My ISP seems to think they are immune to viruses. Please read this and give opinion.

tankman1989

Active Member
Reaction score
5
This is a serious threat to people who have broadband. The mindset of ISP employees is lackadaisical and dangerous. Please read this as you should be informed of my situation and I need opinions as to what to do.

I have a new broadband service provider (DSL) and I have been having problems with the connection speed dropping to .1Mbps and having to reboot the modem. On my 5th call to tech support I had an agent who asked me to download a special file from their server. It was supposed to be a large file and they would just see how long it took to download. I typed in the URL as he said it and when I found that it ended in .scr I told him that I wouldn't download it.

I asked him if he had ever heard of viruses in scr files and he said "never". I told him that I worked as the AV admin for a number of large companies for at least 3 years and had encountered hundreds of viruses that came from .scr files or were still hidden in scr files. That is the only reason I know the extension. This young lad became irritated, rude and semi-baligerant when I refused to download the file. he told me that the reason I had viruses was because I was using some cheap consumer AV, lol. I said "oh really". It was amazing how he know what products I supposedly administered. I then asked him what AV software his company used and he said Symantec Corp. I chuckled and said he needs to read up on his Enterprise AV solution reviews. I actually worked for 3 companies that used Symantec Corp as their AV program and found them woefully inadequate. I installed Sophos and Eset in replacement and found thousands of viruses on one companies network.

In fact, in one small company in Rancho Santa Fe, California (40 mins North East of San Diego), I found an average of 146 viruses/trojans.spyware/worms/malware per machine when I installed Eset in replacement of Symantec Corp (and Eset was 1/3 the price and 1/4 the resource requirements!) So after the 50+ machines were scanned I had a very large task of cleaning the computers. THANK YOU SYMANTEC! There were hundreds of .scr viruses on this network.

After I explained to him about my AV experience he insisted that it was impossible for them to get a virus for they are an ISP. There is no way an ISP could have a virus in the file that 500-600 people download on a weekly basis. I laughed. I asked him if he knew if Symantec or McAfee ever had viruses, he said he didn't think so. I told him he was wrong. He said "why would this file be infected, that is ridiculous". Ah the ignorance and arrogance. That would be the exact file to infect if you wanted to spread the virus as 500-600 people download and execute it each week! If your AV program warns you, you will just say "OK" because it is "trusted".

Well he got really mad and told me that he could no longer help me. he wouldn't forward me to a supervisor either. I asked his name and his supervisors name. I asked for him to have his supervisor call me. He never forwarded the message.

I asked this kid if he knew what ADS or Alternate Data Streams are. He said no. I gave a breif description and said they are used to hide files and they are given a name that seems non-malicious. You could have a filename.txt.exe the .exe is the ADS, and it is present in any NTFS filesystem. I told him he needs to respect his customers wishes when they do not want to download files that are not 100% safe and secure ESPECIALLY when they have a AV administration background and know mountains more about virus hiding and propagation than they. He gave me more lip and told me it was impossible for them to have a virus. I had enough at this point and gave up.

**** I can't believe I forgot about this. I didn't necessarily correlate this with my typing of the URL, but it was a strange coincidence.***********
About 10 mins after I ended the call, Sophos picked up a trojan in my Windows32 directory with a .scr extension. I took a screen shot of it to show tech support at a later date if they even cared.
********

I called back the next day and spoke to the boys manager. He didn't seem to concerned. I don't know what to do. If this is the attitude towards security then they are in for a fall. I don't want my network getting trashed because some 18 yr old is lazy and lets in a virus to their network and infects all their customers. The manager said that he would listen to the recording and talk to the employee. I want to know the outcome and am going to follow up.

I want this taken to their CIO because I want to know why they are sending an executable file to their customers if this is simply a speed test. It doesn't make sense. Should I download the file and post it on an AV board to see if someone can look into it and dissect it? I am thinking there may be more than meets they eye here. Also, what about an op-ed to the paper. I think people should know the mindset of their ISP.

Who should I contact at this company and how should I approach it. Am I going overboard on this or is this a legitimate complaint and concern? What are your thoughts and opinions?

Thanks for any opinions you may have.
 
Last edited:
I agree 100% with you and also would've denied downloading the file. Firstly, some .scr's are legitmate screensavers but they're not 'big downloads' usually <5mb. Secondly, why would you choose the .scr extension for a big download? Can't be bothered to post any more reasons, but there are quite a few more. I also agree totally with what you're saying about Symantec. I see soooo many
companies that use either Symantec Corp. or Mcafee Enterprise and they usually get infected because staff bring in their memory sticks from home.

This whole thing seems to be a bit crazy.
 
youse means I can get virus even tho I have norton 360????


LMAO, yea some ISP's are ridiculous. The real dangerous thing is that they are putting a lot of faith in the "lowest bidder". Especially in their tech laptops. The ISP near me has had virii infections in commercial voip systems even.

To the point of the ISP your dealing with, you prolly wont get anywhere with this...because the companies are so huge that to have any kind of policy change, you will have to have the voice of god.
 
Thanks for the responses. I didn't know if I was over reacting or if it was a legitimate complaint.

The ISP is a small, local company that services my county (1/2 million people) and part of another county so they are by no means a "large" ISP.

I did contact the company this morning and found the supervisors supervisor. I left a VM and am awaiting a response. I will keep this updated to the responses I get.
 
A good test file if they want a large file would be a txt file filled with enough garbage data to build the file to 5+ MB. I wouldn't download anything other then a .txt or .dat file really for a test file. I have always gone and found my own files to download and they can watch the network traffic with monitoring tools.
 
I can not believe the difference in responses that I have gotten between this forum and "Hardforum". I posted the same thread there because I wanted to get a viewpoint from a different pool of people. Over there I was told by a number of people that I was a "cock" yet I was anything but. The closest thing to that was when I asked him to respect my not wanting to download it due to my years of AV admin and knowing the history of these files (and the history of their ISP, which I didn't say).

I guess each forum has a different atmosphere.

Thanks again guys!

Oh, I added this to my original post:
**** I can't believe I forgot about this. I didn't necessarily correlate this with my typing of the URL, but it was a strange coincidence.***********
About 10 mins after I ended the call, Sophos picked up a trojan in my Windows32 directory with a .scr extension. I took a screen shot of it to show tech support at a later date if they even cared.
********

That was very strange and I still don't know how to explain it.
 
Tankman, your ISP has no reason to send you an SCR file. As someone else mentioned, that extension is used for screensavers, but it is also used for scripts to run, such as:
C:\WINDOWS\SafeBoot.scr
C:\WINDOWS\system32\logon.scr

They have no reason to send you anything but a TXT or perhaps a JPG file -- definitely nothing that could be executed.

A couple of folks here said that infecting an ISP's file that is sent out to many customers would be a great way to spread an infection. Just is good is this new virus called W32/Induc-A. It allows Delphi environments to compile a virus into whatever program the developer is creating! (http://www.sophos.com/blogs/sophoslabs/v/post/6117)

-- Patrick B.
 
Back
Top