Film-Tech Cinema Systems
Film-Tech Forum ARCHIVE


  
my profile | my password | search | faq & rules | forum home
  next oldest topic   next newest topic
» Film-Tech Forum ARCHIVE   » Community   » Film-Yak   » Wierd virus (temp directory filling up by itself) (Page 2)

 
This topic comprises 2 pages: 1  2 
 
Author Topic: Wierd virus (temp directory filling up by itself)
Michael Barry
Jedi Master Film Handler

Posts: 584
From: Sydney, NSW, Australia
Registered: Nov 1999


 - posted 05-20-2002 09:18 AM      Profile for Michael Barry   Email Michael Barry   Send New Private Message       Edit/Delete Post 
I intend to start using Win XP at some point, but my machine is currently too slow and the hard drive too small to accomodate it.

I agree that upgrading to XP would probably be the best move, along with using a firewall. Perhaps I could use my current machine as a hardware firewall when I get the new system. How would I get started in achieving this? Any recommendations for sites where I can learn more about this?

 |  IP: Logged

John Pytlak
Film God

Posts: 9987
From: Rochester, NY 14650-1922
Registered: Jan 2000


 - posted 05-20-2002 12:13 PM      Profile for John Pytlak   Author's Homepage   Email John Pytlak   Send New Private Message       Edit/Delete Post 
Here are suggestions that the local Rochester Time-Warner Road Runner site offers about security, especially with a broadband connection:
http://www.rochester.rr.com/security/

------------------
John P. Pytlak, Senior Technical Specialist
Worldwide Technical Services, Entertainment Imaging
Research Labs, Building 69, Room 7525A
Rochester, New York, 14650-1922 USA
Tel: +1 585 477 5325 Cell: +1 585 781 4036 Fax: +1 585 722 7243
e-mail: john.pytlak@kodak.com
Web site: http://www.kodak.com/go/motion

 |  IP: Logged

David Rowley
Film Handler

Posts: 14
From: Burnaby, BC, Canada
Registered: Apr 2002


 - posted 05-20-2002 02:28 PM      Profile for David Rowley   Email David Rowley   Send New Private Message       Edit/Delete Post 
http://www.grc.com is a great security resource site. It has a firewall test, some downloadable security apps, and some very interesting security related articles. Steve Gibson, the guy who runs the site, has discovered a few vulnerabilites in many of the personal firewalls on the market today. His recommendation is for Zone Alarm. I use Zone Alarm Pro, and I much prefer it over other firewall products I've used, such as Black Ice. Note that most "h4X0rs" use Black Ice because of the connection with the book Neuromancer, and not because of it's abilities. I tried it and found some serious deficiencies with it. Granted, that was about a year and a half ago...

 |  IP: Logged

Colin Wiseley
Expert Film Handler

Posts: 123
From: Blacksburg, VA
Registered: Dec 1999


 - posted 05-20-2002 03:32 PM      Profile for Colin Wiseley   Email Colin Wiseley   Send New Private Message       Edit/Delete Post 
Looks like you have the Benjamin worm. Do you use Kazaa, here's a story about it on CNET:

http://news.com.com/2100-1001-918132.html?legacy=cnet&tag=lthd

Here's removal instructions from McAfee:

http://vil.mcafee.com/dispVirus.asp?virus_k=99495

------------------
Colin Wiseley
Lyric Theatre
Blacksburg, VA
www.thelyric.com


 |  IP: Logged

Scott Norwood
Film God

Posts: 8146
From: Boston, MA. USA (1774.21 miles northeast of Dallas)
Registered: Jun 99


 - posted 05-20-2002 04:04 PM      Profile for Scott Norwood   Author's Homepage   Email Scott Norwood   Send New Private Message       Edit/Delete Post 
For a "good and cheap" firewall, I like IPfilter on FreeBSD. It's rock-solid and runs very nicely on older hardware.

Having said that, it's worth pointing out that firewalls are, by themselves, not a panacea for security threats. For most individual users, "get a firewall" is really lousy advice, since it tends to result in a false sense of security for novice users who have just managed to install the latest windows-based firewall software on their PC, without really understanding what it does.

A much better approach would be to configure the operating system properly in the first place, which makes firewalls unnecessary. Turn off all public services (mail and web servics, Windows file sharing, NFS/portmap, etc.) except those whose risk is determined to be justified.

Firewalls are useful in large organizations (companies, etc.) where there are large numbers of machines and the risk that one might be misconfigured is high. The concept of a firewall is not supposed to be a primary defense, but rather an added security measure to protect against accidental misconfiguration. For individual users with one or two computers, I'd strongly suggest spending the time to configure them properly in the first place instead of trying to protect a wide-open OS install with something that may or may not do any good.


 |  IP: Logged

David Rowley
Film Handler

Posts: 14
From: Burnaby, BC, Canada
Registered: Apr 2002


 - posted 05-21-2002 02:17 AM      Profile for David Rowley   Email David Rowley   Send New Private Message       Edit/Delete Post 
Scott, I agree with much of what you have said. However, I think that people, even if they only have one or two computers, MUST use a firewall if they have a constant internet connection. Personal firewalls do much more than to just keep traffic out. A good firewall will also make their machine "invisible" to port scans by not responding to a connection attempt, rather than simply sending a RST back to the scanner.

They also can prevent an app from accessing TCP/IP (or any net protocol). This is very useful for tracking down trojans and/or spyware. Not all malware is obvious, like Kazaa. For instance, a friend of my wife put a free Barbie game she got from a box of cereal on her computer for her daughter. Turns out, it had spyware attached, and would regularly "phone home" with whatever info it had compiled. The firewall I installed on her machine when she got cable caught the executable in the act, and I was able to remove it.

With more and more average joes getting high speed, constant connections to their home computers, as well as setting up home LANs, it gets harder and harder to educate people. How many people who have setup (or had a friend or family member setup) a home LAN know it is a really bad idea to bind TCP/IP to windows services? Not many. In fact, this is one of the most common flaw in home LANs today.

Education is definately important, but it can't do the job alone.

 |  IP: Logged

Mark Lensenmayer
Phenomenal Film Handler

Posts: 1605
From: Upper Arlington, OH
Registered: Sep 1999


 - posted 05-22-2002 11:24 AM      Profile for Mark Lensenmayer   Email Mark Lensenmayer   Send New Private Message       Edit/Delete Post 
"explorer.scr" is the key that says this is the Benjamin worm. It is associated with the KaZaA file sharing network. There is information on this worm and details on getting rid of it at:
http://www.sarc.com/avcenter/venc/data/w32.benjamin.worm.html

www.boingboing.net has posted this info about the virus and its authors:

The Benjamin Worm, virus that's sweeping the Kazaa file-sharing network, is a supposed "white hat" worm that was developed to scare people away from making unauthorized copies of copyrighted works on P2P networks.

According to one of its developers, Paul Komoszki, Benjamin is a "controlled test" of a program designed to disrupt the illegal exchange of copyrighted data and child porn over peer-to-peer networks.
"We do not want to affect the exchange of legal programs and legal music files. Only users who are looking for and sharing copyrighted files could be infected," said Komoszki in an e-mail interview today.

Once it infects a Kazaa user's computer, Benjamin creates numerous copies of itself under file names that may be of interest to other Kazaa users, according to anti-virus firms. Examples include borlanddelphi-full-downloader.exe and Braveheart-Special Edition-divx.exe, according to Kaspersky Labs.


 |  IP: Logged

Jerry Chase
Phenomenal Film Handler

Posts: 1068
From: Margate, FL, USA
Registered: Nov 2000


 - posted 05-22-2002 12:26 PM      Profile for Jerry Chase   Author's Homepage     Send New Private Message       Edit/Delete Post 
""We do not want to affect the exchange of legal programs and legal music files. Only users who are looking for and sharing copyrighted files could be infected," said Komoszki in an e-mail interview today."

Pardon my French, but what a flaming self-rightous scumbag idiot! I hope someone sues the pants off him, and he is placed pantless in front of people his worm has infected. Does he think that because one user of a computer does something he doesn't like, ALL the users of that computer should be punished? This isn't a one person/one computer world. Besides, who the f... does he think he is making such decisions outside of the legal system? White hat worm, bullshit. I can see his little worm infecting unintended targets very easily and causing serious damage. This guys is a man with too many tools and too few brains. Even though I don't file share, and I never have, I have nothing but contempt for this loser.


 |  IP: Logged



All times are Central (GMT -6:00)
This topic comprises 2 pages: 1  2 
 
   Close Topic    Move Topic    Delete Topic    next oldest topic   next newest topic
 - Printer-friendly view of this topic
Hop To:



Powered by Infopop Corporation
UBB.classicTM 6.3.1.2

The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion and agrees to release the authors from any and all liability.

© 1999-2020 Film-Tech Cinema Systems, LLC. All rights reserved.