hidden hit counter
Welcome to WindowsForumz.com!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

xp sp2 security

 
   Windows XP (Home) -> Windows XP Arch -> Help & Support Arch1 RSS
Next:  Internet Explorer Open in new window problem  
Author Message
kb

External


Since: Mar 23, 2005
Posts: 5



(Msg. 1) Posted: Wed Mar 23, 2005 4:47 pm
Post subject: xp sp2 security
Archived from groups: microsoft>public>windowsxp>help_and_support (more info?)

I just installed sp2. The firewall asks whether I want to block certain
programs or parts of programs from running. Initially, I blocked all the
programs but I'm noticing some problems when connecting to the internet so I
unblocked them. Should any of these programs be blocked? I'm thinking
msg32.exe and svchost.exe should not be blocked but the rest I don't know
about.

dirote.exe
msg32.exe
svchost.exe
cywyukrx.exe
kcnlmdkg.exe

 >> Stay informed about: xp sp2 security 
Back to top
Login to vote
JoeM

External


Since: Mar 13, 2005
Posts: 16



(Msg. 2) Posted: Wed Mar 23, 2005 7:59 pm
Post subject: Re: xp sp2 security [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

I do not have any of these programs in my exception list. You my be running
some that may need them.

"kb" wrote in message

 >I just installed sp2. The firewall asks whether I want to block certain
 > programs or parts of programs from running. Initially, I blocked all the
 > programs but I'm noticing some problems when connecting to the internet so
 > I
 > unblocked them. Should any of these programs be blocked? I'm thinking
 > msg32.exe and svchost.exe should not be blocked but the rest I don't know
 > about.
 >
 > dirote.exe
 > msg32.exe
 > svchost.exe
 > cywyukrx.exe
 > kcnlmdkg.exe

 >> Stay informed about: xp sp2 security 
Back to top
Login to vote
Anthony J. Dellarte Jr.

External


Since: Feb 13, 2005
Posts: 3



(Msg. 3) Posted: Wed Mar 23, 2005 8:17 pm
Post subject: Re: xp sp2 security [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

dirote.exe:



File dirote.exe is related to a trojan horse named f0r0r. The file is
located at the directory "%SystemDir%\f0ror\", where %SystemDir% is a
variable, by default this is 'C:\Windows\System' ( Windows 98/Me ) or
'C:\Winodws\System32' (Windows Xp) or 'C:\Winnt\system32' (Windows 2000).
the folder is hidden in the system directory. The file is automatically run
at Windows startup. If your computer is infected by this trojan, you may
also find the process ppi.exe running from the process list.



msg32.exe:



msg32.exe is a process associated with the GigaStudio and GigaSampler music
sampling software.



svchost.exe:



svchost.exe is a system process belonging to the Microsoft Windows Operating
System which handles processes executed from DLLs. This program is important
for the stable and secure running of your computer and should not be
terminated. Note: svchost.exe is a process which is registered as the
W32.Welchia.Worm. It takes advantage of the Windows LSASS vulnerability,
which creates a buffer overflow and instigates your computer to shut down.
To see more information about this vulnerability please look at the
following Microsoft bulletin:
<a rel="nofollow" style='text-decoration: none;' href="http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx" target="_blank">http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx</a> This is a
registered security risk and should be removed immediately.



cywyukrx.exe and kcnlmdkg.exe:



No information to these execution files. I think they are virus infections
and/or spyware.



Go to <a rel="nofollow" style='text-decoration: none;' href="http://www.download.com" target="_blank">www.download.com</a> and search and download Spybot Search & Destroy and
Adaware. Update them, and then run them. In the meantime keep them
blocked.



Anthony



"kb" wrote in message

 >I just installed sp2. The firewall asks whether I want to block certain
 > programs or parts of programs from running. Initially, I blocked all the
 > programs but I'm noticing some problems when connecting to the internet so
 > I
 > unblocked them. Should any of these programs be blocked? I'm thinking
 > msg32.exe and svchost.exe should not be blocked but the rest I don't know
 > about.
 >
 > dirote.exe
 > msg32.exe
 > svchost.exe
 > cywyukrx.exe
 > kcnlmdkg.exe
 >> Stay informed about: xp sp2 security 
Back to top
Login to vote
kb

External


Since: Mar 23, 2005
Posts: 5



(Msg. 4) Posted: Thu Mar 24, 2005 5:13 am
Post subject: Re: xp sp2 security [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Can I just delete the f0r0r directory and contents and any reference in the
registry or do I need to let anti-virus software do it? My anti-virus
(McAfee) didn't catch this.

"Anthony J. Dellarte Jr." wrote:

 > dirote.exe:
 >
 >
 >
 > File dirote.exe is related to a trojan horse named f0r0r. The file is
 > located at the directory "%SystemDir%\f0ror\", where %SystemDir% is a
 > variable, by default this is 'C:\Windows\System' ( Windows 98/Me ) or
 > 'C:\Winodws\System32' (Windows Xp) or 'C:\Winnt\system32' (Windows 2000).
 > the folder is hidden in the system directory. The file is automatically run
 > at Windows startup. If your computer is infected by this trojan, you may
 > also find the process ppi.exe running from the process list.
 >
 >
 >
 > msg32.exe:
 >
 >
 >
 > msg32.exe is a process associated with the GigaStudio and GigaSampler music
 > sampling software.
 >
 >
 >
 > svchost.exe:
 >
 >
 >
 > svchost.exe is a system process belonging to the Microsoft Windows Operating
 > System which handles processes executed from DLLs. This program is important
 > for the stable and secure running of your computer and should not be
 > terminated. Note: svchost.exe is a process which is registered as the
 > W32.Welchia.Worm. It takes advantage of the Windows LSASS vulnerability,
 > which creates a buffer overflow and instigates your computer to shut down.
 > To see more information about this vulnerability please look at the
 > following Microsoft bulletin:
 > <a rel="nofollow" style='text-decoration: none;' href="http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx" target="_blank">http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx</a> This is a
 > registered security risk and should be removed immediately.
 >
 >
 >
 > cywyukrx.exe and kcnlmdkg.exe:
 >
 >
 >
 > No information to these execution files. I think they are virus infections
 > and/or spyware.
 >
 >
 >
 > Go to <a rel="nofollow" style='text-decoration: none;' href="http://www.download.com" target="_blank">www.download.com</a> and search and download Spybot Search & Destroy and
 > Adaware. Update them, and then run them. In the meantime keep them
 > blocked.
 >
 >
 >
 > Anthony
 >
 >
 >


  > >I just installed sp2. The firewall asks whether I want to block certain
  > > programs or parts of programs from running. Initially, I blocked all the
  > > programs but I'm noticing some problems when connecting to the internet so
  > > I
  > > unblocked them. Should any of these programs be blocked? I'm thinking
  > > msg32.exe and svchost.exe should not be blocked but the rest I don't know
  > > about.
  > >
  > > dirote.exe
  > > msg32.exe
  > > svchost.exe
  > > cywyukrx.exe
  > > kcnlmdkg.exe
 >
 >
 >
 >> Stay informed about: xp sp2 security 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
LAN Security (again) - please help! - Hi all, I posted a request some weeks ago for help with security related to upgrading my gateway machine from Win2K to XP Home (clean install SP2). Since upgrading, I have had ongoing problems with file/printer sharing. Since then, I have made some..

security for files on pc - Hi everyone, I hope i'm posting this query in the right category. Is there a way that i can encrypt a WinZip or WinRar folder so that the files inside will only be visible and accessible to those with the correct password? I noticed a Password optio...

Dcomcnfg Com Security XP SP2 - Has anyone seen a problem with the "edit Limits" buttons being disabled under the COM Security tab in Dcomcnfg - My Computer - Properties? Need help in confiuguring COM settings for OPC communications under XP SP2. Thanks in advance. -- Jas...

XP security question - When the computer is waiting for me to select a user and enter a password (no antivirus and firewall software is running), is it vulnerable to attacks from the outside? When it is waiting displaying the welcome screen, I am able to access it on LAN...

Norton Internet Security 2004 w/ XP - We installed Norton Internet Security on our XP based machine. It cleaned up some things but made response so slow as to make the computer virtually useless. Anyone else had this problem? Thanks, jh
   Windows XP (Home) -> Windows XP Arch -> Help & Support Arch1 All times are: Eastern Time (US & Canada)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Categories:
  Windows XP
 Win 2000/NT/98/ME
 Windows Vista!


[ Contact us | Terms of Service/Privacy Policy ]