Main Restorations Software Audio/Jukebox/MP3 Everything Else Buy/Sell/Trade
Project Announcements Monitor/Video GroovyMAME Merit/JVL Touchscreen Meet Up Retail Vendors
Driving & Racing Woodworking Software Support Forums Consoles Project Arcade Reviews
Automated Projects Artwork Frontend Support Forums Pinball Forum Discussion Old Boards
Raspberry Pi & Dev Board controls.dat Linux Miscellaneous Arcade Wiki Discussion Old Archives
Lightguns Arcade1Up Try the site in https mode Site News

Unread posts | New Replies | Recent posts | Rules | Chatroom | Wiki | File Repository | RSS | Submit news

  

Author Topic: Help! My computer has been hijacked!  (Read 1828 times)

0 Members and 1 Guest are viewing this topic.

mr.Curmudgeon

  • It's going to hurt your brain. A lot.
  • Wiki Master
  • Trade Count: (+1)
  • Full Member
  • *****
  • Offline Offline
  • Posts: 3833
  • Last login:October 11, 2021, 07:15:49 pm
  • Huzzah!
Help! My computer has been hijacked!
« on: November 29, 2005, 11:02:27 am »

Ok, I'm at my wits ends trying to figure out what's going on.

I noticed traffic on my router, threw a packet sniffer on my computer and lo and behold, ports 25 and 53...and others, are being overwhelmed with traffic. I've tried Norton AV, HijackThis, Search & Destroy and several other programs and they all found nothing.

It's definitely being used as a mail relay, but I don't have SMTP installed. I don't even have the IIS module on WinXP...so I have no idea how to thwart this.

Windows firewall doesn't do crap. So my question is: How do I find out which program is being referenced as the relay, so I can then destroy/fix the damn thing?




mrC

Havok

  • Keeper of the __Blue_Stars___
  • Trade Count: (+17)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 4530
  • Last login:July 11, 2025, 01:29:48 am
  • Insufficient facts always invite danger.
Re: Help! My computer has been hijacked!
« Reply #1 on: November 29, 2005, 11:09:17 am »
The Windows firewall sucks. It doesn't block outgoing traffic. Load up ZoneAlarm - it's one of the best in my opinion, get it here:

http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp?dc=12bms&ctry=US&lang=en&lid=dbtopnav_zass

Once it starts up, it will block everything until you authorize it. Then, you can track down what the problem is. I would also recommend running the Microsoft Anti-Spyware software. It's actually quite good. Get it here:

http://www.microsoft.com/downloads/details.aspx?FamilyID=321cd7a2-6a57-4c57-a8bd-dbf62eda9671&displaylang=en

I've seen a lot of really sneaky spyware out there - most of the "better" ones have their own SMTP engine, so you don't have to have IIS\SMTP installed for them to work silently in the background.

Good luck!
« Last Edit: November 29, 2005, 11:11:45 am by Havok »

AtomSmasher

  • I'm happy to fly below Saint's radar
  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 3884
  • Last login:September 02, 2022, 03:50:10 am
  • I'd rather be rich than stupid.
    • Atomic-Train
Re: Help! My computer has been hijacked!
« Reply #2 on: November 29, 2005, 11:09:54 am »
I'd try installing a firewall that limits both inbound and outbound traffic.

ChadTower

  • Chief Kicker - Nobody's perfect, including me. Fantastic body.
  • Trade Count: (+12)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 38212
  • Last login:July 30, 2025, 03:29:53 pm
Re: Help! My computer has been hijacked!
« Reply #3 on: November 29, 2005, 11:11:43 am »

You shouldn't be using a software and a hardware firewall together, if that is the case.

Does your router have a firewall in it? If so, use that one.  A firewall inside the network completely defeats the purpose. 

Conceptually... wall to prevent fire... if you put your firewall ON what you are trying to protect, by the time the fire gets there to stop, it's on what you are protecting.

Havok

  • Keeper of the __Blue_Stars___
  • Trade Count: (+17)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 4530
  • Last login:July 11, 2025, 01:29:48 am
  • Insufficient facts always invite danger.
Re: Help! My computer has been hijacked!
« Reply #4 on: November 29, 2005, 11:16:05 am »

You shouldn't be using a software and a hardware firewall together, if that is the case.

Does your router have a firewall in it? If so, use that one.

ChadTower

  • Chief Kicker - Nobody's perfect, including me. Fantastic body.
  • Trade Count: (+12)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 38212
  • Last login:July 30, 2025, 03:29:53 pm
Re: Help! My computer has been hijacked!
« Reply #5 on: November 29, 2005, 11:17:50 am »

Yeah, but if it's managed correctly, that outgoing software doesn't end up on the box inside the network to begin with.

And you can set up your hardware router to block outgoing as well.

AtomSmasher

  • I'm happy to fly below Saint's radar
  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 3884
  • Last login:September 02, 2022, 03:50:10 am
  • I'd rather be rich than stupid.
    • Atomic-Train
Re: Help! My computer has been hijacked!
« Reply #6 on: November 29, 2005, 11:19:34 am »

You shouldn't be using a software and a hardware firewall together, if that is the case.

Does your router have a firewall in it? If so, use that one.

missioncontrol

  • MC-Retro says Wot!
  • Trade Count: (+13)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 7855
  • Last login:November 06, 2024, 06:22:12 pm
Re: Help! My computer has been hijacked!
« Reply #7 on: November 29, 2005, 11:22:24 am »
Unplugging it from the wall helps too

Stingray

  • Official Slacker - I promise to try a lot less
  • Trade Count: (+2)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 10463
  • Last login:April 08, 2021, 03:43:54 pm
Re: Help! My computer has been hijacked!
« Reply #8 on: November 29, 2005, 11:27:20 am »
This is all Bush's fault.

-S
Stingray you magnificent bastard!
This place is dead lately.  Stingray scare everyone off?

missioncontrol

  • MC-Retro says Wot!
  • Trade Count: (+13)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 7855
  • Last login:November 06, 2024, 06:22:12 pm
Re: Help! My computer has been hijacked!
« Reply #9 on: November 29, 2005, 11:32:07 am »
I was waiting for someone to blame Bush  :P

ChadTower

  • Chief Kicker - Nobody's perfect, including me. Fantastic body.
  • Trade Count: (+12)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 38212
  • Last login:July 30, 2025, 03:29:53 pm
Re: Help! My computer has been hijacked!
« Reply #10 on: November 29, 2005, 11:37:33 am »

Well duh, it IS Mr C... the CIA has planted monitoring software on his machine.

I mean how many I HATE BUSH conversations can you have before the FBI tags you? 

Stingray

  • Official Slacker - I promise to try a lot less
  • Trade Count: (+2)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 10463
  • Last login:April 08, 2021, 03:43:54 pm
Re: Help! My computer has been hijacked!
« Reply #11 on: November 29, 2005, 11:54:45 am »
how many I HATE BUSH conversations can you have before the FBI tags you? 

I'll let you know. This is like the licks to the center of a tootsie pop thing, right?

-S
Stingray you magnificent bastard!
This place is dead lately.  Stingray scare everyone off?

SirPoonga

  • Puck'em Up
  • Global Moderator
  • Trade Count: (+1)
  • Full Member
  • *****
  • Offline Offline
  • Posts: 8188
  • Last login:July 20, 2025, 03:37:24 pm
  • The Bears Still Suck!
Re: Help! My computer has been hijacked!
« Reply #12 on: November 29, 2005, 11:55:54 am »

Yeah, but if it's managed correctly, that outgoing software doesn't end up on the box inside the network to begin with.

And you can set up your hardware router to block outgoing as well.

Right, but you can never have too much security.  It is wise to have both a software and hardware firewall.

This is all Bush's fault.
Actually, it's Al Gore's fault, he invented the internet.

ChadTower

  • Chief Kicker - Nobody's perfect, including me. Fantastic body.
  • Trade Count: (+12)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 38212
  • Last login:July 30, 2025, 03:29:53 pm
Re: Help! My computer has been hijacked!
« Reply #13 on: November 29, 2005, 12:05:03 pm »
I'll let you know. This is like the licks to the center of a tootsie pop thing, right?

I knew a stripper who called herself Tootsie Pop. 

It took quite a few licks.

mr.Curmudgeon

  • It's going to hurt your brain. A lot.
  • Wiki Master
  • Trade Count: (+1)
  • Full Member
  • *****
  • Offline Offline
  • Posts: 3833
  • Last login:October 11, 2021, 07:15:49 pm
  • Huzzah!
Re: Help! My computer has been hijacked!
« Reply #14 on: November 29, 2005, 12:05:26 pm »
I have a netopia router with a built-in hardware firewall. I initially started with all ports blocked, and only opened the ports I actually use. However, over time and since I use my computer to do a great many things (P2P, Gaming, Development, IM, etc) there are now a great many number of ports open.

Personally I hate software firewalls, and I've have pretty good protection with the netopia. I believe the trojan got in when I clicked on a file within my LAN. It was included with a file from a trusted source, so I assume the person wasn't aware of the offending program.

I'm going to try ZoneAlarm when I get home from work today and we'll see how that goes.

Btw, is there any kind of program that will allow you to see what's being called on in memory, etc...ie: Kind of like a packet sniffer, but for program tasks (other than task manager, since that doesn't necessarily show you what is being called and how)?

And finally, I blame Cheney...



mrC

ChadTower

  • Chief Kicker - Nobody's perfect, including me. Fantastic body.
  • Trade Count: (+12)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 38212
  • Last login:July 30, 2025, 03:29:53 pm
Re: Help! My computer has been hijacked!
« Reply #15 on: November 29, 2005, 12:18:42 pm »

There are better shareware apps out there that have a GUI like the Task Manager but will allow you to drill down into threads and windows dll calls and such.

NinjaEpisode

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 733
  • Last login:June 16, 2019, 06:47:45 pm
Re: Help! My computer has been hijacked!
« Reply #16 on: November 29, 2005, 12:44:55 pm »
Btw, is there any kind of program that will allow you to see what's being called on in memory, etc...ie: Kind of like a packet sniffer, but for program tasks (other than task manager, since that doesn't necessarily show you what is being called and how)?

Check out Regmon and Filemon.  Both will tell you all that's being accessed, written, deleted, etc. on a machine.

They're created by Sysinternals, who also have a bunch of other tools, such as PMon which will let you take a little closer look at the processes and threads.

mr.Curmudgeon

  • It's going to hurt your brain. A lot.
  • Wiki Master
  • Trade Count: (+1)
  • Full Member
  • *****
  • Offline Offline
  • Posts: 3833
  • Last login:October 11, 2021, 07:15:49 pm
  • Huzzah!
Re: Help! My computer has been hijacked!
« Reply #17 on: November 29, 2005, 12:52:32 pm »


Sweet!  I'll give that stuff a shot. Wish I could leave work right now!


mrC

JackTucky

  • Trade Count: (+1)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 1613
  • Last login:January 04, 2021, 12:00:58 pm
  • Soon I will post that I am a triathalete
Re: Help! My computer has been hijacked!
« Reply #18 on: November 29, 2005, 01:59:45 pm »
You need a software firewall to keep out the other jerks on the LAN, and a hardware firewall to keep the jerks out of the whole LAN.

and I blame Howard Dean.

yeehaa!

Art
Well, that's where we go a-ridin' into town, a whampin' and whompin' every livin' thing that moves within an inch of its life. Except the women folks, of course.

Jess--

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 243
  • Last login:April 05, 2023, 09:51:55 am
    • My Botched Cab
Re: Help! My computer has been hijacked!
« Reply #19 on: November 30, 2005, 06:16:47 am »
if you are trying to find the program doing the work have a quick search for a bit of software called Active Ports

it list all connections in / out of your PC, where they are connecting to, what port they are using and more importantly what program is creating that connection.

also give you a method of killing any active task (even if windows is relying on it.... no protection for any tasks)

saint

  • turned to the Dark Side
  • Supreme Chancellor
  • Trade Count: (+6)
  • Full Member
  • *****
  • Offline Offline
  • Posts: 6149
  • Last login:July 26, 2025, 06:47:53 pm
  • I only work in cyberspace...
    • Build Your Own Arcade Controls
Re: Help! My computer has been hijacked!
« Reply #20 on: November 30, 2005, 08:15:49 am »
Layering your protection is one of the strategies recommended today. Both desktop and gateway protection (be it firewall, antivirus, etc...) is a great approach.


Yeah, but if it's managed correctly, that outgoing software doesn't end up on the box inside the network to begin with.

And you can set up your hardware router to block outgoing as well.
--- John St.Clair
     Build Your Own Arcade Controls FAQ
     http://www.arcadecontrols.com/
     Project Arcade 2!
     http://www.projectarcade2.com/
     saint@arcadecontrols.com

mr.Curmudgeon

  • It's going to hurt your brain. A lot.
  • Wiki Master
  • Trade Count: (+1)
  • Full Member
  • *****
  • Offline Offline
  • Posts: 3833
  • Last login:October 11, 2021, 07:15:49 pm
  • Huzzah!
Re: Help! My computer has been hijacked!
« Reply #21 on: November 30, 2005, 11:49:47 am »

Ok, here's the update:

Ran a couple of the software suites mentioned. ZoneAlarm has successfully stopped the hijack from calling out to the internet, but the infestation is still in the system.

It appears that one of my system tasks has been hijacked and turned into a mail relay.

'Winlogon.exe' is the problem, but it's a necessary sub-system of winXP and I'm not sure how to deal with it, since I can't delete it. I'm searching the 'net for tips, we'll see how it works out.

Suggestions are welcome, especially if someone has dealt with something similar.


mrC

whammoed

  • Trade Count: (+4)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 2310
  • Last login:July 29, 2025, 11:05:33 am
  • Crack don't smoke itself
    • NiceMite
Re: Help! My computer has been hijacked!
« Reply #22 on: November 30, 2005, 12:06:23 pm »
This is sort of a cop out answer, but sometimes a reformat and re-install is quicker than all the time spent trying to figure out your problem...and sometimes you never figure it out.

xar256

  • Trade Count: (+4)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 267
  • Last login:February 03, 2025, 08:50:13 pm
Re: Help! My computer has been hijacked!
« Reply #23 on: November 30, 2005, 12:33:34 pm »
C:\windows\system32\winlogon.exe is a system file.  But there are several other viruses out there that create winlogon.exe in other folders.

Do a search on your system for other versions of that file...You may have your answer.

Xar256 ;D