Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Hacked again??? |
|---|---|
| Date: | Fri, 17 Jun 2005 03:28:40 +0200 |
Mauricio Fernandez schrieb:
I am not sure, but I think that I was hacked again.
Not really. You "hacked" yourself bei using broken software and not using your brain ;-)
I have a w2k SP4 full patched box
Fine.
with KerioFirewall,
Not so fine. Desktop Firewalls are _not_ useful. They can't reliable control outgoing connections, especially if your run your computer as Administrator (and I guess, you do). In some cases, Desktop Firewalls aka Personal Firewalls are making your system weaker (because there were additional bugs in some firewalls). I guess, you are working in a network with other machines ... so check _every_ machine in your network. And ... get off this lousy "firewalls".
Winproc.exe
<http://it.trendmicro-europe.com/enterprise/vinfo/encyclopedia.php?LYstr=VMAINDATA&VName=TROJ_PWSIM.A> Please, completely re-setup your machine and, this is important, CHANGE EVERY PASSWORT YOU EVER USED. TROJ_PWSIM.A is a Keylogger, so every password you typed in during the Malware was active, is PROBABLY STOLEN. Read: <http://www.microsoft.com/technet/community/columns/secmgmt/sm0504.mspx>
Msnmsgr.exe
Several possibilities: <http://www.sophos.com/virusinfo/analyses/w32rbotjz.html> < If this is the real intruder, your machine is not longer yours, probably a zombie in a bigger Bot-Net. Now you have really to re-setup your machine.
Does anyone know some attack with this three files combination?
Read the linked pages. Additionally you can use a very good german tool: <http://ntsvcfg.de/ntsvcfg_eng.html> I did really good experiences with this. Most of this $)§@&$-Malware will not harm you anymore - if you operate your computer wisely, of course! Please, read additionally: <http://www.microsoft.com/technet/archive/community/columns/security/essays/10imlaws.mspx> <http://www.microsoft.com/germany/technet/datenbank/articles/600237.mspx> <http://www.microsoft.com/germany/technet/datenbank/articles/600236.mspx> Greetings, Chris
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Is it hacking?, James M. Clark |
|---|---|
| Next by Date: | RE: Skype bypasses Windows XP Firewall, David Low |
| Previous by Thread: | Re: Hacked again???, Ansgar -59cobalt- Wiechers |
| Next by Thread: | Re: Hacked again???, mod . sparda |
| Indexes: | [Date] [Thread] [Top] [All Lists] |