What's the best Firewall to use? Someone is fudging w/ my computer!

Ryan

Lifer
Oct 31, 2000
27,519
2
81
Since 8am, I have been home alone. This morning, I did my usual rounds to all of my usual websites, and I played a little Quake. At about 9am, I went outside to work on my yard. When I came back in @ 11:30, my desktop and a bunch of my settings had been changed, and the mouse was moving around. I immediatly disconnected my cable modem. then restored everything to usual. I never thought I would get hacked, but now I have :(

I have a copy of Sygate Personal Firewall Pro that I got from, uh, somewhere, which is what I just installed after the incident. My question to you is what do you think the best firewall is, and is there anything I can do to prevent any further meddling with my computer?
 

Double Trouble

Elite Member
Oct 9, 1999
9,270
103
106
Sonds like there's a trojan somewhere on your PC that's allowing the person to take remote control of the PC. Just putting in firewall by itself might not help -- you also have to make sure the trojan is taken out and removed. Install a new virus software package (norton or mcafee or something), then add ZoneAlarm to the machine so you can detect incoming as well as outgoing activity from your PC.
 

Derango

Diamond Member
Jan 1, 2002
3,113
1
0
Originally posted by: tagej
Sonds like there's a trojan somewhere on your PC that's allowing the person to take remote control of the PC. Just putting in firewall by itself might not help -- you also have to make sure the trojan is taken out and removed. Install a new virus software package (norton or mcafee or something), then add ZoneAlarm to the machine so you can detect incoming as well as outgoing activity from your PC.

He might as well reformat/reinstall. There's no telling what that person could have put on your machine that you don't know about. And the only way to be sure everything is clean is to format/reinstall.

 

Ryan

Lifer
Oct 31, 2000
27,519
2
81
Well, I've already got Norton Antivirus installed, I guess I'll do an update and scan my system :Q
 

dakata24

Diamond Member
Aug 7, 2000
6,366
0
76
definately do a anti-virus scan (with latest definitions) and maybe a trojan scan with something like TDS-3 or trojan hunter. both of these packages offer 30-day trial versions.. both of these come highly recommended over at Dslreports Security Forum. As someone already mentioned, sounds like a trojan like back orifice or something..
 

Ryan

Lifer
Oct 31, 2000
27,519
2
81
Originally posted by: dakata24
definately do a anti-virus scan (with latest definitions) and maybe a trojan scan with something like TDS-3 or trojan hunter. both of these packages offer 30-day trial versions.. both of these come highly recommended over at Dslreports Security Forum. As someone already mentioned, sounds like a trojan like back orifice or something..

Thanks! I'm downloading them now :)
 

dakata24

Diamond Member
Aug 7, 2000
6,366
0
76
no problem. hope you get it cleaned up.. please update on what it was.. im curious to know. :)
 

Ryan

Lifer
Oct 31, 2000
27,519
2
81
Originally posted by: MrCodeDude
You actually saw the mouse curser move and all that stuff? Sounds like Sub7.. -- mrcodedude

It didn't really move, it jumped all over the screen to certain spots.
 

RossMAN

Grand Nagus
Feb 24, 2000
78,862
360
136
If you want to ensure that your PC is safe from trojan/viruses/corrupt files/bad drivers --- here's what I would do, some spring cleaning ... reformat your hard drive, re-install windows and everything else then install ZONE ALARM which is the best free firewall software.
 

XZeroII

Lifer
Jun 30, 2001
12,572
0
0
The only way to get rid of a virus like that is to burn your PC and get a new one. Make sure the fire is hot enough before you toss it in so it burns completely and doesn't smoke too bad
 

silverpig

Lifer
Jul 29, 2001
27,703
12
81
Got an old POS computer lying around anywhere? If you do, just install linux mandrake on it, use the auto firewall config, and set it up as your router. Should be good then.

If you don't, then all the other suggestions here are good.
 

Ryan

Lifer
Oct 31, 2000
27,519
2
81
Well, I have have Sygate Personal Firewall Pro running now, and have yet to see any activity..... :)
 

jthsmak

Senior member
Jul 5, 2001
732
0
0
A lot of trojans use a default file name that becomes associated with that trojan. Try closing all possible services (if you're on win2k/xp) and go to task manager and try any suspicious names in google and see if any virus like results pop up. (like expiorer.exe) Then check every possible way a virus could start up on your computer. Check the startup folder, registry under run and runservices and win.ini. Unfortunately, some of the newer trojans can be set to attach themselves to explorer.exe, for example, and are undetectable in this way. Antivirus scanners with current definitions often detect trojans, but trojan servers can be modified enough that they can escape detection. Also, virus scanners may not detect older or uncommon virii. I believe norton could be enabled disabled with a simple registry key, allowing any virus to disable that key and then infect your computer. I'm not sure if this has been fixed yet. The first thing a semi-intelligent hacker would do when connected is delete your netstat.exe and delete necessary dll files in whatever firewall/antivirus you had installed. Reinstall those if you have to. Once you have found out what you are infected with (if anything) do a google search for removal instructions. Example: If you were infected with subseven, do a search for subseven removal. Or you could be lazy and just format and reinstall windows.
 

Ryan

Lifer
Oct 31, 2000
27,519
2
81
Well, if it keeps acting up I might Format/reinstall. So far, since I have installed the firewall, nothing has happened :)
 

SnapIT

Banned
Jul 8, 2002
4,355
1
0
Originally posted by: ffmcobalt
Originally posted by: RossMAN
Zone Alarm

WHAT!? NO! :Q

Go with either Norton Internet Securities 2002 or Sygate Personal Firewall. They're the top two.

nik

Actually, if you want a firewall that costs money, then Zonealarm Pro IS a better choice... it is highly configurable, it has pop-up and cookie stoppers and it blocks not just attacks but also trojans... it has a built in e-mail scanner also... soooo...

If you are looking for something free... TPF - Tiny Personal Firewall is the best solution...
 

rgwalt

Diamond Member
Apr 22, 2000
7,393
0
0
Step one: Go to Best Buy, CompUSA, or something similar.

Step two: Buy a Linksys router/firewall.

Step three: Go home, setup and configure said firewall.

Step four: Reformat your machine if you desire.

Step five: ....

Step six: Profit

Ryan
 

SnapIT

Banned
Jul 8, 2002
4,355
1
0
Good. Don't use ZoneAlarm

I assume you are comparing the free version with the verions that cost money, or are you comparing them to the trialware? that would suck because after 30 days you have NO protection..
 

jthsmak

Senior member
Jul 5, 2001
732
0
0
Originally posted by: rbloedow
Well, if it keeps acting up I might Format/reinstall. So far, since I have installed the firewall, nothing has happened :)

Even if your firewall is blocking all traffic, you still might have a full-blown server using up your systme resources. If the firwall is ever not running, your false sense of security wil be shattered. Try the steps I listed for removing it before you relax.