A question for the group

Jul 05, 2006 22 Replies

I've been lurking awhile and I needed to post this time for help. I believe that I have caught my computer dialing a number which I do not want it to dial. Is such a thing even possible? More specifically, I have several numbers for my local sign-up service, and I do not want my computer to dial any number other than one of these. Is it possible that I might have unintentionally downloaded a virus which is capable of doing this? Is any virus capable of doing this? Has anyone else ever experienced this problem? Do I now need to build a box to defend my lame computer? Please help!



Saxon



It sure is. There are viruses that do this sort of thing. Unplug the phone line to the PC until you solve the problem.

If it is a Windows computer, use a different computer to download the latest anti-virus software and run it on the suspect computer. After you run the virus scan, restart the PC in safe mode and run it again. The restart it again and run it yet again.

If the anti-virus software never reports that it found a virus go buy a different one and try it. After the normal mode and safe mode scan, the

3rd scan should come up clean. It may then be safe to reconnect the phone line. [...]

The box to do this isn't all that hard. All you need is a switch in series with the phone lines.

-- kensmith@rahul.net forging knowledge

When I ran dialup, I had an LED indicator to tell when the computer grabbed the phone line and a swich to disconnect it. This happened most frequently while installing new software that decided to 'phone home' with information.

Viruses and Trojans do this stuff all the time. I now use Zone Alarm to protect my system on DSL.

Luhan

Dealing with Unwanted Spyware and Parasites

formatting link

There are dozens of groups where your question would have been more appropriate:

formatting link
alt.comp.virus alt.comp.anti-virus

24hoursupport.helpdesk comp.os.ms-windows microsoft.public.security.virus microsoft.public.*.*

There are a lot of "call home" applications that get loaded on your computer. If you have IE set to automatically dial your ISP, then these programs will cause IE to call and connect to the net via your ISP. You should select "never dial a connection" in the IE "connections" setup. In times past there have been scams that had persons download "free p*rn viewer" applications that would secretly call expensive dialin numbers in foreign countries resulting in very large phone bills that were difficult to dispute.

The best solution would be a hardware firewall that supports dialup, but I'm not sure if such a thing exists. There are certainly devices that have analogue modem support as a backup, but that is typically only on high-end firewalls. It is also quite practical to use an old computer as a firewall - the linux router project will run on pretty much anything that has a network adaptor.

A real firewall/router will cost about $30, and do a vastly better job of protecting your network or PC from trojans and other nasties. And your ISP should be able to virus-scan your emails for you - again, they will (should!) do a better job than a home system. There are certainly a few things a software firewall can do that a hardware one cannot, so it does no harm to have both, but the absolute rules in a hardware firewall are much harder to break, and being a "plug in and forget it" device, you don't need continuous updating.

In article , Luhan wrote: [....]

Many of the virus writers make sure that the user hasn't interacted with the PC for a while. If you walk away from the PC, flip the switch.

It appears that XP also does it. It needs to do this to send your personal^H^H^H^H^H^H^H^H^H check for updates.

SuSE also does it if you set the "YOU" updater to automatic.

-- kensmith@rahul.net forging knowledge

In article , David Brown wrote: [...]

They don't protect you from trojans. Trojans are named after that Greek horse that the idiots in Troy downloaded to inside their firewall.

I want my ISP to keep its hands off my e-mails. We really don't want the status of ISPs to be changed. Today, very like the phone company, they are not responsible for what is said over their system. I want ISPs to keep this protection.

As far as I know, there are no viruses for Apples. I think that this is in part because they are very well defended. The problem with the PC is that its software has a history that extends back to when "everything can be trusted". Microsoft has to make the new stuff work with the old software but somehow also make it protected against malware. This isn't an easy task even if it is given higher priority that animating that stupid paperclip.

-- kensmith@rahul.net forging knowledge

formatting link
formatting link
formatting link
formatting link

-- kensmith@rahul.net forging knowledge

You are correct - I used the wrong term. They protect you against worms, and direct attacks. The best protection against trojans is using your brain.

In general, that's true - but most offer a decent spam and virus filtering service on their mail servers.

There are viruses for Apples, just as there are viruses for Linux, BSD, and other *nixes. But they are very rare, and have never been a serious issue (there have been a couple of worms that were more serious, but not for a long time). Backwards compatibility is not the main problem with windows (after all, most *nix systems have lots of ancient software as well), but as you say prioritising is a big part of the problem. MS aims solidly for "easy to use" - regardless of whether that also means "easy to break". Windows users run with administrative rights, since it is far easier that way - *nix users run with limited rights, and therefore any malware they get hold of will have limited effect. Windows was always aimed at closed systems (single computers, then closed networks), so security was an afterthought, while *nix was used in the most hostile computer environments on earth (university labs) while BG was still searching dustbins for sample code to steal.

Of course, there is the aspect that there are more windows machines out there, and thus it's a bigger target, but the windows malware market is far out of proportion compared to the *nix malware market.

Hello David,

Plus de-activating "glitzware" such as extensive java scripting or players. This will cause some web sites to become impossible to navigate. However, IMHO such over-sophisticated fluff sites are usually not worth navigating anyway.

Regards, Joerg http://www.analogconsultants.com

It seems a no-brainer to you that a *n*x platform offers the ultimate hardening against Windoze-specific infections, but a guy that runs an M$ platform and obviously doesn't know what every 14-year-old should know

formatting link
isn't likely to get the point. 8-(

...and

formatting link
might be better for a Windoze weenie

...perhaps

formatting link

It sounds like you are talking about XP's built-in software "firewall"

--which doesn't filter egress traffic (making it HALF a software firewall).

Funny, today I made a forecast on another forum that ISPs may become more than just a telco and also offer protection to their customers given the importance of internet nowadays. Not that I want this to happen, but there are already signs that governments want to regulate internet in order to protect their citizens.

This is not quite true. The Apple OS is as vulnerable as any OS to trojan horses and other malware. Don't even think 'user mode' is going to help you (this is a very, very false assumption).

Clever criminals want to make money with your computer. They don't need root or administrator privileges to do so. All they need is a user with enough rights to download and run a program (even if it sits inside a corrupted JPG, PDF document, activeX control, executable, etc, etc) on a computer.

Regardless the OS, you'll need a virus scanner and a malware detector.

Reply to nico@nctdevpuntnl (punt=.) Bedrijven en winkels vindt U op www.adresboekje.nl

Rubbish. It's a false assumption if you think "user mode" will protect you entirely, but it helps enormously. On *nix systems (including Apple OS), a program running with a normal user level clearance cannot corrupt other programs. Even on windows, careful use of NTFS permissions and user level clearances can limit programs' damage to some extent, but on the majority of windows setups, any program can pretty much do what it wants to any files, including vital OS files. Add that on *nix systems, it is hard to get malware programs to run without user intervention, and you have an inherently much safer system (although never completely safe, obviously).

However, a malicious program would normally be able to access and damage your data files, which is often more of a problem - programs can be re-installed, while data files have to be replaced from your backups. And malware running as a user might have access to other user data, such as website logins. Finally, malware running as a user might be able to exploit software bugs to gain root access. So "user mode" is not a brick wall, but it is a very useful hinder against malware.

That's why on *nix systems, websites and emails can't "download and run" programs (Java applets is the nearest, and they are sandboxed by the browser) without user intervention, and why *nix browsers don't support things like ActiveX. They also don't support such absurdities as executable code embedded in wmf files and font files.

There is always the possibility of bugs in code leading to buffer overflow attacks and the like. *nix systems can protect against such attacks in three ways that are better than windows systems. First off is the "user mode" limitation, limiting possible damage. Many serious linux distributions have stack randomisation, making it extremely difficult to make working buffer overflow attacks. Finally, on *nix systems, the concept of shared libraries works properly, so bugs in library code can be updated once (by a download from your distro's website), and all your programs are fixed. With windows, if a bug is found in something like a MSVC run time library, practically every program on your system needs updating.

Regardless of the OS, you need to think about your security risks and take appropriate precautions. Even windows can be locked down pretty securely - if you set IE to maximum security then never use it again, and stick to decent browsers and email programs such as Firefox, Opera, and Thunderbird, with Java disabled unless you really want it, combined with a hardware firewall to block worms and direct attacks, and use some common sense about the sites you visit and the programs you download, then you will not get hit. On the other hand, if you believe your virus scanner and other malware detectors make you impervious, then sooner or later you *will* be hit.

Get Zone Alarm and "train" it. Whenever some program wants to dial or access the internet for the first time ZA pops up a window saying "program X wants to access (whatever)". If you know what it is allow and set to remember. If it's something odd like frgetr541.exe or longdistanceporndialer435.scr deny access and do some research on it. You can always change your mind later if you find it's harmless. Get Avira AV freeware. Good sense is still the best AV.

- YD.

Remove HAT if replying by mail.

I differ with your calls. I want to control just how much and exactly what filtering they do, failing this i minimize what they do. My current bottom line, some spam, some infected traffic gets in; very little legitimate traffic gets blocked. Best of all my ISP implements learning algorithms to see what i "rescue" and what i manually bounce: i make about two passes a month manually. Of course a really good implementation would allow me to use a SMTP client (suitable to a proper workstation) rather that a lowly POP client (suitable to a thin terminal).

Make no mistake, the market is for foolish users on thin clients rather than low grade admin class clients on workstations. The issue is not computational power but the home computer administrators capabilities, they just want it to work. Just the same i want to make IP's and ISP's common carriers; nearly like the way telephone is supposed to be. Net Neutrality is a Good Thing.

JosephKK Gegen dummheit kampfen die Gotter Selbst, vergebens.   --Schiller

Correct. That is why i have protection on all my machines, regardless of OS be it M$Windows, MACOS (including various X), Linux and BSD's. Please remember the very first (the Morris worm) infected Unix systems. Later sneakernet infected a lot of early MSDOS systems.

JosephKK Gegen dummheit kampfen die Gotter Selbst, vergebens.   --Schiller

Hello Joseph,

True neutrality is slowly deflating. A few days ago I ran for the first time into a case where you could not access certain web content if on an American ISP. Deutsche Welle, the German station that has the mission to spread German culture around the world just like VoA does for us, refused to play their TV news. All I got was a message stating that it's off limits for American users. So I wrote to them. Turns out they had struck a deal with Dish Network and the contract required them to cut off web streaming to us here in El Norte.

Regards, Joerg http://www.analogconsultants.com

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required