1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

XP Home Hijacking/Virus - Major Problem

Discussion in 'Security and Privacy' started by jirobert, 2005/02/21.

Thread Status:
Not open for further replies.
  1. 2005/02/21
    jirobert

    jirobert Inactive Thread Starter

    Joined:
    2005/02/19
    Messages:
    2
    Likes Received:
    0
    I believe I have a virus/hijack that becomes a system service, during the installation of XP, with admin privileges. I disabled server service. It is now running and the service no longer shows in MMC or Admin Tools. I am also missing Workstation Service. When I use C:\net config server /hidden:no it returns "The service name is invalid ". The same returns for workstation service.

    I have the XP firewall running with all ports closed, no exceptions. Remote desktop service, smb over tcp service, netbios service and remote assistance service are all disabled. When I start the computer these services start and ports 137, 138, 139, 445 and 3389 are opened as exceptions to the firewall settings. All of this is done before the cable is connected to the internet.

    I have tried lowlevel formatting the drive before installation and the problem returns each time. I have the problem on two computers using different original XP CD's for installation. Help
     
  2. 2005/02/21
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Pro or home? I think Home from your title but want to make sure.
    What SP?

    Does this mean before you hook a cable to the network card (for a local network) or simply before you connect to the internet?
     
    Newt,
    #2

  3. to hide this advert.

  4. 2005/02/22
    lachelp

    lachelp Inactive

    Joined:
    2004/04/15
    Messages:
    4
    Likes Received:
    0
    You have to a bit more work to do...

    Uninstall Microsoft Networking, Windows File and Printer Sharing, disable NetBIOS and uncheck import LMHOST in the advanced settings of TPC/IP and also kill off TCP NetBIOS helper service.

    Cheers!
     
  5. 2005/02/22
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    If you meant 'client for microsoft networks' then OK. But with XP, you cannot remove networking as you could with previous OS versions. All you can do is use a netsh string to reset it to the default values.
     
    Newt,
    #4
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.