pesistant attack on my computer


Reply
 
Thread Tools Display Modes
Old 19-07-2003   #1
T_G
The Consumate Dreamer
 
T_G's Avatar
 
Join Date: 01-01-2000
Location: Somewhere where the Sauer is Kraut and the Wurst is Brat
Posts: 4615
Thanks: 66
Thanked 71 Times in 62 Posts

My System: I bet on red. If I lose, I double the bet on red again. I continue with this until I lost everything.


Muhuhuhahahahahaaaaarrrgggh
pesistant attack on my computer

Well, every time I go online I get a popup with a note that my computer needs to get security updates and anti virus software.
I got Norton internet security and also Zone alarm installed, set up on all the correct settings but still this f***er comes up. Any ideas?
Attached Images
File Type: jpg hacker.JPG (47.9 KB, 15 views)
__________________
I only believe stuff that comes straight from Mr. Horses mouth
T_G is offline   Reply With Quote
Old 19-07-2003   #2
Believe it when I see it Admin.
 
rolfw's Avatar
 
Join Date: 01-05-1999
Location: Southern England
Posts: 27725
Thanks: 34
Thanked 732 Times in 507 Posts
Blog Entries: 3

My System: Sky+, DB 7000s, Gemini 4.3 in flash, Var on USB stick. Transparent 80cm Dish, Moteck SG2100 DiseqC motor, lots of legacy gear. Meters: Satlook Digital NIT, Unaohm EP313, Swires Annie 204 Spectrum, Rover ST-4 Spectrum.

This isn't one of the popups from Windows messenger is it T_G? They also send one out which tells you that you need a popup stopper.
__________________
Rolf
If you enjoy our site, you can help support it by wearing our unique branded merchandise, you can do this by clicking on my baseball cap, making a direct donation with Paypal by clicking on the Donation button below, or using our site supporting advertisers, to do this, click on the central image below



Donate
rolfw is online now   Reply With Quote
Old 19-07-2003   #3
T_G
The Consumate Dreamer
 
T_G's Avatar
 
Join Date: 01-01-2000
Location: Somewhere where the Sauer is Kraut and the Wurst is Brat
Posts: 4615
Thanks: 66
Thanked 71 Times in 62 Posts

My System: I bet on red. If I lose, I double the bet on red again. I continue with this until I lost everything.


Muhuhuhahahahahaaaaarrrgggh

Well, if you look carefully at the screenshot, you can see on the taskbar the following programs open: ICQ, Network status, Modem, Zone Alarm, Volume control, Norton anti virus auto protect and finnaly norton internet security.
The messenger is only on when I switch it on. I don't think it is the ICQ as the pop up comes when it is off as well...
__________________
I only believe stuff that comes straight from Mr. Horses mouth
T_G is offline   Reply With Quote
Old 19-07-2003   #4
Administrator
 
jimbo's Avatar
 
Join Date: 01-01-2000
Location: Greater London
Posts: 3442
Thanks: 2
Thanked 24 Times in 21 Posts

My System: Sky HD, TM6800HD, Manhattan Plaza ST550 and TM1500 CI+. 1.0m dish and 36v motor, Panasonic DVD HDD recorder and Panasonic video/DVD recorder. Sony G800 HD TV stand/surround system + Sony KDL40W2000. Infinity USB, Elvis, CAS1, CAS2.

Win32 opaserv is a worm virus. Have you seen this link T_G http://securityresponse1.symantec.co...serv.worm.html. Any help?
__________________
Jimbo




Last edited by jimbo; 19-07-2003 at 03:20 PM
jimbo is offline   Reply With Quote
Old 19-07-2003   #5
T_G
The Consumate Dreamer
 
T_G's Avatar
 
Join Date: 01-01-2000
Location: Somewhere where the Sauer is Kraut and the Wurst is Brat
Posts: 4615
Thanks: 66
Thanked 71 Times in 62 Posts

My System: I bet on red. If I lose, I double the bet on red again. I continue with this until I lost everything.


Muhuhuhahahahahaaaaarrrgggh

I got Norton to make a full check every night, and I also got the latest virus updates automatically, so I don't think it is a virus. it seems to be some sort of open port. According to a security check I made my computer is save, I got the Norton internet security which is some sort of firewall...
__________________
I only believe stuff that comes straight from Mr. Horses mouth
T_G is offline   Reply With Quote
Old 19-07-2003   #6
Administrator
 
jimbo's Avatar
 
Join Date: 01-01-2000
Location: Greater London
Posts: 3442
Thanks: 2
Thanked 24 Times in 21 Posts

My System: Sky HD, TM6800HD, Manhattan Plaza ST550 and TM1500 CI+. 1.0m dish and 36v motor, Panasonic DVD HDD recorder and Panasonic video/DVD recorder. Sony G800 HD TV stand/surround system + Sony KDL40W2000. Infinity USB, Elvis, CAS1, CAS2.

Ok, so if it's just a pop up it will be triggered by a some small exe file or registry call on your computer. A neighbour had something like that and I first of all used find/search for anything to do with it and deleted that. Then searched the registry and found the trigger in there. Once I'd removed the bits from the registry that was it, all clear.
__________________
Jimbo



jimbo is offline   Reply With Quote
Old 19-07-2003   #7
Registered User
 
Join Date: 11-12-2002
Location: Harwich Essex UK
Posts: 23
Thanks: 0
Thanked 0 Times in 0 Posts

Hi Guys, Another thought, it might be a spybot, antivirus progs won't find it. Try Spybot Search and Destroy, it's free.
Sincerely,
Richard.
oldgit is offline   Reply With Quote
Old 19-07-2003   #8
Believe it when I see it Admin.
 
rolfw's Avatar
 
Join Date: 01-05-1999
Location: Southern England
Posts: 27725
Thanks: 34
Thanked 732 Times in 507 Posts
Blog Entries: 3

My System: Sky+, DB 7000s, Gemini 4.3 in flash, Var on USB stick. Transparent 80cm Dish, Moteck SG2100 DiseqC motor, lots of legacy gear. Meters: Satlook Digital NIT, Unaohm EP313, Swires Annie 204 Spectrum, Rover ST-4 Spectrum.

Have a look here T_G http://www.bitdefender.com/virusi/vi...p?virus_id=101

Go here for a system cleaner http://www.trendmicro.com/download/tsc.asp
__________________
Rolf
If you enjoy our site, you can help support it by wearing our unique branded merchandise, you can do this by clicking on my baseball cap, making a direct donation with Paypal by clicking on the Donation button below, or using our site supporting advertisers, to do this, click on the central image below



Donate
rolfw is online now   Reply With Quote
Old 19-07-2003   #9
Mod and septic resident
 
Channel Hopper's Avatar
 
Join Date: 01-01-2000
Location: London SW
Posts: 7394
Thanks: 1
Thanked 43 Times in 41 Posts

It could be that T_G might be hallucinating as well

He may not even have a PC, but is posting through some other means
__________________
There is a very fine line between "hobby" and "mental illness"
Channel Hopper is offline   Reply With Quote
Old 20-07-2003   #10
Regular Contributor
 
Join Date: 01-01-2000
Location: essex boy
Posts: 160
Thanks: 0
Thanked 0 Times in 0 Posts

it is definitely a worm virus, even norton saying the pc is cleaned but the worm is loaded everytime the pc is switched on, refer to jimbo's link, do a manual removal.
drag0nfly_69uk is offline   Reply With Quote
Old 20-07-2003   #11
T_G
The Consumate Dreamer
 
T_G's Avatar
 
Join Date: 01-01-2000
Location: Somewhere where the Sauer is Kraut and the Wurst is Brat
Posts: 4615
Thanks: 66
Thanked 71 Times in 62 Posts

My System: I bet on red. If I lose, I double the bet on red again. I continue with this until I lost everything.


Muhuhuhahahahahaaaaarrrgggh

OK, I am going to do the system cleaner, why not. The thing is: That thing has nothing to do with the opaservA virus. What the text is saying that my computer is suspected of having this virus. They recommendI go to the update2000.dr.ag (funny URL...) website to get help. What happens then is that once you are on this site and download whatever is on for "Free", you are also downloading a 0190 dialer, I.E. it changes settings on your modem. The moderm then shuts down and then reconnects, but this time you are paying 10 Euro a minut. The thing sometimes changes the text, so it would be all sorts of "Alarming" messages, and sometimes the webaddress changes. This is because I think the webaddresses are being shut down. It seems to be a German thing, I never had a message in English.

P.S just as I was writing this I got another one, see picture
Attached Images
File Type: jpg hacker2.JPG (143.8 KB, 11 views)
__________________
I only believe stuff that comes straight from Mr. Horses mouth

Last edited by T_G; 20-07-2003 at 10:13 AM
T_G is offline   Reply With Quote
Old 20-07-2003   #12
T_G
The Consumate Dreamer
 
T_G's Avatar
 
Join Date: 01-01-2000
Location: Somewhere where the Sauer is Kraut and the Wurst is Brat
Posts: 4615
Thanks: 66
Thanked 71 Times in 62 Posts

My System: I bet on red. If I lose, I double the bet on red again. I continue with this until I lost everything.


Muhuhuhahahahahaaaaarrrgggh

Originally Posted by Channel Hopper
It could be that T_G might be hallucinating as well

He may not even have a PC, but is posting through some other means

I can take the hallucinations and posting through other means, BUT NOT HAVE A COMPUTER?? This is personal!!
__________________
I only believe stuff that comes straight from Mr. Horses mouth
T_G is offline   Reply With Quote
Old 20-07-2003   #13
Administrator
 
jimbo's Avatar
 
Join Date: 01-01-2000
Location: Greater London
Posts: 3442
Thanks: 2
Thanked 24 Times in 21 Posts

My System: Sky HD, TM6800HD, Manhattan Plaza ST550 and TM1500 CI+. 1.0m dish and 36v motor, Panasonic DVD HDD recorder and Panasonic video/DVD recorder. Sony G800 HD TV stand/surround system + Sony KDL40W2000. Infinity USB, Elvis, CAS1, CAS2.

The IP address on that last pop up is in Dusseldorf. You can report abuse to the following: abuse@pppool.de
__________________
Jimbo



jimbo is offline   Reply With Quote
Old 23-07-2003   #14
Believe it when I see it Admin.
 
rolfw's Avatar
 
Join Date: 01-05-1999
Location: Southern England
Posts: 27725
Thanks: 34
Thanked 732 Times in 507 Posts
Blog Entries: 3

My System: Sky+, DB 7000s, Gemini 4.3 in flash, Var on USB stick. Transparent 80cm Dish, Moteck SG2100 DiseqC motor, lots of legacy gear. Meters: Satlook Digital NIT, Unaohm EP313, Swires Annie 204 Spectrum, Rover ST-4 Spectrum.

Try this T_G, the messenger doesn't have to be switched on to provide you with an interesting selection of popups.

Goto start then click on run

type msconfig and press enter

Click on the services tab

Scroll down to messenger and un-tick

press ok and reboot your PC as prompted

When windows has reloaded click the tick box on the pop-up and press ok

This may stop your messages.
__________________
Rolf
If you enjoy our site, you can help support it by wearing our unique branded merchandise, you can do this by clicking on my baseball cap, making a direct donation with Paypal by clicking on the Donation button below, or using our site supporting advertisers, to do this, click on the central image below



Donate
rolfw is online now   Reply With Quote
Old 24-07-2003   #15
T_G
The Consumate Dreamer
 
T_G's Avatar
 
Join Date: 01-01-2000
Location: Somewhere where the Sauer is Kraut and the Wurst is Brat
Posts: 4615
Thanks: 66
Thanked 71 Times in 62 Posts

My System: I bet on red. If I lose, I double the bet on red again. I continue with this until I lost everything.


Muhuhuhahahahahaaaaarrrgggh

Originally Posted by rolfw
Try this T_G, the messenger doesn't have to be switched on to provide you with an interesting selection of popups.

I tried to, but I did not see the messenger there. I think that when I installed it first I did use the option that it won't load automatically with windows...
__________________
I only believe stuff that comes straight from Mr. Horses mouth
T_G is offline   Reply With Quote
Old 24-07-2003   #16
Believe it when I see it Admin.
 
rolfw's Avatar
 
Join Date: 01-05-1999
Location: Southern England
Posts: 27725
Thanks: 34
Thanked 732 Times in 507 Posts
Blog Entries: 3

My System: Sky+, DB 7000s, Gemini 4.3 in flash, Var on USB stick. Transparent 80cm Dish, Moteck SG2100 DiseqC motor, lots of legacy gear. Meters: Satlook Digital NIT, Unaohm EP313, Swires Annie 204 Spectrum, Rover ST-4 Spectrum.

Oh well, worth a try, are you still getting the messages?
__________________
Rolf
If you enjoy our site, you can help support it by wearing our unique branded merchandise, you can do this by clicking on my baseball cap, making a direct donation with Paypal by clicking on the Donation button below, or using our site supporting advertisers, to do this, click on the central image below



Donate
rolfw is online now   Reply With Quote
Old 26-07-2003   #17
T_G
The Consumate Dreamer
 
T_G's Avatar
 
Join Date: 01-01-2000
Location: Somewhere where the Sauer is Kraut and the Wurst is Brat
Posts: 4615
Thanks: 66
Thanked 71 Times in 62 Posts

My System: I bet on red. If I lose, I double the bet on red again. I continue with this until I lost everything.


Muhuhuhahahahahaaaaarrrgggh

Yes, I got them all the time... not that they are doing anything, it is just anoying knowing I have been violated....
__________________
I only believe stuff that comes straight from Mr. Horses mouth
T_G is offline   Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Spare 80cm fixed dish and a computer !! redrooster DISH SETUP: Single sat, Multi-Sat & Motorised systems 6 02-03-2004 10:00 PM
Guard your computer -- or else... net1 Computer Discussion 7 06-01-2004 03:15 PM
Hacker 'attacked port in revenge bid' net1 The Meeting Place 0 06-10-2003 07:31 PM
BBC counters Ball's licence fee attack net1 Daily Satellite and Broadcast industry News 0 22-08-2003 10:22 PM
BSkyB chief launches attack on licence fee net1 Daily Satellite and Broadcast industry News 0 22-08-2003 07:39 PM






All times are GMT +1. The time now is 09:47 PM.


All views and information expressed in users' communications and profiles represent the opinions of the users concerned and do not represent the views of Satellites.co.uk. All images and news content are believed to be in the public domain, except where otherwise stated. Forum software by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.


Content Relevant URLs by vBSEO 3.2.0