I think I have a new record for a malware infested machine

General Network security, firewalls, port filtering/forwarding, wireless security, anti-spyware, as well as spam control and privacy discussions.
Post Reply
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

I think I have a new record for a malware infested machine

Post by YeOldeStonecat »

:rotfl: I can't believe this machine is booting up, no internet, repaired Winsock, installed MS Antispy, so far, over 7,000 files and over 12,000 registry entries cleaned by MS Antispy. And I haven't even done Spybot, Adaware, or Spysweeper yet.

Computer previously protected by McAfee. Guess I'll cancel my afternoon onsite, this one will take a while.
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
Shinobi
Senior Member
Posts: 4455
Joined: Sat Jan 06, 2001 12:00 am
Location: South Carolina

Post by Shinobi »

YeOldeStonecat wrote: :rotfl: I can't believe this machine is booting up, no internet, repaired Winsock, installed MS Antispy, so far, over 7,000 files and over 12,000 registry entries cleaned by MS Antispy. And I haven't even done Spybot, Adaware, or Spysweeper yet.

Computer previously protected by McAfee. Guess I'll cancel my afternoon onsite, this one will take a while.
Holy Hippo Spit ! :eek:

Good Luck to You. :thumb:

Shinobi
_______________________________________________
Vendor neutral certified in IT Project Management, IT Security, Cisco Networking, Cisco Security, Wide Area Networks, IPv6, IT Hardware, Unix, Linux, and Windows server administration
[SIGPIC][/SIGPIC] :thumb:
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

950 something in Spybot
760 something in Adaware
I yanked AVG and McAfree, NOD32 going in next....this'll be fun, you should see all these oddball files in the system32 directory. :eek:
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

Wow, bad infestation with "MidADdle". NOD32's doing the scan now and mopping it up by the dozens.
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
mnosteele52
Posts: 11913
Joined: Tue Jul 24, 2001 12:00 pm
Location: Chesapeake, VA

Post by mnosteele52 »

I'm right there with ya YOSC, the current pc I'm working on was pretty bad as well. I had one last week that has almost 8,000 items SpySweeper found along with almost 400 from KAV then 100-150 each with Ad Aware & SpyBot..... it's crazy isn't it? How people let their machines get this bad.

:) :thumb:
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

mnosteele52 wrote: it's crazy isn't it? How people let their machines get this bad.

:) :thumb:
:rotfl: Yeah I don't know. When they called me, the symptoms were only "It won't finish a defrag, says the hard drive is full!".

I get this Dell, P4, 512 megs, 80 gig drive with over 65 gigs free. :confused: OK hard drive can't be full, but after a few minutes after booting up, sure enough popup city and poking around in add/remove, I knew it'd be a different story.

Spysweeper and NOD32 are going nuts now.
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
Shinobi
Senior Member
Posts: 4455
Joined: Sat Jan 06, 2001 12:00 am
Location: South Carolina

Post by Shinobi »

YeOldeStonecat wrote: Yeah I don't know. When they called me, the symptoms were only "It won't finish a defrag, says the hard drive is full!".
Are you in safe mode man.. I would ..
:D

Shinobi
_______________________________________________
Vendor neutral certified in IT Project Management, IT Security, Cisco Networking, Cisco Security, Wide Area Networks, IPv6, IT Hardware, Unix, Linux, and Windows server administration
[SIGPIC][/SIGPIC] :thumb:
User avatar
mnosteele52
Posts: 11913
Joined: Tue Jul 24, 2001 12:00 pm
Location: Chesapeake, VA

Post by mnosteele52 »

YeOldeStonecat wrote:Dell, P4, 512 megs, 80 gig drive
Decent specs and the funny thing is people like that say "I'll never buy a Dell again, nothing but problems", LOL they don't realize it's their own fault for installing so much malware and not properly protecting themselves.

:rolleyes: :) :D
User avatar
Saboka32
Regular Member
Posts: 163
Joined: Sun Jun 27, 2004 5:27 am
Location: Michigan

Post by Saboka32 »

Dells are pretty good machines, lol its ppl that don't take care of them thats the problem.
User avatar
Shinobi
Senior Member
Posts: 4455
Joined: Sat Jan 06, 2001 12:00 am
Location: South Carolina

Post by Shinobi »

mnosteele52 wrote:Decent specs and the funny thing is people like that say "I'll never buy a Dell again, nothing but problems", LOL they don't realize it's their own fault for installing so much malware and not properly protecting themselves.

:rolleyes: :) :D
The real problem man, is that Dell loads so much programs with new computers.. that it afects memory / performence. True.
_______________________________________________
Vendor neutral certified in IT Project Management, IT Security, Cisco Networking, Cisco Security, Wide Area Networks, IPv6, IT Hardware, Unix, Linux, and Windows server administration
[SIGPIC][/SIGPIC] :thumb:
CableDude
SG VIP
Posts: 26801
Joined: Sat Jun 02, 2001 12:00 pm

Post by CableDude »

Screenshots man! :D We need screenshots!
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

Shinobi wrote:Are you in safe mode man.. I would ..
:D

Shinobi
Yeah when I left the office today I bounced her into safe mode and kicked off a 'fragging. We'll see what awaits me on the screen tomorrow when if I get to the office.

Prior to that, Spysweeper found 70 something items and NOD32 was lighting up the room with red flashes, I'll have to see what the log says tomorrow, that dang variant of MidADdle ad123 which has 3x components which keep morphing themselves will keep it busy. Those 3x components work in harmony, if the first component is killed, on the next bounce one of the other two will re-seed it under a different random name.
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
thepieman
Posts: 13400
Joined: Wed Nov 19, 2003 12:00 pm
Location: Brooklyn , New York

Post by thepieman »

I got a machine in last night that had a Hidden directory called C:\Upload
it had about well over 9500 zip files in it, all with the same file and file size but different file names and descriptions...ALL Cracks, App names, each one was infected with WIN32.crypt.e File names such as Macromedia Flashcom server Unlimited , Kaspersky antivirus V3.xx.
This computer must have been taken over as a zombie and used by one of those crack sites as a mirror of some kind, and these people downloaded these files thinking they were cracks and bootleg software. It even tried to travel through my network! was only one file in each one and it was setup.exe lol :rotfl:
SG Pimp Name : *Treacherous P. Shizzle*
*
The fight for our way of life needs to be fought on our own soil, for our own people and because of our own interests.
*
Hey, If Me & My Buddies Were Making Billions of Dollars I'd Tell Ya What Ya Wanted To Hear Too!
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

thepieman wrote:WIN32.crypt.e
Ugh, that's a fun one, Alan.C or something like that is another name, or cousin.
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
TeenInternetAddict
Regular Member
Posts: 245
Joined: Sat Nov 25, 2000 12:00 am
Location: Topeka, Kansas

Post by TeenInternetAddict »

Mnosteele and Saboka32, I'm using a Dell Dimension 2350, 1.7GHz Intel Celeron, 768MB of PC2100 DDRAM, Windows XP Home Edition, 80gig hard drive with 2MB cache (going to upgrade the hard drive in eight months), etc. My Dell machine runs very fast on the Net and programs open up very fast. I do take very good care of my PC by running spyware and virus applications, run defragmenter and checkdisk every two or three months when the apps starting
to take forever to load, etc. People nowadays are mostly idiots that don't know a thing about PCs (since PCs and Windows XP are easier to use) they are the ones that blame Dell when they mess up their PCs. Listen, it's not Dell's fault that the people let their PC go to all heck by having 7000+ spyware and malware, 1000+ viruses and trojans, etc.
Computer specs:

Dell Dimension 2350 with a 1.7Ghz Intel Celeron Proccesor, Windows XP Home Edition, 80 Gig hard drive, 768Mb of DDRAM PC2100, CDRW and cdrom. Cox.net at 4Mbps down and 512Kbps up.
mmione
Posts: 1814
Joined: Sat Dec 13, 2003 4:21 pm
Location: Ontario, Canada

Post by mmione »

TeenInternetAddict wrote:Mnosteele and Saboka32, I'm using a Dell Dimension 2350, 1.7GHz Intel Celeron, 768MB of PC2100 DDRAM, Windows XP Home Edition, 80gig hard drive with 2MB cache (going to upgrade the hard drive in eight months), etc. My Dell machine runs very fast on the Net and programs open up very fast. I do take very good care of my PC by running spyware and virus applications, run defragmenter and checkdisk every two or three months when the apps starting
to take forever to load, etc. People nowadays are mostly idiots that don't know a thing about PCs (since PCs and Windows XP are easier to use) they are the ones that blame Dell when they mess up their PCs. Listen, it's not Dell's fault that the people let their PC go to all heck by having 7000+ spyware and malware, 1000+ viruses and trojans, etc.
your the one that bought a celeron processor!
.
User avatar
TeenInternetAddict
Regular Member
Posts: 245
Joined: Sat Nov 25, 2000 12:00 am
Location: Topeka, Kansas

Post by TeenInternetAddict »

LOL :) I find out from reading Dell Support forum two or three days ago that I could upgrade the 1.7 GHz Intel Celeron processor
to a 2.8GHz Pentium 4 with 512K RAM cache. A P4 will be way better and faster than an Intel Celeron processor is. By going to PowerLeap which does have upgrades to make your computer runs faster, it's going to cost me
$190 and that don't include the price of having a local computer shop install the CPU for me. I am going to upgrade the CPU next year since this Celeron CPU is too slow. My Dell mobo takes both Celeron and P4 processors. I didn't choose this slow Intel Celeron CPU, the place that I got the computer from did that. I would have choose a Pentium 4 CPU.
Computer specs:

Dell Dimension 2350 with a 1.7Ghz Intel Celeron Proccesor, Windows XP Home Edition, 80 Gig hard drive, 768Mb of DDRAM PC2100, CDRW and cdrom. Cox.net at 4Mbps down and 512Kbps up.
lewengel

Virus Etc

Post by lewengel »

TeenInternetAddict wrote:Mnosteele and Saboka32, I'm using a Dell Dimension 2350, 1.7GHz Intel Celeron, 768MB of PC2100 DDRAM, Windows XP Home Edition, 80gig hard drive with 2MB cache (going to upgrade the hard drive in eight months), etc. My Dell machine runs very fast on the Net and programs open up very fast. I do take very good care of my PC by running spyware and virus applications, run defragmenter and checkdisk every two or three months when the apps starting
to take forever to load, etc. People nowadays are mostly idiots that don't know a thing about PCs (since PCs and Windows XP are easier to use) they are the ones that blame Dell when they mess up their PCs. Listen, it's not Dell's fault that the people let their PC go to all heck by having 7000+ spyware and malware, 1000+ viruses and trojans, etc.
As long as people (like a close friend of mine) have the attitude "why should I have to worry about this? Isn't the computer supposed to protect me?" all of this junk will continue to spread and there will be more and more zombie machines.

Lewis :cry:
Post Reply