Advertisement



Go Back   Zune Boards > Help Forum > Tech. help

New Member?



 
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Tech. help Come here for help with technology related problems.

Reply
 
LinkBack Thread Tools
Old 08-10-2008, 03:59 PM   #1 (permalink)
God of the Post Reports
Support Team
Section Staff
Super Zuner²
 
Locke's Avatar
 
Join Date: May 2008
Location: In the kitchen, preparing a brand new batch of n00blets
Posts: 3,857
Reputation: 545
Send a message via MSN to Locke
Awards Showcase
Member of the Quarter Biggest staff suck-up Biggest Shouter 
Total Awards: 3
Default Anyone recognize this IP?


I've gotten a couple Norton alerts telling me that 89.188.16.99, 80 has been trying to remotely access my computer. Does anyone recognize the IP, or is it just some poor bot computer? There's been a couple rootkits also trying to get into my computer, so could this be related. Here's a screen of the actual log:



__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

Now with links!
Quote:
Originally Posted by Lucifer
Locke: now with higher expectations than most military boot camp instructors.




Locke is offline   Reply With Quote
Old 08-10-2008, 04:41 PM   #2 (permalink)
Purger of Ignorance
zB Programmer
Section Staff
Super Zuner
 
Netrix's Avatar
 
Join Date: Jun 2008
Location: In my own world
Posts: 1,666
Reputation: 231
Send a message via MSN to Netrix
Awards Showcase
Favorite zB Extremity 
Total Awards: 1
Default

Unlucky, you are. I suggest you go here: Trojan.Vundo Removal Tool - Symantec.com, download the Vundo Removal Tool, and run it.

Unfortunately, you appear to have the Vundo Trojan. It is not pleasant.

Also, that IP address is not trying to access your computer. Your computer is trying to access that IP address, probably to download more malware.
__________________
"Against logic there is no armor like ignorance." - Laurence J. Peter

Solitaire for your Zune!
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


Zune Book Reader!
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.




Netrix is offline   Reply With Quote
Old 08-10-2008, 08:26 PM   #3 (permalink)
God of the Post Reports
Support Team
Section Staff
Super Zuner²
 
Locke's Avatar
 
Join Date: May 2008
Location: In the kitchen, preparing a brand new batch of n00blets
Posts: 3,857
Reputation: 545
Send a message via MSN to Locke
Awards Showcase
Member of the Quarter Biggest staff suck-up Biggest Shouter 
Total Awards: 3
Default

Same difference, right? If my computer talks to it, they're getting an in anyways. Also, I've had several "Vundo" related alerts, but I haven't noticed a thing on my computer, it runs fine, no more slowdowns than to be expected from this machine. Is this a privacy problem, or is this actually supposed to do something?
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

Now with links!
Quote:
Originally Posted by Lucifer
Locke: now with higher expectations than most military boot camp instructors.




Locke is offline   Reply With Quote
Old 08-10-2008, 08:27 PM   #4 (permalink)
Member
 
MasterSprtn117's Avatar
 
Join Date: Aug 2007
Location: Dallas, Tx
Posts: 657
Reputation: 27
Default

Maybe Norton is blocking it from downloading more malware?
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.



MasterSprtn117 is offline   Reply With Quote
Old 08-10-2008, 08:46 PM   #5 (permalink)
Windows 7 Tech
Support Team
GFX Crew
Section Staff
Elite Zuner
 
Cloud Strife's Avatar
 
Join Date: Nov 2007
Location: Vancouver, BC
Posts: 2,371
Reputation: 560
Awards Showcase
Taylor's Bitch 
Total Awards: 1
Default

Hmm... search indicates that this IP is from Amsterdam

__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.



Cloud Strife is offline   Reply With Quote
Old 08-11-2008, 01:17 AM   #6 (permalink)
Zune Guardian
 
LancerRevolution's Avatar
 
Join Date: Jun 2007
Location: El Paso, TX
Posts: 754
Reputation: 155
Awards Showcase
Biggest staff suck-up 
Total Awards: 1
Default

we should all go and kill the attacker!:p
im thinking of switching to norton,using avast currently.do you think i should?i got 1gb ddr2@pc5300 ram and cpu 1.8ghz.will it slow down my laptop?
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

Quote:
Lucifer
aside from family assoiations and royal connections, you are like emperer of zewbs.




LancerRevolution is offline   Reply With Quote
Old 08-11-2008, 04:23 AM   #7 (permalink)
Purger of Ignorance
zB Programmer
Section Staff
Super Zuner
 
Netrix's Avatar
 
Join Date: Jun 2008
Location: In my own world
Posts: 1,666
Reputation: 231
Send a message via MSN to Netrix
Awards Showcase
Favorite zB Extremity 
Total Awards: 1
Default

Quote:
Originally Posted by Locke View Post
Same difference, right? If my computer talks to it, they're getting an in anyways. Also, I've had several "Vundo" related alerts, but I haven't noticed a thing on my computer, it runs fine, no more slowdowns than to be expected from this machine. Is this a privacy problem, or is this actually supposed to do something?
There is a fairly large difference. This means that the Vundo Trojan is already on your computer and is trying to do evil things, as opposed to someone trying to access your computer from abroad. It is a lot easier for bad things to happen to your computer when there is already something malicious on it that could do more harm. If it was just someone trying to access your computer, you would be fairly safe because of Norton and any firewalls that you may have. Also, I like to be precise.

You should really get rid of Vundo. It might not be slowing your computer down right now, but it could in the future. If something happens and Norton crashes or does not start up in time when you restart, Vundo might find a way to get access to that IP and download more malware.

SpyNoMore AntiSpyware: Remove Vundo, Vundo Remover

It gives you adware and tries to fool you into downloading bad software.
__________________
"Against logic there is no armor like ignorance." - Laurence J. Peter

Solitaire for your Zune!
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


Zune Book Reader!
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.




Netrix is offline   Reply With Quote
Old 08-11-2008, 05:41 AM   #8 (permalink)
God of the Post Reports
Support Team
Section Staff
Super Zuner²
 
Locke's Avatar
 
Join Date: May 2008
Location: In the kitchen, preparing a brand new batch of n00blets
Posts: 3,857
Reputation: 545
Send a message via MSN to Locke
Awards Showcase
Member of the Quarter Biggest staff suck-up Biggest Shouter 
Total Awards: 3
Default

Oh, believe me, I already ran the tool. I just found it odd that such spyware could behave so well that I wouldn't want to do a thorough cleaning. Though, this is the first time that Vundo's acted like this; usually it's blocked when I try to open certain files, which it then promptly removes.
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

Now with links!
Quote:
Originally Posted by Lucifer
Locke: now with higher expectations than most military boot camp instructors.




Locke is offline   Reply With Quote
Old 08-11-2008, 06:44 AM   #9 (permalink)
Purger of Ignorance
zB Programmer
Section Staff
Super Zuner
 
Netrix's Avatar
 
Join Date: Jun 2008
Location: In my own world
Posts: 1,666
Reputation: 231
Send a message via MSN to Netrix
Awards Showcase
Favorite zB Extremity 
Total Awards: 1
Default

Quote:
Originally Posted by Locke View Post
Oh, believe me, I already ran the tool. I just found it odd that such spyware could behave so well that I wouldn't want to do a thorough cleaning. Though, this is the first time that Vundo's acted like this; usually it's blocked when I try to open certain files, which it then promptly removes.
Okay, that is good, then. Sometimes malware does not do anything for a while in order to help hide itself.
__________________
"Against logic there is no armor like ignorance." - Laurence J. Peter

Solitaire for your Zune!
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


Zune Book Reader!
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.




Netrix is offline   Reply With Quote
Old 08-13-2008, 04:09 AM   #10 (permalink)
God of the Post Reports
Support Team
Section Staff
Super Zuner²
 
Locke's Avatar
 
Join Date: May 2008
Location: In the kitchen, preparing a brand new batch of n00blets
Posts: 3,857
Reputation: 545
Send a message via MSN to Locke
Awards Showcase
Member of the Quarter Biggest staff suck-up Biggest Shouter 
Total Awards: 3
Default

Apparently it's not over yet. The tool has found...nothing.

EDIT: Well ****. Now weird things start happening. Explorer.exe has become unuasable. The taskbar kept dying and reloading, and eventually settled for loaind without a system tray. Very odd. Then I killed it and used RK Launcher to open it, which usually brings back Explorer without fail. My taskbar came back, and so did my desktop. It gave me an error saying My Documents-what I had opened-could not be found, but I've seen that while reloading Explorer before. Then I opened it again. Here's where it got bad. It killed Explorer a second or two after loading My Documents. Everything now ends up with failed attempts. Methinks Vundo found its way in, finally. I was wondering why Norton stopped giving me alerts, and the tool found nothing. I'm going to run the tool again, but anyone have other things I can do? For one thing, I can't disable System Restore unless I can access the Properties window for My Computer.
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

Now with links!
Quote:
Originally Posted by Lucifer
Locke: now with higher expectations than most military boot camp instructors.

Last edited by Locke : 08-14-2008 at 06:16 PM.




Locke is offline   Reply With Quote
Old 08-14-2008, 06:51 PM   #11 (permalink)
God of the Post Reports
Support Team
Section Staff
Super Zuner²
 
Locke's Avatar
 
Join Date: May 2008
Location: In the kitchen, preparing a brand new batch of n00blets
Posts: 3,857
Reputation: 545
Send a message via MSN to Locke
Awards Showcase
Member of the Quarter Biggest staff suck-up Biggest Shouter 
Total Awards: 3
Default

I apologize for the double post, but I need this to get seen because I'm rather terrified at the moment; I still haven't regained control over my computer. I'm really lucky to have Opera running, at the moment.

EDIT: Never mind, the folks over at www.bleepingcomputer.com solved it. Apparently the Norton tool was dated, so they provded me with Malwarebyte's Anti-Malware, which cleaned up the infection in about 3 minutes.
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

Now with links!
Quote:
Originally Posted by Lucifer
Locke: now with higher expectations than most military boot camp instructors.

Last edited by Locke : 08-15-2008 at 07:34 AM.




Locke is offline   Reply With Quote
Old 08-27-2008, 07:22 AM   #12 (permalink)
Squirt
 
Join Date: Aug 2008
Posts: 29
Reputation: 10
Send a message via AIM to Bushor Send a message via MSN to Bushor
Default

use spybot search and destroy, which is freeware, should fix it plus it works better than anything else that i have ever used.




Bushor is offline   Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -8. The time now is 06:23 AM.

 
Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0 RC8
vB Ad Management by =RedTyger=
(C) ZuneBoards 2006-2007
Copyright © 2006 - 2008 Zune Boards | About Zune Boards | Legal | A member of the Crowdgather Forum Community