Berkeley CSUA MOTD:Entry 29318
Berkeley CSUA MOTD
 
WIKI | FAQ | Tech FAQ
http://csua.com/feed/
2025/04/04 [General] UID:1000 Activity:popular
4/4     

2003/8/12-13 [Computer/SW/Virus, Computer/SW/OS/Windows] UID:29318 Activity:high
8/11    I recently installed XP on my laptop, and it's been fine for the
        past few days. STarting today though, I get an error during
        boottime saying Windows can't open up the file TFTP2396, and
        it prompts me to give it a program to open it up with. I hit
        cancel, and then about 10 minutes later the "WinNT Authority"
        hits me with a dialog box saying it has to shut down the machine
        in 60 seconds (and then starts counting down). Anyone have any
        ideas what's going on? Thanks.
        \_ http://isc.sans.org/diary.html?date=2003-08-11
                \_ Cool, thanks a lot.
        \_ Learn to use a firewall and turn off unnecessary services.
           What version of XP are you using, Pro?
                \_ wouldn't this be caught by anti-virus programs?
                  \_ do even drugs catch mutated viruses? have to keep
                    updating after new viruses appear
        \_ And while you're at it, use ad-aware every so often in addition to
           keeping your anti-virus software updated.
        \_ So many stupid suggestions so far. Solution is to not use WinXP.
           \_ LINUX RULEZ!  *BSD IS DEAD!  RIDE BIKE!  D00DE!1   Isn't that
              what you meant to say?
              \_ don't you think maybe your zealous hatred of linux is just
                 as useless and silly as the linux crowd's zealous hatred
                 for windows you're mocking?
                 \_ erm.. where do you see "hatred of linux" in the previous
                    post?  can we get a reading comprehension requirement
                    for motd posting? --scotsman
2025/04/04 [General] UID:1000 Activity:popular
4/4     

You may also be interested in these entries...
2009/5/7-14 [Computer/HW/Laptop, Computer/SW/Virus, Computer/SW/OS/OsX] UID:52968 Activity:nil
5/7     Help, I think something's wrong with my network setting. I'd go to
        a web site, and then it would say "cannot find address". Then I'd
        reload again, occassionally 3 times, to load the page. Is this
        due to DNS being too slow, TTL setting, or something else?
        \_ windows mac or linux ?
           \_ windows (company issued laptop, no alternative)
	...
2009/4/12-20 [Computer/SW/Virus] UID:52844 Activity:nil
4/11    Is there a spyware detector that is free and can scan networked
        drives? Neither AdAware (free edition) nor SpyBot S&D have this
        feature, and I'd prefer to not pay AdAware Pro a penny until
        there really isn't any other alternative.
        \_ How about SuperAntiSpyware?
           \_ Just tried that, no luck :( They let you add remote drives
	...
2008/3/4-7 [Computer/SW/Virus] UID:49325 Activity:kinda low
3/4     Hi, what's the best free anti-virus software for XP?  What about
        anti-spyware?  Currently I'm using Active Virus Shield and Spybot.
        Thanks.
        \_ I've used: avg, spybot s&d, adaware, trend micro's housecall.
           \_ Does Spybot S&D protect Firefox?  It soulds like the injection
              feature only supports IE.
	...
2007/12/15-19 [Computer/SW/OS/Windows] UID:48810 Activity:moderate
12/15   Ran through AdAware and SpyBot but computer still slow and still
        getting weird pop-ups from http://casalemedia.com. Best solution? Block
        all of these IPs in less than a minute!
        http://www.mvps.org/winhelp2002/hosts.htm
        Click on the "To view the HOSTS file in plain text form"
        and then put it in your /etc/hosts file. If using Winblows:
	...
2006/5/8-11 [Computer/SW/Virus] UID:42977 Activity:nil
5/8     apologies if this has been asked recently: friends are asking me
        whats a good windows antivirus software and I've heard this
        thing AVG is good -- and free. anyone use this? is it good? thx
        \_ From the motd archive:
           AVG used to be good when it was the only free program around.
           Most people say that Avast! and AntiVir are better, though.
	...
2006/1/2-4 [Computer/SW/Virus] UID:41199 Activity:nil
1/2     Which Windows anti-virus software do you trust/recommend?
        \_ Linux
        \_ I think the general consensus is that Kaspersky is the best AV
           program you can buy.  Among the free AV programs, Avast! is well
           regarded, followed by AntiVir.  ClamAV seems pretty good if you
           want to go open-source. --jameslin
	...
2005/2/19-22 [Computer/SW/Virus] UID:36255 Activity:kinda low
2/19    What are the best anti-spyware programs?  I am looking for something
        that my parents can run occasionally to try to keep their windows
        machine clean.  I'm a BSD user so I don't deal with this type of
        stuff much. Thanks --jwm
        \_ For PC's use "spybot search & destroy" and "adAware".
        \_ My detected spyware has dropped to almost nil after switching
	...
2005/1/13-14 [Computer/Networking] UID:35697 Activity:high
1/13    I need help fixing someone's Win2K box.  Setup:  Win2K box -> D-Link
        router -> DSL modem.  The Win2K box cannot obtain a DHCP address
        (other computers can).  So, I assign a static IP, and set the default
        gateway and DNS server to be the D-Link router.  After this, the Win2K
        box can access web pages on the Internet as long as you specify the
        web site IP address directly -- but DNS doesn't work.  Computer used
	...
2004/11/16 [Computer/SW/OS/Windows] UID:34917 Activity:nil
11/15   What's the best free software for finding and removing
        spyware from Windows 95/98/me/2000/xp?
        \_ AdAware and Spybot in tandem.
           \_ Not always.
                \_ That's what I use.  What's better than that (and free)?
	...
2004/11/13-14 [Computer/SW/Virus] UID:34875 Activity:high
11/13   I've run the latest version of Ad-aware and gotten rid of
        all the crap that it found.  But there is still some crap on
        my computer that shouldn't be there.  In particular, when I
        start up IE, regardless of what I set my home page as, a
        "Home Search" page comes up, along with a couple of pop-ups,
        before I do anything.  I went into Add/Remove Programs and
	...
2004/9/23-24 [Computer/SW/Virus] UID:33733 Activity:high
9/23    So my PC got infected with this Lop adware bullshit... IE seems
        totally hijacked. Adaware and SpyBot both dont seem able to
        remove it. Anyone have any advice how to get this off my system?
        Also, please use this thread to bitch about this Lop bullshit
        and how evil it is. Thanks.
        \_ Install FireFox.  Ad-aware, SpyBot.  If that doesn't work, google
	...
2004/2/1 [Computer/SW/Virus] UID:12058 Activity:nil
1/31    spybot vs adaware.  I've used adaware for a long time but figured I'd
        give spybot a shot since it was highly regarded in the thread below.
        I ran the newest adware doing a full scan which found a few minor
        things.  Then I installed and ran spybot which found a few other
        things I didn't know about before and adaware missed.  Thank you motd.
        \_ you are welcome
	...
2010/4/28-5/10 [Computer/SW/OS/Windows] UID:53807 Activity:nil
4/28    Win 3.1 was more widely adopted than Win 3.0.  Win XP (5.1) was more
        widely adopted than Win 2k (5.0).  Now it looks like Win 7 (6.1) is
        going to be more widely adopted than Vista (6.0).  Is this a trend on
        Microsoft x.0 versions being bad?
        \_ duh.
        \_ "more widely adopted" ... well... what are you basing these numbers
	...
2010/2/18-3/9 [Computer/SW/WWW/Browsers] UID:53713 Activity:nil
2/18    Why is there now Firefox 3.5.8 when there was already 3.6 a month ago?
        \_ Why is there Windows XP SP3 when there was already Vista?
           Generally companies manage patches for at least two levels of
           product.  -tom
           \_ I see.  So Fx 3.6 is more like a new version than an update to
              3.5.x.  --- OP
	...
2009/8/4-13 [Computer/SW/OS/Windows] UID:53239 Activity:kinda low
8/3     VMWare + Windows XP + Validation question. I need to test stuff with
        Service Pack 3 installed. I have a valid key that I own (yeah yeah I
        actually *bought* a copy, please don't flame me for supporting evil
        M$). Is it possible to register the key once, and then duplicate it
        for testing purposes?  Will Windows or Microsoft detect copies and
        disable the rest the copies?
	...
2009/6/1-3 [Computer/HW/CPU] UID:53068 Activity:high
5/31    History of winners and losers by *popularity*:
        VHS > Beta Max
        USB2 > Firewire
        x86 > PowerPC > Everything Else > DEC Alpha > Itanium
        BlueRay > HDDvd
        \_ It's too early to tell RE: "Blue"Ray. They may both turn out to be
	...
2009/2/20-25 [Computer/SW/OS/Windows] UID:52610 Activity:nil
2/20    I'm using Cygwin/X on XP.  All the X indows (xterm, emacs)
        seem to have a keyboard repeat rate and a repeat delay that's different
        than the one XP uses for other Windows apps.  When I do "mode con
        rate=xx delay=yy", it only changes Windows apps but not the X apps.
        How do I change the keyboard repeat rate and delay for X?  Thanks.
        \_ man xset
	...
2008/11/29-12/6 [Computer/SW/OS/FreeBSD, Computer/SW/OS/VM] UID:52129 Activity:moderate
11/29   I'm experimenting with virtualization, and as a poor college student
        I'm wondering what the best alternatives for virtualization are, and
        how best to cut my teeth on messing with non-linux platforms (or I
        guess interesting stuff on Linux would work too). Right now I've got
        FreeBSD7 running on KVM on my home computer (on a Core 2 Quad), and am
        somewhat at a loss as to how to use it. (More details: bridged
	...
2008/11/15-26 [Computer/SW/OS/Windows] UID:51993 Activity:nil
11/14   I have a bunch of pictures and I find that thumbs.db on
        Windows XP to be very useful, especially when you're on NAS
        and the network is slow. Having that said, my Win XP has
        stopped generating thumbs.db even though I've set it to generate
        thumbs.db (Properties->View->Uncheck "Do not cache thumbnails.").
        How do I force Windows to generate Thumbs.db? Googling seems
	...
2008/10/12 [Computer/SW/OS/Windows] UID:51487 Activity:nil
10/12   When XP boots up on my PC, the screen reads "Microsoft (R) Windows (R)
        5.01. 2600 Service Pack 3 Multiprocessor Free."  What does "Free" mean?
        Thx.
	...
2008/9/22-29 [Computer/SW/OS/OsX] UID:51261 Activity:nil
9/21    So I did it and got myself a Macbook Pro. Any suggestions for the best
        PC->Mac transition?  After finding out that Outlook is not supported
        under Mac; I bought parallels and am installing XP to grab my outlook
        mail archive (~1GB) from the original PC disk (the pc itself is
        basically dead). Any suggestions on a relatively painless import to
        entourage? The Mac Genius guy also reccomended an upgrade to 4GB and
	...
2008/9/18-19 [Computer/HW/Laptop] UID:51217 Activity:low
9/18    My  7 year old Dell laptop is slowly  decending into its death throws.
        I am seriously considering an Mac laptop; but am having a hard time deaa\
        ling with the price. Curious to find out  if people really think that
        the extra $$ upfront was a good investment. a 2K macbook pro with
        standard config can buy a high end dell laptop
        \_ I have both a MacBook Pro (and before that a PowerBook) and a
	...
Cache (1124 bytes)
isc.sans.org/diary.html?date=2003-08-11 -> isc.sans.org/diary.php?date=2003-08-11
Do not base your incidents response solely on this writeup. This worms exploits the Microsoft Windows DCOM RPC Vulnerability announced July 16, 2003. The size of the binary is about 11kByte unpacked, and 6kBytes packed: MD5sum packed: 5ae700c1dffb00cef492844a4db6cd69 (6176 Bytes) Infection sequence: 1. It has the ability to infect Windows 2000, XP and potentially 2003. One it finds a vulnerable system, it will spawn a shell on port 4444 and use it to download the actual worm via tftp. Detection: Existing RPC DCOM snort signatures will detect this worm. As there have been a number of irc bots using the exploit for a few weeks now, it is possible that your system was already infected with one of the prior exploits. If you can not do this and/or the computer resides on a protected or non-Internet connected network, then several Anti-Virus Venders have supplied tools to assist in removing the worm. However, these tools can not clean-up damage from other RPC DCOM malware such as the recent sdbot irc bots. This method of cleaning your system is _not_ recommended, but the URLs are presented below for completeness.