Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> Windows XP Exploit - Please Help.
uapconsole
post Jan 2 2007, 09:01 AM
Post #1


Newbie [ Level 2 ]
Group Icon

Group: Members
Posts: 24
Joined: 10-February 06
Member No.: 11,194



Hello everyone. I have a dell desktop running windows xp home edition. AVG virus checker found an exploit in Firefox's application database in My Documents.

I moved it to the "vault" in AVG. I have several clients to check the safety of my computer and it seems like my machine is secure, however, there is one problem.

My DHCP-cable modem is directly hooked to my computer. However, even when the computer is idle, the "Send/recieve" LED's (lights) constantly blink. Do I still have the exploit or somehow I can't catch the "Trojan" the exploit installed?

I run a home business and security is #1, so this makes me very concerned. I'd be grateful for all feedback.

Thank you and happy new years.
- Demirelli
Go to the top of the page
 
+Quote Post
Mark420
post Jan 2 2007, 10:54 AM
Post #2


The Modernator
Group Icon

Group: Members
Posts: 486
Joined: 6-August 06
From: The Interweb!
Member No.: 15,021



Sounds like you need a firewall as well as some virus protection..what firewall are you using? the winxp built in one? if so get rid of it and get something like Zonelabs or Black Ice..
Also I would do a deep scan with something like Adaware just to check whats eben left behind if anything by the exploit..my guess is that AVG has done its job because its one of the best anti virus on the market.

Go to the top of the page
 
+Quote Post
ne0
post Jan 2 2007, 04:28 PM
Post #3


Newbie [ Level 2 ]
Group Icon

Group: Members
Posts: 14
Joined: 30-December 06
Member No.: 18,945



Probably there are no trojans there.
First look at the connection status. Are there any sent/received bytes?

My best recommendation to you is to hook all the connections (TCP/IP). To do this you should download a tool named CPorts (or CurrPorts). You can download it from www.nirsoft.net .
So what does this tool do ?
It shows all the TCP/IP connections, the ports TCP/UDP and all open ports. By this tool you can view what kind of applications are making connections. So then you can find which of your application (or any running process) is connected to somewhere else.
By the connection you can find the IP adress of the host that application is connecting to. If that IP address belongs to untrusted "X" host then you can kill that application (process). But before killing that proces i recommend to capture for data on that connection. By capturing you can exactly know what kind of informations are uploading/downloading. So in order to capture i recommend you to download a tool named SmartSniff from www.nirsoft.net. SmartSniff captures all the TCP/IP packets that pass through your network adapter. After that probably you will be sure that "x" process is doing "x" things.

Or there maybe some another things ... It's up to your reply. smile.gif

Happy New Year!
Go to the top of the page
 
+Quote Post
uapconsole
post Jan 2 2007, 07:07 PM
Post #4


Newbie [ Level 2 ]
Group Icon

Group: Members
Posts: 24
Joined: 10-February 06
Member No.: 11,194



Thank you for replying, guys. I have a desktop dell and gateway laptop on a wireless network. Router New Linksys/Cisco powered wireless router/switch. My WAN/ISP connection is standard 384kbs DHCP-cable modem from Charter communications.

Both machines run windows xp home edit. they run AVG for virus scanning and Zone Alarm for firewall. AVG did find an exploit in my documents/firefox/...application data/...

I placed this file in the "virus vault" of avg agent. Now, there are no reports of exploits. However I am still a bit paranoid about these LEDs flashing on the cable modem. The Receive Led "flickers" even if both machines are idle. I even turned both machines off completely and the lights continued to blink. This leads me to conclude that perhaps there is a trojan client trying to shake hands with Trojan server that might be installed on one of my nodes. I hope I am being too paranoid, but its good to be on the safe side. I will try the TCP monitor you suggested, Neo, Happy New Years .
Go to the top of the page
 
+Quote Post
FirefoxRocks
post Jan 2 2007, 09:50 PM
Post #5


Super Member
Group Icon

Group: [HOSTED]
Posts: 658
Joined: 12-July 06
From: Ontario, Canada
Member No.: 14,464



The lights on my cable modem blinks even when my computers are off.
It is just an occasional message that your ISP sends you in order to test your connection and stuff like that. It isn't a harmful data packet that is going through (I hope).

Anyways, I wish you best of luck to figure out what it is. And hopefully it isn't something malicious attempting to connect. :|
Go to the top of the page
 
+Quote Post
tansqrx
post Jan 3 2007, 08:18 PM
Post #6


Super Member
Group Icon

Group: [HOSTED]
Posts: 522
Joined: 25-April 05
Member No.: 4,374



There is a lot of garbage that passes through an unfiltered cable connection. One possibility is of course your ISP sending its routine maintenance packets. On my particular network, the raw stream is filled with ARP packets from everyone on my node. I live in a fairly rural area so that could be many square miles.

In the end, think of your cable modem as a miniature computer. It has its own memory, processor, and operating system. Even if your main computer is off, this small computer is still running in the background receiving packets from the Internet. Depending on the model, even if nothing is attached the modem, it can still send ping relies and you can possibly remotely connect to the modem. Some networks are not internally switched so you are actually seeing every conversation on your node. Add to that the fact that just about every IP gets scanned several times a day (possibly 100s) by automated port scanners. In the end, there are a lot of raw packets hitting your cable modem.

A more valid reporting mechanism would be to look at the modem link light. These are the packets that are actually forwarded to your network (in this case you computer). Not every packet hits your computer and this should be a better indication of how much traffic you are receiving. Another monitoring tool is WireShark (formally Ethereal) located at http://www.wireshark.org/. It’s free and all you have to do is open a listener and see what is actually hitting you computer. I’m on the paranoid side so I actually listen to my traffic several times a month just to make sure nothing nasty has gotten in and is trying to phone home. In most cases you should have a very quiet wire as long as you are not surfing the net and avoid the occasional antivirus update.

I think the best solution for you is to get a hardware firewall or even a NAT router. This will stop 99% of the traffic from getting to you computer. I make this a recommendation to everyone who has a computer and just not in your case.
Go to the top of the page
 
+Quote Post
Lewisthemusician
post Jan 5 2007, 11:13 PM
Post #7


Member [ Level 2 ]
Group Icon

Group: Members
Posts: 51
Joined: 5-January 07
Member No.: 19,160



download more anti-virus's and search for virus's
I sugguest Spy Bot Search & Destroy
Go to the top of the page
 
+Quote Post
FirefoxRocks
post Feb 2 2007, 04:45 AM
Post #8


Super Member
Group Icon

Group: [HOSTED]
Posts: 658
Joined: 12-July 06
From: Ontario, Canada
Member No.: 14,464



Multiple Antivirus and Firewall will NOT help. They can cause compatibility issues and will interfere with each other.

Multiple anti-spyware software WILL help because sometimes one doesn't catch all of them. I once had up to 7 anti-spyware programs on my computer. I still have the installation files, just that they can't be installed because Shaw Secure won't allow me to.

SpyBot S&D, Ad-Aware Personal Edition, Yahoo! Toolbar with Anti-Spy are all good software to use to defend yourself from spyware.
Go to the top of the page
 
+Quote Post
Grafitti
post Feb 3 2007, 05:26 AM
Post #9


Premium Idiot
Group Icon

Group: [HOSTED]
Posts: 661
Joined: 9-July 05
From: Switzerland, but currently in Pakistan
Member No.: 6,943



ZoneAlarm's new firewall is pretty tough on rules. I would suggest you try that. When it's running, select "Lock all internet activity" and then see if the lights on the modem still blink. If they do, then that's just the modem checking in, possibly rejecting pings, whatever. then again, any decent firewall should have that option, so probably whatever you're running has it too.
For the paranoid, I haven't found anything yet that beats Kaspersky. I don't use it because it slows down the computer somewhat in its realtime scanning mode, but i don't know how much more secure you can get than that.
Go to the top of the page
 
+Quote Post

Fast ReplyReply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Windows Xp: Simple Way Of Obtaining Admin Access(8)
  2. Aim Virus Messing Around With My C:\windows Folder(10)
  3. Windows Sercurity Centre Is Spyware?(8)
  4. Another Exploit In Phpbb 2.0.17(7)
  5. Cracked Windows "genuine Advantage"(1)
  6. Worm Alert - W32.zotob.a(8)
  7. Gmail Exploit: Discovered By 14 Years Old Boy(33)
  8. IE6 & IE7 Beta 2 Address Bar Spoofing Exploit(4)
  9. Asta Worm ALERT: Exploit.Win32.WMF-PFV Trying To Infect(4)
  10. Windows XP Logon Script(11)
  11. Keep Your Windows XP Protected(9)
  12. My Windows Isn't Genuine?(16)
  13. Windows Has Slowed To A Crawl(4)
  14. MS Windows CSRSS Vulnerability(4)
  15. Difficult To Believe: Pdfs Put Windows Xp At Risk, Says Researcher(20)


 



- Lo-Fi Version Time is now: 6th September 2008 - 07:54 PM