5 ms·
There is a reason windows experts recommend full wipes: They know there are lots of places for nasty stuff to hide and it is not worth the time to try and find
by devopsproject 10y ago
There is a reason windows experts recommend full wipes: They know there are lots of places for nasty stuff to hide and it is not worth the time to try and find it all. Set your ego aside and wipe it.
- emodendroket 10y agoYeah, it is probably possible to recover, but it just doesn't make sense to spend the kind of time it would take to be sure.
- vonklaus 10y agoI have 2 clean compatible ddr3 ram caches and a new HD which I originally installed post breach (what I would do if my system) but I swapped back to orig hardware short term as she couldn't figure out new OS. Do you think it is likely that they installed backdoor(maliscious code)? I am not super familiar with PC but i would want to run the tcpdump equiv for powershell ect. I am just not familiar enough to know wheere files/daemons/ect are and how to diagnose it. Even if I would never reuse this HD, I would like to verify what happened. For me it would be i guess the same result but it would be better to know: if the computer was likely running malware or certainly running malware. in terms of actual actionable steps, they would really be the same fix. however, if i found active system processes sending data to random IPs, i would obviously excalate my concerns.
- emodendroket 10y agoWho knows, man? If you aren't a Windows system administration/Windows internals wizard you can't really hope to untangle it all.
- vonklaus 10y agothanks. i am capable, but i don't want to "untangle" it. I would always treat that system as maliscious. I just want to know if i should confirm it was maliscious. I could, in fact, run some program diagnostics. The impediment is less technical skill than a cost/benefit of me taking her computer back and freaking her out more.
- emodendroket 10y agoI don't understand the distinction you are making. If you are capable of identifying all the malicious software that's most of the way toward removing it.
- vonklaus 10y agoI want to clarify, securing a system from this caliber of attack is fairly trivial: * replace/reformat hardrive * replace RAM sticks for good measure, as I have them already. * config firewall * put on standard windows security settings, remove remote access to computer, ect. lock it down. * shes a grandmother. so essentially, just put a fuckton of addons on chrome and delete/hide other browsers. highest chrome security settings, httpseverywhere, adblock plus(not putting uBlock on, consider target user), ghostery, ect. * explain some high level steps to her about protecting herself, all popups are scams ect * if possible block incoming calls from 800, 900, international, and business numbers. Possible, but could impact her UX of life. * tell her to call me if she has questions first before doing anything. HOWEVER. A confirmation of malware would mean that the attack vector changes significantly. If a confirmation they actually actively did data harvesting or otherwise intend to go after her and her son's IDs or financials. I would escalate. I have already: * changed all card numbers, the router and ISPs passwords, * placed notes of breach in all accounts, ect. * confirmed no suspiscious activity on investments and also secured them to the best I could via that companies policy without needing a 3day verified letter to execute a transfer or change in postion of the portfolio. * replaced debit cards * reset investments login. [ I am aware that allowing her to use the likely compromised hard drive is a risk. but, I believe that between the security measures I have taken and the holiday weekend, I have some time to consider how I fix the issue technically ] But if I actually found proof of maliscious code, it wouldn't be likely they were going to continue scamming: it would be a near certainty. if the attack vector becomes securing any hole in America's horrible financial system, I would have to also set up account/credit monitoring, consider a credit freeze and take further measures. These are things I would possibly do to some extent for myself if this was my own system/life. however I am a technical user with a background in finance and tech, and I worked at a fintech startup where we were trying to sell to banks. So i am not an expert, but have MUCH more knowledge about the industry than the victim here. So I am doing cost/ben on how much I need to do here (also of my own time to some extent) to secure everything while still allowing her not to need to do 2 factor authentication and call her bank everytime she needs to buy groceries. She is 80, so for her demographic she is highly technical. Compared to even a 65 year old, she is certainly not and does not have the technical or peripheral knowledge to execute/do tasks we would consider basic: * make a change from win 7 - win 10 * use a password manager not already set up in chrome * understand seperation of technological concerns. for example, she didn't want to change to win 10 because her passwords are prefilled for her in Google Chrome, and the new operating system would require her to not have them. I am aware of how chrome accounts work, this is an example.