A Windows XP help forum. PCbanter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » PCbanter forum » Microsoft Windows XP » Windows Service Pack 2
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

xp sp2 security



 
 
Thread Tools Display Modes
  #1  
Old March 24th 05, 12:47 AM
kb
external usenet poster
 
Posts: n/a
Default xp sp2 security

I just installed sp2. The firewall asks whether I want to block certain
programs or parts of programs from running. Initially, I blocked all the
programs but I'm noticing some problems when connecting to the internet so I
unblocked them. Should any of these programs be blocked? I'm thinking
msg32.exe and svchost.exe should not be blocked but the rest I don't know
about.

dirote.exe
msg32.exe
svchost.exe
cywyukrx.exe
kcnlmdkg.exe
Ads
  #2  
Old March 24th 05, 12:59 AM
JoeM
external usenet poster
 
Posts: n/a
Default xp sp2 security

I do not have any of these programs in my exception list. You my be running
some that may need them.

"kb" wrote in message
...
I just installed sp2. The firewall asks whether I want to block certain
programs or parts of programs from running. Initially, I blocked all the
programs but I'm noticing some problems when connecting to the internet so
I
unblocked them. Should any of these programs be blocked? I'm thinking
msg32.exe and svchost.exe should not be blocked but the rest I don't know
about.

dirote.exe
msg32.exe
svchost.exe
cywyukrx.exe
kcnlmdkg.exe



  #3  
Old March 24th 05, 01:17 AM
Anthony J. Dellarte Jr.
external usenet poster
 
Posts: n/a
Default xp sp2 security

dirote.exe:



File dirote.exe is related to a trojan horse named f0r0r. The file is
located at the directory "%SystemDir%\f0ror\", where %SystemDir% is a
variable, by default this is 'C:\Windows\System' ( Windows 98/Me ) or
'C:\Winodws\System32' (Windows Xp) or 'C:\Winnt\system32' (Windows 2000).
the folder is hidden in the system directory. The file is automatically run
at Windows startup. If your computer is infected by this trojan, you may
also find the process ppi.exe running from the process list.



msg32.exe:



msg32.exe is a process associated with the GigaStudio and GigaSampler music
sampling software.



svchost.exe:



svchost.exe is a system process belonging to the Microsoft Windows Operating
System which handles processes executed from DLLs. This program is important
for the stable and secure running of your computer and should not be
terminated. Note: svchost.exe is a process which is registered as the
W32.Welchia.Worm. It takes advantage of the Windows LSASS vulnerability,
which creates a buffer overflow and instigates your computer to shut down.
To see more information about this vulnerability please look at the
following Microsoft bulletin:
http://www.microsoft.com/technet/sec.../ms04-011.mspx This is a
registered security risk and should be removed immediately.



cywyukrx.exe and kcnlmdkg.exe:



No information to these execution files. I think they are virus infections
and/or spyware.



Go to www.download.com and search and download Spybot Search & Destroy and
Adaware. Update them, and then run them. In the meantime keep them
blocked.



Anthony



"kb" wrote in message
...
I just installed sp2. The firewall asks whether I want to block certain
programs or parts of programs from running. Initially, I blocked all the
programs but I'm noticing some problems when connecting to the internet so
I
unblocked them. Should any of these programs be blocked? I'm thinking
msg32.exe and svchost.exe should not be blocked but the rest I don't know
about.

dirote.exe
msg32.exe
svchost.exe
cywyukrx.exe
kcnlmdkg.exe



  #4  
Old March 24th 05, 01:13 PM
kb
external usenet poster
 
Posts: n/a
Default xp sp2 security

Can I just delete the f0r0r directory and contents and any reference in the
registry or do I need to let anti-virus software do it? My anti-virus
(McAfee) didn't catch this.

"Anthony J. Dellarte Jr." wrote:

dirote.exe:



File dirote.exe is related to a trojan horse named f0r0r. The file is
located at the directory "%SystemDir%\f0ror\", where %SystemDir% is a
variable, by default this is 'C:\Windows\System' ( Windows 98/Me ) or
'C:\Winodws\System32' (Windows Xp) or 'C:\Winnt\system32' (Windows 2000).
the folder is hidden in the system directory. The file is automatically run
at Windows startup. If your computer is infected by this trojan, you may
also find the process ppi.exe running from the process list.



msg32.exe:



msg32.exe is a process associated with the GigaStudio and GigaSampler music
sampling software.



svchost.exe:



svchost.exe is a system process belonging to the Microsoft Windows Operating
System which handles processes executed from DLLs. This program is important
for the stable and secure running of your computer and should not be
terminated. Note: svchost.exe is a process which is registered as the
W32.Welchia.Worm. It takes advantage of the Windows LSASS vulnerability,
which creates a buffer overflow and instigates your computer to shut down.
To see more information about this vulnerability please look at the
following Microsoft bulletin:
http://www.microsoft.com/technet/sec.../ms04-011.mspx This is a
registered security risk and should be removed immediately.



cywyukrx.exe and kcnlmdkg.exe:



No information to these execution files. I think they are virus infections
and/or spyware.



Go to www.download.com and search and download Spybot Search & Destroy and
Adaware. Update them, and then run them. In the meantime keep them
blocked.



Anthony



"kb" wrote in message
...
I just installed sp2. The firewall asks whether I want to block certain
programs or parts of programs from running. Initially, I blocked all the
programs but I'm noticing some problems when connecting to the internet so
I
unblocked them. Should any of these programs be blocked? I'm thinking
msg32.exe and svchost.exe should not be blocked but the rest I don't know
about.

dirote.exe
msg32.exe
svchost.exe
cywyukrx.exe
kcnlmdkg.exe




 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Not "burning" to Cd after SP2 upgrade \old\ devildog Windows Service Pack 2 4 December 2nd 04 05:33 PM
Enabling security center on domain XP SP2 Workstations SoCal Systems Analyst Windows Service Pack 2 18 September 21st 04 04:56 PM
Security Center--XP SP2 JTKirk Windows Service Pack 2 2 September 1st 04 05:12 AM
I want to Remove Windows XP SP2 Tammy Windows Service Pack 2 22 August 30th 04 10:45 PM






All times are GMT +1. The time now is 05:05 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 PCbanter.
The comments are property of their posters.