How to survive a drive-by malware attack

Malwarebytes
Malwarebytes offers a file assassin feature that can kill locked files in an emergency

It was a Friday evening in December last year. I'd just got in from work, fed the cat, made myself a nice cup of coffee and settled down in front of the PC to catch up on the usual Friday evening internet entertainments: Bob the Angry Flower and the B3ta newsletter.

Chuckles all round, until I clicked one of the B3ta links to an apparently hilarious site, which loaded normally at first, but then appeared to kick Adobe Reader into action. A few seconds later I found that my browser was completely unresponsive. Strange.

Not that strange, though. I use Mozilla SeaMonkey as my main browser at home out of sheer dogged contrariness and I'm used to it occasionally going into a flat spin, especially when it encounters too many Flash ads on a single page. However, the unbidden appearance of Reader seemed a little suspicious and the sudden wild thrashing of the hard drive was a bit worrying as well.

I hit [CTRL]+[ALT]+[DEL], waited what seemed like an age for the Task Manager to appear, then finally gave up, held the power button down for five seconds and restarted.

Damn and Blaster

Like, I imagine, most of us, I take the security of my PC reasonably seriously but I don't obsess over it. I've had this PC since 2003 and before last year it had been compromised approximately once, in the days before SP2 happened and the firewall didn't start by default on a new connection.

My broadband got switched on at my new house, I set it up and within five minutes I had the Blaster worm spewing pop-ups at me and trying to shut my PC down. Annoying, but easily fixed.

Since then I've taken sensible precautions, but nothing over the top. I ran ZoneAlarm for a while until I got SP2 and switched to the Windows Firewall, I use AVG antivirus and my PC sits behind a firewalled router rather than the nasty USB modem that originally came with my broadband package. Nothing spectacular, but it does the trick.

Evil twin

Or at least it did until that fateful evening in December. The PC restarted happily enough, but paranoia had started to creep in, so I figured it wouldn't hurt to have a little peek under the bonnet to check that everything was in order.

I hit [CTRL]+ [ALT]+[DEL] again to bring up the Task Manager and had a scan through what was running. Everything looked normal enough until I spotted something called JimMcCauley.exe, which I was reasonably sure I'd never noticed before.

I ran a search for it and found it nestled in my Windows/System32 folder, where I discovered that it had been created only five minutes previously. Not a good sign. I tried to stop the process, but the process refused to be stopped.

Uh-oh

Next, I launched a command line window and ran Netstat. I love Netstat – it gives you a list of all the internet connections you have open and is very handy for telling you if something's talking to somewhere it shouldn't be.

I was expecting to find maybe one or two slightly suspicious connections. What I got was about a billion connections to Russian mailservers. Oh, shit. I yanked the network cable and panicked for a bit.

Jim McCauley

A professional writer with over a quarter of a century's experience, Jim has been covering mattress and sleep-related subjects for TechRadar, Tom's Guide and T3 over the past few years, gathering an in-depth knowledge of the workings of the mattress industry along the way. Previously Jim has covered a wide variety of subjects, working widely in the tech and gaming sectors, and more recently covering the design and wellness industries.

Latest in Antivirus
Kaspersky Antivirus is banned in the US – here are 3 superb alternatives
A person holding an iPhone close to the camera with the Google search homepage displayed onscreen
That Google Ad you click could be dangerous—here’s why
A stressed out hacker looking at a laptop screen
Your antivirus software will get a major boost from this new hacking competition
Promotional material for McAfee online protection.
Protect your online life with the power of McAfee
"Best Free Antivirus Software" next to a laptop being opened
Best free antivirus in 2025
Antivirus
Which antivirus software works with Malwarebytes?
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day