Re: Computers got Hacked?? Please Help!!!

From: Jeff Cochran (jeff.nospam_at_zina.com)
Date: 09/19/04

  • Next message: Miha Pihler: "Re: I have installed my digital certificate,but where is my public key?"
    Date: Sun, 19 Sep 2004 15:54:33 GMT
    
    

    On Sat, 18 Sep 2004 23:23:03 -0700, itsupport
    <itsupport@discussions.microsoft.com> wrote:

    >2 days ago, something strange has happened to our work computers. It
    >happened to our windows 2003 server and several other users' pcs (win2K and
    >win XP). cmd.exe window will pop up but no scripts is shown. Then, IE will be
    >opened by itself and goes to websites like rotten.com showing gross pics,
    >google and etc. Also, sometimes Solitaire, Calculator, My Documents will be
    >opened too. This happends randomly throughout the day.
    >
    >I've checked the firewall logs, ran spybot,adware and virus scans. But
    >couldn't detect anything. Searched on google for similar incident, but didn't
    >find anything either:(
    >
    >Please help as I'm clueless of what to do next in order to get rid of this
    >prob! I really appreciate your help.

    Sounds like a prank more than a virus or trojan, but if someone has
    access to your system you've already lost. Might try rollbacks on the
    XP systems for a start, restore from backup prior to two days ago for
    the rest. Auditing security events would help track this, ensureing
    systems are properly firewalled and disconnecting from an internet
    connection to determine if this is internal or external might all be
    prudent.

    I also happen to subscribe to the "slash and burn" policy, nuke 'em
    all and rebuild. While nice to know the cause, if your business is at
    risk a full-on assault is warranted.

    Jeff


  • Next message: Miha Pihler: "Re: I have installed my digital certificate,but where is my public key?"

    Relevant Pages