PC Review


Reply
Thread Tools Rate Thread

computer hacked through VNC

 
 
tarun.khurana@gmail.com
Guest
Posts: n/a
 
      18th Oct 2006
I was unaware that VNC connection is not secure without secure
tunneling, and was running on one of my machines for remote connection.
I realized that my computer was hacked into through VNC, and files like
"winserv.exe", "bw.exe" and some other exe files were transferred on my
machine (on my desktop). An IRC client was also installed on the
machine.
I also had zone alarm installed and running, but the hacker managed to
get in since VNC server was always running. I stopped VNC immediately
after i realized this and I haven't noticed any more suspicious
activity since then.
I am now running scans with Norton Antivirus and Spysweeper, but i'm
not sure if that's good enough. Could anyone recommend me as to what
could be done, besides reinstalling windows?

Thanks
Tarun

 
Reply With Quote
 
 
 
 
Yves Leclerc
Guest
Posts: n/a
 
      18th Oct 2006
Which version of VNC? Did VNC have a password? Look for UltraVNC
(www.ultraVNC.com.) This version seems to be more secure than RealVNC since
it has additional login validations (MS Logon.)



On 18/10/2006 "(E-Mail Removed)" <(E-Mail Removed)> wrote:
>I was unaware that VNC connection is not secure without secure
>tunneling, and was running on one of my machines for remote connection.
>I realized that my computer was hacked into through VNC, and files like
>"winserv.exe", "bw.exe" and some other exe files were transferred on my
>machine (on my desktop). An IRC client was also installed on the
>machine.
>I also had zone alarm installed and running, but the hacker managed to
>get in since VNC server was always running. I stopped VNC immediately
>after i realized this and I haven't noticed any more suspicious
>activity since then.
>I am now running scans with Norton Antivirus and Spysweeper, but i'm
>not sure if that's good enough. Could anyone recommend me as to what
>could be done, besides reinstalling windows?
>
>Thanks
>Tarun
>


--
---

Y.

 
Reply With Quote
 
Mark Ritchie
Guest
Posts: n/a
 
      19th Oct 2006
Well, a root kit might have been installed.
F-Secure has a program called blacklight, you can download a trial of it and
do a scan

http://www.f-secure.com/home_user/co...rotection.html



--
Regards,

Mark Ritchie


**************************************
Computer Problems Dragging you Down?
Let us Fix it for you quickly and remotely!
http://www.livetechsupport.ca
(866)730-5403
**************************************
<(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>I was unaware that VNC connection is not secure without secure
> tunneling, and was running on one of my machines for remote connection.
> I realized that my computer was hacked into through VNC, and files like
> "winserv.exe", "bw.exe" and some other exe files were transferred on my
> machine (on my desktop). An IRC client was also installed on the
> machine.
> I also had zone alarm installed and running, but the hacker managed to
> get in since VNC server was always running. I stopped VNC immediately
> after i realized this and I haven't noticed any more suspicious
> activity since then.
> I am now running scans with Norton Antivirus and Spysweeper, but i'm
> not sure if that's good enough. Could anyone recommend me as to what
> could be done, besides reinstalling windows?
>
> Thanks
> Tarun
>



 
Reply With Quote
 
Leythos
Guest
Posts: n/a
 
      19th Oct 2006
In article <(E-Mail Removed)>,
(E-Mail Removed) says...
> I was unaware that VNC connection is not secure without secure
> tunneling, and was running on one of my machines for remote connection.
> I realized that my computer was hacked into through VNC, and files like
> "winserv.exe", "bw.exe" and some other exe files were transferred on my
> machine (on my desktop). An IRC client was also installed on the
> machine.
>
> I also had zone alarm installed and running, but the hacker managed to
> get in since VNC server was always running. I stopped VNC immediately
> after i realized this and I haven't noticed any more suspicious
> activity since then.
>
> I am now running scans with Norton Antivirus and Spysweeper, but i'm
> not sure if that's good enough. Could anyone recommend me as to what
> could be done, besides reinstalling windows?


No version of any remote control application will be secure if all it
takes is a password and the client to connect to it. Your experience
could be the result of a weak password, other unprotected services on
your computer, etc...

I've run VNC for ages, and don't use the default port for it, and have
never seen a connection attempt. In most cases we setup a VPN appliance
and then run VNC on the default port, but for remotely accessible we
always use a nonstandard port and we use Strong Passwords that are
changed once a month.

Now that your system is compromised you need to ensure that it's clean,
there are two methods to clean the system:

1) Connect to a secured network, not allowing inbound, then
wipe/reinstall - this method means that your machine will be 100% free
of malware as you complete the reinstall (provided the reinstall media
was clean).

2) Clean the machine in safe mode and manually editing the registry, and
then HOPE that you/apps got it all.



--

(E-Mail Removed)
remove 999 in order to email me
 
Reply With Quote
 
Paul Greeff
Guest
Posts: n/a
 
      19th Oct 2006
Nothing in any of these posts indicates a reason for wanting to reinstall.
What is the problem that remains?

I've discontinued my use of VNC as well. The trouble, I'm told, is that the
password is not encrypted. I've switched to Remote Administrator instead,
which does encrypt the password. Any comments from anyone?

PG

"Leythos" <(E-Mail Removed)> wrote in message
news:9ZzZg.17038$(E-Mail Removed)...
> In article <(E-Mail Removed)>,
> (E-Mail Removed) says...
> > I was unaware that VNC connection is not secure without secure
> > tunneling, and was running on one of my machines for remote connection.
> > I realized that my computer was hacked into through VNC, and files like
> > "winserv.exe", "bw.exe" and some other exe files were transferred on my
> > machine (on my desktop). An IRC client was also installed on the
> > machine.
> >
> > I also had zone alarm installed and running, but the hacker managed to
> > get in since VNC server was always running. I stopped VNC immediately
> > after i realized this and I haven't noticed any more suspicious
> > activity since then.
> >
> > I am now running scans with Norton Antivirus and Spysweeper, but i'm
> > not sure if that's good enough. Could anyone recommend me as to what
> > could be done, besides reinstalling windows?

>
> No version of any remote control application will be secure if all it
> takes is a password and the client to connect to it. Your experience
> could be the result of a weak password, other unprotected services on
> your computer, etc...
>
> I've run VNC for ages, and don't use the default port for it, and have
> never seen a connection attempt. In most cases we setup a VPN appliance
> and then run VNC on the default port, but for remotely accessible we
> always use a nonstandard port and we use Strong Passwords that are
> changed once a month.
>
> Now that your system is compromised you need to ensure that it's clean,
> there are two methods to clean the system:
>
> 1) Connect to a secured network, not allowing inbound, then
> wipe/reinstall - this method means that your machine will be 100% free
> of malware as you complete the reinstall (provided the reinstall media
> was clean).
>
> 2) Clean the machine in safe mode and manually editing the registry, and
> then HOPE that you/apps got it all.
>
>
>
> --
>
> (E-Mail Removed)
> remove 999 in order to email me



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Computer Hacked Madxgraphics Security, Spyware and Viruses 5 7th Sep 2009 04:57 PM
Has my computer been hacked? MARVINJCOHEN@LYCOS.COM Anti-Virus 17 20th May 2006 02:46 PM
my computer was hacked into =?Utf-8?B?V2VuZHk=?= Windows XP Security 2 22nd Apr 2004 08:00 AM
a hacker hacked my computer and I cant fix it! svince Windows XP Customization 3 6th Nov 2003 03:40 AM
Is my computer being hacked? Qal Windows XP Security 2 1st Sep 2003 04:29 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 09:11 AM.