Page 2 of 3 FirstFirst 123 LastLast
Results 17 to 32 of 45

Thread: Someone is stealing my bandwith ????

  1. #17
    Banhammer in peace PeterB kalniel's Avatar
    Join Date
    Aug 2005
    Posts
    31,025
    Thanks
    1,871
    Thanked
    3,383 times in 2,720 posts
    • kalniel's system
      • Motherboard:
      • Gigabyte Z390 Aorus Ultra
      • CPU:
      • Intel i9 9900k
      • Memory:
      • 32GB DDR4 3200 CL16
      • Storage:
      • 1TB Samsung 970Evo+ NVMe
      • Graphics card(s):
      • nVidia GTX 1060 6GB
      • PSU:
      • Seasonic 600W
      • Case:
      • Cooler Master HAF 912
      • Operating System:
      • Win 10 Pro x64
      • Monitor(s):
      • Dell S2721DGF
      • Internet:
      • rubbish

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by melon View Post
    Update: 5:47am
    Weather: Hostile as a Moose's fart ( Solar Storm ?? )

    Downloaded Emsisoft Anti Malware ( heard it was best - sry kal )
    detected and quarantined 35 objects
    trying to manually remove one called spigot

    m
    Never heard of that before. Is it this one:
    http://www.pcmag.com/article2/0,2817,2364196,00.asp
    ?

    With one off scanners it's no problem running more than one (just not at the same time!) - so try MBAM as well.

    Anyway, sounds like you did have some bad things around. If you have difficulty removing them look up combofix.

  2. #18
    WEEEEEEEEEEEEE! MadduckUK's Avatar
    Join Date
    May 2006
    Location
    Lytham St. Annes
    Posts
    17,297
    Thanks
    653
    Thanked
    1,580 times in 1,006 posts
    • MadduckUK's system
      • Motherboard:
      • MSI B450M Mortar
      • CPU:
      • AMD Ryzen 5 3600
      • Memory:
      • 32GB 3200 DDR4
      • Storage:
      • 1x480GB SSD, 1x 2TB Hybrid, 1x 3TB Rust Spinner
      • Graphics card(s):
      • Radeon 5700XT
      • PSU:
      • Corsair TX750w
      • Case:
      • Phanteks Enthoo Evolv mATX
      • Operating System:
      • Windows 10 x64
      • Monitor(s):
      • Samsung SJ55W, DELL S2409W
      • Internet:
      • Plusnet 80

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by Ephesians
    Do not be drunk with wine, which will ruin you, but be filled with the Spirit
    Vodka

  3. #19
    ɯʎɔɐɹsɐʌʍ mycarsavw's Avatar
    Join Date
    Feb 2007
    Posts
    4,945
    Thanks
    1,097
    Thanked
    653 times in 482 posts
    • mycarsavw's system
      • Motherboard:
      • P8H77-M Pro
      • CPU:
      • i5 3350P
      • Memory:
      • 16Gb
      • Storage:
      • Lots
      • Graphics card(s):
      • R9 285
      • PSU:
      • HX 620w
      • Case:
      • FD Define Mini
      • Operating System:
      • W10
      • Monitor(s):
      • BenQ G2420HDBL + GL2450HT
      • Internet:
      • Sky

    Re: Someone is stealing my bandwith ????

    Work your way through the suggestions in this thread - http://forums.majorgeeks.com/showthread.php?t=35407.

    If you're still stuck at the end of it, start a thread over there and let them sort you out.
    |Kata: "Read title as 'fisting'. Not sure why I clicked. Relieved, really."|
    |TAKTAK: "It was so small that mine wouldn't fit into it"|

  4. Received thanks from:

    melon (09-03-2012)

  5. #20
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by mycarsavw View Post
    Work your way through the suggestions in this thread - http://forums.majorgeeks.com/showthread.php?t=35407.

    If you're still stuck at the end of it, start a thread over there and let them sort you out.
    Sorry but no.

    We've got at least a remote access trojan.

    "I say we take off and nuke the site from orbit."
    throw new ArgumentException (String, String, Exception)

  6. Received thanks from:

    melon (09-03-2012)

  7. #21
    ɯʎɔɐɹsɐʌʍ mycarsavw's Avatar
    Join Date
    Feb 2007
    Posts
    4,945
    Thanks
    1,097
    Thanked
    653 times in 482 posts
    • mycarsavw's system
      • Motherboard:
      • P8H77-M Pro
      • CPU:
      • i5 3350P
      • Memory:
      • 16Gb
      • Storage:
      • Lots
      • Graphics card(s):
      • R9 285
      • PSU:
      • HX 620w
      • Case:
      • FD Define Mini
      • Operating System:
      • W10
      • Monitor(s):
      • BenQ G2420HDBL + GL2450HT
      • Internet:
      • Sky

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by TheAnimus View Post
    Sorry but no.

    We've got at least a remote access trojan.

    "I say we take off and nuke the site from orbit."
    You're not a DM reader, be rational, it's not insurmountable.

    Copying the files off to another location could easily bring the trojan with them, thus infecting another HDD?

    Start with the basics - download the tools you need (from another PC if you can) to perform the suggestions in the thread and then remove the connection to the internet.
    |Kata: "Read title as 'fisting'. Not sure why I clicked. Relieved, really."|
    |TAKTAK: "It was so small that mine wouldn't fit into it"|

  8. #22
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by mycarsavw View Post
    You're not a DM reader, be rational, it's not insurmountable.

    Copying the files off to another location could easily bring the trojan with them, thus infecting another HDD?
    No, no it can't.

    It could write the boot sector of the device, hell it could even convert every JPEG or WMF to have a known exploit for GDI+ system to allow arbitary code execution.

    None of that will be a problem if the steps I gave are followed, refromat from a known good source (ie DVD) Apply all patches, updates and set up MSE or similar. Then in a restricted user scan the drive and copy the files across to restricted places only. Nothing in Program Files or Windows folder.
    Quote Originally Posted by mycarsavw View Post
    Start with the basics - download the tools you need (from another PC if you can) to perform the suggestions in the thread and then remove the connection to the internet.
    We've got a simple trojan already picked up, a few odd connections to an AUZ host (didn't want to pry) but not nearly enough for a computer that has had that kind of infection on average has.

    As such I'd hazard a guess there is a rootkit present, or at the very least stealthed files.

    Given that OP hasn't followed proper security procedures, I don't think he will get a removal of such things right.
    throw new ArgumentException (String, String, Exception)

  9. Received thanks from:

    Apex (09-03-2012),mycarsavw (09-03-2012)

  10. #23
    ɯʎɔɐɹsɐʌʍ mycarsavw's Avatar
    Join Date
    Feb 2007
    Posts
    4,945
    Thanks
    1,097
    Thanked
    653 times in 482 posts
    • mycarsavw's system
      • Motherboard:
      • P8H77-M Pro
      • CPU:
      • i5 3350P
      • Memory:
      • 16Gb
      • Storage:
      • Lots
      • Graphics card(s):
      • R9 285
      • PSU:
      • HX 620w
      • Case:
      • FD Define Mini
      • Operating System:
      • W10
      • Monitor(s):
      • BenQ G2420HDBL + GL2450HT
      • Internet:
      • Sky

    Re: Someone is stealing my bandwith ????

    I agree to a point, but your last statement kinda goes against your first (now in bold)

    Quote Originally Posted by TheAnimus View Post
    None of that will be a problem if the steps I gave are followed, refromat from a known good source (ie DVD) Apply all patches, updates and set up MSE or similar. Then in a restricted user scan the drive and copy the files across to restricted places only. Nothing in Program Files or Windows folder.We've got a simple trojan already picked up, a few odd connections to an AUZ host (didn't want to pry) but not nearly enough for a computer that has had that kind of infection on average has.

    [...]

    Given that OP hasn't followed proper security procedures, I don't think he will get a removal of such things right.
    If it was my PC, I'd want to rescue it (more for the thrill of the challenge than anything but...) - your reasoning is more sound though.

    It's also much quicker to start again.
    |Kata: "Read title as 'fisting'. Not sure why I clicked. Relieved, really."|
    |TAKTAK: "It was so small that mine wouldn't fit into it"|

  11. #24
    Going Retro!!! Ferral's Avatar
    Join Date
    Jul 2003
    Location
    North East
    Posts
    7,860
    Thanks
    562
    Thanked
    1,439 times in 877 posts
    • Ferral's system
      • Motherboard:
      • ASUS Z97-P
      • CPU:
      • Intel i7 4790K Haswell
      • Memory:
      • 12Gb Corsair XMS3 DDR3 1600 Mhz
      • Storage:
      • 120Gb Kingston SSD & 2 Tb Toshiba
      • Graphics card(s):
      • Sapphire Radeon R9 380 Nitro 4Gb
      • PSU:
      • Antec Truepower 750 Watt Modular
      • Case:
      • Fractal Design Focus G Mid Tower
      • Operating System:
      • Windows 10 64 bit
      • Monitor(s):
      • 28" iiyama Prolite 4K
      • Internet:
      • 80Mb BT Fiber

    Re: Someone is stealing my bandwith ????

    Could try removal with Malwarebytes after booting into safe mode without networking. Its pretty comprehensive and manages to remove most things.

    Reformat is the definate get shot of but I always look at recovery first and formost

  12. Received thanks from:

    melon (09-03-2012)

  13. #25
    Not a good person scaryjim's Avatar
    Join Date
    Jan 2009
    Location
    Gateshead
    Posts
    15,196
    Thanks
    1,231
    Thanked
    2,291 times in 1,874 posts
    • scaryjim's system
      • Motherboard:
      • Dell Inspiron
      • CPU:
      • Core i5 8250U
      • Memory:
      • 2x 4GB DDR4 2666
      • Storage:
      • 128GB M.2 SSD + 1TB HDD
      • Graphics card(s):
      • Radeon R5 230
      • PSU:
      • Battery/Dell brick
      • Case:
      • Dell Inspiron 5570
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 15" 1080p laptop panel

    Re: Someone is stealing my bandwith ????

    My experience of dealing with virus-ridden machines (in particular a family with one PC that was used for all their business purposes *and* as the main family PC - two teenage children *shudder*) is that once you hit a certain critical mass of problem files the time spent trying to unpick the problems on the current install is amost always an order of magnitude greater than the time it takes to do a fresh install and restore backed up critical files. Hell, I used to keep a machine around specifically for scanning the backups from infected machines (which I would then nuke and reinstall regularly) so I didn't infect any of my critical machines, and it was *still* quicker and more efficient than trying to clean a heavily infected machine.

    As much as it may be possible to thoroughly and properly clean the OPs computer, I sincerely doubt that it's worth the time and effort, particularly since you only need one unrecognised threat to start the whole nasty mess off again ... after all, no anti-virus or threat detector is 100% effective.

  14. Received thanks from:

    melon (09-03-2012)

  15. #26
    Seriously casual gamer KeyboardDemon's Avatar
    Join Date
    Feb 2012
    Location
    London
    Posts
    3,013
    Thanks
    774
    Thanked
    280 times in 242 posts
    • KeyboardDemon's system
      • Motherboard:
      • Asus Sabretooth Z77
      • CPU:
      • i7 3770k + Corsair H80 (Refurbed)
      • Memory:
      • 16gb (4x4gb) Corsair Vengence Red (1866mhz) - (Because it looks good in a black mobo)
      • Storage:
      • Crucial M550 SSD 1TB + 2x 500GB Seagate HDDs
      • Graphics card(s):
      • EVGA GTX 980 SC ACX 2.0 (Warranty replacement for 780Ti SC ACX)
      • PSU:
      • EVGA 750 watt SuperNova G2
      • Case:
      • Silverstone RV03
      • Operating System:
      • Windows 10 Pro 64 Bit
      • Monitor(s):
      • Asus Swift PG278Q
      • Internet:
      • BT Infinity (40mbs dl/10mbs ul)

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by Ferral View Post
    Could try removal with Malwarebytes after booting into safe mode without networking. Its pretty comprehensive and manages to remove most things.

    Reformat is the definate get shot of but I always look at recovery first and formost
    I tend to follow this school of thought, recover the system, back up essential data/files, gamesaves etc... Then get those files scanned from a protected PC for hidden threats etc... I have an older PC with no OS installed as I ran out of licences so I usually install a trial of Windows, update it and the install a trial of a good Internet Security package like Kaspersky and use this to scan the external HDD with the copied files on.

    Once I'm confident that I have no more files with issues and that my most important files are safe then I will reformat and install from fresh. But I think it has been close to 10 years since I have had to do this on any of my own computers.

  16. Received thanks from:

    melon (09-03-2012)

  17. #27
    Chaos Monkey Apex's Avatar
    Join Date
    Jul 2003
    Location
    Huddersfield
    Posts
    4,706
    Thanks
    1,139
    Thanked
    284 times in 203 posts
    • Apex's system
      • Motherboard:
      • Asus Z87M-PLUS
      • CPU:
      • Intel i5-4670K
      • Memory:
      • 32 GiB
      • Storage:
      • 20 TiB
      • Graphics card(s):
      • PowerColor Radeon RX 6700 Fighter 10GB OC
      • PSU:
      • 750
      • Case:
      • Core View 21
      • Operating System:
      • Windows 10 pro
      • Monitor(s):
      • Dell S2721DGFA
      • Internet:
      • 200Mb nTL Cable

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by TheAnimus View Post
    No, no it can't.

    It could write the boot sector of the device, hell it could even convert every JPEG or WMF to have a known exploit for GDI+ system to allow arbitary code execution.

    None of that will be a problem if the steps I gave are followed, refromat from a known good source (ie DVD) Apply all patches, updates and set up MSE or similar. Then in a restricted user scan the drive and copy the files across to restricted places only. Nothing in Program Files or Windows folder.We've got a simple trojan already picked up, a few odd connections to an AUZ host (didn't want to pry) but not nearly enough for a computer that has had that kind of infection on average has.

    As such I'd hazard a guess there is a rootkit present, or at the very least stealthed files.

    Given that OP hasn't followed proper security procedures, I don't think he will get a removal of such things right.
    ^This - If there is a root kit on there then he/she would be stuffed and wasiting their time trying to unpick it.

    Been there done that leanred when to give up and nuke it.

  18. #28
    Comfortably Numb directhex's Avatar
    Join Date
    Jul 2003
    Location
    /dev/urandom
    Posts
    17,074
    Thanks
    228
    Thanked
    1,027 times in 678 posts
    • directhex's system
      • Motherboard:
      • Asus ROG Strix B550-I Gaming
      • CPU:
      • Ryzen 5900x
      • Memory:
      • 64GB G.Skill Trident Z RGB
      • Storage:
      • 2TB Seagate Firecuda 520
      • Graphics card(s):
      • EVGA GeForce RTX 3080 XC3 Ultra
      • PSU:
      • EVGA SuperNOVA 850W G3
      • Case:
      • NZXT H210i
      • Operating System:
      • Ubuntu 20.04, Windows 10
      • Monitor(s):
      • LG 34GN850
      • Internet:
      • FIOS

    Re: Someone is stealing my bandwith ????

    There's only one solution to an infestation like this.


  19. Received thanks from:

    CAT-THE-FIFTH (09-03-2012),pollaxe (09-03-2012),Terbinator (09-03-2012)

  20. #29
    Anthropomorphic Personification shaithis's Avatar
    Join Date
    Apr 2004
    Location
    The Last Aerie
    Posts
    10,857
    Thanks
    645
    Thanked
    872 times in 736 posts
    • shaithis's system
      • Motherboard:
      • Asus P8Z77 WS
      • CPU:
      • i7 3770k @ 4.5GHz
      • Memory:
      • 32GB HyperX 1866
      • Storage:
      • Lots!
      • Graphics card(s):
      • Sapphire Fury X
      • PSU:
      • Corsair HX850
      • Case:
      • Corsair 600T (White)
      • Operating System:
      • Windows 10 x64
      • Monitor(s):
      • 2 x Dell 3007
      • Internet:
      • Zen 80Mb Fibre

    Re: Someone is stealing my bandwith ????

    This is why I like a system image backup online that is less than a week old.
    Main PC: Asus Rampage IV Extreme / 3960X@4.5GHz / Antec H1200 Pro / 32GB DDR3-1866 Quad Channel / Sapphire Fury X / Areca 1680 / 850W EVGA SuperNOVA Gold 2 / Corsair 600T / 2x Dell 3007 / 4 x 250GB SSD + 2 x 80GB SSD / 4 x 1TB HDD (RAID 10) / Windows 10 Pro, Yosemite & Ubuntu
    HTPC: AsRock Z77 Pro 4 / 3770K@4.2GHz / 24GB / GTX 1080 / SST-LC20 / Antec TP-550 / Hisense 65k5510 4K TV / HTC Vive / 2 x 240GB SSD + 12TB HDD Space / Race Seat / Logitech G29 / Win 10 Pro
    HTPC2: Asus AM1I-A / 5150 / 4GB / Corsair Force 3 240GB / Silverstone SST-ML05B + ST30SF / Samsung UE60H6200 TV / Windows 10 Pro
    Spare/Loaner: Gigabyte EX58-UD5 / i950 / 12GB / HD7870 / Corsair 300R / Silverpower 700W modular
    NAS 1: HP N40L / 12GB ECC RAM / 2 x 3TB Arrays || NAS 2: Dell PowerEdge T110 II / 24GB ECC RAM / 2 x 3TB Hybrid arrays || Network:Buffalo WZR-1166DHP w/DD-WRT + HP ProCurve 1800-24G
    Laptop: Dell Precision 5510 Printer: HP CP1515n || Phone: Huawei P30 || Other: Samsung Galaxy Tab 4 Pro 10.1 CM14 / Playstation 4 + G29 + 2TB Hybrid drive

  21. #30
    Senior Member
    Join Date
    Aug 2005
    Posts
    1,528
    Thanks
    18
    Thanked
    76 times in 63 posts
    • lodore's system
      • Motherboard:
      • X570 AORUS MASTER
      • CPU:
      • Amd Ryzen 5900x
      • Memory:
      • 32GB DDR4 2666 Mhz
      • Storage:
      • 1TB Gigabyte AORUS 7000s SSD and sandisk 1tb sata 3
      • Graphics card(s):
      • EVGA 1080TI 11gb
      • PSU:
      • Ion+ 860W
      • Case:
      • Corsair 4000D AIRFLOW
      • Operating System:
      • Windows 10 pro 64bit
      • Monitor(s):
      • Iiyama 34inch ultra wide quad HD 144hz and 24inch asus HD
      • Internet:
      • 80Mbps Zen

    Re: Someone is stealing my bandwith ????

    I agree with TheAnimus.
    To reduce the risk of infection to the fresh installed OS I would recommend using a antivirus rescue disc to scan the user files copied to external drive. there are a few free solutions avaliable. my favourite atm is the kaspersky one.

  22. #31
    Banned
    Join Date
    May 2011
    Location
    points down
    Posts
    3,223
    Thanks
    467
    Thanked
    132 times in 111 posts

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by kalniel View Post
    Never heard of that before. Is it this one:
    http://www.pcmag.com/article2/0,2817,2364196,00.asp
    ?

    With one off scanners it's no problem running more than one (just not at the same time!) - so try MBAM as well.

    Anyway, sounds like you did have some bad things around. If you have difficulty removing them look up combofix.
    Yes thats it , it detected 25 objects which I deleted as opposed to the other which I just put in quarantine.

    m

  23. #32
    Banned
    Join Date
    May 2011
    Location
    points down
    Posts
    3,223
    Thanks
    467
    Thanked
    132 times in 111 posts

    Re: Someone is stealing my bandwith ????

    Quote Originally Posted by Ferral View Post
    Could try removal with Malwarebytes after booting into safe mode without networking. Its pretty comprehensive and manages to remove most things.

    Reformat is the definate get shot of but I always look at recovery first and formost
    should I try it again then as I just booted in normally ?

    m

Page 2 of 3 FirstFirst 123 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •