Working on a computer that set a new record for ad/spy/malware

General Network security, firewalls, port filtering/forwarding, wireless security, anti-spyware, as well as spam control and privacy discussions.
Post Reply
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Working on a computer that set a new record for ad/spy/malware

Post by YeOldeStonecat »

Get a call from an old client, kid came home from college with computer "running slow"

His older sister who knows something about computers gave up working on it...and the mom called me.

So plug it in, boot up, 2 year old Dell Dimension 8200 with a P4, WinXPp. Yup...running painfully slow soon as desktop draws in.

Shortly after, desktop goes active, and VirginsLovers pages start launching everywhere. Tons of porn popups.

Look at Run in registry...wow, chock full of nuts.

Antivirus subscription expired over a year ago

Off to antivirus.com for quick online scan,
troj.revop.f
troj.winfavs.a
troj.agent.l
java.bytever.a
troj.mscache.a
bkdr.thunk.e
troj.agent.r
bkdr.jeemp.a
troj.golid.a
troj.small.ez
troj.small.eu
troj.banker.af
troj.startpag.eg
troj.small.li
troj.dyfuca.m
troj.agent.ea

Also caught eye of New.Net and Search Enhancement

Now for the crazy part.....go get AdWare, update it, and scan....

1,182 suckers found!!! :eek:

Oh boy is this one gonna be fun!
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
mnosteele52
Posts: 11913
Joined: Tue Jul 24, 2001 12:00 pm
Location: Chesapeake, VA

Post by mnosteele52 »

LOL I know what you will be doing for the rest of the evening. :nod:
mmione
Posts: 1814
Joined: Sat Dec 13, 2003 4:21 pm
Location: Ontario, Canada

Post by mmione »

LOL. Good luck, I cleaned up my cousins computer, not as bad. Had 560 found in Ad-aware and 3 trojans. I hope all goes well.
.
CableDude
SG VIP
Posts: 26801
Joined: Sat Jun 02, 2001 12:00 pm

Post by CableDude »

Amazing. :eek:
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

mnosteele52 wrote:LOL I know what you will be doing for the rest of the evening. :nod:
:rotfl: Initially I just want to save a weeks time and format C.....but man...over a thousand problems from AdAware alone! Not to mention I haven't even run SpyBot, or Hijackthis, or any other AV app yet.

It's like a challenge I can't resist even though I'll be losing a lot of billable hours this week if I tinker with this thing.

And at least that one pr0n popup has some quality pics! :D
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
mnosteele52
Posts: 11913
Joined: Tue Jul 24, 2001 12:00 pm
Location: Chesapeake, VA

Post by mnosteele52 »

I know what you mean, sometimes I like the challenge plus it's a learning experience, then other times it's easier just to Format C:\

:thumb:
CableDude
SG VIP
Posts: 26801
Joined: Sat Jun 02, 2001 12:00 pm

Post by CableDude »

I'll be winders wasn't updated as well. :)
User avatar
Jstyr
Senior Member
Posts: 2822
Joined: Wed Nov 14, 2001 5:04 pm
Location: The Swamp

Post by Jstyr »

YeOldeStonecat wrote:1,182 suckers found!!! :eek:

Oh boy is this one gonna be fun!
Damn!! I'm surprised you were even able to install and run Ad-aware with that much garbage.

You should just bill him for that job :rotfl:
spec-
Rig #1- AMD XP 2400+, A-Bit KR7A/266, Gainward Geforce3 ti200 64mb Golden Sample, 1GB Crucial DDR, 40 gig WD HDD (7200), XP PRO, Vantec Stealth 420 PSU, Soundblaster Live 5.1
Rig #2- P4 2.4c, Abit IC7 800 FSB /w onboard sound, Radeon 9700 Pro 128, 1 Gig Corsair 3200 XMS, Dual (SATA) 36GB WD Raptor's in RAID 0, XP Pro, Antec Truepower 400
Rig #3-AMD Barton 2500+, Albatron KX600 (via), 1 gig Corsair 3200, Radeon 9600 Pro 128, Seagate 80 gig HD, Antec Truepower 400
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

mnosteele52 wrote:I know what you mean, sometimes I like the challenge plus it's a learning experience, then other times it's easier just to Format C:\

:thumb:
Anymore with that many items, I don't consider it a challenge nor educational. I call that a migraine and frustration. :thumb:
User avatar
mnosteele52
Posts: 11913
Joined: Tue Jul 24, 2001 12:00 pm
Location: Chesapeake, VA

Post by mnosteele52 »

blebs99 wrote:Anymore with that many items, I don't consider it a challenge nor educational. I call that a migraine and frustration. :thumb:
I've seen over 4,500 items with Ad-aware alone before. :eek:

When I have the time I don't mind sitting down and figuring out how to remove and fix things so that when I come across the same thing again I know exactly what to do. It's just that all of this spyware/malware evolves so much daily that it's hard to completely keep up with things, thank goodness for these forums.

:thumb: :)
User avatar
Debbie
Posts: 18148
Joined: Sun Sep 08, 2002 12:00 pm
Location: New Rochelle, New York

Post by Debbie »

YeOldeStonecat wrote:Get a call from an old client, kid came home from college with computer "running slow"

His older sister who knows something about computers gave up working on it...and the mom called me.

So plug it in, boot up, 2 year old Dell Dimension 8200 with a P4, WinXPp. Yup...running painfully slow soon as desktop draws in.

Shortly after, desktop goes active, and VirginsLovers pages start launching everywhere. Tons of porn popups.

Look at Run in registry...wow, chock full of nuts.

Antivirus subscription expired over a year ago

Off to antivirus.com for quick online scan,
troj.revop.f
troj.winfavs.a
troj.agent.l
java.bytever.a
troj.mscache.a
bkdr.thunk.e
troj.agent.r
bkdr.jeemp.a
troj.golid.a
troj.small.ez
troj.small.eu
troj.banker.af
troj.startpag.eg
troj.small.li
troj.dyfuca.m
troj.agent.ea

Also caught eye of New.Net and Search Enhancement

Now for the crazy part.....go get AdWare, update it, and scan....

1,182 suckers found!!! :eek:

Oh boy is this one gonna be fun!
Yep. I sent my sis the links for spybot and adaware. She had one of those fake spyware proggys.

The day before yesterday, she ended up with a sasser worm. She managed to get the removal tool and get rid of it. I told her I would do some serious maintenance on her system this weekend.
User avatar
Shinobi
Senior Member
Posts: 4455
Joined: Sat Jan 06, 2001 12:00 am
Location: South Carolina

Post by Shinobi »

YOSC:
Oh boy is this one gonna be fun!


Once my Dad wanted my help in building a sheet metal type shed out in the backyard. This kit had over a 1000 pieces to it,
and it was late afternoon, and almost raining.

He read the first line of the instructions.
"Start early in the day...." :D

After 10 years later, I've used that saying, to many people... and even myself... in regards to any computer troubleshooting / fixing.

"Start early in the day" YOSC. :nod: :thumb:

Be Happy Today,
Shinobi - Currently in CT.
_______________________________________________
Vendor neutral certified in IT Project Management, IT Security, Cisco Networking, Cisco Security, Wide Area Networks, IPv6, IT Hardware, Unix, Linux, and Windows server administration
[SIGPIC][/SIGPIC] :thumb:
User avatar
W_I_Z_K_I_D
Regular Member
Posts: 363
Joined: Sun Jun 10, 2001 9:33 am
Location: !!!Your Computer-You Just Dont Know It YeT!!!

Post by W_I_Z_K_I_D »

Man how many times do people have to say it , those porn sites are filled with spyware , trogans , worms , bad coockies and mutch mutch more.
Any SECURITY CONSIOUS PERSON would know to stay clear of them.
Im a man , i know its hard :cry: LOL but think of the safety and respect for your PC :thumb:
!!!What Man Can Make
Man Can Brake!!! :irate:

Windows XP ( Service Pack 2 )
Pentium 4 (3) GHz
2.00 GB of RAM

** Zone Allarm Pro
** AVG Anti Virus
** Cookie Wall
** Pop Up Stopper
** Spy Bot
** Spy Ware Blasster
** Add Aware se Pro
** Ccleaner
** Clean Up
** Port Bloacker
** Tweek UI WIn XP
** Port Scanner


Dialup 56k
DialUp-Syd.IPrimus....56k(Motorola internal Modem)
User avatar
greEd
Posts: 807
Joined: Wed May 09, 2001 12:00 am
Location: Maryland

Post by greEd »

W_I_Z_K_I_D wrote:Man how many times do people have to say it , those porn sites are filled with spyware , trogans , worms , bad coockies and mutch mutch more.
Any SECURITY CONSIOUS PERSON would know to stay clear of them.
Im a man , i know its hard :cry: LOL but think of the safety and respect for your PC :thumb:
There are safe/spyware free places to get free pr0n from ... thank god :thumb:
"I'm doing a (free) operating system (just a hobby, won't be big and professional...) for AT clones... It's not portable and it probably [won't ever] support anything other than AT hard disks, as thats all I have :-(." --Posted on Usenet August 1991 by Linus Trovalds
http://www.computerglitch.net
curiosity builds security | dd if=/dev/zero of=/dev/hda bs=512 count=100
EOF
User avatar
W_I_Z_K_I_D
Regular Member
Posts: 363
Joined: Sun Jun 10, 2001 9:33 am
Location: !!!Your Computer-You Just Dont Know It YeT!!!

Post by W_I_Z_K_I_D »

greEd wrote:There are safe/spyware free places to get free pr0n from ... thank god :thumb:
LoL greEd...Show me the way pal..~
Not litrally ofcoarse..LoL ;)
:irate:
!!!What Man Can Make
Man Can Brake!!! :irate:

Windows XP ( Service Pack 2 )
Pentium 4 (3) GHz
2.00 GB of RAM

** Zone Allarm Pro
** AVG Anti Virus
** Cookie Wall
** Pop Up Stopper
** Spy Bot
** Spy Ware Blasster
** Add Aware se Pro
** Ccleaner
** Clean Up
** Port Bloacker
** Tweek UI WIn XP
** Port Scanner


Dialup 56k
DialUp-Syd.IPrimus....56k(Motorola internal Modem)
mmione
Posts: 1814
Joined: Sat Dec 13, 2003 4:21 pm
Location: Ontario, Canada

Post by mmione »

Why dont you just get Pest Patrol and set Memory Check and COokiePatrol on and that should keep you safe :P
.
User avatar
AMPLIFRIER
Posts: 1641
Joined: Fri Jun 22, 2001 12:20 am
Location: 127.0.0.1

Post by AMPLIFRIER »

YeOldeStonecat wrote:Get a call from an old client, kid came home from college with computer "running slow"

His older sister who knows something about computers gave up working on it...and the mom called me.

So plug it in, boot up, 2 year old Dell Dimension 8200 with a P4, WinXPp. Yup...running painfully slow soon as desktop draws in.

Shortly after, desktop goes active, and VirginsLovers pages start launching everywhere. Tons of porn popups.

Look at Run in registry...wow, chock full of nuts.

Antivirus subscription expired over a year ago

Off to antivirus.com for quick online scan,
troj.revop.f
troj.winfavs.a
troj.agent.l
java.bytever.a
troj.mscache.a
bkdr.thunk.e
troj.agent.r
bkdr.jeemp.a
troj.golid.a
troj.small.ez
troj.small.eu
troj.banker.af
troj.startpag.eg
troj.small.li
troj.dyfuca.m
troj.agent.ea

Also caught eye of New.Net and Search Enhancement

Now for the crazy part.....go get AdWare, update it, and scan....

1,182 suckers found!!! :eek:

Oh boy is this one gonna be fun!
the guy i work with had a macine come in yesterday that had 2200 objects found in adaware.

untill then the worst one i had seen had like 1200 as well.



AMP
Gigabyte ga-7n400 pro nForce2 mobo, Athlon XP3200, thermalright slk900, 1 gig corsair pc3200 cas2, radeon 9800pro, SB Audigy 2 ZS
case= yeong yang YY-B0221 server cube,550 watt Antec true power,1 wd raptor 74 gig,1 34gig raptor (page) 2 wd 120gig se's raid 1, 1 120gig se. WIN xp Pro, Dual display samsung syncmaster 1100df 21in(Primary) Samsung syncmaster 955df 19in (secondary)".
User avatar
Sava700
Posts: 24051
Joined: Wed Feb 27, 2002 7:51 am
Location: Somewhere

Post by Sava700 »

8months ago.. Adaware check on moms new computer over 1500.. she couldn't get into her Email from the ISP she said it kept sticking at 1% (on 56k) also. I log in at home and download over 2400emails with various virus and crap to go along with it.. I spent 3 hours cleaning that computer. I then wrote down detailed instructions on what to run on a daily bases or at least once a week. Iput alot of stuff on auto update and run to save time.
But as these numbers are impressive others I'm sure will beat that out :nod:
User avatar
Roody
SG VIP
Posts: 30735
Joined: Sun Nov 19, 2000 12:00 am
Location: East Tennessee

Post by Roody »

800+ has been the most I found on one machine at my new job..needless to say it took awhile to get cleaned up. :)
rcnoweis
Member
Posts: 44
Joined: Wed Oct 01, 2003 9:54 pm

Post by rcnoweis »

Wow. How many spyware instances were Porn related?
nevermind, I already know

Has anyone figured out why Spy-Bot is free.
Come on, I am a nice guy too but Pete, you gots to draw the line
somewhere? You could have built the Spy Bot Mansion with spy gadgets and stuff.

Ok I am tired that was bad
User avatar
mnosteele52
Posts: 11913
Joined: Tue Jul 24, 2001 12:00 pm
Location: Chesapeake, VA

Post by mnosteele52 »

Just finished one that had almost 2,600 files infected with all the variants of the Netsky virus along with 4 other trojans and well over 1,500 pieces of spyware. The pc wouldn't even boot into XP, I had to remove the hard drive and put it in my pc (I have a slot in the front for this) to scan it just to get it to boot.

It was the worst I've seen, but it runs like a champ now.

:thumb:
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

Yeah NetSky has to be one of the most prolific viruses I've seen...that sucker went through the entire alphabet in its varieties.

Cleaned this machine up by the 2nd day. Hopefully they'll listen to my advice, get the kid a router when he goes back to the college dorm next year. Kids who plug into most college networks without a firewall are just asking for trouble. Plugging into a college network without antivirus, or in this case long outdated antivirus, plus zero windows updates...LOL. :nope:

The guy who lives next door to me is director of IT for a big college in my area. All students are now given antivirus, since they bought a site license for Symantec Corp Edition. The routers will not let the kids out to access the intranet/internet without passing the check for having this installed, and updated.
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
Roody
SG VIP
Posts: 30735
Joined: Sun Nov 19, 2000 12:00 am
Location: East Tennessee

Post by Roody »

Smart move by the Director of I.T. that is for sure.
CableDude
SG VIP
Posts: 26801
Joined: Sat Jun 02, 2001 12:00 pm

Post by CableDude »

Roody wrote:Smart move by the Director of I.T. that is for sure.

:nod:
Post Reply