Security concern

Discussion in 'Malware Help (A Specialist Will Reply)' started by moe_08, Nov 25, 2007.

  1. moe_08

    moe_08 Private E-2

    hi

    let me start off by admitting that i am completely and utterly ignorant when it comes to computer tech (i only use it for minimal purposes).. that being said, i have a couple of security concerns i would appreciate if any one give
    me some feedback on them...

    i ve just bought a new computer.. after i installed the OS (win xp home sp2) i immediately installed kaspersky internet security 7.0... and then i had to update it so i connected to the Internet and KIS updates takes forever
    and my connection was slow also.. so the computer was connected to the Internet for a very long time was no protection (or obsolete protection as KIS was updating)....



    1- what are the security risks of connecting to the Internet BUT not doing any browsing or downloading except the KIS update definition files downloads...?


    2- what are the security risks if i connect to the Internet (ie hook the ethernet ADSL cable coming from a router and have no antivirus suite installed.. but DONT DO ANY BROWSING or DOWNLOADING..... i had to connect to the Internet before i installed KIS so as to activate my OS from Microsoft?


    also windows not updated until KIS finished (after a long time) then i ran windows update which took even LONGER time


    N.B. i have been attacked before on a different computer but on the same network by an ip from china (i dont know the type but i think its the one that over traffic the Internet?!?)but KIS blocked it.. so i am concerned that this guy who might know my ip address, attack the new computer during the time where KIS was updating.. esp when the attack hit when i opened an email (spam) that had the subject of my financial advisor company name..


    i will be using this computer to access sensitive financial online data.. and i am PARANOID about my safety and security online esp of the issues mentioned above.....
    currently
    i have windows updated ........KIS 7 running and updated with firewall to max... and thats it
    before i start using it for sensitive online action.. i need to feel more protected.. i am still concerned about keyloggers, rootkit virus, trojans,...etc...


    3-how to 100 % check that the computer was not infected by anything of anytype during the updates download?

    4-how to add more protection for the future?

    i am actually considering to write zeros to the WD 160 hard drive.. is that reasonable

    please any feedback is immensely appreciated
    thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You bought a computer and it had no Windows OS on it already? Then I assume this was not purchased via a typical PC manufacturer or seller?

    You were not totally exposed since you already had the current version of Kaspersky installed. Thus this was not as bad as it could be. I have seen "Unprotected" PCs get infected in as little as 10 seconds of connecting to the internet. While this does not always happen and is also less likely with newer updated OS's like WinXP SP2, it could happen. Note you do also need to get all of your Windows Updates too besides just getting Kaspersky updated. However while you were activating Windows, yes you were exposed. But if you had a router with a hardware firewall installed, this also offered you some but totally adequate protection.

    These comments should also address your second question.


    Run this READ & RUN ME FIRST Before Asking for Support and attach the 6 request logs to this thread.

    To be honest there is no check that is 100% accurate but running the READ & RUN ME is a pretty good check.

    See this: How to Protect yourself from malware!
     
  3. moe_08

    moe_08 Private E-2

    hi thanks for the detailed reply

    1-
    i just realized that during the time i was updating kasper and windows (again it took a long time to update mean while the system was with no/obsolete protection)... another computer on the lan had a trojan virus in it.... what are the risks on my computer...

    please note that i dont understand the mechanics of LAN,..etc.. all i know is that this other computer (the infected one) has an ethernet cable from the cpu to a d-link device that has multipe sockets for ethernet cable (where i plug my ethernet cable from new computer to it) and then there is another cable that goes from the d-link device to the router which is connected to my regular phone line....

    and when i first ran KIS it said it detected a network connection and asked what to do i choose "internet in stealth mode"


    i think it look like this

    infected pc ---> d link switcher -----> router ---> splitter---> my regular phone line
    my pc ---------> d link switcher -----> router ---> splitter---> my regular phone line


    2- how to check that nothing bad got in either during windows activation (how ever i reformated the disk full format and re install the os and this time activated after i updated kasper but before updating windows) or that my security is not compromised beacuse the time i spent on the net updating and not fully protected while a computer on the network had a trojan

    3- if you were in my shoes...
    ie
    1-been attacked before but on diffret computer same ip
    2-connected to the internet to activate windows and there was nothing running but windows firewall however formated the disk after
    3- spent a LONG time updating KIS 7 before windows updates and there was an infected pc with a trojan on the computer network
    4- have a win xp sp2 home edition, KIS 7 only

    what would you do to use this system for online sensitive financial data access with a peacful mind?

    thanks for ur help and support
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unknown without knowing exactly what trojan and what other malware and what level of protection was in place on the other computer.

    This is a router or a switch.

    I expect that where you say router, you mean your DSL modem from your ISP. This may or may not be a router.


    In short if you are worried about whether you are infected or not, you need to follow my previous instructions about running the READ & RUN ME and attach all the logs. We can talk about it until we are blue in the face but that will not answer whether or not you are infected.
     
  5. moe_08

    moe_08 Private E-2

    i checked and found that i have a repotec RP-IP1800 which is both a modem and a router but with no hardware firewall..

    also the trojan that was in the infected computer on the network (even though i didnt share both pcs) was Packed.Win32.NSAnti.r..

    sorry i havent been able to the run the things in read and run me because i was not able to use the pc i was visting some relatives..

    i am not sure what to do right now, i am going to say my issue in breif again

    when i first turned on my new built pc
    -i installed the OS winxp sp2
    -then connected to the net with nothing but windows firewall (no hardware) to activate windows
    - installed kaspersky internet security 7
    - updated kasper ( toke a looong time with windows unpatched)
    - updated the windows
    - ran a full kasper scan that was clean..

    ALL THROUGH This, there was a computer on the network (though not sharing with it, it just connected to the same dlink and the same router as mine) that had a trojan (Packed.Win32.NSAnti.r)... obvisouly i didnt know that..

    obvisouly i disconnected the infectd pc form the network but it was there during the first steps where the computer was unpactched and still updating..
    i also ran counterspy scan and spybot scan on the pc and it turned clean...


    do i run more scans.. what prog u recommend
    do i write zeros to the drive and redo the whole things

    now i dont know what to do.. what's next.. do i use it for online financial usage or not yet...will u use it ???

    thanks :)
     
  6. moe_08

    moe_08 Private E-2

    and i did ccleaner
    and i have nothing installed so there is nothig to remove from control panel
    and i will run avg antispyware
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat, you need to run the READ & RUN ME and attach ALL of the requested logs before I can tell you anything else.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds