Computing.Net > Forums > Security and Virus > What should I do now????

What should I do now????

Reply to Message Icon

Original Message
Name: huney
Date: July 28, 2003 at 20:41:46 Pacific
Subject: What should I do now????
OS: XP Pro
CPU/Ram: P4 1.8GHz 768MB Ram
Comment:

I think my computer has been hacked into. And if so, I figure all my data was compromised for at least 5 minutes. This is what happened...I use Zone Alarm Pro for XP, and have been for quite a while now and never had any complaints about it. (And I still don't) I keep it updated regularly also. The other night I was doing some work on my computer when I got up and left it for about 20 to 25 minutes. It was still running and connected to the web. (I have cable hookup for the web) Anyways, I wasnt finished but needed food, but when i got back I noticed that I was no longer connected to the web. I couldnt open my MSN browser, it just would not connect. So I opened IE and as soon as I did that Zone Alarms page came up and said that it has enabled the internet lock because an outside source had attempted to shut down Zone Alarm.

Well it has never ever done that before in all the time i have been using it, so I'm not buying that it was a glitch of some kind. But now I'm noticing that files have been moved around and some deleted even. This is why I believe my computer has been compromised. So my question is...NOW WHAT!!!???? What do I need to do if someone is in my computer and has figured out how to get past my security. How do I get rid of them????


Report Offensive Message For Removal


Response Number 1
Name: why??????????
Date: July 28, 2003 at 21:10:52 Pacific
Subject: What should I do now????
Reply: (edit)

What....nobody knows the answer to this problem???? sheeeesh...I thought for sure I would get a bunch of different opinions. See what I get for thinking!!!!


Report Offensive Follow Up For Removal

Response Number 2
Name: anonproxy
Date: July 28, 2003 at 22:34:07 Pacific
Subject: What should I do now????
Reply: (edit)

Look at the firewall logs and the system event logs. Look for programs contacting the outside, deleted entries, or the obvious.

Close all unnecessary ports. Disable incoming traffic (will only affect anyone trying to get in, not you getting out).

Run a trojan scan (many online) and run your AV once over the drive.


Report Offensive Follow Up For Removal

Response Number 3
Name: ok
Date: July 28, 2003 at 22:36:23 Pacific
Subject: What should I do now????
Reply: (edit)

when i leave my pc i manually enable the internet lockdown,(or the "block all"in sygate)
1st i would run a trojan scan to see if they planted a trojan backdoor, 2nd run antivirus
scan,and to quote capt
"Do some other online antivirus scans from the Trend Micro, Mcafee or Panda websites. Perform the system scans at PC Pitstop, PC Flank and Browsercheck to ensure your security settings are correct. Get and run SWATIT from the Lockdown Corp(free anti-trojan program), and/or try a free trial anti-trojan program that is recommended at the PC Flank website"


Report Offensive Follow Up For Removal

Response Number 4
Name: blender
Date: July 28, 2003 at 22:48:59 Pacific
Subject: What should I do now????
Reply: (edit)

Along with all the other suggestions above...change all your passwords asap, and if you shop with credit cards online...cancel them and renew cards, banking pin numbers, etc...


Report Offensive Follow Up For Removal

Response Number 5
Name: huney
Date: July 28, 2003 at 23:49:50 Pacific
Subject: What should I do now????
Reply: (edit)

Thanx guys I knew you wouldnt let me down!!!! Your the best....god i love this site!!!!


Report Offensive Follow Up For Removal


Response Number 6
Name: huney
Date: July 28, 2003 at 23:52:19 Pacific
Subject: What should I do now????
Reply: (edit)

Oh, one more thing...whats your take on "Black Ice" internet security software????


Report Offensive Follow Up For Removal

Response Number 7
Name: anonproxy
Date: July 29, 2003 at 09:17:56 Pacific
Subject: What should I do now????
Reply: (edit)

Don't use it. At least, don't pay for it. A regular rule-based firewall is fine and exhibits greater reliability.

http://arstechnica.infopop.net/OpenTopic/page?a=tpc&s=50009562&f=174096756&m=2470905073&r=2470905073
http://www.eeye.com/html/Research/Advisories/AL20020208.html


Report Offensive Follow Up For Removal

Response Number 8
Name: murve
Date: July 29, 2003 at 11:26:41 Pacific
Subject: What should I do now????
Reply: (edit)

hi huney,
its ok to use black ice, but remember this, its an intrusion detection program and not a firewall, you can use it in conjunction with a good free firewall such as kerio, sygate, outpost, and or zone alarm.
there may be a patch that you will have to install also, so check the post above.
all the best,
murve


Report Offensive Follow Up For Removal






Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: What should I do now????

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




How often do you use Computing.Net?

Every Day
Once a Week
Once a Month
This Is My First Time!


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge