Trojan Horse Attack
Information and Help Center

( News of the situation will be appened to the end of this page - so log in whenever you want )

Click here ... to e-mail me
Click here ... For the Tools and sites area
Click here ... for news about the healing network

What on-earth happened?!
On Friday (29th January 2005) our network was hit by at least one "Trojan-Horse" kind of virus.
Many computers were hit. On our first reaction to the attack we counted 200 infections on 15 computers
The network came to a standstill and we immedietly got underway with a defence plan.

Are you doing anything about it?
All areas were shut down manualy at main-hub to stop the virus from spreading between network areas.
( This is very much like shutting down partitions in a submarine when it starts getting flooded)
We then started opening up one area after the other, sometimes more than one at a time, and checking every computer in that particular area. All this to try opening up various areas as quick as possible
while keeping the attack at a level we could actually work with.

So can we work on the internet?
At this stage only those who are physicaly connected can work on the "Broadband"
Anyone who has a Dial-up connection, can work with it and we recommend people do so untill we can bring this virus down to it's knees. It's slow but it works

What are we actualy doing about it?
Five people have been recruted so far, to help with this defense plan and we are slowly but surely getting on top of things. We are working on various levels: Checking each computer with the built-in and other, defense software. Keeping a constant 24-hour watch on the network from an emergancy-built headquarters. Studying the situation constantly, trying to pin-point the source(s) of trouble and deal with them
In parallel, we are in contact with various help sources from outside, experts and experienced people in the field.
There is a lot of detective work going on, searching and hunting down the virus, pinpointing it's latest point of attack, learning new tools to deal with this virus. Keeping an eye open for re-infected computers, and at the same time planning for tomorrow too. After all we clean up everything and what happens tomorrow?.....
I will be placing various tools and sites that can be used by every network user, to help clean up this mess, each at his/her level of knowledge and understanding.

I thank you for your patience and understanding

David Ellman  


Tools area:- Please feel free to use them for keeping your computer clean

a. -
"TrendMicro" online virus scanner
b. - "Panda" online virus scanner (use "active scan" at bottom left)
c. - "BitDefender" online virus scanner
d. - "Symantec" online virus scanner (Norton)
e. - "RAV Antivirus" online virus scanner

Warning!! Don't have more than one anti-virus program running on your computer at any one time
(they tend to see each other as viruses and could end up cleaning each other out )

f. - "AVG" free anti-virus - in case you don't have one or don't like the one you have

g. - Spybot - removes spyware programs
h. - Adaware - removes adware programs
I. - WCShredder - removes browser highjack programs

J. - When cleaning viruses you may come across an issue called "Turning system Restore, on or off"
Here is a link that explains what this means and how it is done.


A few things to think about:-

Whichever procedure you use, make sure you do it often enough. You cannot over-clean your computer. Before using your anti-virus program, make sure the virus definitions are updated

Use "SpyBot" and "Adaware" frequently. They clean up all kinds of "spyware" programs. If you have alternative programs that work, and you know what they do, use them.

You could try your hand at "HighjackThis" ( After you reach the page, Roll down till you get to the download section. )
"HighjackThis" is somewhat more complicated. You are dealing with the background services of your system so take care before you remove anything. ( recommended using in SAFE MODE )

Make sure you use "Windows Updates" too, they are there to shut down security holes as they are discovered. If you can't find "Windows Update" on your computer, Click Here

Clean out files you don't need especialy "cookies" and "temporary files". Both can be found in your browser under "tools/options/" and there look for "delete cookies" and "delete files"

Here is an article by AVG, found by Rut Ney. Article deals with cleaning your computer. Give it a try, it might "speak" to you.
For the article Click Here

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 


Latest update Wed. 9/2/05:-

We are about to have a meeting with a group of seven who have volunteered to help out with this crises
This morning I checked the results of last night's manouver with Adi (Kinneret) and we managed to open up ICQ and IRC That had been shut down yesterday. Now all that is closed are the file sharing programs and the PING utility.
This does not allow us to forget about the viruses that are still confined to, but still running rampant on, the network

update Tue. 8/2/05:-

Plan A was to work by areas which proved to be a bad decision as the "clean" area was re-infected
by the next area so fast that it was just impossible to deal with..
Plan B was then put into action by which ALL the areas were turned on and using special equipment and software,
we pin-pointed the infected computer and shut it down till the "ground-patrol" cleaned it.
It was a good plan: "The operation was successful but the patient died" - the network was just
about dead in the water
Plan C, that came from Kinneret was then started by which all special programs were denied working on the network
That includes Kazaa, Emule Edonkey and so on, and IRC, Messenger, ICQ and the famous PING
What is working now is regular browsing and email plus specific programs such as needed by the accounting department

The network seems to be running ok now
This is all temporary until we find a way of getting rid of the viruses that are still running wild inside the network.

Tomrrow (wed) we are having an emergancy meeting to plan our moves ahead.

Update Fri 5/2/05:-

We have 201 written connections to the network. Found so far - 341 viruses on 16 computers
Things have started moving. We see a light at the end of the tunnel, and it's NOT a train!!
We now have four working areas. Closing last security holes - will be expanding a.s.a.p.