Intrusion Attempt

jadinolf

Lifer
Oct 12, 1999
20,952
3
81
I'm on dialup and WinXP home.

Lately when I connect to my access number, NAV2005 pops up and tells me that a worm (Default Block Bla Trojan Horse) is stopped.

I'm just wondering, is some computer just lying in wait for us poor souls to long on?
 

aGreenAgent

Senior member
Apr 25, 2005
274
0
0
You probably have a trojan or worm on your computer, but without internet connectivity, it's not active. So when you connect to the internet, it activates. Get some nice antivirus program and get rid of it.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Sounds like what was happening with my little sister's computer. It inhaled some Trojans/Downloaders that NAV 2005 didn't recognize yet, and they'd keep trying to drag in ones that Norton did recognize. It had quarantined over 4800 of the ones that it did recognize, but was not hitting the root of the problem.

If it were me, I would vaporize the whole Windows installation, and start over and get stuff secure from the start this time around. But I'm just crazy like that :evil: If you don't want to do that just yet, try this real quick:

  1. back up any data you can't afford to lose
  2. Disable System Restore
  3. Download 30-day trial of Webroot SpySweeper, install & update it. Don't scan yet.
  4. Download free ZoneAlarm firewall software from http://www.zonelabs.com but don't install it yet.
  5. Uninstall Norton Antivirus 2005. After all of the Symantec/Norton software is removed, install ZoneAlarm to provide firewall protection. Don't let stuff connect that you don't know what it is, when ZoneAlarm prompts for decisions.
  6. Download 30-day trial of Kaspersky Antivirus Personal 5, install it, configure it like this and update it. You'll probably need a reboot to complete the installation. Don't scan yet.
  7. Download this text file and extract the files as shown, but don't scan yet.
  8. So now you are ready to drop the hammer on this stuff :evil: Restart in Safe Mode, run the McAfee command-line scanner, then scan with Kaspersky, then with SpySweeper.
  9. Restart in normal mode and scan again. Stuff still detected, or is it clean now?
  10. If it's clean, run Microsoft Baseline Security Analyzer and address all of the weaknesses it finds, particularly weak/blank passwords or open shares.
  11. If it's not clean, then I say Drop The Bomb On It? with a full reformat/reinstall, and take steps to secure it during and during the building process.
Hope that helps :)
 

jadinolf

Lifer
Oct 12, 1999
20,952
3
81
Originally posted by: mechBgon
Sounds like what was happening with my little sister's computer. It inhaled some Trojans/Downloaders that NAV 2005 didn't recognize yet, and they'd keep trying to drag in ones that Norton did recognize. It had quarantined over 4800 of the ones that it did recognize, but was not hitting the root of the problem.

If it were me, I would vaporize the whole Windows installation, and start over and get stuff secure from the start this time around. But I'm just crazy like that :evil: If you don't want to do that just yet, try this real quick:

  1. back up any data you can't afford to lose
  2. Disable System Restore
  3. Download 30-day trial of Webroot SpySweeper, install & update it. Don't scan yet.
  4. Download free ZoneAlarm firewall software from http://www.zonelabs.com but don't install it yet.
  5. Uninstall Norton Antivirus 2005. After all of the Symantec/Norton software is removed, install ZoneAlarm to provide firewall protection. Don't let stuff connect that you don't know what it is, when ZoneAlarm prompts for decisions.
  6. Download 30-day trial of Kaspersky Antivirus Personal 5, install it, configure it like this and update it. You'll probably need a reboot to complete the installation. Don't scan yet.
  7. Download this text file and extract the files as shown, but don't scan yet.
  8. So now you are ready to drop the hammer on this stuff :evil: Restart in Safe Mode, run the McAfee command-line scanner, then scan with Kaspersky, then with SpySweeper.
  9. Restart in normal mode and scan again. Stuff still detected, or is it clean now?
  10. If it's clean, run Microsoft Baseline Security Analyzer and address all of the weaknesses it finds, particularly weak/blank passwords or open shares.
  11. If it's not clean, then I say Drop The Bomb On It? with a full reformat/reinstall, and take steps to secure it during and during the building process.
Hope that helps :)

Sorry for the delay in getting back but I was installing and updating "The Cleaner" and "Trojan Remover". Ran scans and no active malicious files were found. I'll follow mechBgon's details and see what happens.

I really didn't think I had a problem. I just thought a trojan was trying to get into my system.

Thanks all
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Sorry for the delay in getting back but I was installing and updating "The Cleaner" and "Trojan Remover". Ran scans and no active malicious files were found. I'll follow mechBgon's details and see what happens.
What would those two be, exactly? There's plenty of bogus spyware-removal stuff out there, I hope you didn't just install and update two of them :)
 

jadinolf

Lifer
Oct 12, 1999
20,952
3
81
These are legit (pay for ) programs. Have never installed them before because I never had a reason to. If anyone knows different, let me know. Thanks.
 

montag451

Diamond Member
Dec 17, 2004
4,587
0
0
Could you post links to the progs you installed?

Otherwise, what Mech suggests is the way to go.
Also, add Trojanhunter [yummy slurp splat] to that.
 

montag451

Diamond Member
Dec 17, 2004
4,587
0
0
wow, never heard of those.

Try trojanhunter - that has picked up on lots that others have failed on.
www.trojanhunter.com/
Be sure to install it, update it, reboot into SAFE mode to run it. Very slow but should be worth it.
 

jadinolf

Lifer
Oct 12, 1999
20,952
3
81
Trojan Hunter results:

Registry scan
No suspicious entries found
Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan
No trojan files found

I'm going to relax.

Thanks all.

 

jadinolf

Lifer
Oct 12, 1999
20,952
3
81
Originally posted by: montag451
Just to make sure, could you post a HIJACKTHIS log

OK, will do.

The message was that Norton stopped the worm. I'm going to wear out my hard drive with all this scanning. :D