BetaONE will rise again!


Reply
  #1  
Old 22nd Mar 04, 08:54 PM
war59312 war59312 is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: U.S.A
Posts: 2,220
war59312 has disabled reputation
Send a message via ICQ to war59312 Send a message via AIM to war59312 Send a message via MSN to war59312 Send a message via Yahoo to war59312
Well I woke up this morning and checked my messages. And noticed my Internet connection was out.

And to my amazement I have 15 messages from Time Warner Cable, my ISP. Last time I heard from them was 6 months ago. So pretty odd. And 15 messages. I thought I was screwed for sure. Thank God that was not the case.

I called them back and I learned that my account had been shutdown due to their believe that a hacker had taken over my computers.

No way!!

Anyways I start checking on stuff and finally I realized that some damn virus got on my system. Turns out it was because my brother disabled the firewall and virus protection while playing a game. He was having problems for some reason. But he forgot to tell me and to turn them back on.

I was at a movie last night.

Well guess I can't trust him anymore. PW protected everything now.

Well it turns out the virus searched and destroyed all .txt, .exe, .zip, .rar, .mp3, .mpg, .avi, and all picture file types. So pretty much everything.

So not sure how but I don't care. Luckily I had just done a Norton Backup right before I left for the movie. I have now scanned everything and found nothing. So it must of got onto my system while I was gone some how. Pretty sure it was IRC as my brother was using it.

We share a wireless connection and he was downloading a lot of files last night. MP3 mostly.

Then I noticed this:



Very strange. Damn virus uploaded 132mb but downloaded almost 6gb in just under four hours.

Luckily I still had a logging program open and it looks like the virus was just waisting bandwidth, for the most part. As no other program attempted to use the Internet.

Though I did notice a few porn links and ip addresses. I bet it was downloading and forwarding porn to someone. Only 132mb though. And yea it seems to have only download about 300mb of porn according to the times in the log. The other bandwidth appears to have just been wasted. Just connecting to different ip address. Maybe trying to take down a website or network. Not sure. Since the ip addresses appear to be random with most being total guess work, meaning not even real ip address rages. Oh well don't really care now as everything is a ok.

Another reason I think someone found a back-door in IRC is because almost the entire log is filled with connections through port 6667 which is the standard IRC port. But still you could fake it so not sure. But pretty sure since it was indeed running last night. But it appears to just have waisted bandwidth, almost 500mb worth. Not sure though, maybe they were trying to download files off my hard drive though mirc. Appears they got nothing. And even if they did it would of all been junk anyways. As they only would of had access to my c drive were only system files are installed. All other drives are locked, password protected, and encrypted. So they got nothing, if they even tried. Appears they did not.

Well my ISP, RR, said it recorded everything and they think they know who it was. They said they had his/her ip address and that they are in the process of contacting their ISP.

No real damage has been done. They said they had shutdown my account just in case. Seeing as 6gb in 4 hours is a lot of bandwidth. Almost 10 times as much as I normally use each day. So they knew something was wrong. Just glad I don't have a bandwidth per. month or I would have been screwed.

And nothing has been damaged since I had a ghost backup. Thank God. Cause if not I would have had to go back a month and would of lost a ton of stuff.

Plus I keep no credit card numbers or anything on my computer. Not even word docs. or anything else considered private. So who ever it he/she was, was pretty damn stupid and picked a pretty bad target to mess with. Guess thats why he/she/they tried. In the end I win!!

But still its the worst virus/Trojan I've had on my system to date. And no I don't know what it was since it successfully killed my virus protection. Remember cause it was turned off so there was nothing to stop it from killing it. So I could not scan my computer with anything. Well yea I could of just reinstalled it but f it. I don't care. Just Glad its backup and running like it should be.

Guess me and my brother learned the hard way. I just cant believe he did that. Was pretty funny because he knows nothing about computers really, nothing more than what I've showed him. He always talked poopie about how secure and paranoid I am. Guess now he knows why. Well not really. Damn aol wannabe. haha He loves aol for some damn reason. He pays $10 a month for that poopie. Maybe that how all this poopie started. Leave it to AOL and everything is fed.

Well damn just glad everything is ok. Just thought I would let off some steam as I'm pretty damn pissed off at my brother. Fing retard. Just glad no real damage was done or he would be getting his donkey kicked.

Maybe I should f his computer up so he sees how it feels. Too late. lol

Its already screwed. Aol is everywhere. haha Damn sypware everyday. And virus every few weeks. Since he always stops the damn updater. Little female canine.

Will have to find a way so he cant stop it once it starts. Even if he restarts computer so it resumes agian. It takes three secs. Hes just fing retard.

He wont even let me touch the damn thing. Fing fag!!!! F him!!!!!! I hate him!!! Really I do. He's a 16 year spollied little brat. Cant wait to move out. Soon hopefully.

Well f it going to play some Urban Terror.

later,
Will
__________________
Ad Muncher Usage Statistics for v4.7 Build 27105/1624
Adverts removed by Ad Muncher: 1,601,933
Approximate bandwidth saved: 12,515 MB
Counter started: April 2, 2003

Download: http://war59312.admuncher.com/download.shtml
Reply With Quote
  #2  
Old 22nd Mar 04, 09:31 PM
Alpine's Avatar
Alpine Alpine is offline
Retired Crew
 
Join Date: Feb 2002
Location: Run Forest, RUN!!
Posts: 3,601
Alpine is on a distinguished road
Send a message via ICQ to Alpine Send a message via AIM to Alpine
Yeah . i have read something about a new virus!!

I have posted that here !!

_http://betaone.net/index.php?showtopic=30962__
Reply With Quote
  #3  
Old 22nd Mar 04, 10:01 PM
war59312 war59312 is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: U.S.A
Posts: 2,220
war59312 has disabled reputation
Send a message via ICQ to war59312 Send a message via AIM to war59312 Send a message via MSN to war59312 Send a message via Yahoo to war59312
Quote:
Originally posted by Alpine@Mar 22 2004, 03:31 PM
Yeah . i have read something about a new virus!!

I have posted that here !!

_http://betaone.net/index.php?showtopic=30962__
um wrong url there buddy.
__________________
Ad Muncher Usage Statistics for v4.7 Build 27105/1624
Adverts removed by Ad Muncher: 1,601,933
Approximate bandwidth saved: 12,515 MB
Counter started: April 2, 2003

Download: http://war59312.admuncher.com/download.shtml
Reply With Quote
  #4  
Old 22nd Mar 04, 10:03 PM
lickablepig lickablepig is offline
BetaONE Supporter
 
Join Date: Oct 2001
Location: PST -08:00
Posts: 261
lickablepig is an unknown quantity at this point
Quote:
Well I woke up this morning and checked my messages
Sorry to hear that, at least u had backed up recently... I was just reading this before logging on to B1 and seeing your post...

Quote:
A handful of Bagle worm variants are attacking Windows users with an insidious new twist:
They can infect computers without tricking them into opening a file attachment -- opening an e-mail is all it takes.

The passel of new worms sport a virtual alphabet soup of labels: "Bagle.q," "Bagle.r," "Bagle.s" and "Bagle.t." Some security firms have dubbed the new variants "beagle." They are mutations of the original Bagle worm first discovered in January.

Bagle exploits a flaw in Outlook, revealed in October of 2003, that allows a hacker to upload and execute a file on a user's PC without that user opening the file. Microsoft has issued a patch for the flaw in October, but users who have not updated their systems with this patch are at risk.


Two-Step Process
The e-mails carrying the new Bagle variants do not have attachments. Experts speculate that the virus writers developed this non-attachment technique to bypass a common firewall technique called "gateway scanning," which intercepts any e-mail with an attachment.
When a user open an e-mail carrying one of these new Bagle variants, the e-mail "goes back out to the Internet and tries to find a certain server that has the Bagle executable on it and bring it down through HTTP,"


First, the carrier e-mail connects though Port 81 to the host server, and opens up a maliciously coded HTML file. Then, a visual basic script (VBS) file is sent to the victim's machine, which connects to the same server and downloads the virus via HTTP.

"That shouldn't be allowed to happen,"  "Opening an e-mail doesn't give some remote machine the authority to drop down a VBS script onto your system. The vulnerability allows that to happen."

If a user's machine is properly patched, Bagle poses no threat

One-Upmanship Game
There have been so many variations on the original Bagle worm that some security experts speculate that virus writers are playing a game of one-upmanship as they create and spread new mutations.


"There have actually been messages between the virus writers embedded within the viruses. The authors of Netsky, Bagle and MyDoom are really at each other's throats trying to create more viruses and outdo each other.

"It's having a horrible impact on the end-users who are the target of these attacks."

Disabling Firewalls
Like earlier versions of Bagle, the new variations disable many firewall and antivirus applications, a technique that has become common among virus writers.


They also spread like the original Bagle, by resending themselves to all addresses found on a user's hard drive, disguising the return address of the e-mail to conceal the identity of the infected machine.




The mass-mailed worm uses a broad array of typical spam-virus subject lines, such as "Fax message received" and "account notify."

P2P Networks

The Bagle virus is coded to survive and propagate rather than delete files, as some worms do. "They are not generally destructive, but they put a huge load on e-mail servers, they cause outages, and there's a cost associated with un-infection,"

Bagle infects every .exe file on a victim's system,
meaning it lurks stubbornly even on apparently cleaned systems.

The worms will keep hundreds of software programs from running, and they deactivate configuration applications, such as regedit and msconfig, that are used to delete viruses.

Bagle places itself -- with a variety of invented file names -- in folders that are commonly used for file-swapping. So, a large P2P network like Kazaa becomes an effective tool for mass propagation.
[/b]
__________________
jizac_aka_lickablepig
(Y) (jizac)
(':') |/
("(")_)0


Reply With Quote
  #5  
Old 22nd Mar 04, 10:36 PM
war59312 war59312 is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: U.S.A
Posts: 2,220
war59312 has disabled reputation
Send a message via ICQ to war59312 Send a message via AIM to war59312 Send a message via MSN to war59312 Send a message via Yahoo to war59312
Running sp2.
__________________
Ad Muncher Usage Statistics for v4.7 Build 27105/1624
Adverts removed by Ad Muncher: 1,601,933
Approximate bandwidth saved: 12,515 MB
Counter started: April 2, 2003

Download: http://war59312.admuncher.com/download.shtml
Reply With Quote
  #6  
Old 23rd Mar 04, 12:20 AM
KingCobra's Avatar
KingCobra KingCobra is offline
Senior Member
 
Join Date: Dec 2001
Location: Illinois
Posts: 2,409
KingCobra is on a distinguished road
Send a message via Yahoo to KingCobra
I called my ISP to ask what my ISP email account password is, because I have never used it. Thought I should do this if they email me about problems.

Come to find out if you don't setup and email account there is none. In fact, the rep told me that they don't email their customers. He said they call or send a certified letter.

@war59312 - Do you use Outlook to manage your email?

P.S. Sorry to hear about the problems but happy nothing was lost other than your time. Brothers, got one myself. :P
__________________
Reply With Quote
  #7  
Old 23rd Mar 04, 10:31 PM
war59312 war59312 is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: U.S.A
Posts: 2,220
war59312 has disabled reputation
Send a message via ICQ to war59312 Send a message via AIM to war59312 Send a message via MSN to war59312 Send a message via Yahoo to war59312
Got two brothers. Well really 7 but I wont go into that. Whoops make than 10 now. Mom got remarried.

Anyways nope just outlook express with popfile. Dont like outlook 2003.
__________________
Ad Muncher Usage Statistics for v4.7 Build 27105/1624
Adverts removed by Ad Muncher: 1,601,933
Approximate bandwidth saved: 12,515 MB
Counter started: April 2, 2003

Download: http://war59312.admuncher.com/download.shtml
Reply With Quote
  #8  
Old 23rd Mar 04, 11:32 PM
Dave Dave is offline
BetaONE Supporter
 
Join Date: Jul 2001
Posts: 173
Dave is an unknown quantity at this point
Glad you didn't have any major trouble and you had everything backed up.

Quote:
Plus I keep no credit card numbers or anything on my computer. Not even word docs. or anything else considered private.
Lots of people don't realize that word docs contain a lot of metadata info that can be a violation of your personal privacy.
If you don't know what I'm talking about, open up word the go to:
File\open
Where it says "files of type" set it for "recover text from any file" and then open up a word document you have had for a while.
You might be shocked with all the hidden stuff you see imbedded in the doc.

There is a cool freeware tool called "DocScrubber" you can use to remove that crap if it concerns you.
/http://www.docscrubber.com/

Dave
Reply With Quote
  #9  
Old 23rd Mar 04, 11:50 PM
war59312 war59312 is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: U.S.A
Posts: 2,220
war59312 has disabled reputation
Send a message via ICQ to war59312 Send a message via AIM to war59312 Send a message via MSN to war59312 Send a message via Yahoo to war59312
Quote:
Originally posted by Dave@Mar 23 2004, 05:32 PM
Glad you didn't have any major trouble and you had everything backed up.



Lots of people don't realize that word docs contain a lot of metadata info that can be a violation of your personal privacy.
If you don't know what I'm talking about, open up word the go to:
File\open
Where it says "files of type" set it for "recover text from any file" and then open up a word document you have had for a while.
You might be shocked with all the hidden stuff you see imbedded in the doc.

There is a cool freeware tool called "DocScrubber" you can use to remove that crap if it concerns you.
/http://www.docscrubber.com/

Dave
Hehe I got better than that. I'm the man, dont u know that? Now you do, my love muffin!! :P

Here it is. Works for office 2003 and office xp (office 2002).

http://www.microsoft.com/downloads/d...displaylang=en
__________________
Ad Muncher Usage Statistics for v4.7 Build 27105/1624
Adverts removed by Ad Muncher: 1,601,933
Approximate bandwidth saved: 12,515 MB
Counter started: April 2, 2003

Download: http://war59312.admuncher.com/download.shtml
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Zafi-C mutant virus targets Google and Microsoft NewsBot NeoWin News 0 28th Oct 04 10:00 PM
EBay virus 'start of worrying trend' NewsBot NeoWin News 0 26th Oct 04 05:30 PM
Virus rips into Macs NewsBot ieXbeta News 0 25th Oct 04 03:30 PM
Microsoft's Worst Nightmare NewsBot NeoWin News 0 25th Oct 04 01:30 AM


All times are GMT +1. The time now is 07:22 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.