gfxgfx
 
Please login or register.

Login with username, password and session length
 
gfx gfx
gfx
76793 Posts in 13502 Topics by 1651 Members - Latest Member: Arnold99 November 23, 2024, 04:23:13 pm
*
gfx*gfx
gfx
WinMX World :: Forum  |  WinMX Help  |  Other WinMX Help  |  Unrequested downloads
gfx
gfxgfx
 

Author Topic: Unrequested downloads  (Read 1216 times)

0 Members and 1 Guest are viewing this topic.

Offline Lorax

  • Forum Member
Unrequested downloads
« on: May 06, 2008, 06:24:06 pm »
I've looked through the forums and haven't found this mentioned.  I'm running WinMX 3.54 on Windows XP Pro SP2.  I generally leave it up overnight.  A couple of mornings ago, I found a lot of incomplete files that I had not downloaded in the incoming directory.  There was a lot of porn, a few mp3 files from groups I hadn't even heard of and a bunch of foreign language filenames.  Has anyone else had anything like this happen?  None of it was completed because I guess our cats had unplugged the network cable as has happened before.  There was no one else in the house at that time except for my wife and our toddler so I'm pretty certain no one in the house started the downloads.  I guess I'm wondering if there's some kind of Malware that can control WinMx, a rogue version of WinMx or if I should be looking for something that's permitting someone to have even broader access to my computer?

At the time, I didn't think that much of it and just deleted the files, but as time goes by I wonder how long this might have been happening and what's been downloaded through my computer.  I don't share the incoming directory so at least there's that.  I noticed something similar a few months ago, but chalked it up to my nephew, who was staying with us at the time, but he wasn't there during this last episode.  I'm a little freaked out by this.  Does anyone have any ideas?

Thanks

Offline Me Here

  • Ret. WinMX Special Forces
  • WMW Team
  • *****
  • We came, We Saw, We definitely Kicked Ass!
Re: Unrequested downloads
« Reply #1 on: May 06, 2008, 09:11:34 pm »
Hi Lorax,

To my knowledge which is quite vast there is no program that is making rounds that will control WinMX causing it to download things you didnt ask for. 

This leaves only a few possibilities,
1) As you mentioned someone in the house controlling the machine and using it to get these files, and I'm with you, If your toddler did this your going to need a lot of money for college tuition's.. lol so i wouldn't think them,  So I'm wondering is it possible that when Nephew came and  tried files, were some of them still left in the Incoming folder and some how when this happen the last time, winmx found sources for those and added them to the screen?  Not likely.  If your sure its not the Mrs, and absolutely no one else could have had access within the house... then move to 2
   
2) Just how  good with computers is your nephew, or has anyone else had access to the machine in the last few months that could have installed a program like RealVNC (this is a program designed to allow remote desktop control).  Windows has this ability built into it and you may want to go through a few things to ensure its not installed or been activated.  This would allow someone anywhere else in the world access when ever they wanted.
   a) Go through the control panel > add/remove programs - Make sure everything there is something you use, know, and look at   the dates last used of anything you don't know.  Remove anything suspicious.
   b) Go to Start > Run > type in                  msconfig
  A box will open, click on Start Up Items Tab, and go through that list of things starting up with Windows, anything odd?   any thing you don't know what it is........Google it and find out.  Untick anything suspicious, basically lots of things put   start up items in here that are quite innocent but still don't need to start with windows, you can start most of them on   your own instead and have more control.
   c) Go in the Control Panel > Administrative Tools > Services and make sure that any remote desktop services or Stopped, if   you find any running stop them.
   d) If you do find these things on the System, consider making a basic User account for when family esp kids are over and   do some research on making user accounts with parental controls and password protect Your account on the system. 
  This will allow younger ones to still use the PC but you can set it so that no downloads can take place, no browsing those   'sites', and that they cant install things without the administrative passwords.

3) Make sure your system is running clean, and run the needed spyware and adware programs along with a good antivirus scan to be sure its ok.  Most of these types of things wont do what your describing but its a good idea any time a kid has been on a PC to clean it after, hey its just fun to click all that stuff that looks so cool, they don't really understand always that just clicking ads or neat looking programs can add major problems to a PC.
Here is a page that gives you some we recommend:
Virus, and Nasties Removal and Prevention

Post back and let us know how your doing or if you have any questions.

Offline Lorax

  • Forum Member
Re: Unrequested downloads
« Reply #2 on: May 07, 2008, 02:31:14 am »
Hello Me Here,

Thank you so much for the advice.  I think you might have hit the nail on the head.  At some point RealVNC 4.11 has been installed on my machine.   On top of that, from the internet I gather that this version has some real security problems that would make it custom made for this sort of thing.  Needless to say, it's toast now although it looks like it's been here for quite a while - long enough to account for the earlier episode I noticed.  I feel like a noob for not noticing that the RealVNC program  was running all this time, but we have other computers and the problem one sits unattended most of the time.

I have the firewall, and the anti-virus/spyware/adware programs but of course none of those flagged any problems.  I'm assuming that either someone has deliberately installed the remote desktop program or it somehow piggybacked on another installed program.  Either way, I'm keeping a closer eye on the machine now and I'm thinking it will spend its night off from now on.  I'm also checking to see how this got past the firewalls - I thought incoming remote desktop connection ports were usually blocked by default.

Thanks again.

Lorax

Offline Me Here

  • Ret. WinMX Special Forces
  • WMW Team
  • *****
  • We came, We Saw, We definitely Kicked Ass!
Re: Unrequested downloads
« Reply #3 on: May 07, 2008, 03:01:49 am »
I'm glad you found the culprit, its more then likely something that someone with access in your house has installed thats probably why it didnt get noticed before and anyone knows how to use this can easily open port for it in the router or can set it to non default ports.  Its a good program with many legitimate uses, so its not likely to be bundled with anyting else.

Either way its not all bad, if for example it is the nephew lets just say... hes a smart kid and just needs better uses for those talents of his.. lol  Get him some programing books for his next christmas lol.

Good luck and let us know if there is anything else we can help with.

WinMX World :: Forum  |  WinMX Help  |  Other WinMX Help  |  Unrequested downloads
 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Warning: this topic has not been posted in for at least 120 days.
Unless you're sure you want to reply, please consider starting a new topic.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
What program is this site about?:
What year is it next year?:
What's the name of the site this forum belongs to?:

gfxgfx
gfx
©2005-2024 WinMXWorld.com. All Rights Reserved.
SMF 2.0.19 | SMF © 2021, Simple Machines | Terms and Policies
Page created in 0.009 seconds with 23 queries.
Helios Multi © Bloc
gfx
Powered by MySQL Powered by PHP Valid XHTML 1.0! Valid CSS!