Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > "Unusual TFTP files"

Reply
Thread Tools Display Modes

"Unusual TFTP files"

 
 
Tref
Guest
Posts: n/a

 
      04-15-2005
In article 826955 concerning the Blaster worm, Microsoft recommends looking
for "unusual *TFTP files" but then never explains which TFTP files ARE
unusual. What TFTP are normally found on an XP computer?
Thank you.
 
Reply With Quote
 
 
 
 
David H. Lipman
Guest
Posts: n/a

 
      04-16-2005
From: "Tref" <>

| In article 826955 concerning the Blaster worm, Microsoft recommends looking
| for "unusual *TFTP files" but then never explains which TFTP files ARE
| unusual. What TFTP are normally found on an XP computer?
| Thank you.

On WinXP or Win2K on TFTP.EXE.

http://vil.nai.com/vil/content/v_100547.htm
- Presence of unusual TFTP* files
- Presence of the file msblast.exe in the WINDOWS SYSTEM32 directory
- Error messages about the RPC service failing (causes system to reboot)
- The worm randomly opens 20 sequential TCP ports for listening. This is a constantly
revolving range (ie. 2500-2520, 2501-2521, 2502-2522). The purpose of this action is unknown

So if you find files like; TFTP2453, TFTP1257, TFTP6743, etc.

The Lovsan/Blaster is NOT the only infector that will create this type of file. If the are
found, the system *must* be scanned by anti virus software and not just the tools Microsoft
provides becuase they are insufficient and not Broadspectrum enough.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


 
Reply With Quote
 
Tref
Guest
Posts: n/a

 
      04-16-2005
Thank you


"David H. Lipman" wrote:

> On WinXP or Win2K on TFTP.EXE.
>
> http://vil.nai.com/vil/content/v_100547.htm
> - Presence of unusual TFTP* files
> - Presence of the file msblast.exe in the WINDOWS SYSTEM32 directory
> - Error messages about the RPC service failing (causes system to reboot)
> - The worm randomly opens 20 sequential TCP ports for listening. This is a constantly
> revolving range (ie. 2500-2520, 2501-2521, 2502-2522). The purpose of this action is unknown
>
> So if you find files like; TFTP2453, TFTP1257, TFTP6743, etc.
>


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
"This application has requested the Runtime to terminate it in an unusual way." SapperPest19 Windows Vista Performance 7 04-25-2009 04:19 PM
"Unusual" fault message Myron Bennett Windows Vista General Discussion 1 11-13-2008 05:04 PM
unusual "Vista Plus Pack" on February 15th John Smith Windows Vista General Discussion 1 01-16-2008 02:20 PM
New and unusual "Find Album Info" behavior dba Windows Media Player 22 12-13-2007 10:09 AM
Fail to restart TFTp Server TFTP Download fails. Rahul Windows Vista General Discussion 2 07-23-2006 02:57 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59