Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

UDP datagram trying to be sent?, Unwise problem

Thread Tools
 
Search this Thread
 
Old 08 March 2003, 11:39 AM
  #1  
Jeff Wiltshire
Scooby Regular
Thread Starter
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

You've got a Trojan

Have a look here

http://securityresponse.symantec.com...nettrojan.html
Old 08 March 2003, 07:56 PM
  #2  
jameswrx
Scooby Regular
iTrader: (4)
 
jameswrx's Avatar
 
Join Date: Sep 2002
Location: Kent
Posts: 6,535
Received 40 Likes on 27 Posts
Post

Thanks for that.

Just downloaded a virus checker, found BugBear.A on my computer, done a search for it, something to do with emails and controlling my printer. Also downloaded a special BugBear remover and all seems to be successful.

But I still have Unwise problem that only allows me to fully start windows xp only when I have moved 3 processes for Unwise.exe from the task manager.

Any ideas?
Old 08 March 2003, 08:48 PM
  #3  
Jeff Wiltshire
Scooby Regular
Thread Starter
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

You still have the Trojan......You need to follow the removal process on that link. Bugbear will not do what your experiencing.
Old 08 March 2003, 09:10 PM
  #4  
jameswrx
Scooby Regular
iTrader: (4)
 
jameswrx's Avatar
 
Join Date: Sep 2002
Location: Kent
Posts: 6,535
Received 40 Likes on 27 Posts
Post

I done a full system scan (all files) but nothing was discovered about the trojan files
Old 08 March 2003, 09:28 PM
  #5  
Jeff Wiltshire
Scooby Regular
Thread Starter
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Look at the removal procedure regarding the registry settings (ie all the info about RunOnce & Unwise.exe).

Check that your machine does not have these settings.

and so on.

Which Virus checker to you get ??? Has it got the latest definition file ???


3. Deleting the value from the registry

CAUTION: Symantec strongly recommends that you back up the registry before you make any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

a. Click Start, and then click Run. (The Run dialog box appears.)
b. Type regedit, and then click OK. (The Registry Editor opens.)
c. Navigate to each of these keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\RunOnce
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\RunServicesOnce

NOTE: All the keys do not exist on all the systems.

d. In the right pane, delete the value:

WinLoader %windir%\UNWISE.EXE

NOTE: This value may vary. Look for any value that refers to the files detected as Backdoor.NetTrojan.

e. Exit the Registry Editor.
Old 08 March 2003, 09:33 PM
  #6  
jameswrx
Scooby Regular
iTrader: (4)
 
jameswrx's Avatar
 
Join Date: Sep 2002
Location: Kent
Posts: 6,535
Received 40 Likes on 27 Posts
Post

I tried deleting the winloader/unwise from the registry but I delete them in the order below

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\RunOnce
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\RunServicesOnce


and when I click back on the first one the winloader/unwise.exe is back as it is on all of them, I delete them and they come back.

I got something called Gladiator antivirus
Old 08 March 2003, 10:50 PM
  #7  
Jeff Wiltshire
Scooby Regular
Thread Starter
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

One or more of your files is infected ....

Try and get a version of Norton AV or Symantec which should find the relevant files. I've never heard of Gladiator
Old 08 March 2003, 10:58 PM
  #8  
jameswrx
Scooby Regular
iTrader: (4)
 
jameswrx's Avatar
 
Join Date: Sep 2002
Location: Kent
Posts: 6,535
Received 40 Likes on 27 Posts
Post

just got norton and it said like you did that a backdoor trojan was detected, said it can't repair and gave me a link to the page you did.

Trouble is norton didn't finish installing properly and something happened and every time I click on norton or my gladiator virus checkers i get an error pop up saying;

windows cannot access the specified device, path or file. You may not have the appropriate permission to access the item.
Old 09 March 2003, 06:11 AM
  #9  
Jeff Wiltshire
Scooby Regular
Thread Starter
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Which files did it say where infected ? You need to delete the ones that are infected.

I suggest that you uninstall both your AV products and then try and install Norton again.
Old 09 March 2003, 09:08 AM
  #10  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Talking

My bruv asked me to check out his pc last week, he'd been on ADSL for a week without a firewall
I think the ISP's should provide some basic firewall software as the majority of people don't have a clue what's going on with their PC's.

You should have seen the amount of connections established on his PC
It's tighter than a ducks ar5se now though
Old 09 March 2003, 10:45 AM
  #11  
Jeff Wiltshire
Scooby Regular
Thread Starter
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

People still think that Hackers/Script Kiddies etc will only go after large corporates....the reverse is true....I see upwards of 20 scans of my broadband connection per day.

If you have an always on connection get a firewall & Anti Virus software!

Simply really.

James

How far have you got with your machine ?
Old 09 March 2003, 10:52 AM
  #12  
jameswrx
Scooby Regular
iTrader: (4)
 
jameswrx's Avatar
 
Join Date: Sep 2002
Location: Kent
Posts: 6,535
Received 40 Likes on 27 Posts
Post

I wish I could uninstall both my av programs but when I click on control panel for example, a box with a red cross pops up saying 'cannot find C:\windows\etc\etc...' for whatever I click on, Norton, etc, can't even use the 'Run, regedit function.

Only the internet works!
Old 09 March 2003, 11:19 AM
  #13  
Jeff Wiltshire
Scooby Regular
Thread Starter
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Looks like the Trojan has completely trashed your PC......time for a re-install I'm afraid.
Old 09 March 2003, 11:40 AM
  #14  
jameswrx
Scooby Regular
iTrader: (4)
 
jameswrx's Avatar
 
Join Date: Sep 2002
Location: Kent
Posts: 6,535
Received 40 Likes on 27 Posts
Post

Yeah I think so!

Thanks for the help anyway
Old 03 August 2003, 10:45 AM
  #15  
jameswrx
Scooby Regular
iTrader: (4)
 
jameswrx's Avatar
 
Join Date: Sep 2002
Location: Kent
Posts: 6,535
Received 40 Likes on 27 Posts
Post

Someone from 218.74.45.187, port 1653 wants to send UDP datagram to port 1434 owned by 'UNWISE.EXE' on your computer

This is what keeps happening (shown up by my firewall.

I have real problems with Unwise??, every time I turn the computer on it wont load until you remove Unwise from the proccesses in the task manager 3 times!

What is it?, and as I say I get lots of requests from IP addresses either trying to get to Unwise or Unwise trying to send stuff out?

I put a new firewall on yesterday and it actually said that an IP wanted to contact Unwise as soon as Windows XP started loading.

Any ideas?



[Edited by jameswrx - 3/8/2003 10:52:05 AM]
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Abx
Subaru
22
09 January 2016 05:42 PM
PetrolHeadKid
Driving Dynamics
10
05 October 2015 05:19 PM
T.K
General Technical
10
02 October 2015 11:35 AM
the shreksta
Other Marques
26
01 October 2015 02:30 PM
minguela
Wheels And Tyres For Sale
0
29 September 2015 11:28 AM



Quick Reply: UDP datagram trying to be sent?, Unwise problem



All times are GMT +1. The time now is 08:06 AM.