IWETHEY v. 0.3.0 | TODO
1,095 registered users | 1 active user | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Folks, I need help....
Well, I finally decided to rid myself of the spyware/trojan/worm/whatever that I have had bottled up behind my McAfee firewall for the last so may months. So I triple-R'd my machine, reformatted the hard drive (the second "R"), and reinstalled Win2K, immediately followed with SP4 (which one of my colleagues at my former job downloaded from MSDN and burned onto CD for me). I then installed my modem software (which took about a half-day because Micros~1's installer insisted that I couldn't query the modem, even though as it turns out I can access it anyway).

Then I went looking for another firewall, as I didn't want to spend the time installing the entire all-but-useless McAfee AV suite just to get its firewall. So I went off to ZoneLabs to get the ZoneAlarm firewall. While there, I saw the blurb for a free spyware scan. Hmmm. I hadn't installed my rather outdated versions of AdAware SE or SpyBot S&D yet, and...well, it is ZoneLabs, after all, so how dangerous could it be? So I started the download. After about 15 seconds a message pops up stating that I have a "Netscape(Mozilla) browser" (actually firefox 1.0.1), and since the thing needs to download an ActiveX control, I need to use Insecure Exposer to get it. Damn! Well, it is ZoneLabs...how dangerous could it be? So, through clenched teeth I fired up IE and navigated to the ZoneLabs page, where I started the download.

Now I'm doing this over a 36.0K modem link, so I don't expect speed. But I'm watching the modem icon in the system tray and noticing a lot of traffic in both directions, but no activity on the screen. So I get impation, and kill everything, power down and then start up again. This time, I forego the spyware scan (I'll get it later), and simply go to download ZoneAlarm. Well, the download starts running...then starts walking...then slows to a crawl (<1.2MB/s), then stops altogether. No activity on the modem icon, and I cannot access IWETHEY. So, I hang up and try again.

During this connection, I notice a lot of activity when nothing is supposedly happening. Not good. So I fire up the modem status box and notice that I'm sending about 13K of stuff every second,a nd receiving somewhere about 1/2 to 3K in that same second. Furthermore, during the download, I'm registering 1K of data saved to my download file for every 12-15K of data actually downloaded. So, somehow, I've become a clearinghouse for somebody. Apparently, I've been zombied.

What I can't understand is, how is this happening? A "clean" reboot and rebuild, and net access through a dialup where I get a new IP address on each connection.

So, How do I fix this? I can't download anything because all the zombie traffic is clogging up may narrow pipe. My dated versions of AdAware and SpyBot S&D say I'm clean. I can't install AVG Antivirus because it requires Net access to get the serial number, and that's not happening. (This message is being posted through my wife's machine and was created offline because about halfway through the connection, I started noticing a bunch of unexplained traffic, to which I responded by summarily hosing the connection.

(I saw Grygus's thread about the "invisible" VX2, and will try to download the tools he suggests. And I will also put up the McAfee AV suite anyway just to get some form of firewall protection.)

Any ideas as to where to go from here?

thanx-
jb4
shrub\ufffdbish (Am., from shrub + rubbish, after the derisive name for America's 43 president; 2003) n. 1. a form of nonsensical political doubletalk wherein the speaker attempts to defend the indefensible by lying, obfuscation, or otherwise misstating the facts; GIBBERISH. 2. any of a collection of utterances from America's putative 43rd president. cf. BULLSHIT

New Are you sure the SP4 CD is OK?
I had to ask.

I'd recommend a [link|http://z.iwethey.org/forums/render/content/show?contentid=195304|hardware firewall]. It would save you a lot of grief in situations like this.

I don't know if you're infected yet. You might be getting hammered by folks looking to make your machine a zombie, but might not actually be infected yet. But it's hard to know. It doesn't sound right that you're sending out packets when you shouldn't be, but it might be something in Winders doing that.

I'd be suspicious about the system having trouble finding the modem early on. That might indicate that something is amiss.

Until you get a hardware firewall, I would suggest wiping your system again (using a known-good FDISK/format program) and getting a copy of MEPIS or some similar Linux live CD (from a friend perhaps?). Use it to download everything you need for Windows. Disconnect from the network, do a fresh install, and install all the patches and protections before you connect to the network.

[edit:] It's worse on the server side of Windows. [link|http://www.theregister.co.uk/2005/03/18/windows_server_firewall/|TheReg]. [/edit]

[edit2:] I finally remembered that you're on dial-up. It's difficult to use a hardware firewall with dial-up unless you get a box that works with an external modem. I have an old [link|http://froogle.google.com/froogle?q=DI-704p&btnG=Search+Froogle&scoring=p|DI-704p] (the brown model) that worked well for me for that purpose when coupled with an external USR V.90 voice faxmodem. I see the DI-704p can be had for $20 at various stores, and as little as about $3 on eBay (but be careful - it looks like the newer silver models don't have a serial connection). An external V.90 modem can be had for $10-$20 or less on eBay. You'd need a serial cable between the modem and the DI-704p, and a CAT-5 cable between your PC and the DI-704P. More on the wiring is [link|http://z.iwethey.org/forums/render/content/show?contentid=50525|here].

If you're interested, I might be prepared to part with my stuff. :-) [/edit2]

HTH. Luck!

Cheers,
Scott.
Expand Edited by Another Scott March 18, 2005, 05:24:39 PM EST
Expand Edited by Another Scott March 18, 2005, 09:48:11 PM EST
New Seems to be...
...the latest AVG Antivirus didn't have any truck with it.

I will be going to a Broadband connection soon, and will need to network my two machines together to have access to it. I haven't done any research on it yet (CDW is my friend), but I believe that a Linksys or similar broadband wireless modem should do the trick; according to our cable carrier (Comcast, of course), that's what they use, and the model that they use is supposed to contain a firewall of some sort (naturally, the sales lady, while very nice, didn't have a clue about what model that was....)
jb4
shrub\ufffdbish (Am., from shrub + rubbish, after the derisive name for America's 43 president; 2003) n. 1. a form of nonsensical political doubletalk wherein the speaker attempts to defend the indefensible by lying, obfuscation, or otherwise misstating the facts; GIBBERISH. 2. any of a collection of utterances from America's putative 43rd president. cf. BULLSHIT

New All right...got it!
The latest upgrade of AVG Free found the bastard! "Trojan Horse IRC/Back Door.SdBot.145.0". Actually, both my machines had it on it, as well as a number of Alexa probes. But the thing didn't appear to have my slower machine as badly tied up, so I was able to get the AVG Free (7.0x) download and its latest virus definition downloaded; it was that latest virus definition that found it. (Running AVG Free 7.0 w/o the latest definitions didn't find it...)

Anyway, both PCs are surrounded by ZoneAlarm, and have latest AVG Free, SpyBot and AdAware running. Damn! Grygus is right...if this is what it takes to keep your machine "safe" running (if that's the correct term) Windozw connected to the net, then his timeline for making the entire net useless is right on schedule!

And in answer to Another Scott who posited whether the SP$ disk was OK...it did pass inspection. However, consider this: On my "slow" (read: older PII 400MHz) machine, I wiped the disk, then loaded SP4, then ZoneAlarm, then updated it to its latest version while running its "older" self, then installed SpyBot, updated it to its latest version, then ran it...and it found Alexa. Is Micros~1 shipping Alexa with its software? Andrew?
jb4
shrub\ufffdbish (Am., from shrub + rubbish, after the derisive name for America's 43 president; 2003) n. 1. a form of nonsensical political doubletalk wherein the speaker attempts to defend the indefensible by lying, obfuscation, or otherwise misstating the facts; GIBBERISH. 2. any of a collection of utterances from America's putative 43rd president. cf. BULLSHIT

New Alexa shipping with windows? Yes.
It's the "related links" foofaraw in tools/related links. If you use that, IE will contact Alexa servers. There is a registry entry in brand spanking new installs that allows for this. Thus, Alexa does indeed ship with Windows.
-----------------------------------------
"In this world of sin and sorrow there is always something to be thankful for. As for me, I rejoice that I am not a Republican."
-- H. L. Mencken

Support our troops, Impeach Bush.
D. D. Richards
New Yeah, but it makes a good test . .
. . to prove your spyware program is actually working and hasn't been disabled by something. Even a SP will usually put Alexa back on.
[link|http://www.aaxnet.com|AAx]
     Folks, I need help.... - (jb4) - (5)
         Are you sure the SP4 CD is OK? - (Another Scott) - (1)
             Seems to be... - (jb4)
         All right...got it! - (jb4) - (2)
             Alexa shipping with windows? Yes. - (Silverlock)
             Yeah, but it makes a good test . . - (Andrew Grygus)

Yeah, would be nice if "despair" wasn't such an appropriate word choice.
87 ms