Compatible Support Forums: Massive data upload when dialup adapter is running

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Massive data upload when dialup adapter is running

#1 User is offline   videobruce 

  • enthusiast
  • Group: Members
  • Posts: 382
  • Joined: 03-March 02

Posted 16 October 2003 - 07:25 PM

After a few minutes without a browser running using DU Meter as a in/out monitor I'm getting a massive (for a analog connection) upload of unknown data to a unknown destination by a unknown process.

I have:
Done a virus scan (though not up to date definations)
Used AdAware V6 and SpyBot V1.2
Checked processes running

I am running 2k w/sp3 The laptop was upgraded with Idiot Exploiter 6 from M$'s site (this isn't my laptop BTW).

Before the dialer was starting byself, now it seems ok, but not sure yet.
The laptop freezes where only a reboot solves the condition (no browser running the last time).

The IE update was the last upgrade/change AFAIK.

It is almost as this machine was doing a DOS attack to another site by uploading massive amounts of data somewhere.
0

#2 User is offline   Sampson 

  • veteran
  • Group: Members
  • Posts: 1458
  • Joined: 18-December 01

Posted 16 October 2003 - 08:29 PM

It sounds a lot like the Opaserv virus. Check to see if there are any of these files: ALEVIR.EXE, BRASIL.EXE, BRASIL.PIF, SCRSVR.EXE or MARCO!.SCR on the hard drive. There is also another Trojan called Q-Hosts. See if the hosts file occurs more than once.
0

#3 User is offline   videobruce 

  • enthusiast
  • Group: Members
  • Posts: 382
  • Joined: 03-March 02

Posted 16 October 2003 - 10:44 PM

All came up negitive.

Tried to install Zone Alarm, but I get a KMODE exception when I try to run iy. I guess there are problems with display drivers and this is a Laptop with no updated driver. I even turned the accerlation down all the way and I still get a BSOD.
0

#4 User is offline   Sampson 

  • veteran
  • Group: Members
  • Posts: 1458
  • Joined: 18-December 01

Posted 17 October 2003 - 04:46 AM

There was a virus that did this same kind of thing called the Backdoor.NTHack virus. Norton's explains it here: http://www.symantec.com/avcenter/venc/data/backdoor.nthack.html
0

#5 User is offline   videobruce 

  • enthusiast
  • Group: Members
  • Posts: 382
  • Joined: 03-March 02

Posted 17 October 2003 - 04:55 AM

To make a short story long, it appears to be a worm;

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_NACHI.A

Problem is I can't install that M$ patch because the install I did is a slipstreamed SP3 burned CD and on top of that I also I do a 'LittleWhiteDog NTOSKRNL mod' using Resource Hacker to change that damn M$ splash screen.
I get a error when I try to install that patch stating I need something newer that SP2. I already have SP3 installed.

Not to stop there, since I didn't know what was doing this and thought it was the dialup adapter I connected the Laptop to my network so I could d/l a updated virus package from TrendMicro (which I did). After running the updated virus definitions that NACHI.A worm showed up.
I had my main box on also and that got affected also!

NACHI.A just did my machine.

I did a manual remove on both machines and it seems to be gone. Too early to tell yet. I don't know where he got it from.
0

#6 User is offline   jmmijo 

  • veteran
  • Group: Members
  • Posts: 1550
  • Joined: 29-May 02

Posted 19 October 2003 - 09:51 PM

Quote:


{snip}

I did a manual remove on both machines and it seems to be gone. Too early to tell yet. I don't know where he got it from.


Is there any P2P app installed on the machine or some extra .SCR files say from a news group ?!?

As for the Slipstream install CD, you can update it to SP4 the same way, just create a new Slipstreamed CD with SP4 instead then add the hack back afterwards unless of course the hack doesn't work with SP4 frown
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users