RE: Windows 98 box is 'owned'

From: Akins, Keith A (EM, ITS) (keith.akins_at_ge.com)
Date: 09/30/04

  • Next message: Corio, Jim: "RE: Looking for some good sources"
    Date: Thu, 30 Sep 2004 16:54:33 -0400
    To: <bulliver@badcomputer.no-ip.com>, <security-basics@securityfocus.com>
    
    

     This a actually a virus. Mydoom if I remember right. It looks for any
    folder named download and makes copies of itself with various names like
    you mentioned. Download the fix tool from Symantec.

    -----Original Message-----
    From: Darren Kirby [mailto:bulliver@badcomputer.no-ip.com]
    Sent: Wednesday, September 29, 2004 10:04 PM
    To: security-basics@securityfocus.com
    Subject: Windows 98 box is 'owned'

    Hello all,

    I am writing this on behalf of my Mom. She was complaining that her
    computer was sluggish, and that her HD space was getting used up faster
    than it should. So I went over and fired up my trusty Linux live cd and
    had a look.

    Anyway, I found a directory right in C: named 'Downloads', and inside
    were about 50 or so files, which were all warez, porn, windows exploits
    and cracker 'howto's. Quite obviously this computer is owned, and is
    being used as a warez server. I deleted the files, booted win, but they
    reappeared after about 10 minutes. The strange thing is that these files
    are ALL 29k, and all have filenames like:

    Adobe Photoshop crack.exe
    Smashing the Stack.txt.exe
    Eminem - full album.mp3.exe
    Office 2003 full.exe
    ...
    On further inspection I found an identical directory at
    C:/windows/Downloaded Program Files/. God only knows how many trojans
    and other nasties are sprinkled around...

    So I yanked the power cord out of her adsl modem, and told her not to
    plug it back in unless she was checking her mail. Bad advice for sure,
    but try telling your mom that her computer is rooted by punk kids and it
    is too cracked to have safe internet access at all. Seems that a
    complete OS reinstall is in order, but it seems to me that if they can
    own her box once they can own it again just as easy, which leads me to
    this list...I would like to try some investigating, and try to figure
    out where the backdoor is, what exactly they are doing...and of course
    how to prevent it.

    Some background on myself...I am a Linux sysadmin, and have a great deal
    of experience with UNIX operating systems...however, I have never run a
    windows box, and have only used one in the 'point-and-drool' sort of
    way. So I really know nothing of how the underlying OS works (or
    doesn't...).

    So I guess I am just asking for some opinions of the situation, and
    perhaps some links to docs about this type of attack, and how to prevent
    it. Also, any software along the lines of chkrootkit or other forensic
    tools, but for windows would be a big help.

    TIA
    -d

    --
    Part of the problem since 1976
    http://badcomputer.no-ip.com
    Get my public key from
    http://keyserver.linux.it/pks/lookup?op=index&search=bulliver
    "...the number of UNIX installations has grown to 10, with more
    expected..."
    - Dennis Ritchie and Ken Thompson, June 1972 
    

  • Next message: Corio, Jim: "RE: Looking for some good sources"

    Relevant Pages

    • RE: Lost My Desktop
      ... Some of this does not apply if you have Windows XP SP2. ... Make sure of these settings and nothing will install without you ... Enable Install On Demand (Internet Explorer) ... [[Specifies to automatically download and install Web components if a Web ...
      (microsoft.public.windowsxp.general)
    • Re: Spyware possible being on one account and not the other
      ... > the browser in the guest account is jacked to some site. ... using Windows XP "prettifications". ... If you want to know when one of your applications is trying to obtain ... are pay - some you can only download if you are registered - but it is best ...
      (microsoft.public.windowsxp.security_admin)
    • Re: 16 Bit Error
      ... Something was wrong with the download. ... was just lumped in with whatever the Repair Install did. ... MS-MVP Windows Shell/User ... sure that the directory path exists, and disk space is available. ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: FTC Complaint filed
      ... There is no way to limit what M$ wants to install on your system because they hide the descriptions, ... And they don't need that particular download at all to put more copy protection code on your pc. ... I have long said, in my opinion and pre-Vista, that Windows 95 was the best OS Microsoft ever made. ... should be with your PCB software maker. ...
      (microsoft.public.windowsmedia.player)
    • Re: Sasser & Blaster problem
      ... >> Windows XP systems: ... >> installation of the patch as well as removal of the worm. ... >> following commands must be typed in a command prompt ... >> must download and install the MS04-011 patch from the MS04-011 download ...
      (microsoft.public.security)