How is this possible?

Miscellaneous Forums/General Discussion/How is this possible?

I came home this evening to find my computer booted up... thought that was odd as it was switched off.

I have a Cable connection to the internet with ZoneAlarm as a firewall.

Anyway... I can only assume some how wakeup on Lan has been triggered, how would one do this remotely?

Then just to make matters worse I've just found a file on my computer C drive called Thankyou.txt with the lovely message in it reading
Thanks for the access to your computer, zone alarm is CRAP!!

H4X0RZ 1Z EZ
OK... At this point I'm a touch concerned now.

On top of this WINLOGON.EXE keeps trying to access the internet which it never has tried before, ZoneAlarm says it's perfectly safe for it to do so but I'm denying it.

AVG is up to date and a full system scan reveals nothing.

Spybot is up to date and full system scan reveals nothing.

From now on I'm going to be unplugging from the internet when I go out, literally unplug the RJ45 out and wakeup on LAN is now switched off. It seems it defaults to on and I've not monkeyed in the BIOS since I bought the motherboard as it all autoconfigures.

If anyone has any suggestions/ideas/thoughts I really really want to hear it.

Ditch Zone Alarm for a start. Not so much because it may not be up to the task, but just so that you're changing the configuration of your PC. Hopefully this will be sifficient to deter the recent hacker.

Also, is you PC physically secure? Might it be possible that someone actually got into the room your PC was in, perhaps someone even playing a joke on you? Put a BIOS boot password on your PC. If your BIOS allows it, set a keyboard combination as the only way of powering on your PC. I have enabled this on mine and it's a great feature. Saves me having to bend down to the floor to turn my PC on :)

For an alternative software firewall, give Agnitium Outpost Personal Firewall a try. Or get Personal Computer World January issue which has a full 6 months worth of Panda Internet Security 2006 on the coverdisc. I don't kow how resilient Panda's firewall is, but it's not a popular (i.e. attractive to hackers) choice due to it being quite an expensive product.

You should consider totally reformatting your PC. One a system has been compromised, I consider it compromised until the next full format and reinstall. You might be harbouring a real nasty piece of software. A scan with Panda's TruPrevent active will possibly show up the nasty. Scan with a McAfee antivirus as well, it has an option to scan the ADS on your NTFS volumes (basically, very [i]very[/a] hidden files). If neither scan finds anything, you can be 99% sure that you're OK.

sounds bad!

zone alarm is alright... me thinks you'd better put up an esp or telekenisis shield around your computer...

:)


--Mike

That's worrying, although I guess you must have had Power-On-Lan enabled as I don't see that it's possible to boot your PC remotely unless this is enabled in your BIOS.

You have to wonder what they did with the access to your PC. I guess they could have pinched your source code, or something. :/

another good (free) firewall would be Sygate.

Anyway, let some (well trusted and security-related) sites on the net scan your pc for possible backdoors - try Sygate's homepage for a starter or search for "online portscan".

If you disable WakeOnLan and your ports are locked, your system is safe.

You may want to check it is the genuine winlogon.exe that is trying to run - not a spoof of it. It can be affected by trojans - if so, your system may have been made insecure for whoever to then get in.

It is normal for winlogon.exe to connect - in fact, mine is currently allowed access to the internet.

If you do have ZoneAlarm (as suggested) - take up the free Professional trial version - it comes with free Zonelabs software that will look for trojans, etc.

Also in addition - use task manager (or similar) to look at every running process on your PC - then google all of them - the top of the google list will link to sites that supply process information.

Use a site like this one - http://process.networktechs.com/

Or just google each one individually and pick from the top entries.

i use this

www.hijackthis.de

download / scan /paste in textarea and make a test

Get yourself a router. They act as firewalls, and you won't even need ZoneAlarm.

But first, you've got a problem. I don't know if AVG is a virus scanner or not, but you should run Macaffee and possibly Norton as well. There's a good chance the hacker left a trojan on your system. Then again, he appaears to be a white hat hacker because he left you a note saying your system had been compromised. So maybe the winlogon thing acessing the net is simply normal Windows behavior. In fact, the hacker may have simply eneabled windows update so that your PC would automatically download the latest security patches. Just because the hacker accessed your PC doesn't mean that he intended to damage it, and may in his own way be trying to help people or help himself at least, by resucing the number of vulnerable PC's on the net that could be used as zombies to attack other PC's.

But I'd still scan the hell out of my system with every anti-spyware and anti-virus tool I could get my hands on.

Also, port scan your computer - see what is visible to prying eyes:

https://www.grc.com/x/ne.dll?bh0bkyd2

Or similar.

There are various real-time port watchers you can use to see who connects to your computer and how they are doing it. The simplest is the old NetStat command - others are Active Ports, Antiy Ports, tcp view, lps - I quite like Active Ports.

Wake on LAN usually works by means of a cable between the network card and the motherboard, if the LAN port is integrated then it's BIOS controlled, otherwise remove the cable.

The best protection from hackers is a router.

All firewalls are equal in what they do, but vary greatly in the way the user can allow acess (afterall a computer completely locked out from the net is not on the net at all) but there is no such thing as a totally secure firewall, even the US military has had system breaches in the past.

The most important task for you now are

A) Secure your system
B) Remove residual damage

In the case of A, change your internet IP#. If you are on cable modem ask your ISP to renew your DHCP lease. This will be like moving house and not telling the hacker where you have gone so if the same hacker comes back you just aren't there. Secondly, if the hacker was a kid and hasn't learned about spoofing your ISP may be able to trace the hacker.

If the hacker cannot be traced move onto plan B which is to secure your system, Puki's suggestion of googling the task manager is a good one. If your comfortable with doing this and know your way around Regedit and the various other Windows security loopholes (also known as startup items!) then you can remove all traces of collaterol damage from your system.

If you are not 100% sure on this, your safest bet is a reformat and reinstall. This method at least leaves nothing to chance - but does mean you will loose everything not backed up, don't forget to backup your email contacts and favorites too (I can be relied upon to forget this!).

WinPatrol is great at weeding out crap that loads on startup. it is the first of the three apps i use to help "cleanse" a system (the others being AntiVir Personal and Ad-Aware Personal).

http://www.winpatrol.com/
http://www.freeav.com/
http://www.lavasoftusa.com/software/adaware/

That HijackThis website reports that the Blitz ides are a virus. :-)

Check your startup list too:

START >> RUN >>> msconfig

Um, I am connected to the net via a wireless router/modem, so does this mean I'm safe to ditch ZoneAlarm completely, then?

ppl seem to say so .. I'm on a normal router and I run ZA .. dunno.. I guess 'better safe than sorry'..

You should always pull the plug on a PC when not in use - there's no harm in that guys!

IPete2.

Do a system restore to at least restore what you can, revert back to a day before it occurred.

We used a router at work for security. I still kept ZoneAlarm loaded though, to catch anything trying to phone home.

Routers act like firewalls. That's why they often interfere with hosting servers for opnline games. Worms like the ones that will infect your PC within minutes if you connect to the net without a firewall can't infect you if you connect with a router, because there is no IP address for your PC, only an IP address for your router. When they try to connect to the IP they connect to the router, but the router doesn't route the connection to your PC, because it doesn't know which PC to route the connection to, because there might be a bunch connected to it.

When you connect to a website, what happens, I think, is that the router records the IP address you communicated with, and the port used for the communication, and any communications that come back to the router's ip, from that ip, on that port go to your PC.

This makes it impossible to connect to your PC without you first initiating the connection. At least if I have that right.

Anyway I have been connecting to the net for years with no firewall software, not even the XP firewall, and the only times I have gotten hit with anything was when I was dumb and clicked on a popup in IE (even closing one with the X counts as a click... press F4 instead). I have never gotten attacked, other than my router reporting getting hit with attempts to use it to help attack another PC, and those apparently all failed.

I suppose a software firewall will warn you if you infect YOURSELF by running a bad program, after it tries to access the net and you are already infected, but those firewalls always report things trying to connect that should be allowed to so you're never sure what is legit and what isn't. I found being paranoid all the time was worse than taking a slight risk that I might run someting I should not. I do have an antivirus running. And maybe I should have an anti-spyware running too. I think that would be more than sufficient to protect me. If I had both of those then the software firewall in addition to my router would definitely be uneccessary, and the anti-spyware would surely do a better job than a firewall that only gives me an indication I might be infected AFTER I'm infected.

sswift: press Alt+F4. I know u know this, just needs a teeny edit. F4 on it's own drops droplists.

That's a funny story because it didn't happen to me.

If the Haxxor is so fond of ZoneAlarm, try Kerio. It acts much the same as ZA and is also free (and has less P2P problems).

You guys will probably laugh at this, but (in addition to Zonealarm, a virus checker, popup blocker and a few other things) I have just about everything in my IE security settings set to 'Prompt' (except cookies which are turned off).

It means browsing is a nightmare of yes/no dialog boxes but it does give me control over whether a website runs activex controls and scripts (and 99% of the time I don't allow them to run).

Now I might be wrong, but this seems to help filter out a lot of crap.

The infobar in XPSP2 does the same thing for me without all the annoying yes/no boxes ;]

While you are at GRC.com, look for the GRC podcasts and download them all, then listen to them all; work smarter, not harder. You'll know what to do next after you listened to them all. Large amounts of good advice there but more than that you'll end up with an understanding - you won't get that in many places, for free, or pay for.

MadJack, your security settings in IE make no difference. The fact is you are using IE which is out of date and highly vulnerable to cookie exploitation and browser hijacking.

Um, I am connected to the net via a wireless router/modem, so does this mean I'm safe to ditch ZoneAlarm completely, then?

All routers have a built in firewall, in addition to sswift's explanation of the router not knowing who to send packets too. You can check your firewall settings by browsing to your routers IP# (192.168.2.1 usually).

If you are using a software firewall in addition to a router the effect your software firewall is having is:

A) To block connections such as file sharing to other computers on your local network - if you have multiple PC's in the house.
B) To block anything missed by your routers firewall, which if it is switched on, is absolutely nothing because routers really are the be all and end all of security. There's people out there who can get past routers especially if you dont have an admin password or you have left it at the factory default setting.

The instances of hacker attempts to a PC that is not running a firewall or router on the internet is on average once every 15 minutes. In the evenings this can extend to once every 5 minutes.

This includes not just people wanting acess to your PC, but spammers trying to find out if you are a relay, people wanting to hack something more important and use you as a relay, and the ocassional innocent but misguided traffic.

It's amazing how many times my router has blocked incoming connection attempts by worms/hackers.

My log shows almost every connection attempt listed on this page:
http://www.linklogger.com/commonscans.htm

yes, with no router I had several hundreds of hacking attempts a day. A router plus a software firewall is a good combination, plus an active Antivirus guard in the background.

Zonealarm is not bad, but like all firewalls it can be tunneled. Zonealarm has unlike most other firewall special Modification alerts, so it would prevetn other apps from editing its components. Of course this works only in Windows, as long as the computer is bootin in dos mode, everything can be done, including the modification of zonealarm to become an open door for anyone. During the boot sequence there is no protection of files.

Of course, disable boot on lan, as well al all other boot on whatever things you don't need (guess you don't need anything at all). Then unplug your machine from the web. Uninstall your firewall and your Antivirus App, then reinstall it from a clean Disk (eg. a Papermag Coverdisk). Do a OS repair with the OS CD ad add all patches / service packs etc, still offline (from the MS security disk that was published for free lately).

Uninstalling and reinstaling your firewall will make sure all compoments will use the original version, not hacked ones.

Updating your antivirus and firewall software over the web can be risky too. When your opponent has access to your Domain name server, he may redirect your connection to a spoofed Domain and let you download a modified "update". That said, this may happen with any software you download from the web. Usually only police and secret services are using this kind of attack, unless your DNS server is so old and weak that a script kid can spoof it.

ZoneAlarm has an Exploit available for it which allows An Attacker to route past it, without it blocking the attackers traffic.

The Attacker would have either used this to Shell in via an O-Day Exploit for UPNP or some other windows service thats running on your system, once in he will have exploited ZA's trafic filters to allow him to use tftp to upload his backdoor of choice, if hes good its one he coded himself so no virus scanners will detect it.

He will then just port into your syetem when ever he wants.

Worst case Senario :: Hes a Pro, and your computer is now nothing more than a Zombie, which we will either use to bounce future attacks off of, or he will use your system to attack some one else Direct..

Best Case Senario :: And this sounds like the one you have based on what you have said, He's a Skript kiddie, used the exploit and once in didnt have a clue what he was gona do next, so he @#!*ed about for a bit then left you that message.


A Pro would be in and out and never show it, A lighter shade of gray pro would be in and out and the only evidence you would have is a well detailed e-mail explaining how , why, where and when , as well as how to fix it and probably a link to the download for the ZA Patch.


My Suggestion to you would be get a Hardware firewall, and remove your PC from Direct connection to the Internet, this will make your system a hell of a lot more secore and keep 99% of the skript kiddies out of your hair.



PS. If you use Windows restore, I would use it now, and backup to a time you know or have a good feeling that your system was safe. Its possible the guy put a stealth keeper in as well while he was installing the trojan. the keeper just makes sure that the Trojan is alive, if you kill the trojan the keeper spawns a new one in a new place with a new name. and the Keeper only runs for a split second at boottime, so its extreamly hard to detect.

During the boot sequence there is no protection of files.

Ahh, so I'm not insane for unplugging my cable modem's power cable during reboot... :) I always wondered if there was a brief window of vulnerability (and only started doing it when my virus scanner started booting up before ZoneAlarm and "phoning home" before ZA loaded) - but I've always been a paranoid guy - and now it seems right to be so! :)

@Wendell .. I dont think you need to worry about files getting online as you boot before ZA kicks in, even though Cable and even DSL is always on, there is still a small Delay as your system starts up and the connection is reestablished.

What you need to do is scan your registry under windows->run , run_once and a few other less known about places for files that get started at boot.

Hello.

The general advice I've seen is to use a router and a software firewall, again with anti-malware products active. It makes sense to me, pain as it is, but better safe than sorry.

On a kinda related note - USB modems, are they dangerous? I heard someone recently suggest that they're riskier than smearing your wedding tackle with cream cheese and dipping it into a barrel of hungry rats...Hmm, maybe not that risky, but can anyone clear up that point?

Goodbye.

I've opened an entire class full of CD drives using my mobile phone, my home phone, my home pc and an internet connection. That looked super-cool to the rest of the class when i carried it out in class :)

A USB modem is no a router, it directly connects your machine to the internet. Using such a device means that you must rely upon a software firewall to protect your machine.

I use an ethernet modem, and that's connected to a wireless router. The modem itself has no firewall but the wireless router does. Basically any routing device that connects to multiple PC's rather than just 1 is safe, if it connects to just 1 device (like a USB modem) then you need to rely on a software firewall.

Yavin - the problem appears when the hacker writes a batch file that will modify zonealarm during the next boot process. A lot of important files are locked and protected, this is the reason why most hacks require to reboot the machine, even if you alter some stuff in the system, you need to reboot.

Additionally the network card is initialized before zonealarm starts, so I think it's possible to have a connection during the hardware initialisation.

it's always useful when you can see the LED light of your Ethernet Adapter. When it's blinking while Zonelalarm doesn't show any traffic, there may be something wrong.

I am glad this never happens here, I got a PCMCIA ethernet card and I can see the light all the time. Whenever it's blinking, Zonealarm shows traffic. And with Win98, the only process that asks for web access is the web browser.

If I don't start the browser, there's not a single program trying to access the web. Well, Windows explorer tried sometimes :) the sucker. Simply forbid it. And Mediaplayer of course.

That's another good thing about having a wireless connection, I s'pose: it takes a good few seconds after booting into windows for the connection to be made. By this time, firewall etc. are all up and running.

P.S. Why is MediaPlayer considered such a threat? I hear this all the time but haven't really bothered to investigate - computer security bores me rigid and I've never had any probs. Sheesh, all these security concerns are giving me a headache. :P It's getting so we won't have any time to actually work on our computers as we'll be spending the entire time dealing with security issues. :/

Best solution:

DONT USE YOUR COMPUTER.

'nuff said.

Found the cause:

Troj/LewDl-E

Protection since: 15 December 2005 23:12

So looks like I got that hot off the press!


Yavin - the problem appears when the hacker writes a batch file that will modify zonealarm during the next boot process. A lot of important files are locked and protected, this is the reason why most hacks require to reboot the machine, even if you alter some stuff in the system, you need to reboot.



God thats old school .. lol. there are easier safer ways to do this now and anyone using a .bat is, erm. old. :D


Additionally the network card is initialized before zonealarm starts, so I think it's possible to have a connection during the hardware initialisation.



I know from my system and others, this is not the case, as your system boots and resources are being heavily dented to load key files your NIC might try to connect but the connection isnt active (Normally) until after the firewall gets started.

Testing this many times and the only way I could take advantage of the gap in protection was by coding something to make that little gap a little wider, in my case it was some code that faked the firewall startup and then started it for real a few moments after giving my connection the time to route through.


I am glad this never happens here, I got a PCMCIA ethernet card and I can see the light all the time. Whenever it's blinking, Zonealarm shows traffic. And with Win98, the only process that asks for web access is the web browser.



Your still using 98 ? - if so you might want to know that processes can be hidden from the tasker, in fact in 98 you can hide a process from the OS (ok not really but it looks that way) so i would update .. its your call tho.

[/quote]


Media Player is a risk because of the way it handles plugins and such, its just another way in the front door. You would be supprised how many different methods ways and exploits that exist for some attacker to gain access to your computer.

The way in may be different each time but the process is very much the same every time.

1. Find a Target
2. Check the port/service/deamon your after is running
3. Flood the service causing it overwrite the CPU's registers
4. feed the new instruction code commonly cmd.exe and bind it to a port.
5. Telnet into the port, and run tftp with a single line command to upload your trojan of choice.
6. run the trojan.

All of the above, once you have a target takes seconds, if your both on a fast connection iv seen it take like 5-6 seconds. depending of course on the size of your backdoor programme.

Your best bet is still to use a Hardware firewall, this can be in the form of a router, or a second Crappy PC that you never use, just set it up to connect to the net and then route everything through it.

I used to do this ages ago, had a HoneyPot running on it, so was so funny watching attackers as they thought they were rooting it, when in fact all they were doing was showing me all their tricks MUHAHHA.