• HEXUS
  • HEXUS.tv
  • channel
  • gaming
  • lifestyle
  • trust
  • community
  • ESReality
  • HEXUS.community discussion forumsVisit Corsair.com

    Welcome to the HEXUS.community discussion forums forums.

    You are currently viewing our boards as a guest which gives you limited access to view most discussions and other features. By joining our free community you will have access to post topics, respond to polls and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

    Go Back   HEXUS.community discussion forums > HEXUS.help - buying advice & technical queries > Networking and Broadband

    Networking and Broadband ADSL, cable, internet and network advice and chat Add RSS Feed

    Reply
     
    LinkBack Thread Tools
    Old 23-01-2004, 11:43 PM   #1 (permalink)
    Senior Member
     
    Join Date: Jul 2003
    Location: 3rd Rock from the sun..
    Posts: 367
    Thanks: 5
    Thanked 3 Times in 2 Posts
    Question Blaster Worms Question.

    Hey All,

    1) I Was just wondering the net, and then this samll warning box called "Microsoft" pops up saying something like "Warning, your computer may be infected. Click ok to start scan registry, to determine if you are infected." I didn't click ok. I just clicked the "X" button in the top right hand corner to clear it.

    2) If a blaster worm virus gets into your pc, does it show up in the startup list ? This one > (Start/Run/Msconfig/Startup tab.)
    Because there are a number of strange names in my startup list.
    Some of the names:
    Intf32S (C:\Windows\System\Intf32S.exe)
    (Above name only appeared after that "Mircosoft" warning box appeared.)
    ScanRegistry (C:\Windows\scanregw.exe /autorun)
    BlstApp (C:\Windows\System\Blstapp.exe)
    Essdc (essdc.exe)

    Cheers, Dave.
    Dave_07 is offline   Reply With Quote
    Old 23-01-2004, 11:57 PM   #2 (permalink)
    Team HEXUS.net
     
    joshwa's Avatar
     
    Join Date: Jul 2003
    Location: Liverpool, UK
    Posts: 4,546
    Thanks: 65
    Thanked 50 Times in 48 Posts
    joshwa's system
    View joshwa's Twitter Profile
    you need to
    a) have antivirus software (up to date) to make sure you're not infected
    b) update windows (windowsupdate.microsoft.com) to make sure windows can't be infected by blaster / welchia
    c) have a firewall so that you are protected from being attacked by this kind of virus.

    i think that if you had up to date anti-virus software, a full scan would tell you whether you're infected or not. (www.grisoft.com do free stuff if you don't have any).

    joshwa is offline   Reply With Quote
    Old 25-01-2004, 10:05 PM   #3 (permalink)
    I can't get no sleep
     
    Join Date: Jul 2003
    Location: 123 Fake Street, Leighton Buzzard
    Posts: 796
    Thanks: 32
    Thanked 3 Times in 3 Posts
    I could not find any references to Intf32S.exe, nor find the file in any of my Windows XP, 2000 or 98 SE installations. Just want to check, is the name correct?
    The scanregw.exe entry is required by windows. It scans the registry and backs it up.
    blstapp.exe puts access to Creative's BlasterControl in the System Tray.
    essdc.exe is to do with an ESS Solo soundcard, apparently.

    It could just be something as simple as a crappy pop-up message. I have a feeling that this message popping up is not a symptom of the Blaster Worm. Some specific info from symantec and microsoft. Have you turned off the messenger service? Control Panel -> Administrative Tools -> Services -> Messenger, Disabled it.

    You should do as Josh said regardless because it is good practice. Also get Spybot Search and Destroy and LavaSoft AdAware.

    "Keyboard missing - press F3 to continue" Message seen on an Apricot PC.
    "To start press any key. Where's the any key?" Homer Simpson.
    Hexus Trust
    Anders is offline   Reply With Quote
    Old 26-01-2004, 02:15 AM   #4 (permalink)
    Senior Member
     
    Join Date: Jul 2003
    Location: 3rd Rock from the sun..
    Posts: 367
    Thanks: 5
    Thanked 3 Times in 2 Posts
    I checked the System Startup tray again to be sure, and I have just noticed that not all the startup item names start with a capital letter, which I thought they did.
    So the capital "I" at the start of "Intf32S.exe" could very well be a lower case "L".
    This is how it appears in the list > lntf32S.exe
    I have also tracked down "lntf32S.exe" and where it is on my comp.
    This is all the info i could get on the item:

    lntf32S.exe Properties:
    Type: Application
    Location: C:\Windows\System
    Size: 64.0KB
    MS-DOS Name : lNTF32S.EXE (< The first letter may be a "L" or an "I" i can't tell)
    Created: 23 January 2004
    Modified: 16 December 2003
    Accessed: 26 January 2004
    Attributes: Read-Only: NO, Archive: YES, Hidden: NO

    Also I should add, this is all on an older computer (that dosen't like av/fw progs) Not the system in the sig.
    This older comp is running Win98 (none SE) and dose have a Creative Blaster 3D graphics card and onboard ESS sound device. So that explains the blstapp.exe and essdc.exe itmes on the list, the scanregw.exe is also ok.

    Also whilst I was gathering the above info on the lntf32S.exe item.
    I clicked on the application icon by accident, and it started the prog.
    However nothing happed (yet) so i don't know if that means anything.
    I have searched for the lntf32S.exe file again since I clicked on it,
    but it now seems to have gone from comp.

    Oh, aswell, I think you may be right Anders about the "Microsoft" box just being a small popup. Like when you get those "Tune your computer up" or "Your system clock is wrong, download such and such a thing to set it wright" popup adds.

    Cheers for you help and replys Anders & Josh, Thankx.

    Dave.

    Last edited by Dave_07; 26-01-2004 at 02:22 AM..
    Dave_07 is offline   Reply With Quote
    Old 26-01-2004, 08:37 AM   #5 (permalink)
    Eccentric Trend setter
     
    Join Date: Aug 2003
    Location: Torquay, Devon, UK
    Posts: 513
    Thanks: 0
    Thanked 0 Times in 0 Posts
    I'd download this if I were you

    Lord Kordir is offline   Reply With Quote
    Reply

    Breadcrumb
    Go Back   HEXUS.community discussion forums > HEXUS.help - buying advice & technical queries > Networking and Broadband


    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Trackbacks are On
    Pingbacks are On
    Refbacks are On


    Similar Threads
    Thread Thread Starter Forum Replies Last Post
    Quick question re: hpi check Stu HEXUS.automotive - Cars & Bikes 3 21-01-2004 05:53 PM
    teeny tiny question shiato storm General discussion 1 16-12-2003 06:09 PM
    Ghost licence question? Jimmy Little Software and web development 1 10-11-2003 02:02 PM
    RAM and new rig question quarryman HEXUS.hardware 3 27-10-2003 04:50 PM
    Worms Blast on Cube Zak33 HEXUS.gaming 3 15-10-2003 06:08 PM



    All times are GMT. The time now is 09:00 AM.

    Any representations/statements made on the HEXUS.community discussion forums are the representations/statements of the author i.e. the person/organisation making them. If any such representations/statements are disputed they are a matter between the parties concerned.
    HEXUS Limited accepts no responsibility for any misrepresentations, inaccurate or false statements made by any person/organisation other than HEXUS Limited employees.
    For more information please read HEXUS Limited's terms, conditions and privacy policy.

    Hosted Exchange

    Powered by vBulletin® Version 3.8.4
    Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
    Content Relevant URLs by vBSEO 3.3.2
    © Copyright 2009 HEXUS® Limited. All rights reserved. Unauthorised reproduction strictly prohibited.