PC Review


Reply
 
 
RB
Guest
Posts: n/a
 
      18th Dec 2003
http://wired.com/news/technology/0,1...=wn_techhead_5

Check out the above report. It's something that should be of concern to
those of us who run either cable or DSL.

The questions left hanging by the article are:

1. How does one tell if his pc has this going on?

2. What the heck do you do about it if you think your pc may be infected?

Anyone have answers to these questions?


 
Reply With Quote
 
 
 
 
Chris Norton
Guest
Posts: n/a
 
      18th Dec 2003
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> 1. How does one tell if his pc has this going on?


If your internet connection all of a sudden seems to be always in use
even when you are not using it.
This could be a sign that someone or something is using your computer
as a "host" for something.

> 2. What the heck do you do about it if you think your pc may be
> infected?


Press ctrl+alt+del and look at the current programs running. look for
something out of the ordinary.
If you are using Windows XP the following are normal XP run programs:
services.exe, spoolsv.exe sbchost.exe
taskmgr.exe, winlogon.exe are all normal XP processes. If you have a
program running that you did not start
or do not know about simply goto start > search and look for the .exe
file and see where they are located

Keep up to date with anti-virus software DAT files and check your
system once a week. Don't open email
attachments unless you scan them for viruses first but even then be
careful. I am sure someone else can give
you even more tips.

Chris Norton

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com>

iQA+AwUBP+HqWOr4xSt9KmOhEQIeQQCbBAvrg17X+i5BBEg2taYytHiQLt8Al2VX
/jChw82F9FWw1MtEu7NtBGk=
=BWwy
-----END PGP SIGNATURE-----


 
Reply With Quote
 
 
 
 
null@zilch.com
Guest
Posts: n/a
 
      18th Dec 2003
On Thu, 18 Dec 2003 09:44:01 -0600, "RB" <(E-Mail Removed)>
wrote:

>http://wired.com/news/technology/0,1...=wn_techhead_5
>
>Check out the above report. It's something that should be of concern to
>those of us who run either cable or DSL.


Or dialup or whatever.

>The questions left hanging by the article are:
>
>1. How does one tell if his pc has this going on?


The usual way is to use a good antivirus scanner. There are other more
general ways to detect many backdoors and internet worms.

>2. What the heck do you do about it if you think your pc may be infected?


Eradicate the malicious code.

>Anyone have answers to these questions?


Why are you fussing over this article in particular? Backdoors and
internet worms have been around for quite some time now.


Art
http://www.epix.net/~artnpeg
 
Reply With Quote
 
Chris Norton
Guest
Posts: n/a
 
      18th Dec 2003
that should be svchost.exe not sb. sorry about that.


--
Chris Norton
cooljay16 at bellsouth dotgoeshere net


 
Reply With Quote
 
RB
Guest
Posts: n/a
 
      18th Dec 2003
}}} Why are you fussing over this article in particular? Backdoors and
internet worms have been around for quite some time now. {{{

Sorry 'bout that. The way I read the threat in the article it comes at me
as if it's something recent. If what is being written about in the article
are plain old worms or backdoors, then yes, those are "old business", and
that fits in with your stating the fix is an a/v program.

However, note the phrase in the article "within the last six months", and
the dateline of Dec 3. That leads me to believe what the author is
addressing IS a new threat.


 
Reply With Quote
 
null@zilch.com
Guest
Posts: n/a
 
      18th Dec 2003
On Thu, 18 Dec 2003 12:52:23 -0600, "RB" <(E-Mail Removed)>
wrote:

>}}} Why are you fussing over this article in particular? Backdoors and
>internet worms have been around for quite some time now. {{{
>
>Sorry 'bout that. The way I read the threat in the article it comes at me
>as if it's something recent. If what is being written about in the article
>are plain old worms or backdoors, then yes, those are "old business", and
>that fits in with your stating the fix is an a/v program.
>
>However, note the phrase in the article "within the last six months", and
>the dateline of Dec 3. That leads me to believe what the author is
>addressing IS a new threat.


The only thing new that the article points out is the depth to which
spamming has sunk


Art
http://www.epix.net/~artnpeg
 
Reply With Quote
 
David W. Hodgins
Guest
Posts: n/a
 
      18th Dec 2003
On Thu, 18 Dec 2003 12:52:23 -0600, "RB" <(E-Mail Removed)> wrote:

>However, note the phrase in the article "within the last six months", and
>the dateline of Dec 3. That leads me to believe what the author is
>addressing IS a new threat.


Six months is a very long time in the development of malware and
anti malware.

The author is probably referring to the release of the sobig virus,
and many since then, that appear to have been written for big time
spammers.

Regards, Dave Hodgins
--
Change nomail.afraid.org to rogers.com to reply by email.
(nomail.afraid.org has been set up specfically for
use in usenet. Feel free to use it yourself.)
 
Reply With Quote
 
Gabriele Neukam
Guest
Posts: n/a
 
      18th Dec 2003
On that special day, RB, ((E-Mail Removed)) said...

> http://wired.com/news/technology/0,1...=wn_techhead_5
>
> Check out the above report. It's something that should be of concern to
> those of us who run either cable or DSL.


I've seen it for *months*, spam mail sent to me from such zombies.

Read
http://www.lurhq.com/sobig-f.html
http://www.securityfocus.com/news/4217
http://www.kaspersky.com/news.html?id=982906

to understand what's going on.


> The questions left hanging by the article are:
>
> 1. How does one tell if his pc has this going on?


Your ISP will tell you that your machine is spewing. The ISP is told by
some aggravated recipients of the spam, like me.

> 2. What the heck do you do about it if you think your pc may be infected?


Format all partitions.
Re-install
Apply all patches, especially those regarding internet security
DUMP that goddamn security lacking barndoor "Internet Explorer and
Outlook Express", use Mozilla or its derivatives instead


Gabriele Neukam

(E-Mail Removed)


--
Ah, Information. A good, too valuable theses days, to give it away, just
so, at no cost.
 
Reply With Quote
 
Dirk
Guest
Posts: n/a
 
      19th Dec 2003

"RB" <(E-Mail Removed)> schreef in bericht
news:%RjEb.17235$(E-Mail Removed)...
> http://wired.com/news/technology/0,1...=wn_techhead_5
>
> Check out the above report. It's something that should be of concern to
> those of us who run either cable or DSL.
>
> The questions left hanging by the article are:
>
> 1. How does one tell if his pc has this going on?
>
> 2. What the heck do you do about it if you think your pc may be infected?
>
> Anyone have answers to these questions?


What is new about this? Nothing to my knowneldge.


 
Reply With Quote
 
mzlindyone@aol.comx
Guest
Posts: n/a
 
      19th Dec 2003
On Thu, 18 Dec 2003 12:52:23 -0600, "RB" <(E-Mail Removed)>
wrote in alt.comp.anti-virus:

>However, note the phrase in the article "within the last six months", and
>the dateline of Dec 3. That leads me to believe what the author is
>addressing IS a new threat.



I think a couple of the issues they bring up are cause for concern if
not alarm, given that "AV on every PC" is a worthy but probably not
achievable goal (nevermind more technically detailed education), and
these and worse are likely to continue.

"British police recently warned that crime syndicates, many in Eastern
Europe, are using denial-of-service attacks to blackmail businesses,
threatening to knock them offline unless they pay a small fee."

Seems a decent enough description of a virtual protection racket.

However I think Eastern European crime sydicates have little to do
with the Mimail worm being used to DoS major spam blocklist
maintainers like monkeys.com, which was shut down by the attacks, and
spamhaus.org, which survives. I don't think there was any blackmail
involved there - spammers just wanted them offline, period.

This isn't some cracker managing to grab some idiot's Visa number
because they were stupid enough to run that interesting looking file
that came in e-mail, nor is even some spammer finding or installing a
proxy or relay by the same means -- this article is talking about
*organized crime*, and no amount of knowledge on the victim's end
could stop it. At the moment only massive available bandwidth works.

Carol

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Zombie PPP adapter - help! Bill Cohagan Windows XP Help 0 30th Jul 2004 04:34 PM
Zombie PPP adapter - help! Bill Cohagan Windows XP General 6 30th Jul 2004 09:14 AM
V1@Gra spam zombie John L. Windows XP Help 1 6th Jun 2004 02:36 PM
V1@Gra spam zombie John L. Windows XP Help 0 6th Jun 2004 02:11 PM
Outlook zombie Proccess Aaron Lewis Microsoft Outlook 0 10th Nov 2003 08:03 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 03:04 AM.