Hello all, I am posting today desperately hoping to get some advice...
I know I'm too late here to do any good, but I'm kind of surprised no one suggested to the OP that he:
Power-off and disconnect all wires including cable & power from all of the
- modem(s)
- router(s)
- computer(s)
- any IoT connected devices (sorry SmartTV, cameras, and such, but y'all gonna have to go dumb a bit)
- TURN OFF Wi-Fi ON YOUR CELL PHONE & LEAVE IT OFF
Now no thing is connected in any way to any other thing. OK, now that you're totally air-gapped you need a shopping list:
- NEW MODEM (personal or ISP) >>> DO NOT GET/USE A COMBO MODEM-ROUTER <<<
- NEW ROUTER (personal or ISP)
- NEW COMPUTER (cheap, even Chromebook, is fine for this)
- NEW ADAPTER IF NEEDED TO CONNECT ETHERNET TO THE NEW COMPUTER
- NEW SHORT ETHERNET CABLES (2-3) IF NEEDED
- PAPER & PENCIL
EDIT 30APR20
These really should be here...
- NOTIFY FINANCIAL INSTITUTIONS
- REPLACE CREDIT CARDS
- SETUP CREDIT LOCK or FREEZE (Transunion, Equifax, Experian, etc.)
If you do this right after the shopping you'll have your stuff, be able to confirm the purchases, then be able to await replacements. The security people I've worked with for these things have always been very professional, polite, and helpful. They want to get you back on track as much as you do.
There are about a gazillion reasons NOT to get a combo modem-router that are beyond the scope of this post. Don't. Just say NO. You really want your own personal private router. Also, you'll notice I did NOT say "reset (___) to factory original". You want fresh equipment at this point even if you have to buy it.
Now let's start getting you back up. Setup your cell phone as an access point:
plug your phone into wall power either now or after setting it up
- if you don't use iOS: >>> FACTORY RESET YOUR PHONE | USE NEW PASSCODE <<<
- if you don't use iOS: use your phone to query how to do 1-6 BELOW
if you do use iOS...
- on iOS: Settings > General > About | Wi-Fi Address (WRITE THIS MAC ADDRESS DOWN)
- on iOS: Settings > General > About | Bluetooth (WRITE THIS MAC ADDRESS DOWN)
- on iOS: Settings > Touch ID & Passcode > Change Passcode ENTER A NEW PASSCODE
- on iOS: Settings > Cellular > Cellular Data [ON]
- on iOS: Settings > Personal Hotspot > Allow Others to Join [ON]
- USE A GOOD MIxEd PASSPHRASE with numbers & special characters
Now you have fairly secure*, fully-powered, battery backed-up access to the internet. Let's do your new-safe laptop next:
- WRITE DOWN THE MAC ADDRESS(ES) OF YOUR NEW LAPTOP
- plug the laptop into wall power
- go to the BIOS/UEFI
- setup a hard drive password
- require a ctl-alt-del to wake from sleep or whatever
- exit the BIOS/UEFI and setup a DIFFERENT password to log onto the OS
Now you have a fairly secure, fully-powered, battery backed-up portable computer. Let's setup this NEW computer to use the internet:
- CONNECT your new computer to your cell phone's new personal hotspot
OK. Now you have temporary, slower, and more expensive online access to references & vendors assuming you don't go down rabbit holes or playing games. You also have a safer way to connect if you're away from home.
You can change ISP's but what for? Because you're mad? All ISPs tend to be equally unresponsive unless something threatens THEIR network plant, which can have literally millions of "you" on them. If it does they can be very helpful, but you need to fix your own stuff first. So let's stick to first-things-first and setup your NEW MODEM.
- WRITE DOWN THE MAC ADDRESS(ES) OF YOUR NEW MODEM
>>> CHANGE YOUR PASSWORD WITH YOUR ISP <<<
- Connect the NEW MODEM to your ISP & power
>>> DO NOT PLUG IN ROUTER YET <<<
- Use your phone to call or chat with your ISP
- Did you CHANGE YOUR ISP PASSWORD? N|Y
- If N, CHANGE YOUR PASSWORD WITH YOUR ISP
- If Y, provision your new modem
- This could take 30-min or more, so be patient.
Now you have a new IP from your ISP on a new modem mostly "guaranteed" not to have been infected by you or your nemesis, and for the time being to be
invisible. I have old ASUS instructions here, you'll have to look-up what doesn't match.
Let's setup your NEW ROUTER.
- WRITE DOWN THE MAC ADDRESS(ES) OF YOUR NEW LAPTOP
- WRITE DOWN THE MAC ADDRESS(ES) OF YOUR NEW ROUTER
- Plug your new router into power
>>> DO NOT CONNECT THE ROUTER TO THE MODEM <<<
- Ethernet your NEW LAPTOP to your NEW ROUTER
- LOCK DOWN THE ROUTER
- Change every default and don't hook anything up yet
- Set the router to USE WHITELIST-ON to access it (temporarily)
- on ASUS: Wireless > Wireless MAC Filter >
- do this for both bands
- Enable MAC Filter [x] YES
- Enter the MAC ADDRESSES your have been writing down into the Whitelist
- Is your CELL PHONE whitelisted?
- Is your NEW COMPUTER whitelisted?
- Set your router to reboot every night
- on ASUS: Administration > System > Enable Reboot Scheduler [x] YES
this generally improves performance & enhances security
- Make it invisible to the internet
- on ASUS: Firewall > General > Respond ICMP Echo (ping) Request from WAN [x] NO
- this enhances that "invisibility"
- AFTER every possible setting you can customize is done, then...
- CONNECT ROUTER TO MODEM
>>> DO NOT CONNECT ROUTER TO LAN/BUILDING LAN <<<
- Setup the WLAN (Wi-Fi LAN) part of your router
- Setup a throw-away Guest Network with ZERO LOCAL ACCESS
- You will use this for gaming
>>> DO NOT connect your IoT things (TV, security, etc) to this <<<
- This ASSUMES a bad actor will again go after you
- Turn this network ON to play, then turn it OFF when finished
- E-V-E-R-Y ... T-I-M-E
Fwiw, my old ASUS RT-87 allows me to setup four (4) guest networks: two on 2.4 GHz and two on 5 GHz. I'm guessing this is common across most of their line. Just tossing that out there.
If you have a hardwired or wired-building LAN, DO NOT connect to it yet. You still don't know how bad this is. You could have compromised equipment you have not considered like a NAS, hub, switch, or printer so let's be safe for awhile.
Now that you have a known-safe means of accessing the internet, you can disconnect from your cellphone hotspot and turn that hotspot off releasing your phone. You can also setup your NEW LAPTOP for Wi-Fi access to your NEW ROUTER and unplug the ethernet.
OK, now that you have hope, let's preserve your sanity so you can tend to all of the other things you'll need to do.
- SmartTV? Security cameras? Alarms?
- Start with what will give you the best sanity breaks excluding gaming
>>> NO GAMING FOR NOW <<< I think this is self-explanatory for the time-being
- Take each service and each device for that service one-at-a-time
- CHANGE THE PASSWORD FOR THAT SERVICE, e.g., TV, alarms
- WRITE DOWN THE MAC ADDRESS FOR EACH DEVICE IN THAT SERVICE
- Do a full factory reset of each device in that service
- Enter the MAC address on the router whitelist
- Connect that first "sanity saver" device to the router
- Repeat for the next service
Using a whitelist on your router is a major PITA, but for right now it will save your six from mistakenly allowing an infected device onto your LAN/WLAN. After you get everything fixed up, you can disable the MAC Filter (whitelist). Also, entering wired item MAC into the whitelist may be useless as they often only attach to Wi-Fi. However, if you are checking to see who is on your network, having those MACs handy can be a real life saver.
Now that you have a working LAN/WLAN, and your sanity-savers in-place, you can begin the tedious work of...
-
NOTIFYING FINANCIAL INSTITUTIONS
-
REPLACING CREDIT CARDS moved up list 30APR20
- CHANGING ALL OF YOUR ONLINE PASSWORDS
- etc., etc.
Then you can start the even more tedious tasks of cleaning/wiping/factory-resetting/replacing the various pieces or parts of equipment AND TOYS in your network.IF you get ahead of this guy and get your passwords, financials, and credits changed before he starts sucking up your money, you may avoid having your identity actually stolen and whacked.
Make no mistake, IT IS A RACE.
Sky
*I hedge secure here because nothing in this world is ever 100% secure 100% of the time. Security has been and always will be a matter of keeping what needs to be secret long enough so it no longer needs to be secret, even if that means changing it mid-stream. Steve Gibson (GRC) has some pretty good primers on https://www.grc.com/intro.htm