Hacking

Discussion in 'Malware Help (A Specialist Will Reply)' started by bdelapp, Mar 13, 2011.

  1. bdelapp

    bdelapp Specialist

    Ok... a few sincere and legitimate comments/questions to who ever is the best and most knowledge person(s) in the area of forced computer intrusions.
    Background: I'm a 63 year old, educated, trained and skilled professional in observation and analytical problem solving.
    Although not my field, for fun I dilly dally in theory, including particle physics, quantum mechanics and other interesting little child games.
    Observation: I believe I've seen what I will call for the lack of better words, forced instrusions into my computers and computers of friends and family.
    These intrusions which I playfully refer to as 'bangs' were almost subliminal in nature initially, but appear to be becoming more blatant and easily observable by anyone.
    I mentioned in a previous post that I thought my MSE was compromised.
    My rational for my thoughts were physical by actually having found maleware and virus programs that only occured after one of these bangs, and in part on what I would refer to as collective observation and perception.
    I will add here, that thinking back I believe I observed some of this activity 8 or 10 years ago when I got my first computer.
    At this time, I wrote it off as I did in fact look at internet porn. Hey, I was new on the world wide web.. lol
    Initially I had McAfee on a computer, but I removed it when I begin to have invasions of every description which appeared to happen so easily without
    any indication of McAfee having seen it.
    I then used Norton, and during that period, other than being unable to communicate with their techs (due to their help desk personnels inability to speak english) it all worked well. Whether a little porn or friends WMVs with bugs, it was bang, zap, everything thrown at my computer was caught and taken care off with little or no pain.
    Now, I use my computers to check emails, don't go to chat rooms, do go to FaceBook, read the news and when my mind wanders aimlessly I research ionic wind generators, super conductive metals and ceramics and chemical generated power power systems on the nano level.
    What I see now are my monitor suddenly and for no apparent reason flashing (it appears there is a 2 flash pattern) sometimes a prompt pops up, always very legitimate looking which says windows installer is attempting to install ______ (insert your own term here)and the most recent time a prompt popped up and informed me that my PDF file was opening. Needless to say, I was not attempting to open any PDF file. But there it suddenly was, a PDF file attempting to open.
    Now... I'm not crazy or losing it here folks, I'm a trained observer and I confine my sipping of fine bourbon and smoking of good cigars to the hot tub with my wife. The wacky weed was in my college days...
    This last incursion I was reading something on the front page of MSN. Suddenly there were two distinct flashes of the monitor and it popped up and said your PDF is downloading. As I said above, there it was, a PDF file trying to open.
    As I reached for the power supply switch (I have my power supply set up close at hand) and turned it off, I looked quickly at the bottom bar before I punched the power off and I saw the MSE icon disappear. I hit the button and turned the puter off.
    I did a safe mode start, MSE wouldn't start and I ran malwarebytes (full scan) which was already on the puter and it came up with nothing.
    I then got on MG and started asking questions as I could not get on the internet no matter what anyone suggested or I tried. I was going to run MGs malware procedure step by step.
    I had to restart 3 times before I could get into a F8 safe mode start to the administrator because the damn thing just kept attempting to start up in normal mode. The screen flickered and the machine acted almost as if it had a mind of its own... totally wierd..
    When I was finally able to bet into administrator, I could not get MSE to run at all, it said it was unavailable, I could not log into run to open any services, I could not open task manager because it said... hell, I don't remember... I went to control panel and security, neither security or windows firewall would open... I tried to shut off system restore and it wouldn't let me do that...
    I know it had to be a virus or some insanely well written and dastardly bug, and I truly believe this is the 5th time in about 8 years that my computer virus protection has been banged, compromised and made useless.
    Both McAfee and MSE.
    Truthfully, and call it intuition or gut feeling but I'm not even sure that the invader wasn't using MSE as a home base.
    So, a little paranoia maybe, but a whole lot of cold, hard, analytical observations based on my profession and the training you all have given me here on MG.
    Now I'm going to have that bourbon and watch Syfy..
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no 100% guaranteed solution to protect you from all the various types of malware that exist on the internet. You don't even have to open a browser to surf to get infected. Simply connecting a PC to an active internet cable can result in infection in under 10 seconds, if your PC is not properly protected. Does it always happen in 10 seconds, no! Does it always even happen, no! But it does happen especially if your IP address already known due to surfing various sites ( like porn sites which you openly admit to frequenting ).

    Proper protection is covered in this >> How to Protect yourself from malware!


    Highlighting some key things for proper protection
    • Keep Windows and all other programs fully updated to avoid security holes
    • You must have active protection in each of the below categories
      • antivirus
      • antispyware
      • firewall - software firewall and do not use the rely on the windows firewall for this since it is totally inadequate. The software firewall provides both incoming and outgoing protection and gets updated with the software to stay current with security risks.
    • You really should have a hardware firewall inbetween your PC and your internet connection. This means either your cable or DSL modem must have a firewall or you should have a router with hardware firewall inbetween your modem and PC. This hardware firewall will stop lots of unwanted attempts from ever even getting to your PC.
    • Remember the problems begin and end with you. You and the people using the PC can be the largest problem or can be the most important part of your protection.
    However all the above being stated, people who really practice safe habits and that have proper protection do sometimes managed to get infected. If proper protection was in place then in most cases the infections are not too severe and can easily be removed. But sometimes, backdoor infections or serious PE file infections occur and the safest most reliable thing to do is to reinstall. Also some infections can wreak so much internal damage to Windows and other programs that even when you remove the infection, there can be all kinds of strange problems on your PC. Again, it is easier and more reliably to just reinstall in these cases.
     
    Last edited: Mar 13, 2011
  3. bdelapp

    bdelapp Specialist

    Hi Chaslang and thanks... you've confirmed what my observations and analysis.
    I was told once by a supposed computer person who worked on my office computers that if you hid behind a router, then they couldn't get to your puter. I take it from your statement that you are confirming this arrangement and I need to replaced our wireless router, after the service's modem with a router with firewall, and this will lessen the chance of bettin banged.

    Oh yes, to be clear, I have looked at porn in the far past, but this was on 'other' computers, and long ago and 3 different houses and 2 services ago. I have never looked at porn at this address on either of these two computers.

    Also, I assumed that when I put these two new computers online, I would have different IPs and there would not be a way to connect my old IP to my new ones?

    Also, for the record, I ran another full scan with Avast last night and when I looked at the screen this morning it reported that:

    'C:\HP\Fin\Autoplay.exe' was infected wtih Win32:Trojan-Gen.

    As it was less than half way done, I left the room for more coffee and when I returned, Avast was off and my computer had restarted on its own. I found this interesting as after my complete recovery, I restarted in safe mode and turned off system restore, then restarted again in normal mode and turned system restore back on. It was after this that Avast discovered the trojan in normal mode.

    Am I not looking in the right place, (I have the free version) as I can find no log in Avast to see if the infection was quarentined, removed or not so I'm not sure where that leaves me.

    Given this fact, I then ran Malwarebytes full scan (updated) and it found nothing.

    I am currently rerunning Avast full scan (updated) to see if it encounters the same virus again.

    In closing, I have a feeling, just as with other areas of life, there are sites out there on the net on which the bad guys list or sell your IPs, your names, etc. and maybe somehow, someone made a connection.
    But more likely, I believe someone already knows who I am and is intentionally bangin' the hell out of our service/puters with bugs every day or so.

    Again, ACES to MG and everyone here... I've told more than 50 people about you guys since I came on in late 2008 and I hope it gets you some business and $$$...

    Hasta la vista baby,
     
    Last edited by a moderator: Mar 15, 2011
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No. This is not 100% true. What you are doing is adding an additional layer of protection to make it harder to get to you. You can still have problems especially if you open up doors for the hackers by opening up ports ( doors ) thru the firewall to run gaming applications, P2P and torrent downloaders, etc. You computer is only as safe as you allow it to be.

    What makes you think your wireless router does not already have a firewall. Most newer ones do. Also if using wireless, you need to make sure you have protected your wireless network with encryption and password protect your router ( make sure it is a strong password ).

    Your router automatically provides the IP address for your internal network using DHCP ( Dynamic Host Control Protocol ). Basically this means you set your PC to automatically acquire an IP address from your router and it will be based upon the network configuration that you setup in your router.

    The other side of your router that faces your modem, gets one and only one IP address provided by your ISP. You have no control over this IP. Your router acts as a NAT ( Network Address Translator ) which translates between your ISPs network, and your internal home network.

    False detection.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds