jon123
June 25th, 2008, 09:36 PM
After a quick glance last week at this thread seems I have the same prob http://www.wilderssecurity.com/showthread.php?t=211813&highlight=rootkit+router
So here's the situation.
I run windows behind a 4port nat router with the latest available firmware, setup with what might be described as "paranoid settings.
I have had it running untouched this way for a couple of years. The modem I turn off when not being used, and according to the tech at my isp it's firmware is non-upgradeable.
Couple of weeks ago:
nic started to fail. Initially the traffic indicator light on the router became intermittent and then it's prescence (as indicated by the lights) disappeared altogether. Though initially device manager indicated that it was working properly, it eventually vanished altogether.
Initially suspecting a hardware failure of some sort I tried it in different slots, no go.
Next steps:
-Flash mobo bios, rundisk utility and find bad sectors.
-Format, take a "cloned to disk" backup of about a year ago and clone back. (EDIT: again run disk util, all fine)
Voila! All seems fine. Update av, after a few days same thing.
-Take hard drive clone of three years ago off shelf, do not update anything.
Voila! All seems fine. After a few days, same thing.
Under every circumstance linux works fine. (I dual boot) Clones were without linux. Linux was installed after clone back to known functional setup each time.
Would seem nic or router has been comprised, router has not been re-flashed and is currently running fine (EDIT: under linux) for several days, including browsing. Router traffic seems to initiate on it's own with modem off. (I also have a habit of powering off router) Haven't as yet checked for traffic with computer off.
I run several utils to disable all kinds of stuff. I don't normally use IE though it is there, and Internet Properties is even more paranoidly set. Firefox or Opera under Win. After available update at MS (again some years back) the messenger service could not be disabled.
My next step is to replace nic with same model (brand new) and spare unused router of same model, and go through same procedure of flash format and clone. I'm betting all will be fine under Win.
What do you suppose has caused this?
So here's the situation.
I run windows behind a 4port nat router with the latest available firmware, setup with what might be described as "paranoid settings.
I have had it running untouched this way for a couple of years. The modem I turn off when not being used, and according to the tech at my isp it's firmware is non-upgradeable.
Couple of weeks ago:
nic started to fail. Initially the traffic indicator light on the router became intermittent and then it's prescence (as indicated by the lights) disappeared altogether. Though initially device manager indicated that it was working properly, it eventually vanished altogether.
Initially suspecting a hardware failure of some sort I tried it in different slots, no go.
Next steps:
-Flash mobo bios, rundisk utility and find bad sectors.
-Format, take a "cloned to disk" backup of about a year ago and clone back. (EDIT: again run disk util, all fine)
Voila! All seems fine. Update av, after a few days same thing.
-Take hard drive clone of three years ago off shelf, do not update anything.
Voila! All seems fine. After a few days, same thing.
Under every circumstance linux works fine. (I dual boot) Clones were without linux. Linux was installed after clone back to known functional setup each time.
Would seem nic or router has been comprised, router has not been re-flashed and is currently running fine (EDIT: under linux) for several days, including browsing. Router traffic seems to initiate on it's own with modem off. (I also have a habit of powering off router) Haven't as yet checked for traffic with computer off.
I run several utils to disable all kinds of stuff. I don't normally use IE though it is there, and Internet Properties is even more paranoidly set. Firefox or Opera under Win. After available update at MS (again some years back) the messenger service could not be disabled.
My next step is to replace nic with same model (brand new) and spare unused router of same model, and go through same procedure of flash format and clone. I'm betting all will be fine under Win.
What do you suppose has caused this?