Click here to get back home

Virus cleanup - fix compromised windows firewall settings

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Virus cleanup - fix compromised windows firewall settings Cloud9Flyer 08-21-2007
Get Chitika Premium
Posted by Kurt Sarens [MSFT] on August 23, 2007, 11:45 am
Please log in for more thread options
Hi Cloud9Flyer,

First of all, get your AV vendor envolved!
If your box gets reinfected, it means that it is not properly cleaned or
that there is still other malware envolved controlling your box.
Inform your AV vendor about the reinfection and provide them with the binary
of the virus (if possible).

You can run below online scanners to verify if your box is clean, as said by
Leythos, there is never a guarantee that your system is clean after a
compromise.

OneCare: http://safety.live.com
Kaspersky: http://www.kaspersky.com/virusscanner
eTrust Antivirus Web Scanner:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Trend Micro HouseCall: http://housecall.trendmicro.com/
Panda ActiveScan:
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
McAfee FreeScan: http://us.mcafee.com/root/mfs/default.asp?cid=9914
F-Secure Online Virus Scanner:
http://support.f-secure.com/enu/home/ols.shtml

Also, raise a case with Microsoft
http://www.microsoft.com/protect/support/default.mspx.

Thanks,
Kurt Sarens [MSFT]
Security Resources online: http://support.microsoft.com/security

This posting is provided "AS IS" with no warranties, and confers no rights.

This e-mail address does not receive e-mail, but is used for newsgroup
postings only.
>> sean.bl...@hifiit.com says...
>>
>> > I totally agree, normally. But regretfully we're dealing with a
>> > horrible ISP that will take weeks to wipe the box. We also have no
>> > clean area to do a reinstall in because it's remote. Also, it's
>> > supposed to be behind a firewall, but I just don't think the ISP has
>> > very strict rules on the firewall.
>>
>> Why are you using ISP's hardware if they have shown they can't protect
>> the OS/apps?
>>
>> Either get your own servers and firewall or find another ISP to host
>> your applications.
>>
>> --
>>
>> Leythos
>> - Igitur qui desiderat pacem, praeparet bellum.
>> - Calling an illegal alien an "undocumented worker" is like calling a
>> drug dealer an "unlicensed pharmacist"
>> spam999f...@rrohio.com (remove 999 for proper email
>
> It's political. The client's CEO and the owner of the ISP are old
> drinking buddies. I've tried to get the servers moved, but the boss
> won't let it happen.
>
> At any rate, my hands being tied how they are, we're way off-topic. I
> would LOVE to move the server to a better ISP, and I would LOVE to
> have the machine rebuilt, but I cannot make that happen in any
> reasonable amount of time. So, I have to work with the cards I'm
> dealt. I don't like it more than anybody else.
>
> Does anybody have any ideas on how to clean this up? I need to get
> this port out of the firewall, but I can't figure out where it's
> hiding. I deleted a registry entry for windows Firewall, and it now
> shows the policy = none when I do the show state, so that's good.
> But, that open port is still open and grayed out so I can't modify
> it. Does anybody have any idea where this might be hiding.
>


Posted by Cloud9Flyer on August 24, 2007, 3:25 am
Please log in for more thread options
On Aug 23, 10:45 am, "Kurt Sarens [MSFT]"
> Hi Cloud9Flyer,
>
> First of all, get your AV vendor envolved!
> If your box gets reinfected, it means that it is not properly cleaned or
> that there is still other malware envolved controlling your box.
> Inform your AV vendor about the reinfection and provide them with the binary
> of the virus (if possible).
>
> You can run below online scanners to verify if your box is clean, as said by
> Leythos, there is never a guarantee that your system is clean after a
> compromise.
>
> OneCare:http://safety.live.com
> Kaspersky:http://www.kaspersky.com/virusscanner
> eTrust Antivirus Web
Scanner:http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
> Trend Micro HouseCall:http://housecall.trendmicro.com/
> Panda
ActiveScan:http://www.pandasoftware.com/activescan/com/activescan_principal.htm
> McAfee FreeScan:http://us.mcafee.com/root/mfs/default.asp?cid=9914
> F-Secure Online Virus Scanner:http://support.f-secure.com/enu/home/ols.shtml
>
> Also, raise a case with
Microsofthttp://www.microsoft.com/protect/support/default.mspx.
>
> Thanks,
> Kurt Sarens [MSFT]
> Security Resources online:http://support.microsoft.com/security
>
> This posting is provided "AS IS" with no warranties, and confers no rights.
>
> This e-mail address does not receive e-mail, but is used for newsgroup
>
>
> >> sean.bl...@hifiit.com says...
>
> >> > I totally agree, normally. But regretfully we're dealing with a
> >> > horrible ISP that will take weeks to wipe the box. We also have no
> >> > clean area to do a reinstall in because it's remote. Also, it's
> >> > supposed to be behind a firewall, but I just don't think the ISP has
> >> > very strict rules on the firewall.
>
> >> Why are you using ISP's hardware if they have shown they can't protect
> >> the OS/apps?
>
> >> Either get your own servers and firewall or find another ISP to host
> >> your applications.
>
> >> --
>
> >> Leythos
> >> - Igitur qui desiderat pacem, praeparet bellum.
> >> - Calling an illegal alien an "undocumented worker" is like calling a
> >> drug dealer an "unlicensed pharmacist"
> >> spam999f...@rrohio.com (remove 999 for proper email
>
> > It's political. The client's CEO and the owner of the ISP are old
> > drinking buddies. I've tried to get the servers moved, but the boss
> > won't let it happen.
>
> > At any rate, my hands being tied how they are, we're way off-topic. I
> > would LOVE to move the server to a better ISP, and I would LOVE to
> > have the machine rebuilt, but I cannot make that happen in any
> > reasonable amount of time. So, I have to work with the cards I'm
> > dealt. I don't like it more than anybody else.
>
> > Does anybody have any ideas on how to clean this up? I need to get
> > this port out of the firewall, but I can't figure out where it's
> > hiding. I deleted a registry entry for windows Firewall, and it now
> > shows the policy = none when I do the show state, so that's good.
> > But, that open port is still open and grayed out so I can't modify
> > it. Does anybody have any idea where this might be hiding.

I did manage to get the port exception removed using netsh commands.
The exception "name" was null, so I think that was causing the
problem.

I'll run those online scans as well.


Similar ThreadsPosted
Firewall/security center settings April 4, 2006, 9:15 am
Firewall Settings when Joing a Domain June 24, 2008, 2:42 pm
Does Windows Server 2003 need Mcafee virus scan? January 4, 2006, 11:47 am
Compromised Web Server? Anybody recognize these programs? January 9, 2008, 9:11 am
ftp + windows firewall September 20, 2006, 6:02 am
Does the SCW break Windows Firewall? August 18, 2005, 1:49 am
Firewall of Windows 2003 October 2, 2005, 1:31 am
What's wrong with Windows 2k3 firewall? HELP ME PLEASE! October 9, 2005, 6:53 pm
i want to enable the windows firewall on a DC October 28, 2005, 5:37 am
Windows 2003 firewall November 22, 2005, 12:09 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap