sudden networking problems (partial)

  • Thread starter Thread starter Joshua Turcotte
  • Start date Start date
J

Joshua Turcotte

About the beginning of Oct 03 something strange happened
to my system... its a new DELL, runs xp home, I'm sitting
behind a netgear wireless router (mr814) and sharing my
DSL (prexar usa) connectivity with my brother via a static
IP address (we have internals here)... This has worked
fine for the longest time. About a week and a half ago,
that changed however, and prexar blames netgear and
netgear blames prexar, but I now suspect something has
been damaged or silently changed with XP or my network
setup (perhaps due to one of my -frequent- crashes).

The symptomes are occasional, but specific... my brother
can access google.com, I now cannot (this is a real pain
in the butt)... he can download the roxio cd burning
software I recently bought (though their client
simultaneously installs the software, nullifying any
potential good in that situation) and I cannot... I can
still get to my primary client's two host servers via ftp
and ssh, but a quick client (templeton.org) refuses
connection giving an error of (530)... regardless of the
fact that I had the correct login info (which even if it
had been wrong wouldn't have resulted in a 530 error).

Could XP's networking be damaged? No settings have been
changed for many many months prior to the start of the
problem... the router has been checked out, the ISP denies
any changes on their end... and besides that I must
reiterate that my brother's machine remains unaffected on
the same LAN... I need a fix.. this is costing me work and
money i've spent on softwares I'm unable to download
thanks to this problem. Does this sound familiar to
anyone? Clues, hints, pointers? help!
 
Hi,

It sounds like you've been infected with the Trojan.Qhost bug.
The new Qhosts bug exploits the unpatched residual vulnerability in
MS03-032.

Information regarding this can be found here.
http://vil.nai.com/vil/content/v_100719.htm and
http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html

The removal tool for this trojan is available here:
http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.removal.tool.html

The bug sets all search values to google. You may wish to change your
configuration on your Internet
Explorer search settings as desired, if you don't want google.

To prevent this exploit, install the critical update described by
bulletin MS03-040 and KB828750. To test your browser vulnerability to
this exploit, see http://www.secunia.com/MS03-032/.
 
Back
Top