The following is the Featured ITKnowledge Exchange Tip for April 21, 2005.
"LMullen" writes: I'm an IT administrator with a little over 500 end users, running Windows 2000 and XP. One of our users is experiencing a problem with her Internet connection suddenly dropping for no apparent reason. When she restarts her computer, everything works fine for awhile, but then the connection drops again. The funny thing is, she's noticed that her AOL Instant Messenger service still works even when she can't access her e-mail. We've already run Netstat and noticed that more unknown open connections are being used to certain ports. This particular user has a laptop and works from home frequently, so we're not sure all updates have been installed.
Has her computer been hacked? If so, what can I do initially to contain the damage, and what steps can I take to prevent such occurrences in the future?
If there is an antivirus on the machine, I would make sure it is up to date and run a full system scan on it in safe mode with system restore turned off (alone with all your other antispyware scans), because viruses and spyware have a tendency to keep themselves in the system volume information and system restore. This allows them to come back easily due to the fact that a lot of scans do not scan there by default because system restore basically "locks" the folder. If you do not have an antivirus, I would suggest Computer Associates EZArmor, which is their AV/firewall combo. It is a very "lite" program as far as not using much memory and space (compared to using Norton or McAfee). There are updates out for the AV every day, and if there is a new version out, you have full access to download and install it (for the first year). Also the firewall is very easily configurable, and the whole suite is very easy to us. Make sure that your Windows Operating System is up to date. If the machine is XP, make sure SP2 is installed. All this can be accessed from here.
I doubt you have been hacked. Make sure you check the 'hosts' files on your machine, but most likely the dropping off of the network is due to spyware or a virus.
Also, AOL messenger has the potential for bringing things into the network. You should rethink the use of this product on company owned equipment.
Start your own discussion
Do you have a Windows security dilemma that needs quick attention? Talk about it in ITKE.
About the ITKnowledge Exchange
ITKnowledge Exchange is a place where IT pros can share ideas, expertise and get answers to their technical and strategic questions. It provides direct access between groups or individuals who are grappling with similar IT issues in a safe and seamless environment. Click to start participating today or go to the Tip of the Week archives.