republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security Cleanup » [Virus] Virus's and spyware!
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
« HJT Log - Can't clean computer, please help  
AuthorAll Replies


CalamityJane
Premium,VIP,MVM
join:2002-08-27
Eustis, FL

reply to icex _
Re: [Virus] Virus's and spyware!

I have a really bad feeling that by helping you remove the infected files, that I'm giving you a false sense of security and that the original owner of this PC will be left in the dark about how serious this breach of their computer has been and the security implications with running this as a trusted machine in the future.

quote:
This computer has two accounts. On the "Mom" account it seems fine. On the other account, (their both admin accounts by the way) all is not fine
Has "Mom" been informed fully that this computer has been hosed to the point that there is no guarantee that these "fixes" will keep their info and data safe in the future and, more importantly, the very real possibility that any sensitive data stored on this PC is now at risk and could very well be in the hands of an attacker?

Some points to note as we are removing infected files and you may NOT notice symptoms of system changes by the attacker:
said by Jesper M. Johansson, Ph.D., CISSP, MCSE, MCP+I,
Security Program Manager,Microsoft Corporation, Published: May 7, 2004 :

So, you didn’t protect the system and it got hacked. What to do? Well, let’s see:

• You can’t clean a compromised system by patching it. Patching only removes the vulnerability. Upon getting into your system, the attacker probably ensured that there were several other ways to get back in.

• You can’t clean a compromised system by removing the back doors. You can never guarantee that you found all the back doors the attacker put in. The fact that you can’t find any more may only mean you don’t know where to look, or that the system is so compromised that what you are seeing is not actually what is there.

• You can’t clean a compromised system by using some “vulnerability remover.” Let’s say you had a system hit by Blaster. A number of vendors (including Microsoft) published vulnerability removers for Blaster. Can you trust a system that had Blaster after the tool is run? I wouldn’t. If the system was vulnerable to Blaster, it was also vulnerable to a number of other attacks. Can you guarantee that none of those have been run against it? I didn’t think so.

• You can’t clean a compromised system by using a virus scanner. To tell you the truth, a fully compromised system can’t be trusted. Even virus scanners must at some level rely on the system to not lie to them. If they ask whether a particular file is present, the attacker may simply have a tool in place that lies about it. Note that if you can guarantee that the only thing that compromised the system was a particular virus or worm and you know that this virus has no back doors associated with it, and the vulnerability used by the virus was not available remotely, then a virus scanner can be used to clean the system. For example, the vast majority of e-mail worms rely on a user opening an attachment. In this particular case, it is possible that the only infection on the system is the one that came from the attachment containing the worm. However, if the vulnerability used by the worm was available remotely without user action, then you can’t guarantee that the worm was the only thing that used that vulnerability. It is entirely possible that something else used the same vulnerability. In this case, you can’t just patch the system.

• You can’t clean a compromised system by reinstalling the operating system over the existing installation. Again, the attacker may very well have tools in place that tell the installer lies. If that happens, the installer may not actually remove the compromised files. In addition, the attacker may also have put back doors in non-operating system components.

• You can’t trust any data copied from a compromised system. Once an attacker gets into a system, all the data on it may be modified. In the best-case scenario, copying data off a compromised system and putting it on a clean system will give you potentially untrustworthy data. In the worst-case scenario, you may actually have copied a back door hidden in the data.

• You can’t trust the event logs on a compromised system. Upon gaining full access to a system, it is simple for an attacker to modify the event logs on that system to cover any tracks. If you rely on the event logs to tell you what has been done to your system, you may just be reading what the attacker wants you to read.

• You may not be able to trust your latest backup. How can you tell when the original attack took place? The event logs cannot be trusted to tell you. Without that knowledge, your latest backup is useless. It may be a backup that includes all the back doors currently on the system.

• The only way to clean a compromised system is to flatten and rebuild. That’s right. If you have a system that has been completely compromised, the only thing you can do is to flatten the system (reformat the system disk) and rebuild it from scratch (reinstall Windows and your applications).

The above quote taken from this page:
»www.microsoft.com/technet/commun···504.mspx

Not having the original install disk and/or backups prior to the compromise makes this option pretty much impossible. However, continuing to use this PC on the internet as a trusted machine is a risk for future use. It might be time for a new computer and retire this one.

I can tell you that I would not use it after this serious a breach. Give your friend this link if they do not understand what happens when your computer is wide open and under control of a remote access trojan:
Invasion of the Computer Snatchers
»www.washingtonpost.com/wp-dyn/co···342.html

That is the reality of what we are dealing with here. This PC has been so seriously compromised that I do not want to mislead you into thinking that this "cleaning" will reverse the potential of the damage already done. The fact that it was hosting Multiple rootkits and backdoor trojans makes the breach pretty much a worst case scenerio, with many of these problems you have seen thus far trying to "clean" the system.
Security Management - July 2004
Help: I Got Hacked. Now What Do I Do? Part II

»www.microsoft.com/technet/commun···704.mspx
quote:
with a rootkit on the system that makes the system no longer trustworthy. Windows Explorer and the command line will no longer show you the files that are actually on the system. The registry editor is now lying. Account manager tools will not show you all the users. At this stage of an intrusion, you can no longer trust the system to tell you about itself. That’s where you get into a flatten and rebuild (some people call it "nuke and pave") scenario. The system is now completely compromised.
--
It takes a disaster to make a woman out of a female
Microsoft MVP/Windows Security 2003-2007
Proud Member of ASAP (Alliance of Security Analysis Professionals)


icex _
Premium
join:2004-05-22
USA
clubs:
I'm going to call her and see what she wants me to do. I will probaly offer to build her a computer, better and cheaper then dell.
--
Team Discovery


CalamityJane
Premium,VIP,MVM
join:2002-08-27
Eustis, FL
I think that's a good idea to let her know because this machine IS a security risk even if we try to clean it up. Refer her to this topic and our posts here.


icex _
Premium
join:2004-05-22
USA
clubs:

I called and she wasent home. I left a message.

I am going to ask her if she has entered credit cards, or anything like that, and if she has to keep a check on her credit report and possibly alert the credit card company to look for suspicious charges, since her computer was pretty much hacked. I found a keylogger on here to when I first worked on the computer, so that pretty much is a high risk that any passwords, credit card numbers, etc has been logged.
--
Team Discovery


CalamityJane
Premium,VIP,MVM
join:2002-08-27
Eustis, FL


edit:
July 3rd, @02:47PM

said by icex _ See Profile :

I called and she wasent home. I left a message.

I am going to ask her if she has entered credit cards, or anything like that, and if she has to keep a check on her credit report and possibly alert the credit card company to look for suspicious charges, since her computer was pretty much hacked. I found a keylogger on here to when I first worked on the computer, so that pretty much is a high risk that any passwords, credit card numbers, etc has been logged.
Yes, please do follow up on that. If a keylogger was found that further complicates any data at all on that computer. Earlier I linked an FAQ here that should also help:
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
»Security »How to report ID theft, fraud, drive-by installs, hijacking and malware?

ALL passwords to ANY accounts should be changed and monitored for suspicious activity. That would include, in addition to any personal financial information or accounts but also emails, internet accounts anything at all could have been stolen and you have to assume it was, as badly hacked as this PC was/is (it's still got a rootkit and other nasties lurking on there so make sure this doesn't go on the net anymore). The presence of a keylogger further solidifies the malicious intent of the intruder.

Consider also any other information or records that may belong to others and stored on that PC? The keylogger records keystrokes; those backdoor trojans can steal any documents/info they want and can just access anything (documents, addressbooks, etc.) without the knowledge of the user.
--
It takes a disaster to make a woman out of a female
Microsoft MVP/Windows Security 2003-2007
Proud Member of ASAP (Alliance of Security Analysis Professionals)


icex _
Premium
join:2004-05-22
USA
clubs:

I will let you know when she calls back what's going on. She may just say to clean it the best I can and give it to her, or she may say she'll buy a new one. I have wasted a whole week on this thing, pretty much for nothing, because I doubt she's going to pay me for something unfixable.
--
Team Discovery


icex _
Premium
join:2004-05-22
USA
clubs:

reply to CalamityJane
One more thing I forgot to mention, she uses a debit card ALL THE TIME on her computer, so I told her to call the credit card company and the credit bureau or whatever and tell them to watch her credit for a month or two for suspicious activity.
--
Team Discovery
Thread is
Forums » Up and Running » Security » Security Cleanup« HJT Log - Can't clean computer, please help  


Monday, 01-Dec 12:18:48 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [47] AT&T Metered Billing Trial Hits Second Market
· [37] Comcast Tries To Slow Verizon's Philly Entry
· [3] Embarq Rejected Higher Offer
· [2] FCC To Vote On Free National Wireless Broadband
Most people now reading
· Is this a good thing for the net? [news,99366]
· Upverting DVD players vs Blue ray DVD players. [General Questions]
· Why does the USA have such a high divorce rate? [General Questions]
· VOIPo Launching Monday 12/1/2008 [VOIP Tech Chat]
· Hacking router [Security]
· Level 80 PVP gear info? [World of Warcraft]
· Computer sends data without any input from me. [Security]
· New IMG Push Dec. 6th [Verizon FIOS TV]
· Circuit City asks for ID with credit card purchase [General Questions]
· How to get off, DELETE this ?? [Security]