Virus Drains Data Bundle R10 000 later.

Status
Not open for further replies.
Yesterday(out of my own stupidity) i got infected with the works. Virusses, malware, trojan downloaders, you name it.
Get out of MY town! I don't want you near me you virus infected thing you. :p It has happened to me in the past. Forgot to run a file in the sandbox. "oops"
Was a nice learning experiment though. Nice little IRC bot virus thing. AVG and Packet Sniffer FTW! It Connected to some IRC server, I watched it. I became one of thousands of Zombies in there. :eek:

..So my argument is, that although his AV was up to date, it doesn't mean he was NOT infected? Like in my case, i thought i was clean, but i wasn't!Thats my theory. Does it makes sense?

Yes it does. Nice theory. Quite possible. One must be careful these days with those things running in the background. But I have accustomed myself to always watch the activity/usage whenever I'm on the internet. You never know what is really going on.

But the user/customer does not know about these things. Well, most of them don't. They don't understand these underlaying dangers that could land them a free R10K bill in the post.
 
The argument was that bruce's friend's Anti-Virus was up to date, and it didnt pick up any virus/malware etc. This is debateable, and i'll tell you why...

Yesterday(out of my own stupidity) i got infected with the works. Virusses, malware, trojan downloaders, you name it. As my Anti-Virus was up to date, i did a full system scan and found the lot of them. Cleaned it, and those who could not be cleaned deleted. I even went to safe mode to take out the tough ones.

Went back into Windows, everythig seemed fine. I connected, and left it idle. Again, take note, my AV was up to date.

After about so 30mins, i accidentally checked my usage(yes accidentally as i moved my mouse over 2computers icon in the taskbar) and was shocked! 30Megs GONE! In 30Mins! And what did i do? I left it idle!

I disconnected. Did another scan(with Ad-Aware) and found some more. Deleted that, rebooted, did a scan in safe mode, rebooted, and got back into Windows(my thought here is, i got rid of everything right??)

Connected, i watched my usage like a hawk. AV still up to date, no virus/malware warnings. Upon inspecting the usage, i found that whatever i was infected with, caused me to download about 1meg per minute...

Bruce's friend was using his weekender at the time(as bruce said his friends uses that when his PPDB runs out). So the OOB rate would be R2 a Meg.

So it hit me last night...

1meg per minute, that would be +- 60megs per hour. 24hours in 1day, so that would be 60 multiplied by 24, giving me approximately 1500megs per day.

Bruce's friend left it connected for 3 consecutive days. That 1500 multipleid by 3, giving me about +-4500Megs for the 3days.

Taking into consideration the OOB rate of R2 a meg, multiply that by 2 and you get a bill close to 10k.

So my argument is, that although his AV was up to date, it doesnt mean he was NOT infected? Like in my case, i thought i was clean, but i wasnt!

Thats my theory. Does it makes sense?

Holy ****!!! If you find out what it was please share it with us. That scares me! :eek::eek:
 
Holy ****!!! If you find out what it was please share it with us. That scares me! :eek::eek:

I still got the infection in Quarantine. I scanned with Ad-Aware twice and and it didnt remove it. I had to physically go the file and delete it. Everything is well with my laptop now!
 
Holy ****!!! If you find out what it was please share it with us. That scares me! :eek::eek:
Yesterday(out of my own stupidity) i got infected with the works. Virusses, malware, trojan downloaders, you name it.

Seems quite clear what is was. And also easy to prevent, detect & stop/remove imho.

Prevent: Stay away from those dangerous and pr0n sites :p. Keep Anti-Virii Software up to date. Run a good firewall. Don't leave connection running while you are not using it. Dont do whatever Iam3G did. :p
Detect: You connected, not using the internet, but the usage light are going crazy? Detected. Do what Iam3G did.
Stop: Format the PC (shortest route to explain :D) Or, Do what Iam3G did.


This is not the Ultimate Virus, malware et al prevention, detection and removal advise. Results not guaranteed. The best advise there is around: Use.Your.Common.Sense.
 
Seems quite clear what is was. And also easy to prevent, detect & stop/remove imho.

Prevent: Stay away from those dangerous and pr0n sites :p. Keep Anti-Virii Software up to date. Run a good firewall. Don't leave connection running while you are not using it. Dont do whatever Iam3G did. :p
Detect: You connected, not using the internet, but the usage light are going crazy? Detected. Do what Iam3G did.
Stop: Format the PC (shortest route to explain :D) Or, Do what Iam3G did.


This is not the Ultimate Virus, malware et al prevention, detection and removal advise. Results not guaranteed. The best advise there is around: Use.Your.Common.Sense.

Was doing a favor for a friend... he owns me 50 odd Megs! :D

I'm fairly sure I posted about the possibility of malware some 300 odd posts back.

I know you did. I was with you on that subject. But they all dismissed it as "Bruce's friend's AV was up to date". Plus we couldnt prove it. And i think i just did, becoz the logic is fairly accurate.
 
I still got the infection in Quarantine. I scanned with Ad-Aware twice and and it didnt remove it. I had to physically go the file and delete it. Everything is well with my laptop now!

Maybe not. Read up on rootkits and scan for that.

If your virus software was up to date and you got infected, how did it happen? Could well be a rootkit. Most virus scanners can't detect them.
 
Maybe not. Read up on rootkits and scan for that.

If your virus software was up to date and you got infected, how did it happen? Could well be a rootkit. Most virus scanners can't detect them.

Possibly a rootkit, but i doubt it. This is how i got infected...

I was looking for something for a friend of mine. Found it. Downloaded it. It was a self-extracting zip file. It was scanned and nothing was found. I then extacted it, it finished its "installation" and after 5mins or so the sh@t started happening.

So thats how i got infected with my up to date AV, so i doubt its a rootkit. If i've time, i'll see what i can dig up on here, maybe i even have one and i dont know about it.
 
One cannot rely on any single piece of anti-malware s/w in a Windoze environment, and there are times when 3 or more anti-malware packages all don't detect a particular infection, like v3g posted, in particular rootkits are usually never detected by anti-malware s/w.

One cannot scientifically prove the absence of any malware based on anti-malware s/w's scan results saying nothing was found, IOW just bcos malware wasn't detected, does not mean that malware is not present.

Likewise it is impossible to figure out specifically what happened on Bruce000's friend's notebook bcos none of us have physical access to that notebook, and IIRC the friend sold the notebook to a gullible person, so there really is no chance of proving or disproving anything related to that particular notebook.

It is however perfectly reasonable to suggest that a malware infection on that particular notebook, was the likely cause of the OOBR data usage, but equally reasonable to suggest that someone left P2P running, even Skype left running on a PC that is not firewalled can act as a super-node and generate lots of P2P traffic.

Understood.
 
The argument was that bruce's friend's Anti-Virus was up to date, and it didnt pick up any virus/malware etc. This is debateable, and i'll tell you why...

Yesterday(out of my own stupidity) i got infected with the works. Virusses, malware, trojan downloaders, you name it. As my Anti-Virus was up to date, i did a full system scan and found the lot of them. Cleaned it, and those who could not be cleaned deleted. I even went to safe mode to take out the tough ones.

Went back into Windows, everythig seemed fine. I connected, and left it idle. Again, take note, my AV was up to date.

After about so 30mins, i accidentally checked my usage(yes accidentally as i moved my mouse over 2computers icon in the taskbar) and was shocked! 30Megs GONE! In 30Mins! And what did i do? I left it idle!

I disconnected. Did another scan(with Ad-Aware) and found some more. Deleted that, rebooted, did a scan in safe mode, rebooted, and got back into Windows(my thought here is, i got rid of everything right??)

Connected, i watched my usage like a hawk. AV still up to date, no virus/malware warnings. Upon inspecting the usage, i found that whatever i was infected with, caused me to download about 1meg per minute...

Bruce's friend was using his weekender at the time(as bruce said his friends uses that when his PPDB runs out). So the OOB rate would be R2 a Meg.

So it hit me last night...

1meg per minute, that would be +- 60megs per hour. 24hours in 1day, so that would be 60 multiplied by 24, giving me approximately 1500megs per day.

Bruce's friend left it connected for 3 consecutive days. That 1500 multipleid by 3, giving me about +-4500Megs for the 3days.

Taking into consideration the OOB rate of R2 a meg, multiply that by 2 and you get a bill close to 10k.

So my argument is, that although his AV was up to date, it doesnt mean he was NOT infected? Like in my case, i thought i was clean, but i wasnt!

Thats my theory. Does it makes sense?

@Iam3g. What AV are you using ??
:cool:
 
Get out of MY town! I don't want you near me you virus infected thing you. :p It has happened to me in the past. Forgot to run a file in the sandbox. "oops"
Was a nice learning experiment though. Nice little IRC bot virus thing. AVG and Packet Sniffer FTW! It Connected to some IRC server, I watched it. I became one of thousands of Zombies in there. :eek:



Yes it does. Nice theory. Quite possible. One must be careful these days with those things running in the background. But I have accustomed myself to always watch the activity/usage whenever I'm on the internet. You never know what is really going on.

But the user/customer does not know about these things. Well, most of them don't. They don't understand these underlaying dangers that could land them a free R10K bill in the post.

This is a point I have been trying to make all the time.

Those underlying gogga's those you can not see.

I have been using Bitdefender Internet Security V10 & have just upgraded to Ver 11 (2008). So far so good. I just don't trust leaving my System connected all the time but look at this.

http://mybroadband.co.za/vb/showthread.php?p=1234498#post1234498. This was me being active on the Net for those ours.

:cool:
 
My system is rendered useless. Been struggling to get my laptop working since the day before yesterday, and i gotta do my work on that laptop!

I'm gonna have to purchase a External HDD Casing and get my 80Gig from my gf and make backups. A format is my only option now.

I cant even install anything on my laptop. This is what you get for helping a friend!

@Csnoopy, using McAfee Virusscan Enterprise version 8.0i. Was preloaded when VodacomIT setup my laptop.

I've got a long weekend ahead of me...
 
My system is rendered useless. Been struggling to get my laptop working since the day before yesterday, and i gotta do my work on that laptop!

I'm gonna have to purchase a External HDD Casing and get my 80Gig from my gf and make backups. A format is my only option now.

I cant even install anything on my laptop. This is what you get for helping a friend!

@Csnoopy, using McAfee Virusscan Enterprise version 8.0i. Was preloaded when VodacomIT setup my laptop.

I've got a long weekend ahead of me...


Formatting is the only 100% guaranteed way to get rid of those pesky buggers:o
 
Status
Not open for further replies.
Top
Sign up to the MyBroadband newsletter
X