View Full Version : Bunch of P2P Apps Installed Out of Nowhere
Smurf_Pimp
December 7th, 2004, 04:33 PM
A friend of mine recently installed Azureus and downloaded a file off of it. I believe when I installed it for her I used for 30000 as the port for it to use for connections and I opened it on her NAT. When she went on there today, half of her hard drive was used up, and just about every P2P app known to man was installed on there. Her father made her uninstall every P2P app that was installed along with all of her old ones until he found out what went wrong. A virus scan using AVG came up clean. She is saying that it was probably caused by my opening the port but I don't know of any exploit in port 30000 that would do that? So what could it be? My best guess was a trojan but why wouldn't AVG pick it up? Also, there may have been a ware downloaded but I do not know of it's contents so I can't really comment on it. It was my other suspicion.
The Hunter
December 7th, 2004, 04:47 PM
An antivirus is not a program best used to find a trojan. First off have spyware tests been run? IE spybot search and destroy, and adaware? Also online virus scanners are a good thought. these must be run in Internet Explorer.
http://housecall.trendmicro.com/
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
Give these a try, and post your results.
Smurf_Pimp
December 7th, 2004, 04:51 PM
tried them all and nothing. but i think i may have found the root of the problem. i got her to send me that ware, and when i tried to run it spysweeper went nuts. it tried to make something run on startup and changed my IE main page so i am almost positive that it was the main cause...
The Hunter
December 7th, 2004, 04:55 PM
First off, stop using IE. Firefox is much more secure. Did she try the three finger salute? IE controll alt delete, to see what was running?
Smurf_Pimp
December 7th, 2004, 05:12 PM
I do use firefox, and so does she, I just said that it changed my IE homepage because that is what spysweeper told me.
Solved my own problem. The thing that the ware caused to run at startup was called letsroll.exe, also known as W32.Depress@mm. As seen here it is known for installing many P2P apps. http://techrepublic.com.com/5208-6239-0.html?forumID=49&threadID=162907
The Hunter
December 7th, 2004, 05:18 PM
The suggestion of spywareblaster is a good one also. Ares is the program i personally use, and Im getting all the files I want, just dont install navhelper during the install. Some of these nasties can be tough to get rid of.
vBulletin® v3.8.4, Copyright ©2000-2010, Jelsoft Enterprises Ltd.