View Full Version : Massive data upload when dialup adapter is running
videobruce
10-16-2003, 12:20 PM
After a few minutes without a browser running using DU Meter as a in/out monitor I'm getting a massive (for a analog connection) upload of unknown data to a unknown destination by a unknown process.
I have:
Done a virus scan (though not up to date definations)
Used AdAware V6 and SpyBot V1.2
Checked processes running
I am running 2k w/sp3 The laptop was upgraded with Idiot Exploiter 6 from M$'s site (this isn't my laptop BTW).
Before the dialer was starting byself, now it seems ok, but not sure yet.
The laptop freezes where only a reboot solves the condition (no browser running the last time).
The IE update was the last upgrade/change AFAIK.
It is almost as this machine was doing a DOS attack to another site by uploading massive amounts of data somewhere.
doctorgonzo
10-16-2003, 12:34 PM
Could be totally innocent, but you should check to make sure.
Run a firewall (like ZoneAlarm). It should be able to tell you who you are connecting to so you can judge whether it is valid or not.
Also, you really need to scan your computer with updated virus definitions.
videobruce
10-16-2003, 12:48 PM
DU Meter is showing between 60 and 110 kbps which is slightly unusual for a dialup connection!
It starts after a few minutes, runs for a few minites, stops for maybe 20secs, then resumes.
Right now as I type this it is showing around 90kbps uplaod. It is so bad it slows the d/l's to a point I can't even post in forums as this one.
doctorgonzo
10-16-2003, 12:52 PM
This is on dialup? That sounds totally screwy. A scan for virii and trojans should be done before anything else.
videobruce
10-16-2003, 02:39 PM
Yes it is on dialup.
I tried to run Zone Alarm, but there is a problem betwen the display driver and the program. There isn't any update for the display device either, so no Zone Alarm (this is a Laptop).
videobruce
10-16-2003, 10:01 PM
To make a short story long, it appears to be a worm;
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_NACHI.A
Problem is I can't install that M$ patch because the install I did is a slipstreamed SP3 burned CD and on top of that I also I do a 'LittleWhiteDog NTOSKRNL mod' using Resource Hacker to change that damn M$ splash screen.
I get a error when I try to install that patch stating I need something newer that SP2. I already have SP3 installed.
Not to stop there, since I didn't know what was doing this and thought it was the dialup adapter I connected the Laptop to my network so I could d/l a updated virus package from TrendMicro (which I did). After running the updated virus definitions that NACHI.A worm showed up.
I had my main box on also and that got affected also!
NACHI.A just did my machine.
I did a manual remove on both machines and it seems to be gone. Too early to tell yet. I don't know where he got it from.
vBulletin® v3.7.0, Copyright ©2000-2008, Jelsoft Enterprises Ltd.