Linux.


Incedently, I've been using ZoneAlarm on Win2K, and it seemed to protect me. Any one know of a really good free firewall? TinyFirewall isn't free anymore :(
 
Last edited:

Winston

Active Member
Joined
Aug 30, 2002
Messages
6,128
Gender
Undisclosed
HSC
2003
not everything has to do with RPC. The coming service pack 2 for XP will address issued withing vulenrabilities exposed to RPC, and this time they're dead set fixing it for sure.
 

Collin

Active Member
Joined
Jun 17, 2003
Messages
5,084
Gender
Undisclosed
HSC
N/A
'There was a recent intrusion attempt: Sassar'

Good ol' firewall.

Anyway I have a dilemma: A few weeks ago I got hit by w32.blaster.. and I downloaded the patch thing from symantec but after running the exe. it said that it detected no trace of it. I knew it was w32.blaster because the antivirus came up telling me that it was and that the file it corrupted (some SYSTEM32 file) couldn't be repaired.
The odd thing was, I've been hit by 32 before, and after running the same patch from symantec it got rid of it.. but this time the patch couldn't detect it.. and regedit and msconfig wouldn't load, so I couldn't manually get rid of it. I just ended up reformatting my drive. @!#@
 
Last edited:

mojako

Active Member
Joined
Mar 27, 2004
Messages
1,333
Gender
Male
HSC
2004
Guys...
Kaspersky is a very good antivirus program which detects a lot of rare viruses which are not detected by "popular" brands.
It also detects many non-dangerous programs such as malicious jokes.
The most noticable point is probably that it detects many trojans and understands a lot of compression methods.
Version 4.x is a bit too "expert"-style and may cause a bit of trouble & heavy slowdown on XP systems if you don't change something.
Version 5 is very user-friendly, although I think it has problems on multiple user accounts. If it's run under user A then we switch user to user B, then user B can open virus-infected files. I'm still exploring this problem though.. it may be because there's some error during the installation.
 

raging_squid

Member
Joined
Jun 11, 2004
Messages
36
Gender
Male
HSC
2005
i use avg anti-virus its an excelent anti-virus for a freeware program and i have had no problems or viruses with it yet. I use to use vet anti virus but it made my pc run slower so i got rid of it
 

fatmuscle

Active Member
Joined
Jul 6, 2002
Messages
3,707
Location
Hornsby
Gender
Male
HSC
2001
a decent linux user wouldn't have a RedHat logon in their avatar...
 

raging_squid

Member
Joined
Jun 11, 2004
Messages
36
Gender
Male
HSC
2005
yeh i tryed redhat on the skool computers for IT, easy network setting up but we had trouble with mouse config's
 

Seraph

Now You've done it.......
Joined
Sep 26, 2003
Messages
897
Gender
Male
HSC
N/A
Damn Norton Resource Eater!!
 

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

Top