Computer Security

Joined
Jul 26, 2008
Messages
2
Reaction score
0
Hi guys,

need some help here.

It seems like some changes were amde to my Mcafee and when I looked at the recent event, the following looked suspicious.

  1. Systemguard has allowed one time change to your computer. Rule type = registry, process=c:\windows\system32\rundll32.exe, process description=run dll as an app. DOES THIS MEAN THAT SOMEBODY PHYSICALLY CHANGED SOMETHING ON MY COMPUTER SO THAT THEY CAN REMOTELY ACCESS IT.
  2. Worm Stopper detected email activity, Process=C:\windows\system32\telnet.exe, Process description=Microsoft Telnet client, allowed=yes. DOES THIS MEAN THAT SOMEBODY TELNETTED INTO MY COMPUTER.
Do I need to worry about the above mentioned items. What do I need to do if it is not safe to use my computer.

Thanks

Usman
 
Hi,

After some searching on the net it seems that problem one could be spyware, it seems from other peoples posts and answers that you should have a message telling you to run it as an app, but none show that it has changed itself.

Soooo, it does seem that someone has changed it themselves as both mcafee and norton recognise it as a worm/trojan and give you the option of what to do.

If you don't already have Superantispyware download it for free and run that, see what it finds.

goodluck

As for problem two i am looking.

Oh are you on vista or xp?
 
I am on XP. If somebody has my IP address, can they remotely access my computer and change it remotely instead of physically doing it?

Thanks for your help
 
As far as i understand yes, but they can't hide the settings changes.

Also the rundll32.exe takes part of an application and stores in in the memory so when you want to use said application it will run smoother/open faster, it will access the internet for tracking cookies and such but should give you the option.

Instead of mcafee get kapersky internet as it has an outgoing firewall as well as incoming so it is much much better than mcafee or norton.

You can download a free version of Kapersky labs (just google the name) or buy the full version for about £10.

Finally check your network and sharing options and make sure they are the way you have them, also check to see if you still have the same amount of hard drive space left as peeps don't just take info of a computer they put stuff onto them as well.

Hopefully it will be mcafee playing up.
 
Help on TELNET being used to send mail, possibly SPAM & also rundll purposes etc.

livelife06360 said:
Hi guys,

need some help here.

OK, here goes then:

livelife06360 said:
It seems like some changes were amde to my Mcafee and when I looked at the recent event, the following looked suspicious.

  1. Systemguard has allowed one time change to your computer. Rule type = registry, process=c:\windows\system32\rundll32.exe, process description=run dll as an app. DOES THIS MEAN THAT SOMEBODY PHYSICALLY CHANGED SOMETHING ON MY COMPUTER SO THAT THEY CAN REMOTELY ACCESS IT.


  1. Well, on this first one, typically, rundll32.exe is used to call functions from "dynamic link libraries" (they end in .DLL), & this can be the std. ones in the Operating System + Programs you use, OR, malicious ones as well.

    A good way to think of DLL's is, they are programs that cannot launch themselves, but, instead, allow other programs to load & use portions of them (functions) into their OWN memory section, for code reuse of proven working functions (no need to reinvent the wheel, hence the term "API" (applications programming interface, which all the Win32 API is, for instance, is a set of functions from DLL's really))

    (This really depends on the commandline used, w/ rundll32.exe program... & the functions actually called too, as well as the library name... get me that? I can tell you a LOT more!)

    So, this can be "benign", or malicious... I'd have to see more, like something from the inside of say, msconfig.exe... & a commandline there, that uses the rundll32.exe tool!


    For instance? Nvidia vidcards have commandlines for their stuff, that you can see using msconfig.exe (so, they're NOT ALL BAD, if rundll32.exe is concerned, for instance).

    E.G.-> RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    ----

    livelife06360 said:
    [*]Worm Stopper detected email activity, Process=C:\windows\system32\telnet.exe, Process description=Microsoft Telnet client, allowed=yes. DOES THIS MEAN THAT SOMEBODY TELNETTED INTO MY COMPUTER.
livelife06360 said:
Do I need to worry about the above mentioned items. What do I need to do if it is not safe to use my computer.

Thanks

Usman

Ok, on THIS one? You CAN, technically & not just 'theoretically', send mail via telnet (mail servers have a pretty simple commandset, like HELO & other commands), this being an example:

(MAN! This? This is some "old school ****e", if you catch my drift, but here goes an example):

---------------------------------------------------------------

Example - How do I send faked/spoofed mail, via TELNET?

Telnet to port 25 of the machine you want the mail to appear to originate from. Enter your message as in this example:

HELO pcreview.co.uk
MAIL FROM: (e-mail address removed)
RCPT TO: (e-mail address removed)
DATA
YOU HAVE BEEN OWNED & ARE NOW MY SLAVE, SENDING MAILS FOR ME FOR SPAM
.
QUIT

---------------------------------------------------------------

(HOWEVER - On systems that have RFC 931 implemented, spoofing your "MAIL FROM:" line will not work. Test by sending yourself fakemail first. For more information read RFC 822 "Standard for the format of ARPA Internet text messages.")

----

:)

& There ya are... I would worry about the TELNET one more, because odds are, I can see a hacker/cracker/malware in general maker (especially SPAM MAILERS) using a system that way. Heh, IF this is the case?

He ( "the attacker", assuming there IS actually one here) is an "OLD SCHOOLER" for sure...

APK

P.S.=> Correct me IF I am wrong, but... isn't TELNET gone from VISTA? I don't use VISTA myself, but for SOME reason, this is "ringing a bell here", etc. et al... EDITING - ok, "non-sequitur" on my part (user asking for help here is on XP, so this probably applies on the TELNET stuff)... apk
 
Last edited:
Lastly: Want the BEST possible security & speed online?

See subject-line, & this URL's content here on this site:

https://www.pcreview.co.uk/forums/thread-3511888.php

:)

* Do that, & I am certain you will be pleased w/ the results... proof? Well, let's let OTHERS' RESULTS, do that, for me:

EXAMPLE FEEDBACK FROM A USER (on his home machines, business machines & network, PLUS end-user client's systems):

http://www.xtremepccentral.com/forums/showpost.php?p=207534&postcount=59

SALIENT QUOTE/EXCERPT, as to results, after applying my guide:

------------------------------------------------------
"I recently, months ago when you finally got this guide done, had authorization to try this on simple work station for kids. My client, who paid me an ungodly amount of money to do this, has been PROBLEM FREE FOR MONTHS! I haven't even had a follow up call which is unusual. Now I don't recommend this for the average joe, but it if can work for a kids PC it can work for anything!"
------------------------------------------------------

AND

http://www.xtremepccentral.com/forums/showpost.php?p=204956&postcount=50

SALIENT QUOTE/EXCERPT, as to results, after applying my guide:

------------------------------------------------------
"APK, thanks for such a great guide. This would, and should, be an inspiration to such security measures. Also, the pc that has "tweaks": IS STILL GOING! NO PROBLEMS!"
------------------------------------------------------

AND

http://forums.guru3d.com/showpost.php?p=2714028&postcount=108

SALIENT QUOTE/EXCERPT:
------------------------------------------------------
"And for the speed and security registry files you emailed to me, theres alot of things i didn't know windows could do, and my internet does seem snappier."
------------------------------------------------------

:)

APK

P.S.=> That guide of mine, works... you MAY be interested in pursuing its points (1-3 hrs. of your time, for F A S T E R & safer computing, today - especially today: FOR YEARS INTO THE DISTANCE, for a little bit of your time)... apk
 
Last edited:
Back
Top