Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Instant viruses via BTBroadband

Thread Tools
 
Search this Thread
 
Old 09 February 2004, 08:54 PM
  #1  
dba
Scooby Regular
Thread Starter
 
dba's Avatar
 
Join Date: May 2001
Posts: 2,214
Likes: 0
Received 0 Likes on 0 Posts
Default Instant viruses via BTBroadband

I got some viruses somehow,they came in after an XP fresh install before i had installed an AV,i went for the security patches first thinking i wont get viruses so quickly,so is used Stinger and then switched to McAfee.

I got Blaster,Nachi,Lovsan and SVChost

Then I made the same mistake with my sons PC when loading XP

basically,i assume they are coming in via the hole that the Blaster patch shuts down,but how am i getting them so quickly,literally minutes within first connecting to the web?

are they just scanning for open ports without the Windows patch and downloading them? and how are they doing this via BT?

I have no end of hassle,but in future i will load a firewall first,then go to Windows update

Last edited by dba; 09 February 2004 at 08:55 PM.
Old 09 February 2004, 09:51 PM
  #2  
john_s
Scooby Regular
iTrader: (1)
 
john_s's Avatar
 
Join Date: Dec 2002
Location: Preston, Lancs.
Posts: 2,977
Likes: 0
Received 0 Likes on 0 Posts
Default

Not sure about the rest, bu blaster certainly scans for open ports.

You could download the patch that srt out the hole that blaster exploits and keep it on a floppy to install it before going online with a fresh intall.

John.
Old 09 February 2004, 09:52 PM
  #3  
dba
Scooby Regular
Thread Starter
 
dba's Avatar
 
Join Date: May 2001
Posts: 2,214
Likes: 0
Received 0 Likes on 0 Posts
Default

yeah,i have done that now,after bitter experience,i just cant believe it happened twice that quickly
these scans must be on all the time
Old 09 February 2004, 10:12 PM
  #4  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

and how are they doing this via BT?
Just means there's a number of infected PCs on the BT Broadband network and you get hit straight away.

Service Pack 2 for XP improves the firewall drastically in a number of ways.
Old 09 February 2004, 11:14 PM
  #5  
dba
Scooby Regular
Thread Starter
 
dba's Avatar
 
Join Date: May 2001
Posts: 2,214
Likes: 0
Received 0 Likes on 0 Posts
Default

i havent seen a service pack 2,is that coming to the update page soon?
Old 10 February 2004, 07:00 AM
  #6  
RichiW
Scooby Regular
 
RichiW's Avatar
 
Join Date: Jul 2001
Posts: 1,416
Likes: 0
Received 0 Likes on 0 Posts
Default

I did the same with my m8's machine, went online and installed the updates before installing AV/ firewall ... got a virus within minutes, couldn't believe it!!



Live and learn i guess
Old 10 February 2004, 07:48 AM
  #7  
elgordano
Scooby Regular
 
elgordano's Avatar
 
Join Date: Jan 2002
Location: Herts
Posts: 1,125
Likes: 0
Received 0 Likes on 0 Posts
Wink

you should do the fresh install off the network so that when you conenct you have a/v and firewall already in place.

Gordo
Old 10 February 2004, 08:39 AM
  #8  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

MS should be releasing SP2 for Windows XP first half of this year.

It also brings pop-up ad blocking to Internet Explorer.

Once it's out, you'll see it listed in Windows Update. Any copies floating around the 'Net now will be betas and previews, so I'd avoid them.
Old 10 February 2004, 11:20 AM
  #9  
Jiggerypokery
Scooby Regular
 
Jiggerypokery's Avatar
 
Join Date: Apr 2003
Location: Location: Location:
Posts: 1,097
Likes: 0
Received 0 Likes on 0 Posts
Default

"I got Blaster,Nachi,Lovsan and SVChost"

Me too (on BT)! Fresh install of XP on Sunday, connected to the internet and literally watched the suspicious .exe's adding to the process list and registry. I think McAfee had difficulty cleaning SVChost as the machine was rebooting regularly with SVChost errors until all updates were installed.
Old 10 February 2004, 01:40 PM
  #10  
200+Bhp
Scooby Regular
 
200+Bhp's Avatar
 
Join Date: Apr 2003
Location: A Bar Near You !
Posts: 416
Likes: 0
Received 0 Likes on 0 Posts
Question

"I got Blaster,Nachi,Lovsan and SVChost"
Is svchost.exe a virus for definate, I thought it was a service within WinXP

How did you guys scan for these I run Norton right up to date with definations etc. and it doesnt pick anything up
Old 10 February 2004, 02:36 PM
  #11  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

svchost.exe is not a virus, but as an executable file is open to infection by a virus.
Old 10 February 2004, 02:43 PM
  #12  
Markus
Scooby Regular
 
Markus's Avatar
 
Join Date: Mar 1999
Location: The Great White North
Posts: 25,080
Likes: 0
Received 0 Likes on 0 Posts
Default

Blaster is evil! getting it within seconds of putting a machine on the internet is not uncommon, we had the same problem here, brand new machine, hooked it up to net (outside our firewall, just to see what happened) wham, 5 seconds after plugging the Cat 5 cable in, Norton picked up a Blaster attack.
Old 10 February 2004, 04:14 PM
  #13  
R1916v
Scooby Regular
 
R1916v's Avatar
 
Join Date: May 2002
Posts: 1,002
Likes: 0
Received 0 Likes on 0 Posts
Default

And the moral here is put your AV and patches on before connecting to the net

Make sure you download all the hotfixes etc for these before you format, store them on another partition or something.
Old 10 February 2004, 07:40 PM
  #14  
i8gtmf
Scooby Regular
 
i8gtmf's Avatar
 
Join Date: Jul 2003
Location: Sunny Derbyshire
Posts: 910
Likes: 0
Received 0 Likes on 0 Posts
Default

I had exactly the same fresh install of xp when straight to windows update, next thing i know is my pc is shutting down and iv'e got W32.Welchia.Worm and that svchost.
The svchost was going nuts trying to connect to the internet and kept creating a file called .Daz which came back everytime i deleted it.When i opened the .Daz file in notepad al i could make out amongst the gibberish was "user exceeded bandwidth"
When i deleted svchost everything sorted
Old 10 February 2004, 07:57 PM
  #15  
scottywrx
Scooby Regular
 
scottywrx's Avatar
 
Join Date: Feb 2002
Location: MK
Posts: 387
Likes: 0
Received 0 Likes on 0 Posts
Default

As Gordon said ...

Never Never Never connect your pc unpatched to the internet . It does not matter if its BTBroadBand or whatever ...
the blaster variants are out there just waiting for their victims ...

Ask a m8 to download the patches and get anti-v & firewall installed before you consider plugging into the wild wild internet !! ...
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Wingnuttzz
Member's Gallery
30
26 April 2022 11:15 PM
Mister:E
Subaru Parts
2
24 September 2015 01:37 PM
BUDA
ScoobyNet General
29
01 June 2001 05:33 PM
a2jcy
ScoobyNet General
3
30 May 2001 12:38 PM
Big RS Dave
ScoobyNet General
5
14 April 2001 08:12 PM



Quick Reply: Instant viruses via BTBroadband



All times are GMT +1. The time now is 05:54 PM.