I had an intrusion? A virus attack?

My recommendation would be to use an up to date and secure browser. I really like brave and some of the privacy focused Firefox variants. The most important thing is just be vigilant on what you visit and watch what you click.

1 Like

I used cuckoo sandbox. Reverting to an older recovery point should be fine. Iā€™d also get a better AV. Thereā€™s a lot out there so pick what works best for you.

In my personal opinion, I donā€™t like running Windows bare metal. It might as well be malware itself. But thatā€™s just my 2 cents and not everyone agrees.

2 Likes

Thanks :slight_smile:
By the way, which anti virus software do you recommend? I installed Kaspersky on my parents computers a while back and it seems to work reasonably well.
I switched to linux (fedora) about two years ago, found everything that I need and I regret nothing :grin:

As far as I know, Windows Defender does a pretty decent job for most users, without interfering too much. Other AV software often has its own bunch of vulnerabilities, while also inspecting encrypted traffic and things like that.

1 Like

Donā€™t get me wrong, itā€™s not a bad AV. Iā€™ve worked with a few Microsoft TAMs that are really proud of it. But IMHO I would choose a company who focuses on security. Just my two cents, but everyone is free to choose what they want to run.

If I had my way, and it was affordable, Iā€™d say everyone should be running carbon black, lol.

2 Likes

I actually like Kaspersky. ESET, avast and Trend Micro are all pretty good as well. Trend probably being my top pick for affordable home AV.

1 Like

Thanks for your opinion. I always find it useful to know whatā€™s around, have not heard about Trend and carbon black before. I never went into depth with AV software.

No, the US. We wonā€™t loose our memes for at least another 6 months:)

It was running for about 2 seconds. About 1 second to realize what was happening, and another second to superman dive across the living room to pull the ethernet and hit the power switch. But this has me more worried. I will record for awhile with nothing running and see if I can post the file. I am a little slow and half retarded, so it might take me a while.
Thank you for looking at it. You are appreciated greatly.

Uhmmm, this could be bad? What happens when I have a solid internet connection and wireshark detects no network to capture on?
Edit- just checked and my npf has stopped and it will not start?

ā€œIn Windows, with Wireshark 2.0.4, running as Administrator did not solve this for me. What did was restarting the NetGroup Packet Filter Driver (npf) service:
Open a Command Prompt with administrative privileges.
Execute the command sc query npf and verify if the service is running.
Execute the command sc stop npf followed by the command sc start npf.
Open WireShark and press F5.ā€

Another edit- OK I was able to reinstall it and open it as admin. I will run it for a while and post results:)

OK, that went smoother than expected. Here is about 15 minutes worth.
In the background, I had MSI Afterburner and Corsairā€™s iCUE open, Iā€™m hoping that didnā€™t affect it. Also showing in the background is Windows defender, Intel rapid storage, and Realtek HD audio manager.
To me it just looks like the router and pc talking back and forth. But I honestly donā€™t really understand what I am seeing, so I have no doubts I am wrong:)
It wonā€™t upload the fileā€¦OK, I looked up how to convert a pcapng file, and I guess it canā€™t be converted easily. Can it be 7-zipped?

object linking and embedding!
this little trick is used by a lot of bots to link a word to direct you to their website, you see that often on some sites until the admin gets around to cleaning it up!
another trick is stegonagraphy! (hiding a transparent link) linking on an image or part of the image to send you some-place else.( this trick was used by a lot of child pornography distributors. (for example you would download a cute cat picture and while scrolling the mouse pointer over it you could watch the bar at the bottom of the browser or screen and it would tell you where the link was pointing to)

it can be, yes.

OK, I tried to zip it.
Wireshark 15 Min Capture.zip (9.6 KB)

Youā€™re fine, nothing but normal traffic.

1 Like

Very interesting thread. I really need to play with and learn Wireshark. Ive used it a little and it is quite amazing software.

1 Like

Gods be praised! That is good news! I really appreciate someone a whole lot smarter than me looking at it.
Is it possible that this was not a malicious attack, but just a tactic to put a stop to digging deeper? Iā€™m just wondering, because it isnā€™t a link or a file, itā€™s an actual .com address. And I would think a real hacker would be way more sophisticated than this.
The only thing I could think of is that it was obvious on purpose?

While this might be the case (albeit being illegal), I doubt it. Many attacks arenā€™t that sophisticated, which is why updating your system is a good approach most of the time. (Ublock and NoScript do their part as well though^^). It isnā€™t without reason that on sites like exploitdb the vulnerability rating factors in ease of use :wink:
Also, keep in mind that against a highly sophisticated attacker (coupled with enough resources) there is probably not much you can do. There is always some kind of way.

1 Like

So the way this would work is browsers allowing changes to be made to system files through various means. This is also used legitimately by some websites, though o think it to be horrible and over-reaching design.

Itā€™s most likely that either you werenā€™t vulnerable to whatever exploit it was trying to exploit, or you stopped it before it could complete itā€™s work.

Like others have said, just try to keep up with best practices, patch frequently, and be security minded and youā€™ll be fine.

1 Like