Solved

Rogue remote control identification

Posted on 2011-09-02
11
303 Views
Last Modified: 2012-05-12
Hi all

We had a report from an end-user this morning about a rogue remote control session on her PC. The user witnessed the remote session reading e-mails and then shutting down her PC.

I've checked the event logs and there's nothing there, and have also ran a number of anti-spyware tools (CA, AVG, MalwareBytes, Spybot Search & Destroy) and none of them have found anything malicious.

What else can I check to identify the cause and source of the intrusion?

Cheers,

Paul
0
Comment
Question by:vistasupport
  • 4
  • 4
  • 2
11 Comments
 
LVL 37

Accepted Solution

by:
Gerwin Jansen earned 250 total points
ID: 36472820
Hi, possibly a rootkit. You can scan for rootkits using GMER. Please scan (will take some time) and post back the results.
0
 
LVL 2

Assisted Solution

by:Sarcast
Sarcast earned 250 total points
ID: 36473832
Check the firewall and turn it on. No connection, no session.

Apart from that, if a rootkit or virus is involved, it's always safer and the best solution to backup and reinstall the system.

Apart from that you can run the netstat command to see open connections.
0
 

Author Comment

by:vistasupport
ID: 36474041
the only results from the GMER scan is that our AV product (CA) is being identified as an API Interceptor.

Other than that, there's no other entries.

I will reinstall the system, but I'd like to identify the cause to try to prevent future occurrences, as well as provide answers to senior people - something I can't do at the moment.

Thanks

Paul
0
 
LVL 37

Expert Comment

by:Gerwin Jansen
ID: 36475143
In that case, what kind of remote / management application are you using? It may be as simple as someone knowing a password and just using Windows Remote assistance or some other commercial aplication that you use. I'm assuming your WindowsXP is SP3 and fully patched.
0
 

Author Comment

by:vistasupport
ID: 36483137
We use Dameware remote control, which writes to the event log upon connection as well as notify the end user.  Windows Remote Assistance is disabled.  Yes, Win XP SP3 fully patched through WSUS.

I've now run 5 different scans against and still not picking anything up.  How likely is it that such a tool can completely remove itself and if it is doing that, how is it getting back on (assuming the attacker would wish to get back on)?

I'm struggling to understand how there's no trace of such activity.

Thanks

Paul
0
Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

 
LVL 37

Expert Comment

by:Gerwin Jansen
ID: 36483388
>> How likely is it that such a tool can completely remove itself and if it is doing that, how is it getting back on (assuming the attacker would wish to get back on)?

I'm afraid this is possible in theory but it will require that the person has knowledge of an administrative password (domain or local) or a 0-day security issue. Copying files through a share to %TEMP%, starting a service through psexec, connecting and reversing the whole, including removing its traces.

This is a difficult case, I'm thinking of a way to log all inbound traffic, either by means of a firewall or some packet logger like wireshark.

Has this issue happened again in the meanwhile? Do you know of the same incident with other employees?
0
 
LVL 2

Expert Comment

by:Sarcast
ID: 36483432
Did you find any evidence at all of this happening, apart fromt he User 'seeing it happen' ?

Not to discredit the user, but I've seen users having misinterpreted technical issue's rather often.
For example, a wireless mouse with low battery can do funny things with a mouse and a restart could also be caused by windows update.

0
 

Author Comment

by:vistasupport
ID: 36483867
gerwinjansen - We haven't had reports of any other incidents so this does seem to be an isolated event.  We'll take a look at the security on our LAN as we've just gone through some log files with our firewall people and there's absolutely no evidence the attack originated externally.

sarcast - from the users description, it's unlikely to be a technical issue.  The remote session loaded up some e-mails and then clicked on the Start button, chose shutdown and then shutdown the PC.  That seems to be a clear number of specific steps.  We did initially think it was technical, but after that description it's unlikely.



0
 
LVL 37

Expert Comment

by:Gerwin Jansen
ID: 36484293
>> we've just gone through some log files with our firewall people and there's absolutely no evidence the attack originated externally

That is (partially) good news, means that no one was able to access your system(s) from the outside. But it also means that someone from the inside may know admin usernames/passwords. I would change them if this is not already normal practice after such an incident. Do you have local admin accounts or only domain admin accounts?
0
 

Author Comment

by:vistasupport
ID: 36488172
Yes, it seems unlikely we are going to track this down so we need to review our security.

We have local admin accounts on each PC, but member server admin accounts are disabled. Default domain admin account is also disabled.

Looks like we need to reset the password on every local admin (or disable it?) and lock down the firewall to only accept Dameware connections from specific IPs (those in IT dept).

One problem we have is managing password change for remote users.

We have two groups:

Business Development team - equipped with laptops that are members of our domain, but have offline files enabled. They visit the office and connect to the domain on an irregular basis - there's no guarantee that they will receive a password expiry notification (currently 14 days) during their visit.

Field workers - will login to OWA & Sharepoint via a remote web browser (home PC, etc) from non-domain PCs.

Currently we set their passwords to not expire - what's the best way for them to change their password while off our domain should their password expire?  
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

The month of August was another action packed month for hackers and a security nightmare for many retailers and restaurant establishments. Some of the more notable data breach victims this past month included supermarket giants SUPERVALU and Alberts…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
This tutorial demonstrates a quick way of adding group price to multiple Magento products.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now