Scary Virus Stuff

trotsky

Registered user
Joined
Jan 20, 2004
Messages
1,433
Reaction score
0
Location
150 metres from London
As part of an ongoing technical problem, best described as "software that appears to have been puked rather than developed" (see http://www.ukgser.com/forums/showthread.php?s=&threadid=29303 if you are thinking about buying a Navman GPS) I have today installed Windows XP on a spare disk I stuck in my PC and connected to t'Internet via a dial up modem. Now this may not sound terribly exciting but I would normally not go into the wild without a Cisco PIX firewall and a network address translating ADSL router between me and the baddies.

To allow this crappy software to activate I had to switch off any firewalling and turn off my anti-virus software while running as administrator :eek: . Now no sensible person does this on a working system, and I count myself in that group on every second day, so I dug out an old 10GB disk, plugged it in to my PC with every other disk disconnected and put a partially patched (everything pre Win XP Service Pack 2) operating system and the minimum of other software. I put on a firewall and ran it in "monitor, notify but don't block" mode. I then plugged in a dial up modem and connected to uku.co.uk who run a "no charge but dialup cost" ISP service.

The first probes appeared in ten seconds of connection; by 30 seconds I was getting "click here to protect your machine from spyware" and "Russian Girls want your Love" popups and after 50 seconds I got a "Your machine is about to shutdown" message and I had lost the rights to shut the machine down myself. By this time the machine had slowed to a crawl and the firewall couldn't keep up with attempts to probe my ports.

So the lesson is don't connect any machine to the network unless it is patched to the best possible standard (this month's PC magazines have Windows XP Service Pack 2 disks on, buy it now and save tears later on), virus protected and firewalled.

I've spent all week cursing laptop users who try to connect virus infected machines to my network at work. Now I know how messy things really are I shall be a little more tolerant... Perhaps.
 
Just had a similar problem

While using my dial-up connection tonight, I noticed the connection was very slow -the got this pop-up that said ' the computer is about to shutdown ' etc etc. Sure enoguh it did. Did a re-start, dialled up again only to see that the usual google hompage was Lithuanian (Google.li) and the number dialled from the dial-up window was
0067816584 !!!!!

Re-configured my dial-up connection to my local free ISP, downloaded the latest AVG virus update and did a complete virus scan. Nothing found.

Rebooted the PC, logged on again only to find that the number about to be dialled was the bloody Lithuanian one again !!

Deleted the default connection and added a new one, again to my local ISP.

I'm afraid to reboot in case the same sh1t happens again.

Anyone got any ideas on how to fix this crap ?

Ferg
 
Run spybot Search & Destroy and Adaware they should get rid of any nasties and dialers.

Spybot

Adaware

Also go into your connection settings...

START - Controll panel - Network & internet connections - Network connections. You should then see all your accounts and therefore see any expensive dialers.
 
Thanks Andy

Am downloading Spybot now. Already have adaware and tried that early on tonight but it didn't pick up anything unusual.

Lets hope the spybot does the trick !

Cheers

:beerjug:
 
Ooops forgot to mention when you install spybot, before you run it remember to check for updates.:rolleyes:
 
I would like to addtwo points to the above discussion.

I used to work for a subsidiary of one of the largest retail chains in the UK (better not state where) - put 2003 server on a brand new HP 380 server - forgot to turn on the firewall and connected to the network (behind proxy, firewall etc. etc.) and within 1 minute it came up with the "Windows will shut down in 60 seconds" message. They blamed it on the retail stores plugging in infected PCs!? :rolleyes:

As to Spybot Search& Destroy, it is a very good program but does not always find the offending files. If it persists you need to do a google search entering the exact symptoms - there are many tools out there and some very helpful advice on how to use them to get rid of these pests. Somebody at work somehow got infected with something that changed the homepage to: "about:blank: showing a search page with the helpful advice that the PC was infected - would you like to pay $29.99 for software to get rid of it. The fix found on Google involved 3 freeware programs and a registry hack.

Good luck with getting rid of it!
 


Back
Top Bottom