Someone trying to hack into my computer.

Discussion in 'Malware Help (A Specialist Will Reply)' started by fedorvod, May 10, 2008.

  1. fedorvod

    fedorvod Private E-2

    My Norton Firewall has been giving me popups of intrusion attempts. I've been getting these periodically the last few months, but about a week ago I got alot more attempts than usual:
    http://i188.photobucket.com/albums/z86/ballbusting101/hack.jpg

    Those 3,609 attempts were in under one hour. I turned my DSL modem off,

    then back on and the attacks stopped. I believe it is because I was

    issued a new IP when I turned my modem off and on. So I did a search with

    Norton Antivirus and it found nothing. I was still getting attacks, but

    now I get a different message from my Firewall. The message looks like

    this:
    http://i188.photobucket.com/albums/z86/ballbusting101/hack1.jpg

    I get that popup over and over, so often that it is such a paid to click

    block each time that I leave the popup open. One thing I notice is that

    often the first 8 numbers are the same, but the numbers after the ":"

    change. Also, now that I am getting that popup, the "Recent intusion

    attempts" (as seem in the first picture) shows zero intrusion attempts.

    Anyway, I ran a virus search with Norton AntiVirus and it found nothing. I searched again with some other programs: Spybot Search and Destroy, Windows Defender and Windows Live Safety Center. They all found nothing. Then I searched with a program called Avast Antivirus and it found 3 Trojans. It removed them, but the attacks are still continuing. I re-ran the search and it found nothing. I tried yet another program, Ashampoo AntiSpyWare 2 and it also found no problems on my computer. It is clean according to all these programs, but I am still getting attacks. Anyone have any idea what the problem is?

    My computer is a Compaq with Windows XP SP2.
     
    Last edited by a moderator: May 10, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This IP address is probably your ISP. I assume you use SBC. That address maps to adsl-75-63-51-16.dsl.emhril.sbcglobal.net



    Now it appears you have possibly changed ISPs. This one maps to S0106000f66877ad9.cn.shawcable.net

    It is quite normal for many ISPs to be testing you connection. You can just block it and also do the same and ignore the logs as long as they are from your ISP. You can also call your ISP and ask them what they are doing/why it is necessary to ease your mind.
     
  3. fedorvod

    fedorvod Private E-2

    I do use SBC, but I've been using SBC for the past 3 years, I haven't changed ISPs.
     
  4. fedorvod

    fedorvod Private E-2

    Also, I went to shawcable.net and it redirected me to shawcable.ca, a Canadian company. I am from America.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but that does not change the fact that the first address you list is from them and that is what your firewall was flagging. They probably added some new diagnostic feature.

    As far as shawcable, they are a valid company too. Not sure why this would show up unless SBC is somehow getting bandwidth thru them.
     
  6. fedorvod

    fedorvod Private E-2

    Thank you for your help thus far. I didn't know I could look up the loction of the IPs trying to connect to my computer.

    I don't know about SBC getting bandwith though other places. I looked up the location of the IPs attacking me today:

    72.241.176.71 US UNITED STATES OHIO TOLEDO BUCKEYE CABLEVISION INC
    76.222.58.60 US UNITED STATES NEW YORK NEW YORK AT&T INTERNET SERVICES
    60.172.219.1 CN CHINA BEIJING BEIJING CHINANET ANHUI PROVINCE NETWORK
    60.172.219.2 CN CHINA BEIJING BEIJING CHINANET ANHUI PROVINCE NETWORK
    220.168.44.233 CN CHINA HUNAN CHANGSHA CHINANET-HN CHANGSHA NODE NETWORK
    24.64.167.223 CA CANADA ALBERTA CALGARY SHAW COMMUNICATIONS INC
    24.64.139.0 CA CANADA ALBERTA CALGARY SHAW COMMUNICATIONS INC
    24.64.152.66 CA CANADA ALBERTA CALGARY SHAW COMMUNICATIONS INC
    76.176.120.136 US UNITED STATES CALIFORNIA SAN DIEGO ROAD RUNNER HOLDCO LLC
    24.64.210.254 CA CANADA BRITISH COLUMBIA VICTORIA SHAW COMMUNICATIONS INC

    China and Canada???

    One thing I deglected to mention in my earlier posts is that every time Windows starts, I got a message from Ashampoo AntiSpyWare 2 that "The Windows hostfile was changed." It says that if it was unauthorized it may be a sign of an infection. It gives me an option to allow the change or undue it, but everytime I click undue, the message just repeats and repeats, leaving me no choice but to keep the popup open, or allow the change, just to close it. And again, according to all 4 or 5 antivirus and antimalware programs I've scanned my computer with, it is clean.:confused
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's find out what your PC is running and what your malware status is. Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide


    I have a feeling that you may be running a P2P or torrent downloading program and people are connecting to you for downloads.
     
  8. fedorvod

    fedorvod Private E-2

    OK, I've followed all the steps except one - ComboFix. Before the program ran, I got a message that said 1 in 100 computers don't make it though the scan. I assumed that it ment 1 in 100 computers crash while using the program and I chickened out. I attached the logs requested.

    After one of the programs rebooted the computer, the Windows Defender appeared on the Windows tray by the clock. That normally doesn't happen.
     

    Attached Files:

  9. fedorvod

    fedorvod Private E-2

    I am still getting the popup from my firewall that people are trying to access my computer.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No that is not what it means. It means on 1 in 100 computers ComboFix just will not run for some unknown reason. Please run it it, it often finds things that other scans will not. Attach the log.

    You already had Windows Defender installed. It is normal for it to appear in the tray. Perhaps you were previously disabling startups with MSconfig which you should not do as mentioned in step 1 of the READ ME.

    You need to cleanup your Desktop ASAP. All of that junk does not belong there and is an invitiation for malware to hide. Also it can slow your PC down. Move everything you really need to a more permanent storage location and delete things you don't need. Try to keep just links/shortcuts to things you use all the time on your Desktop.


    I still don't believe you are having major malware issues. I think this may be just a case where you have used P2P and torrent type sharing programs and people have your address now and are trying to link to you for downloading. You should just be telling your software firewall to block these and always do the same and to do it quitely with telling you. This is normal firewall behavior. Do you use a router and does it also have a hardware firewall.


    After running ComboFix and attaching your log, please continue on with the below.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')

    After clicking Fix, exit HJT.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. fedorvod

    fedorvod Private E-2

    All steps done. In analyse.exe, I could not find O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" I checked twice and did not see it. Other than that I had no problems with the directions.

    The file fixme.reg was successful. Can I delete it from my desktop now?

    The bad news - I am still getting the messages from my firewall. I had my modem turned off during the ComboFix scan. Later when I turned it back on to download the current version of Sun Java, I got the warning from my firewall before I could even get to the download page. I've gotten the warning 4 or 5 times while writing this responce, too.
     

    Attached Files:

  12. fedorvod

    fedorvod Private E-2

    I forgot to answer this question; Do you use a router and does it also have a hardware firewall.

    I don't have a router, I have a DSL modem provided by AT&T/SBC. I don't know if it has a hardware firewall.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not bad news. This is normal firewall behavior. You just need to set your firewall to block these incoming reports silently. This happens on all PCs and is the purpose of having a firewall.

    If you install a router which goes inbetween your DSL Modem and your PC, it would also possibly block some issues before they ever get to your PC.

    Your logs are clean. These are not malware issues. It is just normal behavior that happens.
     
  14. fedorvod

    fedorvod Private E-2

    OK, thanks for your time with this. I feel more comfortable about the popups now knowing it's not due to a trojan/virus.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:

    1. You can uninstall SUPERAntispyware now
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  16. fedorvod

    fedorvod Private E-2

    An update - Two days ago my Norton AntiVirus subscription ran out, so I uninstalled it and I am now running Avast! Antivirus instead. I am still using Norton Firewall. Since the uninstallation of Norton Antivirus, I have not had a single instusion attempt. It hadn't stop until then.

    Don't know if this is a coincidence or what, but thought I'd give the update. It's alot nicer operating my PC with the annoying firewall popups:)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is highly recommended that you totally uninstall ALL of Norton. You probably have a load of excess baggage from them running just to keep their firewall. You should really use another firewall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds