Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
This is a little long and I apologize, but any input on this weird situation would greatly be appreciated:
I got my phone bill yesterday and on it was charges to the UK for a total of $136.00. There was 3 Charges each lasting 20 mins for $45.43 each.
I called this 3rd party phone carrier and they stated that someone gave permission to charge our telephone for access to a website. She would not give me the website name saying it would violate the privacy act.
I told her that there is NO WAY that anyone in my household could have done this, one because of the early morning hours and one late evening. She also stated that is was not anything pornographic.
I have gotten nowhere as to finding out what website that we supposidly accessed 3 times in a row and these odd times. I have the phone number, but have be unsuccessful as to finding out what business it is associated with.
Because we dont have a firewall (which, now Im getting one) and we have high speed internet connection, that someone possibly could have tapped into our line and did this?
Im at a total loss.The phone companies are: USBI & One Call Communications. Both of which would not give me any information on these charges.
Any help or advice would greatly be appreciated.
Renee

hi renee,
you might have a trojan dialer in your computer.
lets find out:
hit your start button, then go to run, then type in command and click OK.
a dos prompt box will open up, at the flashing cursor type in "netstat -an" without the quotes and hit the enter key.
a box pops up with active connections opens up, it shows 4 columns, the most important being foreign address, and state.
if there is any address and port number in the foreign address and the word established in the state column, make note of them.
exit out of netstat.
go to www.thepublicworks.com, security section, and link to tantalo ports and enter the port number in the search box, if it comes up positive such as stating that it is a trojan, while at the publicworks, go to the payware section and hit the trojan hunter anti-trojan link, while there look for the download a 30 day free trial of it.
once downloaded, get the latest definitions, then also get the latest defs of your anti-virus. next go to safe mode by rebooting your computer, and hitting the f8 key while booting. once in safe mode scan your computer with trojan hunter and after that scan with your anti-trojan. delete all files that they come up with. also while there, in safe mode, clean your temporary internet files, your temp files, your history files, and your cookies folder. if you have adaware and spybot i would also scan with them in safe mode.
reboot your machine.
it would be a good idea to install a good free firewall such as outpost, or sygate, don't install the newer version of zone alarm as they are having problems with version 5. if you can get version 4.5 it would be better.
hope this helps, all the best,
murve

Thanks alot Murve! I will print out the instructions and jump on this tonight. I totally shut down my computer until I can get this fixed. I dont understand though is why I am not allowed the website information. That really upsets me. Is this something that I should report to the FBI?
Renee

First and for most, lets get you up-to-date on security. Download, install, update, and run all the programs I mention, if you dont update them, then dont bother downloading them, they will only work properly if you update them. Also, they are all free, so don't go out and buy some unneccassary program when you can get it for free!
SPYBOT (an excellent spyware detecter)</
Ad-Aware (an excellent spyware detecter)
After you download, install, update, and run those. Download the next tool.
It will install to your control panel, it is called Startup, open this and disable every program you don't recognize, then reboot. This will prevent nasty programs from loading when you start your computer. Download a free antivirus here.After you have downloaded it, install it, update it, and run it, then continue with my instructions.
Now you need to update your Windows operating system security. Do this by going to Start button-->settings-->control panel (same location as the startup program I mentioned) and open the windows update program. If you cant find this go here.
Download, install the updates, then reboot to enssure they are running.Finally,
Go to here to preform a scan on all open ports, this will tell you if your PC is vulnerable to internet attack. If it finds open ports, it will offer free programs to close them.
****************
If you have any problems, questions, comments, post back and I will walk you through it.
Let me know if this helps.
*****************
Have you checked your internet browser's history to see what websites were visited at the times you are charged on your bill?
Do this by going to history button under internet explorer, or start button-->search--->Temporary internet filesThis folder will tell you exact times and dates when the website was accessed. Please post back and update us on how these ideas helped.

I downloaded and installed Sygate for my firewall, I then downloaded and installed & ran AVG. AVG found: Trojan horse dialer.7.B PLUS 3 other virus that it was able to get rid of. The trojan horse dialer was not able to be removed but put into the virus vault.
Renee

hi renee,
avg, while being a good free anti-virus, it is not an anti-trojan, so if you can scan with trojan hunter anti-trojan, it will delete the dialer from your registry(that's why its coming back) and from your windows directory.
all the best,
murve

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |