• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

Weirdest attack ive ever seen...

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.

MadSkillzMan

Member
Joined
Nov 16, 2003
Location
Cleveland OHIO
Ok guys, i was out all weekend for prom. Now i have a small home network of about 5 computers.

My main, which is kind of the server is the one in my sig, my test rig, my bros rig which is almost identical to the test rig running xp pro, the family computer which is pretty beefed up at 1.8ghz, winxp home, very important stuff on it....and 2 computers that get switched in and out of my router

Ok so to the point, our DSL has a firewall, our router has one, and each computer has Zone Alarm pro installed which is up to date as well as norton 2004.

Now, the family computer is connected directly to the DSL through the USB port. The router is on the ethernet port and runs upstairs to our other computers.

So these computers upstairs kinda have 3 firewalls. DSL, Linksys, and ZA. The DSL isnt a huge firewall, it just limits attacks. I noticed significantly less attacks once we got DSL over dialup. I really have no conflicts, and nothing ever gets through without me knowing about it.

Heres the weird part...i come home sat nite, and my bros all freaked...hes not computer smart, but he knows somethings wrong. In short, someone got thru the DSL, thru the router, and beat down zone alarm on HIS computer. its a 400mhz, 128megs of ram winxp POS with hardly ANYTHING on it. Whoever it was, passed up a linux box, a computer set up as a server, and a few other computers that actually had no protection.

They got through and dropped a trojan or two. Norton cant detect it,...but its acting weird.

Why would they go through that trouble? i dont understand. Why not attack the family computer that would have been way easier.

I didnt even know it was possible to connect to an IP like that and drop something. I dont even have the netsend service enabled. I disabled the service part that allows files to be transfered.

The machine is quarantined from the network. I cant figure out whats wrong with it. Keeps asking for components....keeps trying to connect online...the only guess is my bro has a PC cam thats always lit up. But then again i do on my main rig...


There was a TON of spyware also. Whats it called when websites download info to your machine without you knowing it? i suspect a .tmp file but again he was just sitting there. It sat on idle for about an hour or so and went nuts.

Thanx guys.
 
Sounds like your computers are locked down ok.

I hate to say it, but it is more likely that something like that was internal. By that, some web site that someone went to managed to drop a file in there via a popup or some other such method. I actually got a little virus on my computer the other day that way, and it is locked up tighter than a drum.

On a side note, my brother had a similar problem where he works where one of his employees went to the wrong website and ended up with close to 300 spyware objects and I think 3+ viruses and trojan horses. It wouldn't even boot right.

My way of fixing would be in the following order.

*First Safe Mode
Ad-Aware
Spybot
Clear all temp internet files
*Normal Bootup
Update Virus Defs and run full scan
Get free Active Ports and see is anything is connecting out.
Now check the services that are running and google the unfamiliar ones.

If all the above fails:
TDS-3
The Cleaner
If you are familiar with the registry, check your run and runonce programs to see if things are firing up at startup. (if not, I can explain more)

Don't you just hate it when someone does those things that wastes all your time fixing. Good luck.
 
MadSkillzMan said:

its a 400mhz, 128megs of ram winxp POS with hardly ANYTHING on it. Whoever it was, passed up a linux box, a computer set up as a server, and a few other computers that actually had no protection.



If the box has that little on it, maybe a reformat would be easier than tracking everything down. 'Course, if you're looking to learn how it was done, then do it the long way. :D
 
Back